§
    Âi¬k  ã                   óF  — d Z ddlZddlZddlmZ ddlmZ ddlZddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ ddlmZ dZdZdZdZdZdZdZej        dfd„Z G d„ dej        ej        ej        ej        ¦  «        Z G d„ dej        ¦  «        Z g fd„Z!dS )aÇ  Google Cloud Impersonated credentials.

This module provides authentication for applications where local credentials
impersonates a remote service account using `IAM Credentials API`_.

This class can be used to impersonate a service account as long as the original
Credential object has the "Service Account Token Creator" role on the target
service account.

    .. _IAM Credentials API:
        https://cloud.google.com/iam/credentials/reference/rest/
é    N)Údatetime)Ú_exponential_backoff)Ú_helpers©Úcredentials)Ú
exceptions)Úiam)Újwt)Úmetrics)Ú_clientz*Unable to acquire impersonated credentialsi  z#https://oauth2.googleapis.com/tokenzKhttps://iamcredentials.{}/v1/projects/-/serviceAccounts/{}/allowedLocationsÚauthorized_userÚservice_accountÚ external_account_authorized_userc                 óÀ  — |p<t           j                             t          j        |¦  «                             |¦  «        }t          j        |¦  «                             d¦  «        } | |d||¬¦  «        }t          |j
        d¦  «        r|j
                             d¦  «        n|j
        }|j        t          j        k    rt          j        t"          |¦  «        ‚	 t          j        |¦  «        }	|	d         }
t'          j        |	d         d¦  «        }|
|fS # t*          t,          f$ r5}t          j        d                     t"          ¦  «        |¦  «        }||‚d	}~ww xY w)
aÅ  Makes a request to the Google Cloud IAM service for an access token.
    Args:
        request (Request): The Request object to use.
        principal (str): The principal to request an access token for.
        headers (Mapping[str, str]): Map of headers to transmit.
        body (Mapping[str, str]): JSON Payload body for the iamcredentials
            API call.
        iam_endpoint_override (Optiona[str]): The full IAM endpoint override
            with the target_principal embedded. This is useful when supporting
            impersonation with regional endpoints.

    Raises:
        google.auth.exceptions.TransportError: Raised if there is an underlying
            HTTP connection error
        google.auth.exceptions.RefreshError: Raised if the impersonated
            credentials are not available.  Common reasons are
            `iamcredentials.googleapis.com` is not enabled or the
            `Service Account Token Creator` is not assigned
    úutf-8ÚPOST©ÚurlÚmethodÚheadersÚbodyÚdecodeÚaccessTokenÚ
expireTimez%Y-%m-%dT%H:%M:%SZz6{}: No access token or invalid expiration in response.N)r	   Ú_IAM_ENDPOINTÚreplacer   ÚDEFAULT_UNIVERSE_DOMAINÚformatÚjsonÚdumpsÚencodeÚhasattrÚdatar   ÚstatusÚhttp_clientÚOKr   ÚRefreshErrorÚ_REFRESH_ERRORÚloadsr   ÚstrptimeÚKeyErrorÚ
ValueError)ÚrequestÚ	principalr   r   Úuniverse_domainÚiam_endpoint_overrideÚiam_endpointÚresponseÚresponse_bodyÚtoken_responseÚtokenÚexpiryÚ
caught_excÚnew_excs                 ún/var/www/html/jarvis.com/web/backend/venv/lib/python3.11/site-packages/google/auth/impersonated_credentials.pyÚ_make_iam_token_requestr:   <   sf  € ð6 )ð ­CÔ,=×,EÒ,EÝÔ+¨_ñ-ô -ç‚fˆYÑÔð õ Œ:�dÑÔ×"Ò" 7Ñ+Ô+€Dàˆw˜<°ÀÈdÐSÑSÔS€Hõ
 �8”= (Ñ+Ô+ð	ˆŒ×Ò˜WÑ%Ô%Ð%àŒ]ð ð „�+œ.Ò(Ð(ÝÔ%¥n°mÑDÔDÐDð&Ýœ MÑ2Ô2ˆØ˜}Ô-ˆÝÔ" >°,Ô#?ÐAUÑVÔVˆà�fˆ}Ðøå•jÐ!ð &ð &ð &ÝÔ)ØD×KÒKÝñô ð ñ	
ô 
ˆð ˜:Ð%øøøøð&øøøs   Ã:D ÄEÄ(0EÅEc                   ó°  ‡ — e Zd ZdZddedddfˆ fd„	Zd„ Zd„ Zd„ Zd„ Z	e
d„ ¦   «         Ze
d	„ ¦   «         Ze
d
„ ¦   «         Ze
d„ ¦   «         Z ej        ej        ¦  «        d„ ¦   «         Zd„ Z ej        ej        ¦  «        d„ ¦   «         Z ej        ej        ¦  «        d„ ¦   «         Z ej        ej        ¦  «        dd„¦   «         Zedd„¦   «         Zˆ xZS )ÚCredentialsar
  This module defines impersonated credentials which are essentially
    impersonated identities.

