Ë
    U¼Sf�3  ã                   ó–   — d Z ddlZddlZddlZddlZdZ	 dZ	 dZ	 dZdZ	 G d„ d	e
«      Z G d
„ dej                  j                  «      Zy)a6  Non-API-specific IAM policy definitions

For allowed roles / permissions, see:
https://cloud.google.com/iam/docs/understanding-roles

Example usage:

.. code-block:: python

   # ``get_iam_policy`` returns a :class:'~google.api_core.iam.Policy`.
   policy = resource.get_iam_policy(requested_policy_version=3)

   phred = "user:phred@example.com"
   admin_group = "group:admins@groups.example.com"
   account = "serviceAccount:account-1234@accounts.example.com"

   policy.version = 3
   policy.bindings = [
       {
           "role": "roles/owner",
           "members": {phred, admin_group, account}
       },
       {
           "role": "roles/editor",
           "members": {"allAuthenticatedUsers"}
       },
       {
           "role": "roles/viewer",
           "members": {"allUsers"}
           "condition": {
               "title": "request_time",
               "description": "Requests made before 2021-01-01T00:00:00Z",
               "expression": "request.time < timestamp("2021-01-01T00:00:00Z")"
           }
       }
   ]

   resource.set_iam_policy(policy)
é    Nzroles/ownerzroles/editorzroles/viewerz_Assigning to '{}' is deprecated. Use the `policy.bindings` property to modify bindings instead.zWDict access is not supported on policies with version > 1 or with conditional bindings.c                   ó   — e Zd ZdZy)ÚInvalidOperationExceptionz1Raised when trying to use Policy class as a dict.N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__© ó    úRC:\Users\user\Documents\project_loop\venv\Lib\site-packages\google/api_core/iam.pyr   r   M   s   „ Ù;àr
   r   c                   ó   — e Zd ZdZefZ	 efZ	 efZ		 dd„Z
d„ Zd„ Zd„ Zd„ Zd„ Zd	„ Zd
„ Zed„ «       Zej(                  d„ «       Zed„ «       Zej(                  d„ «       Zed„ «       Zej(                  d„ «       Zed„ «       Zej(                  d„ «       Zed„ «       Zed„ «       Zed„ «       Zed„ «       Zed„ «       Zed„ «       Zed„ «       Z d„ Z!y)ÚPolicya1  IAM Policy

    Args:
        etag (Optional[str]): ETag used to identify a unique of the policy
        version (Optional[int]): The syntax schema version of the policy.

    Note:
        Using conditions in bindings requires the policy's version to be set
        to `3` or greater, depending on the versions that are currently supported.

        Accessing the policy using dict operations will raise InvalidOperationException
        when the policy's version is set to 3.

        Use the policy.bindings getter/setter to retrieve and modify the policy's bindings.

