Ë
    A²XjÜ6  ã                   óð   — d Z ddlmZ ddlZddlmZ ddlmZ ddlmZ ddl	m
Z
 	 ddlZ ej                  e«      Z G d	„ d
ej"                  «      Z	 	 dd„Z G d„ d«      Zy# e$ rZ ed«      e‚dZ[ww xY w)zAuthorization support for gRPC.é    )Úabsolute_importN)Ú
exceptions)Ú_mtls_helper)Úmtls)Úservice_accountzWgRPC is not installed from please install the grpcio package to use the gRPC transport.c                   ó0   ‡ — e Zd ZdZdˆ fd„	Zd„ Zd„ Zˆ xZS )ÚAuthMetadataPluginan  A `gRPC AuthMetadataPlugin`_ that inserts the credentials into each
    request.

    .. _gRPC AuthMetadataPlugin:
        http://www.grpc.io/grpc/python/grpc.html#grpc.AuthMetadataPlugin

    Args:
        credentials (google.auth.credentials.Credentials): The credentials to
            add to requests.
        request (google.auth.transport.Request): A HTTP transport request
            object used to refresh credentials as needed.
        default_host (Optional[str]): A host like "pubsub.googleapis.com".
            This is used when a self-signed JWT is created from service
            account credentials.
    c                 óT   •— t         t        | �  «        || _        || _        || _        y ©N)Úsuperr	   Ú__init__Ú_credentialsÚ_requestÚ_default_host)ÚselfÚcredentialsÚrequestÚdefault_hostÚ	__class__s       €ú`/var/www/html/content_generation/venv/lib/python3.12/site-packages/google/auth/transport/grpc.pyr   zAuthMetadataPlugin.__init__5   s*   ø€ ô 	Ô  $Ñ0Ô2Ø'ˆÔØˆŒØ)ˆÕó    c                 ó|  — i }t        | j                  t        j                  «      rB| j                  j	                  | j
                  rdj                  | j
                  «      nd«       | j                  j                  | j                  |j                  |j                  |«       t        |j                  «       «      S )z½Gets the authorization headers for a request.

        Returns:
            Sequence[Tuple[str, str]]: A list of request headers (key, value)
                to add to the request.
        zhttps://{}/N)Ú
isinstancer   r   ÚCredentialsÚ_create_self_signed_jwtr   ÚformatÚbefore_requestr   Úmethod_nameÚservice_urlÚlistÚitems)r   ÚcontextÚheaderss      r   Ú_get_authorization_headersz-AuthMetadataPlugin._get_authorization_headers>   s–   € ð ˆô �d×'Ñ'¬×)DÑ)DÔEØ×Ñ×5Ñ5Ø<@×<NÒ<N�×$Ñ$ T×%7Ñ%7Ô8ÐTXôð 	×Ñ×(Ñ(Ø�M‰M˜7×.Ñ.°×0CÑ0CÀWô	
ô �G—M‘M“OÓ$Ð$r   c                 ó4   —  || j                  |«      d«       y)a   Passes authorization metadata into the given callback.

        Args:
            context (grpc.AuthMetadataContext): The RPC context.
            callback (grpc.AuthMetadataPluginCallback): The callback that will
                be invoked to pass in the authorization metadata.
        N)r$   )r   r"   Úcallbacks      r   Ú__call__zAuthMetadataPlugin.__call__V   s   € ñ 	�×0Ñ0°Ó9¸4Õ@r   r   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r$   r'   Ú__classcell__)r   s   @r   r	   r	   $   s   ø„ ñõ *ò%ö0Ar   r	   c                 ó¢  — t        | |«      }t        j                  |«      }|r|rt        j                  d«      ‚|sgt        j                  «       }|r$|r" |«       \  }	}
t        j                  |	|
¬«      }n-|rt        «       }|j                  }nt        j                  «       }t        j                  ||«      }t        j                  ||fi |¤ŽS )au  Creates a secure authorized gRPC channel.

    This creates a channel with SSL and :class:`AuthMetadataPlugin`. This
    channel can be used to create a stub that can make authorized requests.
    Users can configure client certificate or rely on device certificates to
    establish a mutual TLS channel, if the `GOOGLE_API_USE_CLIENT_CERTIFICATE`
    variable is explicitly set to `true`.

    Example::

        import google.auth
        import google.auth.transport.grpc
        import google.auth.transport.requests
        from google.cloud.speech.v1 import cloud_speech_pb2

        # Get credentials.
        credentials, _ = google.auth.default()

        # Get an HTTP request function to refresh credentials.
        request = google.auth.transport.requests.Request()

        # Create a channel.
        channel = google.auth.transport.grpc.secure_authorized_channel(
            credentials, regular_endpoint, request,
            ssl_credentials=grpc.ssl_channel_credentials())

        # Use the channel to create a stub.
        cloud_speech.create_Speech_stub(channel)

    Usage:

    There are actually a couple of options to create a channel, depending on if
    you want to create a regular or mutual TLS channel.

