o
    ×èFhc  ã                   @   sˆ   d Z ddlmZ ddlmZ ddlmZ ddlmZ G dd„ deƒZ	G dd	„ d	eƒZ
G d
d„ de
ƒZG dd„ deƒZG dd„ de
ƒZdS )z%Manage access to objects and buckets.é    )Ú _add_generation_match_parameters)Ú_DEFAULT_TIMEOUT)ÚDEFAULT_RETRY)Ú)DEFAULT_RETRY_IF_METAGENERATION_SPECIFIEDc                   @   s~   e Zd ZdZdZdZdZddd„Zdd	„ Zd
d„ Z	dd„ Z
dd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ ZdS )Ú
_ACLEntitya¾  Class representing a set of roles for an entity.

    This is a helper class that you likely won't ever construct
    outside of using the factor methods on the :class:`ACL` object.

    :type entity_type: str
    :param entity_type: The type of entity (ie, 'group' or 'user').

    :type identifier: str
    :param identifier: (Optional) The ID or e-mail of the entity. For the special
                       entity types (like 'allUsers').
    ÚREADERÚWRITERÚOWNERNc                 C   s   || _ tg ƒ| _|| _d S ©N)Ú
identifierÚsetÚrolesÚtype)ÚselfÚentity_typer   © r   úQ/var/www/html/loop/nvenv/lib/python3.10/site-packages/google/cloud/storage/acl.pyÚ__init__)   s   

z_ACLEntity.__init__c                 C   s   | j st| jƒS dj| d�S )Nz{acl.type}-{acl.identifier})Úacl)r   Ústrr   Úformat©r   r   r   r   Ú__str__.   s   
z_ACLEntity.__str__c                 C   s   d| › dd  | j¡› d�S )Nz<ACL Entity: z (z, z)>)Újoinr   r   r   r   r   Ú__repr__4   s   z_ACLEntity.__repr__c                 C   s   | j S )zšGet the list of roles permitted by this entity.

        :rtype: list of strings
        :returns: The list of roles associated with this entity.
        )r   r   r   r   r   Ú	get_roles7   s   z_ACLEntity.get_rolesc                 C   s   | j  |¡ dS )zoAdd a role to the entity.

        :type role: str
        :param role: The role to add to the entity.
        N)r   Úadd©r   Úroler   r   r   Úgrant?   s   z_ACLEntity.grantc                 C   s   || j v r| j  |¡ dS dS )zyRemove a role from the entity.

        :type role: str
        :param role: The role to remove from the entity.
        N)r   Úremover   r   r   r   ÚrevokeG   s   
ÿz_ACLEntity.revokec                 C   ó   |   tj¡ dS )z(Grant read access to the current entity.N)r   r   ÚREADER_ROLEr   r   r   r   Ú
grant_readP   ó   z_ACLEntity.grant_readc                 C   r"   )z)Grant write access to the current entity.N)r   r   ÚWRITER_ROLEr   r   r   r   Úgrant_writeT   r%   z_ACLEntity.grant_writec                 C   r"   )z)Grant owner access to the current entity.N)r   r   Ú
OWNER_ROLEr   r   r   r   Úgrant_ownerX   r%   z_ACLEntity.grant_ownerc                 C   r"   )z+Revoke read access from the current entity.N)r!   r   r#   r   r   r   r   Úrevoke_read\   r%   z_ACLEntity.revoke_readc                 C   r"   )z,Revoke write access from the current entity.N)r!   r   r&   r   r   r   r   Úrevoke_write`   r%   z_ACLEntity.revoke_writec                 C   r"   )z,Revoke owner access from the current entity.N)r!   r   r(   r   r   r   r   Úrevoke_ownerd   r%   z_ACLEntity.revoke_ownerr
   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r#   r&   r(   r   r   r   r   r   r!   r$   r'   r)   r*   r+   r,   r   r   r   r   r      s"    
	r   c                   @   sX  e Zd ZdZdZdZdddddd	d
œZeg d¢ƒZ	 dZ	dZ
dZdZdd„ Zefdd„Zedd„ ƒZdd„ Zdd„ Zdd„ Zdd„ Zd<dd„Zdd„ Zd<d d!„Zd"d#„ Zd$d%„ Zd&d'„ Zd(d)„ Zd*d+„ Zd,d-„ Zed.d/„ ƒZ d0d1„ Z!dee"fd2d3„Z#ddddee$fd4d5„Z%ddddddee$fd6d7„Z&dddddee$fd8d9„Z'dddddee$fd:d;„Z(dS )=ÚACLz7Container class representing a list of access controls.r   ÚpredefinedAclÚprojectPrivateÚ
publicReadÚpublicReadWriteÚauthenticatedReadÚbucketOwnerReadÚbucketOwnerFullControl)zproject-privatezpublic-readzpublic-read-writezauthenticated-readzbucket-owner-readzbucket-owner-full-control)Úprivater3   r4   r5   r6   r7   r8   FNc                 C   s
   i | _ d S r
   )Úentitiesr   r   r   r   r   �   s   
zACL.__init__c                 C   s   | j s| j|d� dS dS )zéLoad if not already loaded.

