§
    ÂiÂ  ã                   ób  — d Z ddlZddlmZ ddlZddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ej        ej        ej        ej        hZd	gZ eed
¦  «        r ej        ¦   «         rde	j        › �Zn
de	j        › �Zde› d�Zedz   Zedz   Zedz   Zedz   Z G d„ de
j        ¦  «        ZdS )zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_exponential_backoff)Ú_helpers)Úcredentials)Úcrypt)Ú
exceptions)Ú_mtls_helperz#https://www.googleapis.com/auth/iamÚcheck_use_client_certziamcredentials.mtls.ziamcredentials.zhttps://z!/v1/projects/-/serviceAccounts/{}z:generateAccessTokenz	:signBlobz:signJwtz:generateIdTokenc                   óp   — e Zd ZdZd„ Zd„ Zed„ ¦   «         Z ej	        e
j        ¦  «        d„ ¦   «         ZdS )ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 ó0   — || _         || _        || _        dS )aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestr   Úservice_account_emails       úY/var/www/html/jarvis.com/web/backend/venv/lib/python3.11/site-packages/google/auth/iam.pyÚ__init__zSigner.__init__J   s!   € ð   ˆŒØ'ˆÔØ&;ˆÔ#Ð#Ð#ó    c                 ó(  — t          j        |¦  «        }d}t                               t          j        | j        j        ¦  «                             | j	        ¦  «        }ddi}t          j        dt          j        |¦  «                             d¦  «        i¦  «                             d¦  «        }t!          j        ¦   «         }|D ]º}| j                             | j        |||¦  «         |                      ||||¬¦  «        }|j        t*          v rŒL|j        t,          j        k    r,t1          j        d                     |j        ¦  «        ¦  «        ‚t          j        |j                             d¦  «        ¦  «        c S t1          j        d¦  «        ‚)	z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {}z#exhausted signBlob endpoint retries)r   Úto_bytesÚ_IAM_SIGN_ENDPOINTÚreplacer   ÚDEFAULT_UNIVERSE_DOMAINr   Úuniverse_domainÚformatr   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder   ÚExponentialBackoffÚbefore_requestr   ÚstatusÚIAM_RETRY_CODESÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)	r   Úmessager   r   r   r   ÚretriesÚ_Úresponses	            r   Ú_make_signing_requestzSigner._make_signing_request^   ss  € åÔ# GÑ,Ô,ˆàˆÝ ×(Ò(ÝÔ/°Ô1BÔ1Rñ
ô 
ç
Š&�Ô,Ñ
-Ô
-ð 	ð "Ð#5Ð6ˆÝŒzØ�Ô(¨Ñ1Ô1×8Ò8¸ÑAÔAÐBñ
ô 
ç
Š&�‰/Œ/ð 	õ 'Ô9Ñ;Ô;ˆØð 	=ð 	=ˆAØÔ×,Ò,¨T¬]¸FÀCÈÑQÔQÐQà—}’}¨°VÀ$ÐPW�}ÑXÔXˆHàŒ¥/Ð1Ð1ØàŒ¥+¤.Ò0Ð0Ý Ô/Ø<×CÒCÀHÄMÑRÔRñô ð õ ”:˜hœm×2Ò2°7Ñ;Ô;Ñ<Ô<Ð<Ð<Ð<ÝÔ'Ð(MÑNÔNÐNr   c                 ó   — dS )zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        N© )r   s    r   Úkey_idzSigner.key_id|   s	   € ð ˆtr   c                 ó`   — |                       |¦  «        }t          j        |d         ¦  «        S )NÚ
signedBlob)r6   r%   Ú	b64decode)r   r2   r5   s      r   ÚsignzSigner.sign†   s+   € à×-Ò-¨gÑ6Ô6ˆÝÔ ¨Ô 6Ñ7Ô7Ð7r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r6   Úpropertyr9   r   Úcopy_docstringr   r   r=   r8   r   r   r   r   ?   s…   € € € € € ðð ð<ð <ð <ð(Oð Oð Oð< ðð ñ „Xðð €XÔ˜Uœ\Ñ*Ô*ð8ð 8ñ +Ô*ð8ð 8ð 8r   r   )rA   r%   Úhttp.clientÚclientr-   r#   Úgoogle.authr   r   r   r   r   Úgoogle.auth.transportr   ÚINTERNAL_SERVER_ERRORÚBAD_GATEWAYÚSERVICE_UNAVAILABLEÚGATEWAY_TIMEOUTr,   Ú
_IAM_SCOPEÚhasattrr	   r    Ú_IAM_DOMAINÚ_IAM_BASE_URLÚ_IAM_ENDPOINTr   Ú_IAM_SIGNJWT_ENDPOINTÚ_IAM_IDTOKEN_ENDPOINTr   r8   r   r   ú<module>rS      sŸ  ððð ð €€€Ø !Ð !Ð !Ð !Ð !Ð !Ø €€€à ,Ð ,Ð ,Ð ,Ð ,Ð ,Ø  Ð  Ð  Ð  Ð  Ð  Ø #Ð #Ð #Ð #Ð #Ð #Ø Ð Ð Ð Ð Ð Ø "Ð "Ð "Ð "Ð "Ð "Ø .Ð .Ð .Ð .Ð .Ð .ð Ô%ØÔØÔ#ØÔð	€ð 4Ð4€
ð €GˆLÐ1Ñ2Ô2ðJà*ˆÔ*Ñ,Ô,ðJð
 O¨Ô)LÐNÐN€K€KàI KÔ$GÐIÐI€Kð L˜;ÐKÐKÐK€ð Ð 6Ñ6€Ø" [Ñ0Ð Ø%¨
Ñ2Ð Ø%Ð(:Ñ:Ð ðJ8ð J8ð J8ð J8ð J8ˆUŒ\ñ J8ô J8ð J8ð J8ð J8r   