    See:
        IAM Policy https://cloud.google.com/iam/reference/rest/v1/Policy
        Policy versions https://cloud.google.com/iam/docs/policies#versions
        Conditions overview https://cloud.google.com/iam/docs/conditions-overview.
    Nc                 ó.   — || _         || _        g | _        y ©N)ÚetagÚversionÚ	_bindings)Úselfr   r   s      r   Ú__init__zPolicy.__init__r   s   € ØˆŒ	ØˆŒØˆ�r
   c                 óH   — | j                  «        d„ | j                  D «       S )Nc              3   ó2   K  — | ]  }|d    sŒ	|d   –— Œ y­w)ÚmembersÚroleNr	   )Ú.0Úbindings     r   ú	<genexpr>z"Policy.__iter__.<locals>.<genexpr>z   s   è ø€ ÒT GÀÈÓAS�˜•ÑTùs   ‚
�
)Ú__check_version__r   ©r   s    r   Ú__iter__zPolicy.__iter__w   s   € Ø×ÑÔ áT¨t¯~©~ÔTÐTr
   c                 óf   — | j                  «        t        t        | j                  «       «      «      S r   )r   ÚlenÚlistr   r   s    r   Ú__len__zPolicy.__len__|   s$   € Ø×ÑÔ ä”4˜Ÿ™›Ó(Ó)Ð)r
   c                 ó¼   — | j                  «        | j                  D ]  }|d   |k(  sŒ|d   c S  |t        «       dœ}| j                  j                  |«       |d   S ©Nr   r   ©r   r   )r   r   ÚsetÚappend)r   ÚkeyÚbÚnew_bindings       r   Ú__getitem__zPolicy.__getitem__�   sb   € Ø×ÑÔ Ø—‘ò 	$ˆAØ�‰y˜CÓØ˜‘|Ò#ð	$ð  #¬s«uÑ5ˆØ�‰×Ñ˜kÔ*Ø˜9Ñ%Ð%r
   c                 ó¶   — | j                  «        t        |«      }| j                  D ]  }|d   |k(  sŒ||d<    y  | j                  j                  ||dœ«       y r$   )r   r&   r   r'   )r   r(   Úvaluer   s       r   Ú__setitem__zPolicy.__setitem__�   s\   € Ø×ÑÔ Ü�E“
ˆØ—~‘~ò 	ˆGØ�v‰ #Ó%Ø%*�˜	Ñ"Ùð	ð 	�‰×Ñ s°uÑ=Õ>r
   c                 ó¤   — | j                  «        | j                  D ]'  }|d   |k(  sŒ| j                  j                  |«        y  t        |«      ‚)Nr   )r   r   ÚremoveÚKeyError)r   r(   r)   s      r   Ú__delitem__zPolicy.__delitem__–   sN   € Ø×ÑÔ Ø—‘ò 	ˆAØ�‰y˜CÓØ—‘×%Ñ% aÔ(Ùð	ô �s‹mÐr
   c                 ó„   — | j                   duxr | j                   dkD  }|s| j                  «       rt        t        «      ‚y)z[Raise InvalidOperationException if version is greater than 1 or policy contains conditions.Né   )r   Ú_contains_conditionsr   Ú_DICT_ACCESS_MSG)r   Úraise_versions     r   r   zPolicy.__check_version__ž   s=   € àŸ™¨DÐ0ÒE°T·\±\ÀAÑ5Eˆá˜D×5Ñ5Ô7Ü+Ô,<Ó=Ð=ð 8r
   c                 óL   — | j                   D ]  }|j                  d«      €Œ y y)NÚ	conditionTF)r   Úget)r   r)   s     r   r5   zPolicy._contains_conditions¥   s,   € Ø—‘ò 	ˆAØ�u‰u�[Ó!Ñ-Ùð	ð r
   c                 ó   — | j                   S )aE  The policy's list of bindings.

        A binding is specified by a dictionary with keys:

        * role (str): Role that is assigned to `members`.

        * members (:obj:`set` of str): Specifies the identities associated to this binding.

        * condition (:obj:`dict` of str:str): Specifies a condition under which this binding will apply.

          * title (str): Title for the condition.

          * description (:obj:str, optional): Description of the condition.

          * expression: A CEL expression.

        Type:
           :obj:`list` of :obj:`dict`

        See:
           Policy versions https://cloud.google.com/iam/docs/policies#versions
           Conditions overview https://cloud.google.com/iam/docs/conditions-overview.

        Example:

        .. code-block:: python

           USER = "user:phred@example.com"
           ADMIN_GROUP = "group:admins@groups.example.com"
           SERVICE_ACCOUNT = "serviceAccount:account-1234@accounts.example.com"
           CONDITION = {
               "title": "request_time",
               "description": "Requests made before 2021-01-01T00:00:00Z", # Optional
               "expression": "request.time < timestamp("2021-01-01T00:00:00Z")"
           }

           # Set policy's version to 3 before setting bindings containing conditions.
           policy.version = 3

           policy.bindings = [
               {
                   "role": "roles/viewer",
                   "members": {USER, ADMIN_GROUP, SERVICE_ACCOUNT},
                   "condition": CONDITION
               },
               ...
           ]
        ©r   r   s    r   ÚbindingszPolicy.bindings«   s   € ðd �~‰~Ðr
   c                 ó   — || _         y r   r<   )r   r=   s     r   r=   zPolicy.bindingsß   s	   € à!ˆ�r
   c                 óž   — t        «       }| j                  D ]*  }| j                  |d«      D ]  }|j                  |«       Œ Œ, t	        |«      S )zÒLegacy access to owner role.

        Raise InvalidOperationException if version is greater than 1 or policy contains conditions.