    Impersonated Credentials allows credentials issued to a user or
    service account to impersonate another. The target service account must
    grant the originating credential principal the
    `Service Account Token Creator`_ IAM role:

    For more information about Token Creator IAM role and
    IAMCredentials API, see
    `Creating Short-Lived Service Account Credentials`_.

    .. _Service Account Token Creator:
        https://cloud.google.com/iam/docs/service-accounts#the_service_account_token_creator_role

    .. _Creating Short-Lived Service Account Credentials:
        https://cloud.google.com/iam/docs/creating-short-lived-service-account-credentials

    Usage:

    First grant source_credentials the `Service Account Token Creator`
    role on the target account to impersonate.   In this example, the
    service account represented by svc_account.json has the
    token creator role on
    `impersonated-account@_project_.iam.gserviceaccount.com`.

    Enable the IAMCredentials API on the source project:
    `gcloud services enable iamcredentials.googleapis.com`.

    Initialize a source credential which does not have access to
    list bucket::

        from google.oauth2 import service_account

        target_scopes = [
            'https://www.googleapis.com/auth/devstorage.read_only']

        source_credentials = (
            service_account.Credentials.from_service_account_file(
                '/path/to/svc_account.json',
                scopes=target_scopes))

    Now use the source credentials to acquire credentials to impersonate
    another service account::

        from google.auth import impersonated_credentials

        target_credentials = impersonated_credentials.Credentials(
          source_credentials=source_credentials,
          target_principal='impersonated-account@_project_.iam.gserviceaccount.com',
          target_scopes = target_scopes,
          lifetime=500)

    Resource access is granted::

        client = storage.Client(credentials=target_credentials)
        buckets = client.list_buckets(project='your_project')
        for bucket in buckets:
          print(bucket.name)

