Ë
    U¼SfC  ã                   ó€   — d Z ddlZddlmZ ddlZddlmZ ddlmZ ddlm	Z	 dZ
e
dz   Z G d„ d	ej                  «      Zy)
zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_helpers)Úcrypt)Ú
exceptionsz(https://iamcredentials.googleapis.com/v1z0/projects/-/serviceAccounts/{}:signBlob?alt=jsonc                   óp   — e Zd ZdZd„ Zd„ Zed„ «       Z ej                  e
j                  «      d„ «       Zy)ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 ó.   — || _         || _        || _        y)aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestÚcredentialsÚservice_account_emails       úNC:\Users\user\Documents\project_loop\venv\Lib\site-packages\google/auth/iam.pyÚ__init__zSigner.__init__-   s   € ð   ˆŒØ'ˆÔØ&;ˆÕ#ó    c                 ór  — t        j                  |«      }d}t        j                  | j                  «      }ddi}t        j                  dt        j                  |«      j                  d«      i«      j                  d«      }| j                  j                  | j                  |||«       | j                  ||||¬«      }|j                  t        j                   k7  r.t#        j$                  dj                  |j&                  «      «      ‚t        j(                  |j&                  j                  d«      «      S )z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {})r   Úto_bytesÚ_SIGN_BLOB_URIÚformatr   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder
   Úbefore_requestr	   ÚstatusÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)r   Úmessager   r   r   r   Úresponses          r   Ú_make_signing_requestzSigner._make_signing_requestA   sû   € ä×#Ñ# GÓ,ˆàˆÜ×#Ñ# D×$?Ñ$?Ó@ˆØ!Ð#5Ð6ˆÜ�z‰zØœ×(Ñ(¨Ó1×8Ñ8¸ÓAÐBó
ç
‰&�‹/ð 	ð 	×Ñ×(Ñ(¨¯©¸ÀÀWÔMØ—=‘= S°¸dÈG�=ÓTˆà�?‰?œkŸn™nÒ,Ü×+Ñ+Ø8×?Ñ?ÀÇÁÓNóð ô �z‰z˜(Ÿ-™-×.Ñ.¨wÓ7Ó8Ð8r   c                  ó   — y)zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        N© )r   s    r   Úkey_idzSigner.key_idV   s   € ð r   c                 óT   — | j                  |«      }t        j                  |d   «      S )NÚ
signedBlob)r,   r   Ú	b64decode)r   r*   r+   s      r   ÚsignzSigner.sign`   s(   € à×-Ñ-¨gÓ6ˆÜ×Ñ ¨Ñ 6Ó7Ð7r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r,   Úpropertyr/   r   Úcopy_docstringr   r   r3   r.   r   r   r   r   "   sJ   „ ñò<ò(9ð* ñó ðð €X×Ñ˜UŸ\™\Ó*ñ8ó +ñ8r   r   )r7   r   Úhttp.clientÚclientr%   r   Úgoogle.authr   r   r   Ú_IAM_API_ROOT_URIr   r   r.   r   r   ú<module>r>      sA   ðñó Ý !Û å  Ý Ý "à>Ð Ø"Ð%WÑW€ôA8ˆU�\‰\õ A8r   