o
    í6WjS  ã                   @   sö   d Z ddlmZ ddlmZmZmZmZ ddlZ	ddl
mZ ddlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ ddlmZ ddlZ	ddlmZ ddlmZ dZe ¡ Ze ¡ ZeG dd„ dƒƒZG dd„ dej ƒZ!G dd„ dej"ej#ƒZ$dS )zAECDSA verifier and signer that use the ``cryptography`` library.
é    )Ú	dataclass)ÚAnyÚDictÚOptionalÚUnionN)Úbackends)Úhashes)Úserialization)Úec)Úpadding)Údecode_dss_signature)Úencode_dss_signature)Ú_helpers)Úbases   -----BEGIN CERTIFICATE-----c                   @   s^   e Zd ZU dZeed< ejed< eed< e	de
ejejf fdd„ƒZe	dejfd	d
„ƒZdS )Ú_ESAttributeszÑA class that models ECDSA attributes.

    Attributes:
        rs_size (int): Size for ASN.1 r and s size.
        sha_algo (hashes.HashAlgorithm): Hash algorithm.
        algorithm (str): Algorithm name.
    Úrs_sizeÚsha_algoÚ	algorithmÚkeyc                 C   s   |   |j¡S ©N)Ú
from_curveÚcurve)Úclsr   © r   úc/home/esfera/Documents/content_generation/venv/lib/python3.10/site-packages/google/auth/crypt/es.pyÚfrom_key6   s   z_ESAttributes.from_keyr   c                 C   s,   t |tjƒr| dt ¡ dƒS | dt ¡ dƒS )Né0   ÚES384é    ÚES256)Ú
isinstancer
   Ú	SECP384R1r   ÚSHA384ÚSHA256)r   r   r   r   r   r   <   s   z_ESAttributes.from_curveN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚintÚ__annotations__r   ÚHashAlgorithmÚstrÚclassmethodr   r
   ÚEllipticCurvePublicKeyÚEllipticCurvePrivateKeyr   ÚEllipticCurver   r   r   r   r   r   (   s   
 
ÿr   c                   @   sd   e Zd ZdZdejddfdd„Ze e	j
¡dededefd	d
„ƒZedeeef dd fdd„ƒZdS )Ú
EsVerifierzëVerifies ECDSA cryptographic signatures using public keys.

    Args:
        public_key (
                cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePublicKey):
            The public key used to verify signatures.
    Ú
public_keyÚreturnNc                 C   s   || _ t |¡| _d S r   )Ú_pubkeyr   r   Ú_attributes)Úselfr1   r   r   r   Ú__init__R   s   zEsVerifier.__init__ÚmessageÚ	signaturec              	   C   s¨   t  |¡}t|ƒ| jjd krdS tj|d | jj… dd�}tj|| jjd … dd�}t||ƒ}t  |¡}z| j 	||t
 | jj¡¡ W dS  ttjjfyS   Y dS w )Né   FÚbig©Ú	byteorderT)r   Úto_bytesÚlenr4   r   r(   Ú
from_bytesr   r3   Úverifyr
   ÚECDSAr   Ú
ValueErrorÚcryptographyÚ
exceptionsÚInvalidSignature)r5   r7   r8   Ú	sig_bytesÚrÚsÚasn1_sigr   r   r   r@   V   s   


ÿzEsVerifier.verifyc                 C   sR   t  |¡}t|v rtj |t¡}| ¡ }nt 	|t¡}t
|tjƒs%tdƒ‚| |ƒS )aŠ  Construct a Verifier instance from a public key or public
        certificate string.

        Args:
            public_key (Union[str, bytes]): The public key in PEM format or the
                x509 public key certificate.

        Returns:
            google.auth.crypt.Verifier: The constructed verifier.

        Raises:
            ValueError: If the public key can't be parsed.
        z2Expected public key of type EllipticCurvePublicKey)r   r=   Ú_CERTIFICATE_MARKERrC   Úx509Úload_pem_x509_certificateÚ_BACKENDr1   r	   Úload_pem_public_keyr    r
   r-   Ú	TypeError)r   r1   Úpublic_key_dataÚcertÚpubkeyr   r   r   Úfrom_stringg   s   
ÿ
zEsVerifier.from_string)r$   r%   r&   r'   r
   r-   r6   r   Úcopy_docstringr   ÚVerifierÚbytesÚboolr@   r,   r   r+   rS   r   r   r   r   r0   I   s    
 r0   c                   @   sÜ   e Zd ZdZ	ddejdee ddfdd„Ze	defdd	„ƒZ
e	e ej¡dee fd
d„ƒƒZe ej¡dedefdd„ƒZe	ddeeef dee dd fdd„ƒZdeeef fdd„Zdeeef ddfdd„ZdS )ÚEsSignera�  Signs messages with an ECDSA private key.

