o
    ÔèFhC  ã                   @   sf   d Z ddlZddlmZ ddlZddlmZ ddlmZ ddlm	Z	 dZ
e
d ZG dd	„ d	ejƒZdS )
zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_helpers)Úcrypt)Ú
exceptionsz(https://iamcredentials.googleapis.com/v1z0/projects/-/serviceAccounts/{}:signBlob?alt=jsonc                   @   s@   e Zd ZdZdd„ Zdd„ Zedd„ ƒZe 	e
j¡dd	„ ƒZd
S )ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 C   s   || _ || _|| _dS )aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestÚcredentialsÚservice_account_email© r   úH/var/www/html/loop/nvenv/lib/python3.10/site-packages/google/auth/iam.pyÚ__init__-   s   
zSigner.__init__c                 C   s˜   t  |¡}d}t | j¡}ddi}t dt |¡ 	d¡i¡ 
d¡}| j | j|||¡ | j||||d�}|jtjkrCt d |j¡¡‚t |j 	d¡¡S )z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {})r   Úto_bytesÚ_SIGN_BLOB_URIÚformatr   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder   Úbefore_requestr   ÚstatusÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)r	   Úmessager   r   r   r   Úresponser   r   r   Ú_make_signing_requestA   s    
ÿþ
ÿzSigner._make_signing_requestc                 C   s   dS )zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        Nr   )r	   r   r   r   Úkey_idV   s   zSigner.key_idc                 C   s   |   |¡}t |d ¡S )NÚ
signedBlob)r(   r   Ú	b64decode)r	   r&   r'   r   r   r   Úsign`   s   
zSigner.signN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r(   Úpropertyr)   r   Úcopy_docstringr   r   r,   r   r   r   r   r   "   s    


	r   )r0   r   Úhttp.clientÚclientr!   r   Úgoogle.authr   r   r   Ú_IAM_API_ROOT_URIr   r   r   r   r   r   Ú<module>   s   