o
    ×èFh»  ã                   @   s´   d Z ddlZddlZddlZddlZddlmZ ddlm	Z	 ddlm
Z
 e ¡ Zg d¢Ze ddd	g¡Z	 G d
d„ dƒZG dd„ deƒZG dd„ deƒZG dd„ deƒZdd„ ZdS )zFirebase credentials module.é    N)Úrequests)Úcredentials)Úservice_account)z.https://www.googleapis.com/auth/cloud-platformz)https://www.googleapis.com/auth/datastorez5https://www.googleapis.com/auth/devstorage.read_writez(https://www.googleapis.com/auth/firebasez/https://www.googleapis.com/auth/identitytoolkitz.https://www.googleapis.com/auth/userinfo.emailÚAccessTokenInfoÚaccess_tokenÚexpiryc                   @   s    e Zd ZdZdd„ Zdd„ ZdS )ÚBasez>Provides OAuth2 access tokens for accessing Firebase services.c                 C   s    |   ¡ }| t¡ t|j|jƒS )z©Fetches a Google OAuth2 access token using this credential instance.

        Returns:
          AccessTokenInfo: An access token obtained using the credential.
        )Úget_credentialÚrefreshÚ_requestr   Útokenr   )ÚselfÚgoogle_cred© r   úS/var/www/html/loop/nvenv/lib/python3.10/site-packages/firebase_admin/credentials.pyÚget_access_token/   s   
zBase.get_access_tokenc                 C   s   t ‚)z?Returns the Google credential instance used for authentication.)ÚNotImplementedError©r   r   r   r   r	   9   s   zBase.get_credentialN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r	   r   r   r   r   r   ,   s    
r   c                       óP   e Zd ZdZdZ‡ fdd„Zedd„ ƒZedd„ ƒZed	d
„ ƒZ	dd„ Z
‡  ZS )ÚCertificatez9A credential initialized from a JSON certificate keyfile.r   c              
      sÈ   t t| ƒ ¡  t|ƒr%t|ƒ�}t |¡}W d  ƒ n1 sw   Y  nt|tƒr-|}nt	d 
|¡ƒ‚| d¡| jkrDt	d 
| j¡ƒ‚ztjj|td�| _W dS  t	yc } zt	d 
|¡ƒ‚d}~ww )a]  Initializes a credential from a Google service account certificate.

        Service account certificates can be downloaded as JSON files from the Firebase console.
        To instantiate a credential from a certificate file, either specify the file path or a
        dict representing the parsed contents of the file.

        Args:
          cert: Path to a certificate file or a dict representing the contents of a certificate.

        Raises:
          IOError: If the specified certificate file doesn't exist or cannot be read.
          ValueError: If the specified certificate is invalid.
        Nz}Invalid certificate argument: "{0}". Certificate argument must be a file path, or a dict containing the parsed file contents.ÚtypezZInvalid service account certificate. Certificate must contain a "type" field set to "{0}".©Úscopesz?Failed to initialize a certificate credential. Caused by: "{0}")Úsuperr   Ú__init__Ú_is_file_pathÚopenÚjsonÚloadÚ
isinstanceÚdictÚ
ValueErrorÚformatÚgetÚ_CREDENTIAL_TYPEr   ÚCredentialsÚfrom_service_account_infoÚ_scopesÚ_g_credential)r   ÚcertÚ	json_fileÚ	json_dataÚerror©Ú	__class__r   r   r   C   s4   
ÿ€
þÿÿÿ€ÿzCertificate.__init__c                 C   ó   | j jS ©N)r,   Ú
project_idr   r   r   r   r5   f   ó   zCertificate.project_idc                 C   r3   r4   )r,   Úsignerr   r   r   r   r7   j   r6   zCertificate.signerc                 C   r3   r4   )r,   Úservice_account_emailr   r   r   r   r8   n   r6   z!Certificate.service_account_emailc                 C   ó   | j S ©z�Returns the underlying Google credential.