    Args:
        private_key (
                cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePrivateKey):
            The private key to sign with.
        key_id (str): Optional key ID used to identify this private key. This
            can be useful to associate the private key with its associated
            public key or certificate.
    NÚprivate_keyÚkey_idr2   c                 C   s   || _ || _t |¡| _d S r   )Ú_keyÚ_key_idr   r   r4   )r5   rY   rZ   r   r   r   r6   “   s   zEsSigner.__init__c                 C   s   | j jS )zkName of the algorithm used to sign messages.
        Returns:
            str: The algorithm name.
        )r4   r   ©r5   r   r   r   r   š   s   zEsSigner.algorithmc                 C   s   | j S r   )r\   r]   r   r   r   rZ   ¢   s   zEsSigner.key_idr7   c                 C   sR   t  |¡}| j |t | jj¡¡}t|ƒ\}}|j| jj	dd�|j| jj	dd� S )Nr:   r;   )
r   r=   r[   Úsignr
   rA   r4   r   r   r   )r5   r7   Úasn1_signaturerG   rH   r   r   r   r^   §   s   
ÿzEsSigner.signr   c                 C   s:   t  |¡}tj|dtd�}t|tjƒstdƒ‚| ||d�S )al  Construct a RSASigner from a private key in PEM format.

        Args:
            key (Union[bytes, str]): Private key in PEM format.
            key_id (str): An optional key id used to identify the private key.

        Returns:
            google.auth.crypt._cryptography_rsa.RSASigner: The
            constructed signer.

        Raises:
            ValueError: If ``key`` is not ``bytes`` or ``str`` (unicode).
            UnicodeDecodeError: If ``key`` is ``bytes`` but cannot be decoded
                into a UTF-8 ``str``.
            ValueError: If ``cryptography`` "Could not deserialize key data."
        N)ÚpasswordÚbackendz4Expected private key of type EllipticCurvePrivateKey)rZ   )	r   r=   r	   Úload_pem_private_keyrM   r    r
   r.   rO   )r   r   rZ   Ú	key_bytesrY   r   r   r   rS   ²   s   
ÿzEsSigner.from_stringc                 C   s0   | j  ¡ }| jjtjjtjjt 	¡ d�|d< |S )z1Pickle helper that serializes the _key attribute.)ÚencodingÚformatÚencryption_algorithmr[   )
Ú__dict__Úcopyr[   Úprivate_bytesr	   ÚEncodingÚPEMÚPrivateFormatÚPKCS8ÚNoEncryption©r5   Ústater   r   r   Ú__getstate__Ð   s   

ýzEsSigner.__getstate__rp   c                 C   s$   t  |d d¡|d< | j |¡ dS )z3Pickle helper that deserializes the _key attribute.r[   N)r	   rb   rg   Úupdatero   r   r   r   Ú__setstate__Ú   s   zEsSigner.__setstate__r   )r$   r%   r&   r'   r
   r.   r   r+   r6   Úpropertyr   r   rT   r   ÚSignerrZ   rV   r^   r,   r   rS   r   r   rq   rs   r   r   r   r   rX   ‡   s8    ÿÿÿ
þ


ÿ
ÿÿþ
rX   )%r'   Údataclassesr   Útypingr   r   r   r   Úcryptography.exceptionsrC   Úcryptography.hazmatr   Úcryptography.hazmat.primitivesr   r	   Ú)cryptography.hazmat.primitives.asymmetricr
   r   Ú/cryptography.hazmat.primitives.asymmetric.utilsr   r   Úcryptography.x509Úgoogle.authr   Úgoogle.auth.cryptr   rJ   Údefault_backendrM   ÚPKCS1v15Ú_PADDINGr   rU   r0   ru   ÚFromServiceAccountMixinrX   r   r   r   r   Ú<module>   s*    >