§
    Âi/#  ã                   ó®   — d Z ddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlm	Z	 d	Z
d
ZdZ ej        d¬¦  «        Z G d„ dej        ¦  «        ZdS )z'Experimental GDCH credentials support.
é    N)Ú_helpers)Ú_service_account_info)Úcredentials)Ú
exceptions)Újwt)Ú_clientz/urn:ietf:params:oauth:token-type:token-exchangez-urn:ietf:params:oauth:token-type:access_tokenz.urn:k8s:params:oauth:token-type:serviceaccounti  )Úsecondsc                   ó¬   ‡ — e Zd ZdZˆ fd„Zd„ Z ej        ej	        ¦  «        d„ ¦   «         Z
d„ Zed„ ¦   «         Zed„ ¦   «         Zed„ ¦   «         Zˆ xZS )	ÚServiceAccountCredentialsaÊ  Credentials for GDCH (`Google Distributed Cloud Hosted`_) for service
    account users.

    .. _Google Distributed Cloud Hosted:
        https://cloud.google.com/blog/topics/hybrid-cloud/            announcing-google-distributed-cloud-edge-and-hosted

    To create a GDCH service account credential, first create a JSON file of
    the following format::

        {
            "type": "gdch_service_account",
            "format_version": "1",
            "project": "<project name>",
            "private_key_id": "<key id>",
            "private_key": "-----BEGIN EC PRIVATE KEY-----
<key bytes>
-----END EC PRIVATE KEY-----
",
            "name": "<service identity name>",
            "ca_cert_path": "<CA cert path>",
            "token_uri": "https://service-identity.<Domain>/authenticate"
        }

    The "format_version" field stands for the format of the JSON file. For now
    it is always "1". The `private_key_id` and `private_key` is used for signing.
    The `ca_cert_path` is used for token server TLS certificate verification.

    After the JSON file is created, set `GOOGLE_APPLICATION_CREDENTIALS` environment
    variable to the JSON file path, then use the following code to create the
    credential::

        import google.auth

        credential, _ = google.auth.default()
        credential = credential.with_gdch_audience("<the audience>")

    We can also create the credential directly::

        from google.oauth import gdch_credentials

        credential = gdch_credentials.ServiceAccountCredentials.from_service_account_file("<the json file path>")
        credential = credential.with_gdch_audience("<the audience>")

    The token is obtained in the following way. This class first creates a
    self signed JWT. It uses the `name` value as the `iss` and `sub` claim, and
    the `token_uri` as the `aud` claim, and signs the JWT with the `private_key`.
    It then sends the JWT to the `token_uri` to exchange a final token for
    `audience`.
    c                 óª   •— t          t          | ¦  «                             ¦   «          || _        || _        || _        || _        || _        || _        dS )af  
        Args:
            signer (google.auth.crypt.Signer): The signer used to sign JWTs.
            service_identity_name (str): The service identity name. It will be
                used as the `iss` and `sub` claim in the self signed JWT.
            project (str): The project.
            audience (str): The audience for the final token.
            token_uri (str): The token server uri.
            ca_cert_path (str): The CA cert path for token server side TLS
                certificate verification. If the token server uses well known
                CA, then this parameter can be `None`.
        N)	Úsuperr   Ú__init__Ú_signerÚ_service_identity_nameÚ_projectÚ	_audienceÚ
_token_uriÚ_ca_cert_path)ÚselfÚsignerÚservice_identity_nameÚprojectÚaudienceÚ	token_uriÚca_cert_pathÚ	__class__s          €úh/var/www/html/jarvis.com/web/backend/venv/lib/python3.11/site-packages/google/oauth2/gdch_credentials.pyr   z"ServiceAccountCredentials.__init__S   sT   ø€ õ 	Õ'¨Ñ.Ô.×7Ò7Ñ9Ô9Ð9ØˆŒØ&;ˆÔ#ØˆŒØ!ˆŒØ#ˆŒØ)ˆÔÐÐó    c                 ó6  — t          j        ¦   «         }|t          z   }d                     | j        | j        ¦  «        }||| j        t          j        |¦  «        t          j        |¦  «        dœ}t          j        t          j
        | j        |¦  «        ¦  «        S )Nzsystem:serviceaccount:{}:{})ÚissÚsubÚaudÚiatÚexp)r   ÚutcnowÚJWT_LIFETIMEÚformatr   r   r   Údatetime_to_secsÚ
from_bytesr   Úencoder   )r   ÚnowÚexpiryÚiss_sub_valueÚpayloads        r   Ú_create_jwtz%ServiceAccountCredentials._create_jwtj   sŽ   € ÝŒoÑÔˆØ•|Ñ#ˆØ5×<Ò<ØŒM˜4Ô6ñ
ô 
ˆð
 !Ø Ø”?ÝÔ,¨SÑ1Ô1ÝÔ,¨VÑ4Ô4ð
ð 
ˆõ Ô"¥3¤:¨d¬l¸GÑ#DÔ#DÑEÔEÐEr   c                 ón  — dd l }t          ||j        j        j        j        ¦  «        st          j        d¦  «        ‚|                      ¦   «         }t          | j
        t          |t          dœ}t          j        || j        |d d| j        ¬¦  «        }t          j        |d ¦  «        \  | _        }| _        }d S )Nr   zeFor GDCH service account credentials, request must be a google.auth.transport.requests.Request object)Ú
grant_typer   Úrequested_token_typeÚsubject_tokenÚsubject_token_typeT)Úaccess_tokenÚuse_jsonÚverify)Úgoogle.auth.transport.requestsÚ
isinstanceÚauthÚ	transportÚrequestsÚRequestr   ÚRefreshErrorr/   ÚTOKEN_EXCHANGE_TYPEr   ÚACCESS_TOKEN_TOKEN_TYPEÚSERVICE_ACCOUNT_TOKEN_TYPEr   Ú_token_endpoint_requestr   r   Ú_handle_refresh_grant_responseÚtokenr,   )r   ÚrequestÚgoogleÚ	jwt_tokenÚrequest_bodyÚresponse_dataÚ_s          r   Úrefreshz!ServiceAccountCredentials.refresh{   sÍ   € à-Ð-Ð-Ð-å˜' 6¤;Ô#8Ô#AÔ#IÑJÔJð 	ÝÔ)Øwñô ð ð
 ×$Ò$Ñ&Ô&ˆ	å-ØœÝ$;Ø&Ý"<ð
ð 
ˆõ  Ô7ØØŒOØØØØÔ%ð
ñ 
ô 
ˆõ )0Ô(NØ˜4ñ)
ô )
Ñ%ˆŒ
�A�t”{ A A Ar   c                 óh   — |                       | j        | j        | j        || j        | j        ¦  «        S )zžCreate a copy of GDCH credentials with the specified audience.