        :type timeout: float or tuple
        :param timeout:
            (Optional) The amount of time, in seconds, to wait
            for the server response.  See: :ref:`configuring_timeouts`
        )ÚtimeoutN)ÚloadedÚreload)r   r;   r   r   r   Ú_ensure_loaded“   s   ÿzACL._ensure_loadedc                 C   s.   | j  ||¡}|r|| jvrtd|› �ƒ‚|S )a:  Ensures predefined is in list of predefined json values

        :type predefined: str
        :param predefined: name of a predefined acl

        :type predefined: str
        :param predefined: validated JSON name of predefined acl

        :raises: :exc: `ValueError`: If predefined is not a valid acl
        zInvalid predefined ACL: )ÚPREDEFINED_XML_ACLSÚgetÚPREDEFINED_JSON_ACLSÚ
ValueError)ÚclsÚ
predefinedr   r   r   Úvalidate_predefinedž   s   zACL.validate_predefinedc                 C   s   | j  ¡  d| _dS )z@Remove all entities from the ACL, and clear the ``loaded`` flag.FN)r:   Úclearr<   r   r   r   r   Úreset¯   s   

z	ACL.resetc                 c   s@   � |   ¡  | j ¡ D ]}| ¡ D ]}|rt|ƒ|dœV  qq
d S )N)Úentityr   )r>   r:   Úvaluesr   r   )r   rH   r   r   r   r   Ú__iter__´   s   €€þÿzACL.__iter__c                 C   s€   |d }|d }|dkr|   ¡ }n|dkr|  ¡ }nd|v r-| dd¡\}}| j||d�}t|tƒs9td|› �ƒ‚| |¡ |S )	aÄ  Build an _ACLEntity object from a dictionary of data.

        An entity is a mutable object that represents a list of roles
        belonging to either a user or group or the special types for all
        users and all authenticated users.

        :type entity_dict: dict
        :param entity_dict: Dictionary full of data from an ACL lookup.

        :rtype: :class:`_ACLEntity`
        :returns: An Entity constructed from the dictionary.
        rH   r   ÚallUsersÚallAuthenticatedUsersú-é   ©r   r   zInvalid dictionary: )ÚallÚall_authenticatedÚsplitrH   Ú
isinstancer   rB   r   )r   Úentity_dictrH   r   r   r   r   r   r   Úentity_from_dict¼   s   



zACL.entity_from_dictc                 C   s   |   ¡  t|ƒ| jv S )a  Returns whether or not this ACL has any entries for an entity.

        :type entity: :class:`_ACLEntity`
        :param entity: The entity to check for existence in this ACL.

        :rtype: bool
        :returns: True of the entity exists in the ACL.
        )r>   r   r:   ©r   rH   r   r   r   Ú
has_entityÜ   s   	zACL.has_entityc                 C   s   |   ¡  | j t|ƒ|¡S )a¯  Gets an entity object from the ACL.