    **IMPORTANT**:
    This class does not validate the credential configuration. A security
    risk occurs when a credential configuration configured with malicious urls
    is used.
    When the credential configuration is accepted from an
    untrusted source, you should validate it before using.
    Refer https://cloud.google.com/docs/authentication/external/externally-sourced-credentials for more details.
    Nc
                 óp  •— t          t          | ¦  «                             ¦   «          t          j        |¦  «        | _        t          | j        t          j        ¦  «        rd| j                             t          j
        ¦  «        | _        t          | j        d¦  «        r&| j        j        r| j                             d¦  «         |j        | _        || _        || _        || _        || _        |pt(          | _        d| _        t/          j        ¦   «         | _        || _        || _        d| _        |	| _        dS )ap  
        Args:
            source_credentials (google.auth.Credentials): The source credential
                used as to acquire the impersonated credentials.
            target_principal (str): The service account to impersonate.
            target_scopes (Sequence[str]): Scopes to request during the
                authorization grant.
            delegates (Sequence[str]): The chained list of delegates required
                to grant the final access_token.  If set, the sequence of
                identities must have "Service Account Token Creator" capability
                granted to the prceeding identity.  For example, if set to
                [serviceAccountB, serviceAccountC], the source_credential
                must have the Token Creator role on serviceAccountB.
                serviceAccountB must have the Token Creator on
                serviceAccountC.
                Finally, C must have Token Creator on target_principal.
                If left unset, source_credential must have that role on
                target_principal.
            lifetime (int): Number of seconds the delegated credential should
                be valid for (upto 3600).
            quota_project_id (Optional[str]): The project ID used for quota and billing.
                This project may be different from the project used to
                create the credentials.
            iam_endpoint_override (Optional[str]): The full IAM endpoint override
                with the target_principal embedded. This is useful when supporting
                impersonation with regional endpoints.
            subject (Optional[str]): sub field of a JWT. This field should only be set
                if you wish to impersonate as a user. This feature is useful when
                using domain wide delegation.
            trust_boundary (Mapping[str,str]): A credential trust boundary.
        Ú_create_self_signed_jwtN)Úsuperr<   Ú__init__ÚcopyÚ_source_credentialsÚ
isinstancer   ÚScopedÚwith_scopesr	   Ú
_IAM_SCOPEr"   Ú_always_use_jwt_accessr>   r/   Ú_universe_domainÚ_target_principalÚ_target_scopesÚ
_delegatesÚ_subjectÚ_DEFAULT_TOKEN_LIFETIME_SECSÚ	_lifetimer5   r   Úutcnowr6   Ú_quota_project_idÚ_iam_endpoint_overrideÚ_cred_file_pathÚ_trust_boundary)ÚselfÚsource_credentialsÚtarget_principalÚtarget_scopesÚ	delegatesÚsubjectÚlifetimeÚquota_project_idr0   Útrust_boundaryÚ	__class__s             €r9   r@   zCredentials.__init__Å   s#  ø€ õX 	�k˜4Ñ Ô ×)Ò)Ñ+Ô+Ð+å#'¤9Ð-?Ñ#@Ô#@ˆÔ õ �dÔ.µÔ0BÑCÔCð 
	GØ'+Ô'?×'KÒ'KÝ”ñ(ô (ˆDÔ$õ ˜Ô0Ð2KÑLÔLðGàÔ,ÔCðGð Ô(×@Ò@ÀÑFÔFÐFà 2Ô BˆÔØ!1ˆÔØ+ˆÔØ#ˆŒØˆŒØ!ÐAÕ%AˆŒØˆŒ
Ý”oÑ'Ô'ˆŒØ!1ˆÔØ&;ˆÔ#Ø#ˆÔØ-ˆÔÐÐó    c                 ó   — t           j        S ©N)r   ÚCRED_TYPE_SA_IMPERSONATE©rT   s    r9   Ú_metric_header_for_usagez$Credentials._metric_header_for_usage  s   € ÝÔ/Ð/r^   c                 óª  — | j         j        t          j        j        k    s| j         j        t          j        j        k    r| j                              |¦  «         | j        | j        t          | j
        ¦  «        dz   dœ}ddt          j        t          j        ¦   «         i}| j                              |¦  «         | j        râ| j        t          j        k    rt%          j        d¦  «        ‚t)          j        ¦   «         }| j        t)          j        | j        pd¦  «        | j        t0          t)          j        |¦  «        t)          j        |¦  «        t4          z   dœ}t7          || j        ||| j        ¬¦  «        }t9          j        |t0          |¦  «        \  | _        | _        }d	S tA          || j        ||| j        | j!        ¬
¦  «        \  | _        | _        d	S )zòUpdates credentials with a new access_token representing
        the impersonated account.

        Args:
            request (google.auth.transport.requests.Request): Request object
                to use for refreshing credentials.
        Ús)rX   ÚscoperZ   úContent-Typeúapplication/jsonzNDomain-wide delegation is not supported in universes other than googleapis.com© )Úissrf   ÚsubÚaudÚiatÚexp)r-   r.   r   ÚpayloadrX   N)r-   r.   r   r   r/   r0   )"rB   Útoken_stater   Ú
TokenStateÚSTALEÚINVALIDÚrefreshrK   rJ   ÚstrrN   r   ÚAPI_CLIENT_HEADERÚ&token_request_access_token_impersonateÚapplyrL   r/   r   r   ÚGoogleAuthErrorr   rO   rI   Úscopes_to_stringÚ_GOOGLE_OAUTH2_TOKEN_ENDPOINTÚdatetime_to_secsrM   Ú_sign_jwt_requestr   Ú	jwt_grantr5   r6   r:   rQ   )rT   r-   r   r   Únowro   Ú	assertionÚ_s           r9   Ú_perform_refresh_tokenz"Credentials._perform_refresh_token  sÙ  € ð Ô$Ô0µKÔ4JÔ4PÒPÐPØÔ'Ô3µ{Ô7MÔ7UÒUÐUàÔ$×,Ò,¨WÑ5Ô5Ð5ð œØÔ(Ý˜DœNÑ+Ô+¨cÑ1ð
ð 
ˆð Ð.ÝÔ%¥wÔ'UÑ'WÔ'Wð
ˆð 	Ô ×&Ò& wÑ/Ô/Ð/ð Œ=ð 	ØÔ#¥{Ô'JÒJÐJÝ Ô0ð,ñô ð õ
 ”/Ñ#Ô#ˆCàÔ-Ý!Ô2°4Ô3FÐ3LÈ"ÑMÔMØ”}Ý4ÝÔ0°Ñ5Ô5ÝÔ0°Ñ5Ô5Õ8TÑTðð ˆGõ *ØØÔ0ØØØœ/ðñ ô ˆIõ *1Ô):ØÕ6¸	ñ*ô *Ñ&ˆDŒJ˜œ Qð ˆFå"9ØØÔ,ØØØ Ô0Ø"&Ô"=ð#
ñ #
ô #
ÑˆŒ
�D”K�K�Kr^   c                 óx   — | j         st          d¦  «        ‚t                               | j        | j         ¦  «        S )aî  Builds and returns the URL for the trust boundary lookup API.