    First let's list the endpoints (regular vs mutual TLS) to choose from::

        regular_endpoint = 'speech.googleapis.com:443'
        mtls_endpoint = 'speech.mtls.googleapis.com:443'

    Option 1: create a regular (non-mutual) TLS channel by explicitly setting
    the ssl_credentials::

        regular_ssl_credentials = grpc.ssl_channel_credentials()

        channel = google.auth.transport.grpc.secure_authorized_channel(
            credentials, request, regular_endpoint,
            ssl_credentials=regular_ssl_credentials)

    Option 2: create a mutual TLS channel by calling a callback which returns
    the client side certificate and the key (Note that
    `GOOGLE_API_USE_CLIENT_CERTIFICATE` environment variable must be explicitly
    set to `true`)::

        def my_client_cert_callback():
            code_to_load_client_cert_and_key()
            if loaded:
                return (pem_cert_bytes, pem_key_bytes)
            raise MyClientCertFailureException()

        try:
            channel = google.auth.transport.grpc.secure_authorized_channel(
                credentials, request, mtls_endpoint,
                client_cert_callback=my_client_cert_callback)
        except MyClientCertFailureException:
            # handle the exception

    Option 3: use application default SSL credentials. It searches and uses
    the command in a context aware metadata file, which is available on devices
    with endpoint verification support (Note that
    `GOOGLE_API_USE_CLIENT_CERTIFICATE` environment variable must be explicitly
    set to `true`).
    See https://cloud.google.com/endpoint-verification/docs/overview::

        try:
            default_ssl_credentials = SslCredentials()
        except:
            # Exception can be raised if the context aware metadata is malformed.
            # See :class:`SslCredentials` for the possible exceptions.

        # Choose the endpoint based on the SSL credentials type.
        if default_ssl_credentials.is_mtls:
            endpoint_to_use = mtls_endpoint
        else:
            endpoint_to_use = regular_endpoint
        channel = google.auth.transport.grpc.secure_authorized_channel(
            credentials, request, endpoint_to_use,
            ssl_credentials=default_ssl_credentials)

    Option 4: not setting ssl_credentials and client_cert_callback. For devices
    without endpoint verification support or `GOOGLE_API_USE_CLIENT_CERTIFICATE`
    environment variable is not `true`, a regular TLS channel is created;
    otherwise, a mutual TLS channel is created, however, the call should be
    wrapped in a try/except block in case of malformed context aware metadata.

    The following code uses regular_endpoint, it works the same no matter the
    created channle is regular or mutual TLS. Regular endpoint ignores client
    certificate and key::

        channel = google.auth.transport.grpc.secure_authorized_channel(
            credentials, request, regular_endpoint)

    The following code uses mtls_endpoint, if the created channle is regular,
    and API mtls_endpoint is confgured to require client SSL credentials, API
    calls using this channel will be rejected::

        channel = google.auth.transport.grpc.secure_authorized_channel(
            credentials, request, mtls_endpoint)

    Args:
        credentials (google.auth.credentials.Credentials): The credentials to
            add to requests.
        request (google.auth.transport.Request): A HTTP transport request
            object used to refresh credentials as needed. Even though gRPC
            is a separate transport, there's no way to refresh the credentials
            without using a standard http transport.
        target (str): The host and port of the service.
        ssl_credentials (grpc.ChannelCredentials): Optional SSL channel
            credentials. This can be used to specify different certificates.
            This argument is mutually exclusive with client_cert_callback;
            providing both will raise an exception.
            If ssl_credentials and client_cert_callback are None, application
            default SSL credentials are used if `GOOGLE_API_USE_CLIENT_CERTIFICATE`
            environment variable is explicitly set to `true`, otherwise one way TLS
            SSL credentials are used.
        client_cert_callback (Callable[[], (bytes, bytes)]): Optional
            callback function to obtain client certicate and key for mutual TLS
            connection. This argument is mutually exclusive with
            ssl_credentials; providing both will raise an exception.
            This argument does nothing unless `GOOGLE_API_USE_CLIENT_CERTIFICATE`
            environment variable is explicitly set to `true`.
        kwargs: Additional arguments to pass to :func:`grpc.secure_channel`.

    Returns:
        grpc.Channel: The created gRPC channel.