        :type entity: :class:`_ACLEntity` or string
        :param entity: The entity to get lookup in the ACL.

        :type default: anything
        :param default: This value will be returned if the entity
                        doesn't exist.

        :rtype: :class:`_ACLEntity`
        :returns: The corresponding entity or the value provided
                  to ``default``.
        )r>   r:   r@   r   )r   rH   Údefaultr   r   r   Ú
get_entityè   s   zACL.get_entityc                 C   s   |   ¡  || jt|ƒ< dS )zƒAdd an entity to the ACL.

        :type entity: :class:`_ACLEntity`
        :param entity: The entity to add to this ACL.
        N)r>   r:   r   rV   r   r   r   Ú
add_entityù   s   zACL.add_entityc                 C   s2   t ||d�}|  |¡r|  |¡}|S |  |¡ |S )aÇ  Factory method for creating an Entity.

        If an entity with the same type and identifier already exists,
        this will return a reference to that entity.  If not, it will
        create a new one and add it to the list of known entities for
        this ACL.

        :type entity_type: str
        :param entity_type: The type of entity to create
                            (ie, ``user``, ``group``, etc)

        :type identifier: str
        :param identifier: The ID of the entity (if applicable).
                           This can be either an ID or an e-mail address.

        :rtype: :class:`_ACLEntity`
        :returns: A new Entity or a reference to an existing identical entity.
        rO   )r   rW   rY   rZ   )r   r   r   rH   r   r   r   rH     s   


ÿz
ACL.entityc                 C   ó   | j d|d�S )zëFactory method for a user Entity.

        :type identifier: str
        :param identifier: An id or e-mail for this particular user.

        :rtype: :class:`_ACLEntity`
        :returns: An Entity corresponding to this user.
        Úuser©r   ©rH   ©r   r   r   r   r   r\     ó   	zACL.userc                 C   r[   )zîFactory method for a group Entity.

        :type identifier: str
        :param identifier: An id or e-mail for this particular group.

        :rtype: :class:`_ACLEntity`
        :returns: An Entity corresponding to this group.
        Úgroupr]   r^   r_   r   r   r   ra   '  r`   z	ACL.groupc                 C   r[   )zÙFactory method for a domain Entity.

        :type domain: str
        :param domain: The domain for this entity.

        :rtype: :class:`_ACLEntity`
        :returns: An entity corresponding to this domain.
        Údomainr]   r^   )r   rb   r   r   r   rb   2  r`   z
ACL.domainc                 C   ó
   |   d¡S )z–Factory method for an Entity representing all users.

        :rtype: :class:`_ACLEntity`
        :returns: An entity representing all users.
        rK   r^   r   r   r   r   rP   =  ó   
zACL.allc                 C   rc   )z²Factory method for an Entity representing all authenticated users.

        :rtype: :class:`_ACLEntity`
        :returns: An entity representing all authenticated users.
        rL   r^   r   r   r   r   rQ   E  rd   zACL.all_authenticatedc                 C   s   |   ¡  t| j ¡ ƒS )z�Get a list of all Entity objects.

        :rtype: list of :class:`_ACLEntity` objects
        :returns: A list of all Entity objects.
        )r>   Úlistr:   rI   r   r   r   r   Úget_entitiesM  s   zACL.get_entitiesc                 C   s   t ‚)z&Abstract getter for the object client.)ÚNotImplementedErrorr   r   r   r   ÚclientV  s   z
ACL.clientc                 C   s   |du r| j }|S )a   Check client or verify over-ride.

        :type client: :class:`~google.cloud.storage.client.Client` or
                      ``NoneType``
        :param client: the client to use.  If not passed, falls back to the
                       ``client`` stored on the current ACL.

        :rtype: :class:`google.cloud.storage.client.Client`
        :returns: The client passed in or the currently bound client.
        N)rh   )r   rh   r   r   r   Ú_require_client[  s   zACL._require_clientc                 C   sp   | j }|  |¡}i }| jdur| j|d< | j ¡  |j||||d�}d| _| dd¡D ]
}|  |  	|¡¡ q+dS )aâ  Reload the ACL data from Cloud Storage.

