Ë
    W¼Sf  ã                   ó¬   — d Z ddlmZmZ ddlZddlmZmZmZmZ ddlm	Z	m
Z
mZ ddlmZ dZdefd	„Zdd
edeeef   fd„Z G d„ d«      Z G d„ d«      Zy)zFirebase App Check module.é    )ÚAnyÚDictN)ÚPyJWKClientÚExpiredSignatureErrorÚInvalidTokenErrorÚDecodeError)ÚInvalidAudienceErrorÚInvalidIssuerErrorÚInvalidSignatureError)Ú_utilsÚ
_app_checkÚreturnc                 ó@   — t        j                  | t        t        «      S ©N)r   Úget_app_serviceÚ_APP_CHECK_ATTRIBUTEÚ_AppCheckService)Úapps    úWC:\Users\user\Documents\project_loop\venv\Lib\site-packages\firebase_admin/app_check.pyÚ_get_app_check_servicer      s   € Ü×!Ñ! #Ô';Ô=MÓNÐNó    Útokenc                 ó6   — t        |«      j                  | «      S )a¥  Verifies a Firebase App Check token.

    Args:
        token: A token from App Check.
        app: An App instance (optional).

    Returns:
        Dict[str, Any]: The token's decoded claims.

    Raises:
        ValueError: If the app's ``project_id`` is invalid or unspecified,
        or if the token's headers or payload are invalid.
        PyJWKClientError: If PyJWKClient fails to fetch a valid signing key.
    )r   Úverify_token)r   r   s     r   r   r      s   € ô " #Ó&×3Ñ3°EÓ:Ð:r   c                   ód   — e Zd ZdZdZdZdZdZdZd„ Z	de
dee
ef   fd„Zd	eddfd
„Zde
de
fd„Zy)r   z?Service class that implements Firebase App Check functionality.z(https://firebaseappcheck.googleapis.com/z/https://firebaseappcheck.googleapis.com/v1/jwksNc                 ó´   — |j                   | _        | j                  st        d«      ‚d|j                   z   | _        t	        | j
                  d¬«      | _        y )Nz·A project ID must be specified to access the App Check service. Either set the projectId option, use service account credentials, or set the GOOGLE_CLOUD_PROJECT environment variable.z	projects/i`T  )Úlifespan)Ú
project_idÚ_project_idÚ
ValueErrorÚ_scoped_project_idr   Ú	_JWKS_URLÚ_jwks_client)Úselfr   s     r   Ú__init__z_AppCheckService.__init__6   sO   € àŸ>™>ˆÔØ×ÒÜð=ó>ð >ð
 #.°·±Ñ">ˆÔä'¨¯©ÀÔGˆÕr   r   r   c                 ó\  — t         j                  d|«       	 | j                  j                  |«      }| j	                  t        j                  |«      «       | j                  ||j                  «      }|j                  d«      |d<   |S # t        t        f$ r}t        d|› �«      ‚d}~ww xY w)z$Verifies a Firebase App Check token.zapp check tokenz)Verifying App Check token failed. Error: NÚsubÚapp_id)Ú_ValidatorsÚcheck_stringr#   Úget_signing_key_from_jwtÚ_has_valid_token_headersÚjwtÚget_unverified_headerÚ_decode_and_verifyÚkeyr   r   r    Úget)r$   r   Úsigning_keyÚverified_claimsÚ	exceptions        r   r   z_AppCheckService.verify_tokenD   s¨   € ä× Ñ Ð!2°EÔ:ð