        DEPRECATED:  use `policy.bindings` to access bindings instead.
        r	   )r&   Ú_OWNER_ROLESr:   ÚaddÚ	frozenset©r   Úresultr   Úmembers       r   ÚownerszPolicy.ownersã   sS   € ô “ˆØ×%Ñ%ò 	#ˆDØŸ(™( 4¨Ó,ò #�Ø—
‘
˜6Õ"ñ#ð	#ô ˜Ó Ð r
   c                 óz   — t        j                  t        j                  dt        «      t
        «       || t        <   y)zÄUpdate owners.

        Raise InvalidOperationException if version is greater than 1 or policy contains conditions.

        DEPRECATED:  use `policy.bindings` to access bindings instead.
        rF   N)ÚwarningsÚwarnÚ_ASSIGNMENT_DEPRECATED_MSGÚformatÚ
OWNER_ROLEÚDeprecationWarning©r   r-   s     r   rF   zPolicy.ownersñ   s/   € ô 	�‰Ü&×-Ñ-¨h¼
ÓCÔEWô	
ð !ˆŒZÒr
   c                 óž   — t        «       }| j                  D ]*  }| j                  |d«      D ]  }|j                  |«       Œ Œ, t	        |«      S )zÓLegacy access to editor role.

        Raise InvalidOperationException if version is greater than 1 or policy contains conditions.

        DEPRECATED:  use `policy.bindings` to access bindings instead.
        r	   )r&   Ú_EDITOR_ROLESr:   rA   rB   rC   s       r   ÚeditorszPolicy.editorsþ   óS   € ô “ˆØ×&Ñ&ò 	#ˆDØŸ(™( 4¨Ó,ò #�Ø—
‘
˜6Õ"ñ#ð	#ô ˜Ó Ð r
   c                 óz   — t        j                  t        j                  dt        «      t
        «       || t        <   y)zÅUpdate editors.

        Raise InvalidOperationException if version is greater than 1 or policy contains conditions.

        DEPRECATED:  use `policy.bindings` to modify bindings instead.
        rQ   N)rH   rI   rJ   rK   ÚEDITOR_ROLErM   rN   s     r   rQ   zPolicy.editors  ó/   € ô 	�‰Ü&×-Ñ-¨i¼ÓEÜô	
ð "ˆŒ[Òr
   c                 óž   — t        «       }| j                  D ]*  }| j                  |d«      D ]  }|j                  |«       Œ Œ, t	        |«      S )zÓLegacy access to viewer role.

        Raise InvalidOperationException if version is greater than 1 or policy contains conditions.

        DEPRECATED:  use `policy.bindings` to modify bindings instead.
        r	   )r&   Ú_VIEWER_ROLESr:   rA   rB   rC   s       r   ÚviewerszPolicy.viewers  rR   r
   c                 óz   — t        j                  t        j                  dt        «      t
        «       || t        <   y)zÅUpdate viewers.

        Raise InvalidOperationException if version is greater than 1 or policy contains conditions.

        DEPRECATED:  use `policy.bindings` to modify bindings instead.
        rX   N)rH   rI   rJ   rK   ÚVIEWER_ROLErM   rN   s     r   rX   zPolicy.viewers(  rU   r
   c                 ó   — d| ›�S )zÇFactory method for a user member.

        Args:
            email (str): E-mail for this particular user.

        Returns:
            str: A member string corresponding to the given user.
        zuser:r	   ©Úemails    r   ÚuserzPolicy.user6  s   � ñ "Ð#Ð#r
   c                 ó   — d| ›�S )zéFactory method for a service account member.

        Args:
            email (str): E-mail for this particular service account.

        Returns:
            str: A member string corresponding to the given service account.

        zserviceAccount:r	   r\   s    r   Úservice_accountzPolicy.service_accountB  s   � ñ ',Ð-Ð-r
   c                 ó   — d| ›�S )zÓFactory method for a group member.

        Args:
            email (str): An id or e-mail for this particular group.

        Returns:
            str: A member string corresponding to the given group.
        zgroup:r	   r\   s    r   ÚgroupzPolicy.groupO  s   � ñ #Ð$Ð$r
   c                 ó   — d| ›�S )zÇFactory method for a domain member.

        Args:
            domain (str): The domain for this member.

