o
    ×èFh  ã                   @   s¢   d Z ddlmZmZ ddlZddlmZmZmZmZ ddlm	Z	m
Z
mZ ddlmZ dZdefd	d
„Zddedeeef fdd„ZG dd„ dƒZG dd„ dƒZdS )zFirebase App Check module.é    )ÚAnyÚDictN)ÚPyJWKClientÚExpiredSignatureErrorÚInvalidTokenErrorÚDecodeError)ÚInvalidAudienceErrorÚInvalidIssuerErrorÚInvalidSignatureError)Ú_utilsÚ
_app_checkÚreturnc                 C   s   t  | tt¡S ©N)r   Úget_app_serviceÚ_APP_CHECK_ATTRIBUTEÚ_AppCheckService)Úapp© r   úQ/var/www/html/loop/nvenv/lib/python3.10/site-packages/firebase_admin/app_check.pyÚ_get_app_check_service   s   r   Útokenc                 C   s   t |ƒ | ¡S )a¥  Verifies a Firebase App Check token.

    Args:
        token: A token from App Check.
        app: An App instance (optional).

    Returns:
        Dict[str, Any]: The token's decoded claims.

    Raises:
        ValueError: If the app's ``project_id`` is invalid or unspecified,
        or if the token's headers or payload are invalid.
        PyJWKClientError: If PyJWKClient fails to fetch a valid signing key.
    )r   Úverify_token)r   r   r   r   r   r      s   r   c                   @   sj   e Zd ZdZdZdZdZdZdZdd„ Z	de
dee
ef fd	d
„Zdeddfdd„Zde
de
fdd„ZdS )r   z?Service class that implements Firebase App Check functionality.z(https://firebaseappcheck.googleapis.com/z/https://firebaseappcheck.googleapis.com/v1/jwksNc                 C   s6   |j | _| jstdƒ‚d|j  | _t| jdd�| _d S )Nz·A project ID must be specified to access the App Check service. Either set the projectId option, use service account credentials, or set the GOOGLE_CLOUD_PROJECT environment variable.z	projects/i`T  )Úlifespan)Ú
project_idÚ_project_idÚ
ValueErrorÚ_scoped_project_idr   Ú	_JWKS_URLÚ_jwks_client)Úselfr   r   r   r   Ú__init__6   s   ÿz_AppCheckService.__init__r   r   c              
   C   sx   t  d|¡ z| j |¡}|  t |¡¡ |  ||j¡}W n t	t
fy2 } ztd|› �ƒ‚d}~ww | d¡|d< |S )z$Verifies a Firebase App Check token.zapp check tokenz)Verifying App Check token failed. Error: NÚsubÚapp_id)Ú_ValidatorsÚcheck_stringr   Úget_signing_key_from_jwtÚ_has_valid_token_headersÚjwtÚget_unverified_headerÚ_decode_and_verifyÚkeyr   r   r   Úget)r   r   Úsigning_keyÚverified_claimsÚ	exceptionr   r   r   r   D   s   ÿ€ÿz_AppCheckService.verify_tokenÚheadersc                 C   s<   |  d¡dkrtdƒ‚|  d¡}|dkrtd|› d�ƒ‚dS )	z9Checks whether the token has valid headers for App Check.ÚtypÚJWTz9The provided App Check token has an incorrect type headerÚalgÚRS256zQThe provided App Check token has an incorrect alg header. Expected RS256 but got Ú.N)r+   r   )r   r/   Ú	algorithmr   r   r   r&   W   s   
ÿÿÿz)_AppCheckService._has_valid_token_headersr,   c              
   C   sþ   i }zt j||dg| jd�}W nD ty   tdƒ‚ ty)   td| j› d�ƒ‚ ty7   td| j› �ƒ‚ tyA   tdƒ‚ t	yS } ztd|› �ƒ‚d	}~ww | 
d
¡}t|tƒrc| j|vrgtdƒ‚| 
d¡ | j¡sttdƒ‚t d| 
d¡¡ |S )z.Decodes and verifies the token from App Check.r3   )Ú
algorithmsÚaudiencez6The provided App Check token has an invalid signature.zbThe provided App Check token has an incorrect "aud" (audience) claim. Expected payload to include r4   z^The provided App Check token has an incorrect "iss" (issuer) claim. Expected claim to include z)The provided App Check token has expired.z(Decoding App Check token failed. Error: NÚaudz>Firebase App Check token has incorrect "aud" (audience) claim.Úissz2Token does not contain the correct "iss" (issuer).z2The provided App Check token "sub" (subject) claimr!   )r'   Údecoder   r
   r   r   r	   Ú_APP_CHECK_ISSUERr   r   r+   Ú
isinstanceÚlistÚ
startswithr#   r$   )r   r   r,   Úpayloadr.   r7   r   r   r   r)   d   sX   
üÿÿÿÿÿÿÿ€ÿ
þz#_AppCheckService._decode_and_verify)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r;   r   r   r   r   r    Ústrr   r   r   r&   r)   r   r   r   r   r   -   s    r   c                   @   s&   e Zd ZdZededefdd„ƒZdS )r#   z‚A collection of data validation utilities.

    Methods provided in this class raise ``ValueErrors`` if any validations fail.
    ÚlabelÚvaluec                 C   s6   |du rt d ||¡ƒ‚t|tƒst d ||¡ƒ‚dS )z&Checks if the given value is a string.Nz%{0} "{1}" must be a non-empty string.z{0} "{1}" must be a string.)r   Úformatr<   rD   )ÚclsrE   rF   r   r   r   r$   –   s
   
ÿz_Validators.check_stringN)r@   rA   rB   rC   ÚclassmethodrD   r   r$   r   r   r   r   r#   �   s    r#   r   )rC   Útypingr   r   r'   r   r   r   r   r   r	   r
   Úfirebase_adminr   r   r   rD   r   r   r#   r   r   r   r   Ú<module>   s   c