        Returns:
          google.auth.credentials.Credentials: A Google Auth credential instance.©r,   r   r   r   r   r	   r   ó   zCertificate.get_credential)r   r   r   r   r(   r   Úpropertyr5   r7   r8   r	   Ú__classcell__r   r   r1   r   r   >   s    #


r   c                       s<   e Zd ZdZ‡ fdd„Zdd„ Zedd„ ƒZdd	„ Z‡  Z	S )
ÚApplicationDefaultz(A Google Application Default credential.c                    s   t t| ƒ ¡  d| _dS )zæCreates an instance that will use Application Default credentials.

        The credentials will be lazily initialized when get_credential() or
        project_id() is called. See those methods for possible errors raised.
        N)r   r?   r   r,   r   r1   r   r   r   }   s   
zApplicationDefault.__init__c                 C   ó   |   ¡  | jS )a:  Returns the underlying Google credential.

        Raises:
          google.auth.exceptions.DefaultCredentialsError: If Application Default
              credentials cannot be initialized in the current environment.
        Returns:
          google.auth.credentials.Credentials: A Google Auth credential instance.)Ú_load_credentialr,   r   r   r   r   r	   †   s   z!ApplicationDefault.get_credentialc                 C   r@   )a  Returns the project_id from the underlying Google credential.

        Raises:
          google.auth.exceptions.DefaultCredentialsError: If Application Default
              credentials cannot be initialized in the current environment.
        Returns:
          str: The project id.)rA   Ú_project_idr   r   r   r   r5   ‘   s   	zApplicationDefault.project_idc                 C   s$   | j stjjtd�\| _ | _d S d S )Nr   )r,   ÚgoogleÚauthÚdefaultr+   rB   r   r   r   r   rA   �   s   ÿz#ApplicationDefault._load_credential)
r   r   r   r   r   r	   r=   r5   rA   r>   r   r   r1   r   r?   z   s    	
r?   c                       r   )ÚRefreshTokenz8A credential initialized from an existing refresh token.Úauthorized_userc                    sœ   t t| ƒ ¡  t|ƒr%t|ƒ�}t |¡}W d  ƒ n1 sw   Y  nt|tƒr-|}nt	d 
|¡ƒ‚| d¡| jkrDt	d 
| j¡ƒ‚tj |t¡| _dS )a³  Initializes a credential from a refresh token JSON file.

        The JSON must consist of client_id, client_secret and refresh_token fields. Refresh
        token files are typically created and managed by the gcloud SDK. To instantiate
        a credential from a refresh token file, either specify the file path or a dict
        representing the parsed contents of the file.

        Args:
          refresh_token: Path to a refresh token file or a dict representing the contents of a
              refresh token file.

        Raises:
          IOError: If the specified file doesn't exist or cannot be read.
          ValueError: If the refresh token configuration is invalid.
        Nz�Invalid refresh token argument: "{0}". Refresh token argument must be a file path, or a dict containing the parsed file contents.r   zSInvalid refresh token configuration. JSON must contain a "type" field set to "{0}".)r   rF   r   r   r    r!   r"   r#   r$   r%   r&   r'   r(   r   r)   Úfrom_authorized_user_infor+   r,   )r   Úrefresh_tokenr.   r/   r1   r   r   r   ¦   s"   
ÿ€
þÿzRefreshToken.__init__c                 C   r3   r4   )r,   Ú	client_idr   r   r   r   rJ   Æ   r6   zRefreshToken.client_idc                 C   r3   r4   )r,   Úclient_secretr   r   r   r   rK   Ê   r6   zRefreshToken.client_secretc                 C   r3   r4   )r,   rI   r   r   r   r   rI   Î   r6   zRefreshToken.refresh_tokenc                 C   r9   r:   r;   r   r   r   r   r	   Ò   r<   zRefreshToken.get_credential)r   r   r   r   r(   r   r=   rJ   rK   rI   r	   r>   r   r   r1   r   rF   ¡   s     


rF   c                 C   s&   zt  | ¡ W dS  ty   Y dS w )NTF)ÚpathlibÚPathÚ	TypeError)Úpathr   r   r   r   Ú   s   
ÿr   )r   Úcollectionsr!   rL   Úgoogle.authrC   Úgoogle.auth.transportr   Úgoogle.oauth2r   r   ÚRequestr   r+   Ú
namedtupler   r   r   r?   rF   r   r   r   r   r   Ú<module>   s"   	<'9