        This method constructs the specific URL for the IAM Credentials API's
        `allowedLocations` endpoint, using the credential's universe domain
        and service account email.

        Raises:
            ValueError: If `self.service_account_email` is None or an empty
                string, as it's required to form the URL.

        Returns:
            str: The URL for the trust boundary lookup endpoint.
        zIService account email is required to build the trust boundary lookup URL.)Úservice_account_emailr,   Ú_TRUST_BOUNDARY_LOOKUP_ENDPOINTr   r/   rb   s    r9   Ú _build_trust_boundary_lookup_urlz,Credentials._build_trust_boundary_lookup_url[  sI   € ð Ô)ð 	ÝØ[ñô ð õ /×5Ò5ØÔ  $Ô"<ñ
ô 
ð 	
r^   c                 óP  — ddl m} t          j                             t
          j        | j        ¦  «                             | j	        ¦  «        }t          j        |¦  «                             d¦  «        | j        dœ}ddi} || j        ¦  «        }	 t          j        ¦   «         }|D ]½}|                     |||¬¦  «        }	|	j        t          j        v rŒ.|	j        t(          j        k    r9t-          j        d                     |	                     ¦   «         ¦  «        ¦  «        ‚t          j        |	                     ¦   «         d	         ¦  «        c |                     ¦   «          S 	 |                     ¦   «          n# |                     ¦   «          w xY wt-          j        d
¦  «        ‚)Nr   ©ÚAuthorizedSessionr   )ro   rX   rg   rh   )r   r   r   zError calling sign_bytes: {}Ú
signedBlobz#exhausted signBlob endpoint retries)Úgoogle.auth.transport.requestsr‰   r	   Ú_IAM_SIGN_ENDPOINTr   r   r   r/   r   rI   Úbase64Ú	b64encoder   rK   rB   r   ÚExponentialBackoffÚpostÚstatus_codeÚIAM_RETRY_CODESr%   r&   r   ÚTransportErrorr   Ú	b64decodeÚclose)
rT   Úmessager‰   Úiam_sign_endpointr   r   Úauthed_sessionÚretriesr�   r2   s
             r9   Ú
sign_byteszCredentials.sign_bytesq  s±  € ØDÐDÐDÐDÐDÐDåÔ2×:Ò:ÝÔ/°Ô1Eñ
ô 
ç
Š&�Ô'Ñ
(Ô
(ð 	õ
 Ô'¨Ñ0Ô0×7Ò7¸Ñ@Ô@Øœð
ð 
ˆð
 "Ð#5Ð6ˆà*Ð*¨4Ô+CÑDÔDˆð	#Ý*Ô=Ñ?Ô?ˆGØð Gð G�Ø)×.Ò.Ø)°7Àð /ñ ô �ð Ô'­3Ô+>Ð>Ð>ØØÔ'­;¬>Ò9Ð9Ý$Ô3Ø6×=Ò=¸h¿mºm¹o¼oÑNÔNñô ð õ Ô'¨¯ª©¬¸Ô(EÑFÔFÐFÐFà× Ò Ñ"Ô"Ð"Ð"ðGð × Ò Ñ"Ô"Ð"Ð"øˆN× Ò Ñ"Ô"Ð"Ð"øøøÝÔ'Ð(MÑNÔNÐNs   ÂB>E; Å;Fc                 ó   — | j         S r`   ©rI   rb   s    r9   Úsigner_emailzCredentials.signer_email“  ó   € àÔ%Ð%r^   c                 ó   — | j         S r`   rœ   rb   s    r9   r„   z!Credentials.service_account_email—  rž   r^   c                 ó   — | S r`   ri   rb   s    r9   ÚsignerzCredentials.signer›  s   € àˆr^   c                 ó   — | j          S r`   )rJ   rb   s    r9   Úrequires_scopeszCredentials.requires_scopesŸ  s   € àÔ&Ð&Ð&r^   c                 ó4   — | j         r| j         d| j        dœS d S )Nzimpersonated credentials)Úcredential_sourceÚcredential_typer.   )rR   rI   rb   s    r9   Úget_cred_infozCredentials.get_cred_info£  s2   € àÔð 	à%)Ô%9Ø#=Ø!Ô3ðð ð ð
 ˆtr^   c           
      ó¨   — |                       | j        | j        | j        | j        | j        | j        | j        | j        ¬¦  «        }| j	        |_	        |S )N)rV   rW   rX   rZ   r[   r0   r\   )
r]   rB   rI   rJ   rK   rN   rP   rQ   rS   rR   )rT   Úcreds     r9   Ú
_make_copyzCredentials._make_copy­  sZ   € Ø�~Š~ØÔ$Ø!Ô3ØÔ-Ø”oØ”^Ø!Ô3Ø"&Ô"=ØÔ/ð ñ 	
ô 	
ˆð  $Ô3ˆÔØˆr^   c                 ó<   — |                       ¦   «         }||_        |S r`   )rª   rS   )rT   r\   r©   s      r9   Úwith_trust_boundaryzCredentials.with_trust_boundary»  s   € à�ŠÑ Ô ˆØ-ˆÔØˆr^   c                 ó<   — |                       ¦   «         }||_        |S r`   )rª   rP   )rT   r[   r©   s      r9   Úwith_quota_projectzCredentials.with_quota_projectÁ  s   € à�ŠÑ Ô ˆØ!1ˆÔØˆr^   c                 ó@   — |                       ¦   «         }|p||_        |S r`   )rª   rJ   )rT   ÚscopesÚdefault_scopesr©   s       r9   rE   zCredentials.with_scopesÇ  s#   € à�ŠÑ Ô ˆØ$Ð6¨ˆÔØˆr^   c                 ó„  — |                      d¦  «        }|                      d¦  «        }|t          k    r!ddlm} |j                             |¦  «        }n|t          k    r!ddlm} |j                             |¦  «        }nS|t          k    r!ddl
m} |j                             |¦  «        }n't          j        d                     |¦  «        ¦  «        ‚|                      d¦  «        }	|	                     d	¦  «        }
|	                     d
¦  «        }|
dk    s|dk    s|
|k    r't          j        d                     |	¦  «        ¦  «        ‚|	|
dz   |…         }|                      d¦  «        }|                      d¦  «        }|p|                      d¦  «        }|                      d¦  «        } | ||||||¬¦  «        S )a¶  Creates a Credentials instance from parsed impersonated service account credentials info.