	Ø×+Ñ+×DÑDÀUÓKˆKØ×)Ñ)¬#×*CÑ*CÀEÓ*JÔKØ"×5Ñ5°e¸[¿_¹_ÓMˆOð %4×$7Ñ$7¸Ó$>ˆ˜Ñ!ØÐøô "¤;Ð/ò 	ÜØ;¸I¸;ÐGóð ûð	ús   ˜AB	 Â	B+ÂB&Â&B+Úheadersc                 óŒ   — |j                  d«      dk7  rt        d«      ‚|j                  d«      }|dk7  rt        d|› d�«      ‚y)	z9Checks whether the token has valid headers for App Check.ÚtypÚJWTz9The provided App Check token has an incorrect type headerÚalgÚRS256zQThe provided App Check token has an incorrect alg header. Expected RS256 but got ú.N)r1   r    )r$   r5   Ú	algorithms      r   r,   z)_AppCheckService._has_valid_token_headersW   sZ   € ð �;‰;�uÓ Ò&ÜÐXÓYÐYà—K‘K Ó&ˆ	Ø˜ÒÜð*Ø*3¨°Að7óð ð  r   r2   c                 óˆ  — i }	 t        j                  ||dg| j                  ¬«      }|j                  d
«      }t        |t        «      r| j                  |vrt	        d«      ‚|j                  d«      j                  | j                  «      st	        d«      ‚t        j                  d|j                  d«      «       |S # t        $ r t	        d«      ‚t
        $ r t	        d| j                  › d�«      ‚t        $ r t	        d| j                  › �«      ‚t        $ r t	        d«      ‚t        $ r}t	        d|› �«      ‚d	}~ww xY w)z.Decodes and verifies the token from App Check.r:   )Ú
algorithmsÚaudiencez6The provided App Check token has an invalid signature.zbThe provided App Check token has an incorrect "aud" (audience) claim. Expected payload to include r;   z^The provided App Check token has an incorrect "iss" (issuer) claim. Expected claim to include z)The provided App Check token has expired.z(Decoding App Check token failed. Error: NÚaudz>Firebase App Check token has incorrect "aud" (audience) claim.Úissz2Token does not contain the correct "iss" (issuer).z2The provided App Check token "sub" (subject) claimr'   )r-   Údecoder!   r   r    r	   r
   Ú_APP_CHECK_ISSUERr   r   r1   Ú
isinstanceÚlistÚ
startswithr)   r*   )r$   r   r2   Úpayloadr4   r?   s         r   r/   z#_AppCheckService._decode_and_verifyd   sj  € àˆð	Ü—j‘jØØØ#˜9Ø×0Ñ0ô	ˆGð: —;‘;˜uÓ%ˆÜ˜(¤DÔ)¨T×-DÑ-DÈHÑ-TÜÐ]Ó^Ð^Ø�{‰{˜5Ó!×,Ñ,¨T×-CÑ-CÔDÜÐQÓRÐRÜ× Ñ Ø@Ø�K‰K˜Óô	 ð ˆøôA %ò 	ÜØHóð ô $ò 	Üð/Ø/3×/FÑ/FÐ.GÀqðJóð ô "ò 	Üð-Ø-1×-CÑ-CÐ,DðFóð ô %ò 	ÜØ;óð ô !ò 	ÜØ:¸9¸+ÐFóð ûð	ús   „$B> Â>A0EÄ.D<Ä<E)Ú__name__Ú
__module__Ú__qualname__Ú__doc__rC   r"   r   r!   r#   r%   Ústrr   r   r   r,   r/   © r   r   r   r   -   sg   „ ÙIàBÐØA€IØ€KØÐØ€LòHð #ð ¨$¨s°C¨x©.ó ð&°ð ¸ó ð*¨ð *¸#ô *r   r   c                   ó*   — e Zd ZdZededefd„«       Zy)r)   z‚A collection of data validation utilities.

    Methods provided in this class raise ``ValueErrors`` if any validations fail.
    ÚlabelÚvaluec                 ó”   — |€t        dj                  ||«      «      ‚t        |t        «      st        dj                  ||«      «      ‚y)z&Checks if the given value is a string.Nz%{0} "{1}" must be a non-empty string.z{0} "{1}" must be a string.)r    ÚformatrD   rL   )ÚclsrO   rP   s      r   r*   z_Validators.check_string–   sK   € ð ˆ=ÜÐD×KÑKÈEÐSXÓYÓZÐZÜ˜%¤Ô%ÜÐ:×AÑAÀ%ÈÓOÓPÐPð &r   N)rH   rI   rJ   rK   ÚclassmethodrL   r   r*   rM   r   r   r)   r)   �   s-   „ ñð
 ðQ ð Q¨Sò Qó ñQr   r)   r   )rK   Útypingr   r   r-   r   r   r   r   r	   r
   r   Úfirebase_adminr   r   r   rL   r   r   r)   rM   r   r   ú<module>rW      sg   ðñ !ç Û 
ß RÓ Rß OÑ OÝ !à#Ð ðO 3ó Oñ;˜ð ;¨$¨s°C¨x©.ó ;÷"añ a÷FQò Qr   