        Returns:
            str: A member string corresponding to the given domain.
        zdomain:r	   )Údomains    r   rd   zPolicy.domain[  s   � ñ %Ð&Ð&r
   c                   ó   — y)z‡Factory method for a member representing all users.

        Returns:
            str: A member string representing all users.
        ÚallUsersr	   r	   r
   r   Ú	all_userszPolicy.all_usersg  s   € ð r
   c                   ó   — y)z£Factory method for a member representing all authenticated users.

        Returns:
            str: A member string representing all authenticated users.
        ÚallAuthenticatedUsersr	   r	   r
   r   Úauthenticated_userszPolicy.authenticated_usersp  s   € ð 'r
   c                 óè   — |j                  d«      }|j                  d«      } | ||«      }|j                  dg «      |_        |j                  D ]   }t        |j                  dd«      «      |d<   Œ" |S )zÖFactory: create a policy from a JSON resource.

        Args:
            resource (dict): policy resource returned by ``getIamPolicy`` API.

        Returns:
            :class:`Policy`: the parsed policy
        r   r   r=   r   r	   )r:   r=   r&   )ÚclsÚresourcer   r   Úpolicyr   s         r   Úfrom_api_reprzPolicy.from_api_repry  st   € ð —,‘,˜yÓ)ˆØ�|‰|˜FÓ#ˆÙ�T˜7Ó#ˆØ"Ÿ,™, z°2Ó6ˆŒà—‘ò 	AˆGÜ!$ W§[¡[°¸BÓ%?Ó!@ˆG�IÒð	Að ˆr
   c                 óÎ  — i }| j                   �| j                   |d<   | j                  �| j                  |d<   | j                  r t        | j                  «      dkD  rˆg }| j                  D ]P  }|j	                  d«      }|sŒ|d   t        |«      dœ}|j	                  d«      }|r||d<   |j                  |«       ŒR |r%t        j                  d«      }t        ||¬«      |d	<   |S )
z€Render a JSON policy resource.

        Returns:
            dict: a resource to be passed to the ``setIamPolicy`` API.
        r   r   r   r   r   r%   r9   )r(   r=   )	r   r   r   r    r:   Úsortedr'   ÚoperatorÚ
itemgetter)r   rm   r=   r   r   r*   r9   r(   s           r   Úto_api_reprzPolicy.to_api_repr�  sÝ   € ð ˆà�9‰9Ð Ø#Ÿy™yˆH�VÑà�<‰<Ð#Ø"&§,¡,ˆH�YÑà�>Š>œc $§.¡.Ó1°AÒ5ØˆHØŸ>™>ò 1�Ø!Ÿ+™+ iÓ0�ÚØ+2°6©?ÄvÈgÃÑ"W�KØ '§¡¨KÓ 8�IÙ Ø3<˜ KÑ0Ø—O‘O KÕ0ð1ñ ä×)Ñ)¨&Ó1�Ü'-¨h¸CÔ'@�˜Ñ$àˆr
   )NN)"r   r   r   r   rL   r@   rT   rP   rZ   rW   r   r   r"   r+   r.   r2   r   r5   Úpropertyr=   ÚsetterrF   rQ   rX   Ústaticmethodr^   r`   rb   rd   rg   rj   Úclassmethodro   rt   r	   r
   r   r   r   S   s’  „ ñð* �=€LØ5à �N€MØ6à �N€MØ6óò
Uò
*ò

&ò?òò>òð ñ1ó ð1ðf ‡_�_ñ"ó ð"ð ñ!ó ð!ð ‡]�]ñ
!ó ð
!ð ñ!ó ð!ð ‡^�^ñ"ó ð"ð ñ!ó ð!ð ‡^�^ñ"ó ð"ð ñ	$ó ð	$ð ñ
.ó ð
.ð ñ	%ó ð	%ð ñ	'ó ð	'ð ñó ðð ñ'ó ð'ð ñó ðó&r
   r   )r   ÚcollectionsÚcollections.abcrr   rH   rL   rT   rZ   rJ   r6   Ú	Exceptionr   ÚabcÚMutableMappingr   r	   r
   r   ú<module>r~      si   ðñ&óP Û Û Û ð €
Ø 4à€Ø 7à€Ø 7ðcÐ ð[Ð ô	 	ô 	ôXˆ[�_‰_×+Ñ+õ Xr
   