        If :attr:`user_project` is set, bills the API request to that project.

        :type client: :class:`~google.cloud.storage.client.Client` or
                      ``NoneType``
        :param client: (Optional) The client to use.  If not passed, falls back
                       to the ``client`` stored on the ACL's parent.
        :type timeout: float or tuple
        :param timeout:
            (Optional) The amount of time, in seconds, to wait
            for the server response.  See: :ref:`configuring_timeouts`

        :type retry: :class:`~google.api_core.retry.Retry`
        :param retry:
            (Optional) How to retry the RPC. See: :ref:`configuring_retries`
        NÚuserProject©Úquery_paramsr;   ÚretryTÚitemsr   )
Úreload_pathri   Úuser_projectr:   rF   Ú_get_resourcer<   r@   rZ   rU   )r   rh   r;   rm   Úpathrl   ÚfoundÚentryr   r   r   r=   j  s    



üÿz
ACL.reloadc
                 C   sª   |   |¡}ddi}
|durg }||
| j< | jdur| j|
d< t|
||||d� | j}|j|| jt|ƒi|
||	d�}| j 	¡  | 
| jd¡D ]
}|  |  |¡¡ qEd| _dS )	a¢  Helper for :meth:`save` and :meth:`save_predefined`.

        :type acl: :class:`google.cloud.storage.acl.ACL`, or a compatible list.
        :param acl: The ACL object to save.  If left blank, this will save
                    current entries.

        :type predefined: str
        :param predefined: An identifier for a predefined ACL.  Must be one of the
            keys in :attr:`PREDEFINED_JSON_ACLS` If passed, `acl` must be None.

        :type client: :class:`~google.cloud.storage.client.Client` or
                      ``NoneType``
        :param client: (Optional) The client to use.  If not passed, falls back
                       to the ``client`` stored on the ACL's parent.

        :type if_generation_match: long
        :param if_generation_match:
            (Optional) See :ref:`using-if-generation-match`

        :type if_generation_not_match: long
        :param if_generation_not_match:
            (Optional) See :ref:`using-if-generation-not-match`

        :type if_metageneration_match: long
        :param if_metageneration_match:
            (Optional) See :ref:`using-if-metageneration-match`

        :type if_metageneration_not_match: long
        :param if_metageneration_not_match:
            (Optional) See :ref:`using-if-metageneration-not-match`

        :type timeout: float or tuple
        :param timeout:
            (Optional) The amount of time, in seconds, to wait
            for the server response.  See: :ref:`configuring_timeouts`

        :type retry: google.api_core.retry.Retry or google.cloud.storage.retry.ConditionalRetryPolicy
        :param retry:
            (Optional) How to retry the RPC. See: :ref:`configuring_retries`
        Ú
projectionÚfullNrj   )Úif_generation_matchÚif_generation_not_matchÚif_metageneration_matchÚif_metageneration_not_matchrk   r   T)ri   Ú_PREDEFINED_QUERY_PARAMrp   r   Ú	save_pathÚ_patch_resourceÚ_URL_PATH_ELEMre   r:   rF   r@   rZ   rU   r<   )r   r   rD   rh   rw   rx   ry   rz   r;   rm   rl   rr   Úresultrt   r   r   r   Ú_save�  s4   
4


ûû

z	ACL._savec	           
      C   s@   |du r
| }|j }	nd}	|	r| j|d|||||||d�	 dS dS )a!  Save this ACL for the current bucket.

        If :attr:`user_project` is set, bills the API request to that project.

        :type acl: :class:`google.cloud.storage.acl.ACL`, or a compatible list.
        :param acl: The ACL object to save.  If left blank, this will save
                    current entries.

        :type client: :class:`~google.cloud.storage.client.Client` or
                      ``NoneType``
        :param client: (Optional) The client to use.  If not passed, falls back
                       to the ``client`` stored on the ACL's parent.