    Raises:
        google.auth.exceptions.MutualTLSChannelError: If mutual TLS channel
            creation failed for any reason.
    zUReceived both ssl_credentials and client_cert_callback; these are mutually exclusive.©Úcertificate_chainÚprivate_key)r	   ÚgrpcÚmetadata_call_credentialsr   ÚMalformedErrorr   Úcheck_use_client_certÚssl_channel_credentialsÚSslCredentialsÚssl_credentialsÚcomposite_channel_credentialsÚsecure_channel)r   r   Útargetr7   Úclient_cert_callbackÚkwargsÚmetadata_pluginÚgoogle_auth_credentialsÚuse_client_certÚcertÚkeyÚadc_ssl_credentilsÚcomposite_credentialss                r   Úsecure_authorized_channelrD   a   s×   € ôh )¨°gÓ>€Oô #×<Ñ<¸_ÓMÐáÑ/Ü×'Ñ'ð,ó
ð 	
ñ Ü&×<Ñ<Ó>ˆÙÑ3á,Ó.‰IˆD�#Ü"×:Ñ:Ø"&°Cô‰Oñ ä!/Ó!1ÐØ0×@Ñ@‰Oä"×:Ñ:Ó<ˆOô !×>Ñ>ØÐ0óÐô ×Ñ˜vÐ'<ÑGÀÑGÐGr   c                   ó6   — e Zd ZdZd„ Zed„ «       Zed„ «       Zy)r6   a*  Class for application default SSL credentials.

    Mutual TLS (mTLS) is enabled if either:

    1. The `GOOGLE_API_USE_CLIENT_CERTIFICATE` environment variable is explicitly
       set to `"true"`.
    2. The `GOOGLE_API_USE_CLIENT_CERTIFICATE` environment variable is unset or empty,
       but a valid workload certificate configuration is found (e.g., via the
       `GOOGLE_API_CERTIFICATE_CONFIG` environment variable or the default gcloud config path).

    See https://google.aip.dev/auth/4114 for client certificate discovery details.

    If client certificate usage is enabled, then for devices with endpoint
    verification support, a device certificate will be automatically loaded and
    mutual TLS will be established.
    See https://cloud.google.com/endpoint-verification/docs/overview.
    c                 ór   — t        j                  «       }|sd| _        y t        j                  «       | _        y )NF)r   r4   Ú_is_mtlsr   Úhas_default_client_cert_source)r   r?   s     r   r   zSslCredentials.__init__+  s*   € Ü&×<Ñ<Ó>ˆÙØ!ˆD�Mä ×?Ñ?ÓAˆD�Mr   c                 ó   — | j                   re	 t        j                  «       \  }}}}|rt        j                  ||¬«      | _        n t        j                  «       | _        d| _         | j
                  S t        j                  «       | _        | j
                  S # t        j                  t        f$ r}t        j                  |«      }||‚d}~ww xY w)a  Get the created SSL channel credentials.

        For devices with endpoint verification support, if the device certificate
        loading has any problems, corresponding exceptions will be raised. For
        a device without endpoint verification support, no exceptions will be
        raised.

        Returns:
            grpc.ChannelCredentials: The created grpc channel credentials.

        Raises:
            google.auth.exceptions.MutualTLSChannelError: If mutual TLS channel
                creation failed for any reason.
        r.   FN)
rG   r   Úget_client_ssl_credentialsr1   r5   Ú_ssl_credentialsr   ÚClientCertErrorÚOSErrorÚMutualTLSChannelError)r   Úhas_certr@   rA   Ú_Ú
caught_excÚnew_excs          r   r7   zSslCredentials.ssl_credentials2  s¾   € ð  �=Š=ð.Ü)5×)PÑ)PÓ)RÑ&�˜$  QÙÜ,0×,HÑ,HØ*.¸Cô-�DÕ)ô -1×,HÑ,HÓ,J�DÔ)Ø$)�D”Mð ×$Ñ$Ð$ô %)×$@Ñ$@Ó$BˆDÔ!à×$Ñ$Ð$øô ×.Ñ.´Ð8ò .Ü$×:Ñ:¸:ÓF�Ø :Ð-ûð.ús   ŽAB ÂCÂ0CÃCc                 ó   — | j                   S )z?Indicates if the created SSL channel credentials is mutual TLS.)rG   )r   s    r   Úis_mtlszSslCredentials.is_mtlsT  s   € ð �}‰}Ðr   N)r(   r)   r*   r+   r   Úpropertyr7   rT   © r   r   r6   r6     s6   „ ñò$Bð ñ%ó ð%ðB ñó ñr   r6   )NN)r+   Ú
__future__r   ÚloggingÚgoogle.authr   Úgoogle.auth.transportr   r   Úgoogle.oauth2r   r1   ÚImportErrorrQ   Ú	getLoggerr(   Ú_LOGGERr	   rD   r6   rV   r   r   Ú<module>r_      s�   ðñ &å &ã å "Ý .Ý &Ý )ðÛð ˆ'×
Ñ
˜HÓ
%€ô:A˜×0Ñ0ô :AðB ØótH÷n?ò ?øðy ò Ù
Øaóàðûðús   ¦A" Á"A5Á'	A0Á0A5