        **IMPORTANT**:
        This method does not validate the credential configuration. A security
        risk occurs when a credential configuration configured with malicious urls
        is used.
        When the credential configuration is accepted from an
        untrusted source, you should validate it before using with this method.
        Refer https://cloud.google.com/docs/authentication/external/externally-sourced-credentials for more details.

        Args:
            info (Mapping[str, str]): The impersonated service account credentials info in Google
                format.
            scopes (Sequence[str]): Optional list of scopes to include in the
                credentials.

        Returns:
            google.oauth2.credentials.Credentials: The constructed
                credentials.

        Raises:
            InvalidType: If the info["source_credentials"] are not a supported impersonation type
            InvalidValue: If the info["service_account_impersonation_url"] is not in the expected format.
            ValueError: If the info is not in the expected format.
        rU   Útyper   r   )r   )r   z.source credential of type {} is not supported.Ú!service_account_impersonation_urlú/z:generateAccessTokenéÿÿÿÿz'Cannot extract target principal from {}é   rX   r[   r°   r\   )r[   r\   )ÚgetÚ'_SOURCE_CREDENTIAL_AUTHORIZED_USER_TYPEÚgoogle.oauth2r   r<   Úfrom_authorized_user_infoÚ'_SOURCE_CREDENTIAL_SERVICE_ACCOUNT_TYPEr   Úfrom_service_account_infoÚ8_SOURCE_CREDENTIAL_EXTERNAL_ACCOUNT_AUTHORIZED_USER_TYPEÚgoogle.authr   Ú	from_infor   ÚInvalidTyper   ÚrfindÚfindÚInvalidValue)ÚclsÚinfor°   Úsource_credentials_infoÚsource_credentials_typer   rU   r   r   Úimpersonation_urlÚstart_indexÚ	end_indexrV   rX   r[   r\   s                   r9   Ú&from_impersonated_service_account_infoz2Credentials.from_impersonated_service_account_infoÍ  s)  € ð8 #'§(¢(Ð+?Ñ"@Ô"@ÐØ"9×"=Ò"=¸fÑ"EÔ"EÐØ"Õ&MÒMÐMØ1Ð1Ð1Ð1Ð1Ð1à!,Ô!8×!RÒ!RØ'ñ"ô "ÐÐð %Õ(OÒOÐOØ5Ð5Ð5Ð5Ð5Ð5à!0Ô!<×!VÒ!VØ'ñ"ô "ÐÐð $ÝGòHð Hð EÐDÐDÐDÐDÐDà!AÔ!M×!WÒ!WØ'ñ"ô "ÐÐõ Ô(Ø@×GÒGØ+ñô ñô ð ð !ŸHšHÐ%HÑIÔIÐØ'×-Ò-¨cÑ2Ô2ˆØ%×*Ò*Ð+AÑBÔBˆ	Ø˜"ÒÐ 	¨R¢ °;ÀÒ3JÐ3JÝÔ)Ø9×@Ò@ÐARÑSÔSñô ð ð -¨[¸1©_¸yÐ-HÔIÐØ—H’H˜[Ñ)Ô)ˆ	ØŸ8š8Ð$6Ñ7Ô7ÐØÐ-˜4Ÿ8š8 HÑ-Ô-ˆØŸšÐ"2Ñ3Ô3ˆàˆsØØØØØ-Ø)ð
ñ 
ô 
ð 	
r^   r`   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__rM   r@   rc   r‚   r†   rš   Úpropertyr�   r„   r¡   r£   r   Úcopy_docstringr   r<   r§   rª   ÚCredentialsWithTrustBoundaryr¬   ÚCredentialsWithQuotaProjectr®   rD   rE   ÚclassmethodrÌ   Ú__classcell__©r]   s   @r9   r<   r<   z   s  ø€ € € € € ðCð CðT ØØ-ØØ"ØðI.ð I.ð I.ð I.ð I.ð I.ðV0ð 0ð 0ðF
ð F
ð F
ðP
ð 
ð 
ð, Oð  Oð  OðD ð&ð &ñ „Xð&ð ð&ð &ñ „Xð&ð ðð ñ „Xðð ð'ð 'ñ „Xð'ð €XÔ˜[Ô4Ñ5Ô5ðð ñ 6Ô5ððð ð ð €XÔ˜[ÔEÑFÔFðð ñ GÔFðð
 €XÔ˜[ÔDÑEÔEðð ñ FÔEðð
 €XÔ˜[Ô/Ñ0Ô0ðð ð ñ 1Ô0ðð
 ðM
ð M
ð M
ñ „[ðM
ð M
ð M
ð M
ð M
r^   r<   c                   ó¶   ‡ — e Zd ZdZ	 	 	 d
ˆ fd„	Zdd„Zd„ Zd„ Z ej	        e