        :type if_generation_match: long
        :param if_generation_match:
            (Optional) See :ref:`using-if-generation-match`

        :type if_generation_not_match: long
        :param if_generation_not_match:
            (Optional) See :ref:`using-if-generation-not-match`

        :type if_metageneration_match: long
        :param if_metageneration_match:
            (Optional) See :ref:`using-if-metageneration-match`

        :type if_metageneration_not_match: long
        :param if_metageneration_not_match:
            (Optional) See :ref:`using-if-metageneration-not-match`

        :type timeout: float or tuple
        :param timeout:
            (Optional) The amount of time, in seconds, to wait
            for the server response.  See: :ref:`configuring_timeouts`

        :type retry: google.api_core.retry.Retry or google.cloud.storage.retry.ConditionalRetryPolicy
        :param retry:
            (Optional) How to retry the RPC. See: :ref:`configuring_retries`
        NT©rw   rx   ry   rz   r;   rm   )r<   r€   )
r   r   rh   rw   rx   ry   rz   r;   rm   Úsave_to_backendr   r   r   Úsaveç  s"   1
÷ÿzACL.savec	           	      C   s*   |   |¡}| jd||||||||d�	 dS )að  Save this ACL for the current bucket using a predefined ACL.

        If :attr:`user_project` is set, bills the API request to that project.

        :type predefined: str
        :param predefined: An identifier for a predefined ACL.  Must be one
                           of the keys in :attr:`PREDEFINED_JSON_ACLS`
                           or :attr:`PREDEFINED_XML_ACLS` (which will be
                           aliased to the corresponding JSON name).
                           If passed, `acl` must be None.

        :type client: :class:`~google.cloud.storage.client.Client` or
                      ``NoneType``
        :param client: (Optional) The client to use.  If not passed, falls back
                       to the ``client`` stored on the ACL's parent.

        :type if_generation_match: long
        :param if_generation_match:
            (Optional) See :ref:`using-if-generation-match`

        :type if_generation_not_match: long
        :param if_generation_not_match:
            (Optional) See :ref:`using-if-generation-not-match`

        :type if_metageneration_match: long
        :param if_metageneration_match:
            (Optional) See :ref:`using-if-metageneration-match`

        :type if_metageneration_not_match: long
        :param if_metageneration_not_match:
            (Optional) See :ref:`using-if-metageneration-not-match`

        :type timeout: float or tuple
        :param timeout:
            (Optional) The amount of time, in seconds, to wait
            for the server response.  See: :ref:`configuring_timeouts`

        :type retry: google.api_core.retry.Retry or google.cloud.storage.retry.ConditionalRetryPolicy
        :param retry:
            (Optional) How to retry the RPC. See: :ref:`configuring_retries`
        Nr�   )rE   r€   )	r   rD   rh   rw   rx   ry   rz   r;   rm   r   r   r   Úsave_predefined+  s   
4
÷zACL.save_predefinedc              
   C   s   | j g |||||||d� dS )aI  Remove all ACL entries.

        If :attr:`user_project` is set, bills the API request to that project.

        Note that this won't actually remove *ALL* the rules, but it
        will remove all the non-default rules.  In short, you'll still
        have access to a bucket that you created even after you clear
        ACL rules with this method.

        :type client: :class:`~google.cloud.storage.client.Client` or
                      ``NoneType``
        :param client: (Optional) The client to use.  If not passed, falls back
                       to the ``client`` stored on the ACL's parent.