        Args:
            audience (str): The intended audience for GDCH credentials.
        )r   r   r   r   r   r   )r   r   s     r   Úwith_gdch_audiencez,ServiceAccountCredentials.with_gdch_audienceš   s8   € ð �~Š~ØŒLØÔ'ØŒMØØŒOØÔñ
ô 
ð 	
r   c                 ó¤   — |d         dk    rt          d¦  «        ‚ | ||d         |d         d|d         |                     dd¦  «        ¦  «        S )	aÌ  Creates a Credentials instance from a signer and service account
        info.

        Args:
            signer (google.auth.crypt.Signer): The signer used to sign JWTs.
            info (Mapping[str, str]): The service account info.

        Returns:
            google.oauth2.gdch_credentials.ServiceAccountCredentials: The constructed
                credentials.

        Raises:
            ValueError: If the info is not in the expected format.
        Úformat_versionÚ1z"Only format version 1 is supportedÚnamer   Nr   r   )Ú
ValueErrorÚget)Úclsr   Úinfos      r   Ú_from_signer_and_infoz/ServiceAccountCredentials._from_signer_and_info©   se   € ð  Ð Ô! SÒ(Ð(ÝÐAÑBÔBÐBàˆsØØ�ŒLØ�ŒOØØ�ÔØ�HŠH�^ TÑ*Ô*ñ
ô 
ð 	
r   c                 ó`   — t          j        |g d¢d¬¦  «        }|                      ||¦  «        S )a×  Creates a Credentials instance from parsed service account info.

        Args:
            info (Mapping[str, str]): The service account info in Google
                format.
            kwargs: Additional arguments to pass to the constructor.

        Returns:
            google.oauth2.gdch_credentials.ServiceAccountCredentials: The constructed
                credentials.

        Raises:
            ValueError: If the info is not in the expected format.
        ©rO   Úprivate_key_idÚprivate_keyrQ   r   r   F©ÚrequireÚuse_rsa_signer)r   Ú	from_dictrV   )rT   rU   r   s      r   Úfrom_service_account_infoz3ServiceAccountCredentials.from_service_account_infoÅ   sJ   € õ  'Ô0Øðð ð ð !ð
ñ 
ô 
ˆð ×(Ò(¨°Ñ6Ô6Ð6r   c                 óf   — t          j        |g d¢d¬¦  «        \  }}|                      ||¦  «        S )ai  Creates a Credentials instance from a service account json file.

        Args:
            filename (str): The path to the service account json file.
            kwargs: Additional arguments to pass to the constructor.

        Returns:
            google.oauth2.gdch_credentials.ServiceAccountCredentials: The constructed
                credentials.
        rX   Fr[   )r   Úfrom_filenamerV   )rT   ÚfilenamerU   r   s       r   Úfrom_service_account_filez3ServiceAccountCredentials.from_service_account_fileã   sN   € õ -Ô:Øðð ð ð !ð
ñ 
ô 
‰ˆˆfð ×(Ò(¨°Ñ6Ô6Ð6r   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r/   r   Úcopy_docstringr   ÚCredentialsrK   rM   ÚclassmethodrV   r_   rc   Ú__classcell__)r   s   @r   r   r   "   sá   ø€ € € € € ð.ð .ð`*ð *ð *ð *ð *ð.Fð Fð Fð" €XÔ˜[Ô4Ñ5Ô5ð
ð 
ñ 6Ô5ð
ð<
ð 
ð 
ð ð
ð 
ñ „[ð
ð6 ð7ð 7ñ „[ð7ð: ð7ð 7ñ „[ð7ð 7ð 7ð 7ð 7r   r   )rg   ÚdatetimeÚgoogle.authr   r   r   r   r   Úgoogle.oauth2r   r?   r@   rA   Ú	timedeltar&   ri   r   © r   r   ú<module>rq      sñ   ððð ð €€€à  Ð  Ð  Ð  Ð  Ð  Ø -Ð -Ð -Ð -Ð -Ð -Ø #Ð #Ð #Ð #Ð #Ð #Ø "Ð "Ð "Ð "Ð "Ð "Ø Ð Ð Ð Ð Ð Ø !Ð !Ð !Ð !Ð !Ð !ð HÐ ØIÐ ØMÐ Ø!ˆxÔ!¨$Ð/Ñ/Ô/€ðY7ð Y7ð Y7ð Y7ð Y7 Ô 7ñ Y7ô Y7ð Y7ð Y7ð Y7r   