j        ¦  «        d„ ¦   «         Z ej	        e
j        ¦  «        d	„ ¦   «         Zˆ xZS )ÚIDTokenCredentialsz;Open ID Connect ID Token-based service account credentials.NFc                 óà   •— t          t          | ¦  «                             ¦   «          t          |t          ¦  «        st          j        d¦  «        ‚|| _        || _        || _	        || _
        dS )a‰  
        Args:
            target_credentials (google.auth.Credentials): The target
                credential used as to acquire the id tokens for.
            target_audience (string): Audience to issue the token for.
            include_email (bool): Include email in IdToken
            quota_project_id (Optional[str]):  The project ID used for
                quota and billing.
        z4Provided Credential must be impersonated_credentialsN)r?   rÙ   r@   rC   r<   r   ry   Ú_target_credentialsÚ_target_audienceÚ_include_emailrP   )rT   Útarget_credentialsÚtarget_audienceÚinclude_emailr[   r]   s        €r9   r@   zIDTokenCredentials.__init__!  su   ø€ õ  	Õ  $Ñ'Ô'×0Ò0Ñ2Ô2Ð2åÐ,­kÑ:Ô:ð 	ÝÔ,ØIñô ð ð $6ˆÔ Ø /ˆÔØ+ˆÔØ!1ˆÔÐÐr^   c                 óH   — |                       ||| j        | j        ¬¦  «        S ©N)rÞ   rß   rà   r[   )r]   rÝ   rP   )rT   rÞ   rß   s      r9   Úfrom_credentialsz#IDTokenCredentials.from_credentials<  s/   € Ø�~Š~Ø1Ø+ØÔ-Ø!Ô3ð	 ñ 
ô 
ð 	
r^   c                 óR   — |                       | j        || j        | j        ¬¦  «        S râ   )r]   rÛ   rÝ   rP   )rT   rß   s     r9   Úwith_target_audiencez'IDTokenCredentials.with_target_audienceD  s2   € Ø�~Š~Ø#Ô7Ø+ØÔ-Ø!Ô3ð	 ñ 
ô 
ð 	
r^   c                 óR   — |                       | j        | j        || j        ¬¦  «        S râ   )r]   rÛ   rÜ   rP   )rT   rà   s     r9   Úwith_include_emailz%IDTokenCredentials.with_include_emailL  s2   € Ø�~Š~Ø#Ô7Ø Ô1Ø'Ø!Ô3ð	 ñ 
ô 
ð 	
r^   c                 óR   — |                       | j        | j        | j        |¬¦  «        S râ   )r]   rÛ   rÜ   rÝ   )rT   r[   s     r9   r®   z%IDTokenCredentials.with_quota_projectT  s2   € à�~Š~Ø#Ô7Ø Ô1ØÔ-Ø-ð	 ñ 
ô 
ð 	
r^   c                 óþ  — ddl m} t          j                             t
          j        | j        j        ¦  «         	                    | j        j
        ¦  «        }| j        | j        j        | j        dœ}ddt          j        t          j        ¦   «         i} || j        j        |¬¦  «        }	 |                     ||t'          j        |¦  «                             d¦  «        ¬¦  «        }|                     ¦   «          n# |                     ¦   «          w xY w|j        t0          j        k    r9t5          j        d	 	                    |                     ¦   «         ¦  «        ¦  «        ‚	 |                     ¦   «         d
         }nC# t8          t:          f$ r/}	t5          j        d|                     ¦   «         ¦  «        }
|