        :type if_generation_match: long
        :param if_generation_match:
            (Optional) See :ref:`using-if-generation-match`

        :type if_generation_not_match: long
        :param if_generation_not_match:
            (Optional) See :ref:`using-if-generation-not-match`

        :type if_metageneration_match: long
        :param if_metageneration_match:
            (Optional) See :ref:`using-if-metageneration-match`

        :type if_metageneration_not_match: long
        :param if_metageneration_not_match:
            (Optional) See :ref:`using-if-metageneration-not-match`

        :type timeout: float or tuple
        :param timeout:
            (Optional) The amount of time, in seconds, to wait
            for the server response.  See: :ref:`configuring_timeouts`

        :type retry: google.api_core.retry.Retry or google.cloud.storage.retry.ConditionalRetryPolicy
        :param retry:
            (Optional) How to retry the RPC. See: :ref:`configuring_retries`
        )rh   rw   rx   ry   rz   r;   rm   N)rƒ   )r   rh   rw   rx   ry   rz   r;   rm   r   r   r   rF   l  s   1
øz	ACL.clearr
   ))r-   r.   r/   r0   r~   r{   r?   Ú	frozensetrA   r<   ro   r|   rp   r   r   r>   ÚclassmethodrE   rG   rJ   rU   rW   rY   rZ   rH   r\   ra   rb   rP   rQ   rf   Úpropertyrh   ri   r   r=   r   r€   rƒ   r„   rF   r   r   r   r   r1   i   s�    ù
ÿ
 

		
+
öY
÷G
÷Cør1   c                       óP   e Zd ZdZ‡ fdd„Zedd„ ƒZedd„ ƒZedd	„ ƒZed
d„ ƒZ	‡  Z
S )Ú	BucketACLzžAn ACL specifically for a bucket.

    :type bucket: :class:`google.cloud.storage.bucket.Bucket`
    :param bucket: The bucket to which this ACL relates.
    c                    ó   t t| ƒ ¡  || _d S r
   )Úsuperr‰   r   Úbucket)r   rŒ   ©Ú	__class__r   r   r   °  ó   
zBucketACL.__init__c                 C   ó   | j jS )z&The client bound to this ACL's bucket.)rŒ   rh   r   r   r   r   rh   ´  ó   zBucketACL.clientc                 C   s   | j j› d| j› �S )ú3Compute the path for GET API requests for this ACL.ú/)rŒ   rr   r~   r   r   r   r   ro   ¹  s   zBucketACL.reload_pathc                 C   r�   ©z5Compute the path for PATCH API requests for this ACL.)rŒ   rr   r   r   r   r   r|   ¾  r‘   zBucketACL.save_pathc                 C   r�   ©z?Compute the user project charged for API requests for this ACL.)rŒ   rp   r   r   r   r   rp   Ã  r‘   zBucketACL.user_project©r-   r.   r/   r0   r   r‡   rh   ro   r|   rp   Ú__classcell__r   r   r�   r   r‰   ©  ó    


r‰   c                   @   s   e Zd ZdZdZdZdS )ÚDefaultObjectACLz9A class representing the default object ACL for a bucket.ÚdefaultObjectAclÚpredefinedDefaultObjectAclN)r-   r.   r/   r0   r~   r{   r   r   r   r   r™   É  s    r™   c                       rˆ   )Ú	ObjectACLz¬An ACL specifically for a Cloud Storage object / blob.

    :type blob: :class:`google.cloud.storage.blob.Blob`
    :param blob: The blob that this ACL corresponds to.
    c                    rŠ   r
   )r‹   rœ   r   Úblob)r   r�   r�   r   r   r   ×  r�   zObjectACL.__init__c                 C   r�   )z$The client bound to this ACL's blob.)r�   rh   r   r   r   r   rh   Û  r‘   zObjectACL.clientc                 C   s   | j j› d�S )r’   z/acl©r�   rr   r   r   r   r   ro   à  s   zObjectACL.reload_pathc                 C   r�   r”   rž   r   r   r   r   r|   å  r‘   zObjectACL.save_pathc                 C   r�   r•   )r�   rp   r   r   r   r   rp   ê  r‘   zObjectACL.user_projectr–   r   r   r�   r   rœ   Ð  r˜   rœ   N)r0   Úgoogle.cloud.storage._helpersr   Úgoogle.cloud.storage.constantsr   Úgoogle.cloud.storage.retryr   r   Úobjectr   r1   r‰   r™   rœ   r   r   r   r   Ú<module>   s   R    D 