|	‚d }	~	ww xY w|| _        t?          j         tC          j"        |d¬¦  «        d         ¦  «        | _#        d S )Nr   rˆ   )ÚaudiencerX   ÚincludeEmailrg   rh   )Úauth_requestr   )r   r   r#   zError getting ID token: {}r5   zNo ID token in response.F)Úverifyrn   )$r‹   r‰   r	   Ú_IAM_IDTOKEN_ENDPOINTr   r   r   rÛ   r/   r   r�   rÜ   rK   rÝ   r   rv   Ú"token_request_id_token_impersonaterB   r�   r   r    r!   r•   r‘   r%   r&   r   r'   r+   r,   r5   r   Úutcfromtimestampr
   r   r6   )rT   r-   r‰   r—   r   r   r˜   r2   Úid_tokenr7   r8   s              r9   rt   zIDTokenCredentials.refresh]  s  € àDÐDÐDÐDÐDÐDåÔ5×=Ò=ÝÔ/ØÔ$Ô4ñ
ô 
÷ Š&�Ô)Ô6Ñ
7Ô
7ð 	ð Ô-ØÔ1Ô<Ø Ô/ð
ð 
ˆð Ð.ÝÔ%¥wÔ'QÑ'SÔ'Sð
ˆð
 +Ð*ØÔ$Ô8Àwð
ñ 
ô 
ˆð	#Ø%×*Ò*Ø%ØÝ”Z Ñ%Ô%×,Ò,¨WÑ5Ô5ð +ñ ô ˆHð × Ò Ñ"Ô"Ð"Ð"øˆN× Ò Ñ"Ô"Ð"Ð"øøøàÔ¥;¤>Ò1Ð1ÝÔ)Ø,×3Ò3°H·M²M±O´OÑDÔDñô ð ð	*Ø—}’}‘” wÔ/ˆHˆHøÝ�*Ð%ð 	*ð 	*ð 	*Ý Ô-Ø*¨H¯MªM©O¬Oñô ˆGð ˜zÐ)øøøøð		*øøøð ˆŒ
ÝÔ/ÝŒJ�x¨Ð.Ñ.Ô.¨uÔ5ñ
ô 
ˆŒˆˆs$   Â+=C= Ã=DÅ%F  Æ G Æ*F;Æ;G )NFNr`   )rÍ   rÎ   rÏ   rÐ   r@   rã   rå   rç   r   rÒ   r   rÔ   r®   r<   rt   rÖ   r×   s   @r9   rÙ   rÙ     sÙ   ø€ € € € € ØEÐEð
 ØØð2ð 2ð 2ð 2ð 2ð 2ð6
ð 
ð 
ð 
ð
ð 
ð 
ð
ð 
ð 
ð €XÔ˜[ÔDÑEÔEð
ð 
ñ FÔEð
ð €XÔ˜[Ô4Ñ5Ô5ð0
ð 0
ñ 6Ô5ð0
ð 0
ð 0
ð 0
ð 0
r^   rÙ   c                 ót  — t           j                             |¦  «        }|t          j        |¦  «        dœ}t          j        |¦  «                             d¦  «        } | |d||¬¦  «        }t          |j        d¦  «        r|j                             d¦  «        n|j        }|j	        t          j        k    rt          j        t          |¦  «        ‚	 t          j        |¦  «        }	|	d         }
|
S # t           t"          f$ r5}t          j        d                     t          ¦  «        |¦  «        }||‚d}~ww xY w)	aû  Makes a request to the Google Cloud IAM service to sign a JWT using a
    service account's system-managed private key.
    Args:
        request (Request): The Request object to use.
        principal (str): The principal to request an access token for.
        headers (Mapping[str, str]): Map of headers to transmit.
        payload (Mapping[str, str]): The JWT payload to sign. Must be a
            serialized JSON object that contains a JWT Claims Set.
        delegates (Sequence[str]): The chained list of delegates required
            to grant the final access_token.  If set, the sequence of
            identities must have "Service Account Token Creator" capability
            granted to the prceeding identity.  For example, if set to
            [serviceAccountB, serviceAccountC], the source_credential
            must have the Token Creator role on serviceAccountB.
            serviceAccountB must have the Token Creator on
            serviceAccountC.
            Finally, C must have Token Creator on target_principal.
            If left unset, source_credential must have that role on
            target_principal.

    Raises:
        google.auth.exceptions.TransportError: Raised if there is an underlying
            HTTP connection error
        google.auth.exceptions.RefreshError: Raised if the impersonated
            credentials are not available.  Common reasons are
            `iamcredentials.googleapis.com` is not enabled or the
            `Service Account Token Creator` is not assigned
    )rX   ro   r   r   r   r   Ú	signedJwtz{}: No signed JWT in response.N)r	   Ú_IAM_SIGNJWT_ENDPOINTr   r   r    r!   r"   r#   r   r$   r%   r&   r   r'   r(   r)   r+   r,   )r-   r.   r   ro   rX   r1   r   r2   r3   Újwt_responseÚ
signed_jwtr7   r8   s                r9   r}   r}   ‘  s6  € õ: Ô,×3Ò3°IÑ>Ô>€Là"­t¬z¸'Ñ/BÔ/BÐCÐC€DÝŒ:�dÑÔ×"Ò" 7Ñ+Ô+€Dàˆw˜<°ÀÈdÐSÑSÔS€Hõ
 �8”= (Ñ+Ô+ð	ˆŒ×Ò˜WÑ%Ô%Ð%àŒ]ð ð „�+œ.Ò(Ð(ÝÔ%¥n°mÑDÔDÐDð	&Ý”z -Ñ0Ô0ˆØ! +Ô.ˆ
ØÐøå•jÐ!ð &ð &ð &ÝÔ)Ø,×3Ò3µNÑCÔCÀ]ñ
ô 
ˆð ˜:Ð%øøøøð	&øøøs   ÃC1 Ã1D7Ä0D2Ä2D7)"rÐ   r�   rA   r   Úhttp.clientÚclientr%   r   r¿   r   r   r   r   r	   r
   r   rº   r   r(   rM   r{   r…   r¹   r¼   r¾   r   r:   rD   rÔ   ÚSigningrÓ   r<   rÙ   r}   ri   r^   r9   ú<module>rú      sÕ  ððð ð €€€Ø €€€Ø Ð Ð Ð Ð Ð Ø !Ð !Ð !Ð !Ð !Ð !Ø €€€à ,Ð ,Ð ,Ð ,Ð ,Ð ,Ø  Ð  Ð  Ð  Ð  Ð  Ø #Ð #Ð #Ð #Ð #Ð #Ø "Ð "Ð "Ð "Ð "Ð "Ø Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø !Ð !Ð !Ð !Ð !Ð !ð >€à#Ð à EÐ àQð  ð +<Ð 'Ø*;Ð 'à&ð 9ð  Ô7Øð;&ð ;&ð ;&ð ;&ð|a
ð a
ð a
ð a
ð a
ØÔØÔ+ØÔØÔ,ñ	a
ô a
ð a
ðHp
ð p
ð p
ð p
ð p
˜Ô@ñ p
ô p
ð p
ðf GIð 7&ð 7&ð 7&ð 7&ð 7&ð 7&r^   