Ë
    U¼SfOB  ã                   ó  — d Z ddlZddlZddlmZ ddlmZ ddlZddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ddlmZ d	gZd
ZdZdZdZdZdZ	 dd„Z G d„ de
j,                  e
j.                  e
j0                  «      Z G d„ de
j.                  «      Zy)aÇ  Google Cloud Impersonated credentials.

This module provides authentication for applications where local credentials
impersonates a remote service account using `IAM Credentials API`_.

This class can be used to impersonate a service account as long as the original
Credential object has the "Service Account Token Creator" role on the target
service account.

    .. _IAM Credentials API:
        https://cloud.google.com/iam/credentials/reference/rest/
é    N)Údatetime)Ú_helpers)Úcredentials)Ú
exceptions)Újwt)Úmetricsz#https://www.googleapis.com/auth/iamzZhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateAccessTokenzOhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:signBlobzVhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateIdTokenz*Unable to acquire impersonated credentialsi  z#https://oauth2.googleapis.com/tokenc                 ór  — |xs t         j                  |«      }t        j                  |«      j	                  d«      } | |d||¬«      }t        |j                  d«      r|j                  j                  d«      n|j                  }|j                  t        j                  k7  rt        j                  t        |«      ‚	 t        j                  |«      }|d   }	t        j                   |d   d«      }
|	|
fS # t"        t$        f$ r1}t        j                  dj                  t        «      |«      }||‚d	}~ww xY w)
aÅ  Makes a request to the Google Cloud IAM service for an access token.
    Args:
        request (Request): The Request object to use.
        principal (str): The principal to request an access token for.
        headers (Mapping[str, str]): Map of headers to transmit.
        body (Mapping[str, str]): JSON Payload body for the iamcredentials
            API call.
        iam_endpoint_override (Optiona[str]): The full IAM endpoint override
            with the target_principal embedded. This is useful when supporting
            impersonation with regional endpoints.

    Raises:
        google.auth.exceptions.TransportError: Raised if there is an underlying
            HTTP connection error
        google.auth.exceptions.RefreshError: Raised if the impersonated
            credentials are not available.  Common reasons are
            `iamcredentials.googleapis.com` is not enabled or the
            `Service Account Token Creator` is not assigned
    úutf-8ÚPOST)ÚurlÚmethodÚheadersÚbodyÚdecodeÚaccessTokenÚ
expireTimez%Y-%m-%dT%H:%M:%SZz6{}: No access token or invalid expiration in response.N)Ú_IAM_ENDPOINTÚformatÚjsonÚdumpsÚencodeÚhasattrÚdatar   ÚstatusÚhttp_clientÚOKr   ÚRefreshErrorÚ_REFRESH_ERRORÚloadsr   ÚstrptimeÚKeyErrorÚ
ValueError)ÚrequestÚ	principalr   r   Úiam_endpoint_overrideÚiam_endpointÚresponseÚresponse_bodyÚtoken_responseÚtokenÚexpiryÚ
caught_excÚnew_excs                úcC:\Users\user\Documents\project_loop\venv\Lib\site-packages\google/auth/impersonated_credentials.pyÚ_make_iam_token_requestr/   @   s  € ð, )ÒK¬M×,@Ñ,@ÀÓ,K€Lä�:‰:�dÓ×"Ñ" 7Ó+€Dá˜<°ÀÈdÔS€Hô
 �8—=‘= (Ô+ð 	�‰×Ñ˜WÔ%à�]‰]ð ð ‡�œ+Ÿ.™.Ò(Ü×%Ñ%¤n°mÓDÐDð&ÜŸ™ MÓ2ˆØ˜}Ñ-ˆÜ×"Ñ" >°,Ñ#?ÐAUÓVˆà�fˆ}Ðøä”jÐ!ò &Ü×)Ñ)ØD×KÑKÜóð ó	
ˆð ˜:Ð%ûð&ús   Â?6C6 Ã6D6Ä,D1Ä1D6c                   óL  ‡ — e Zd ZdZdeddfˆ fd„	Zd„ Z ej                  e	j                  «      d„ «       Zd„ Zd„ Zed„ «       Zed	„ «       Zed
„ «       Zed„ «       Z ej                  e	j&                  «      d„ «       Z ej                  e	j*                  «      dd„«       Zˆ xZS )ÚCredentialsaÒ  This module defines impersonated credentials which are essentially
    impersonated identities.

    Impersonated Credentials allows credentials issued to a user or
    service account to impersonate another. The target service account must
    grant the originating credential principal the
    `Service Account Token Creator`_ IAM role:

    For more information about Token Creator IAM role and
    IAMCredentials API, see
    `Creating Short-Lived Service Account Credentials`_.

    .. _Service Account Token Creator:
        https://cloud.google.com/iam/docs/service-accounts#the_service_account_token_creator_role

    .. _Creating Short-Lived Service Account Credentials:
        https://cloud.google.com/iam/docs/creating-short-lived-service-account-credentials

    Usage:

    First grant source_credentials the `Service Account Token Creator`
    role on the target account to impersonate.   In this example, the
    service account represented by svc_account.json has the
    token creator role on
    `impersonated-account@_project_.iam.gserviceaccount.com`.

    Enable the IAMCredentials API on the source project:
    `gcloud services enable iamcredentials.googleapis.com`.

    Initialize a source credential which does not have access to
    list bucket::

        from google.oauth2 import service_account

        target_scopes = [
            'https://www.googleapis.com/auth/devstorage.read_only']

        source_credentials = (
            service_account.Credentials.from_service_account_file(
                '/path/to/svc_account.json',
                scopes=target_scopes))

    Now use the source credentials to acquire credentials to impersonate
    another service account::

        from google.auth import impersonated_credentials

        target_credentials = impersonated_credentials.Credentials(
          source_credentials=source_credentials,
          target_principal='impersonated-account@_project_.iam.gserviceaccount.com',
          target_scopes = target_scopes,
          lifetime=500)

    Resource access is granted::

        client = storage.Client(credentials=target_credentials)
        buckets = client.list_buckets(project='your_project')
        for bucket in buckets:
          print(bucket.name)
    Nc                 ó   •— t         t        | �  «        t        j                  |«      | _        t        | j                  t        j                  «      rk| j                  j                  t        «      | _        t        | j                  d«      r1| j                  j                  r| j                  j                  d«       || _        || _        || _        |xs t         | _        d| _        t'        j(                  «       | _        || _        || _        y)aL  
        Args:
            source_credentials (google.auth.Credentials): The source credential
                used as to acquire the impersonated credentials.
            target_principal (str): The service account to impersonate.
            target_scopes (Sequence[str]): Scopes to request during the
                authorization grant.
            delegates (Sequence[str]): The chained list of delegates required
                to grant the final access_token.  If set, the sequence of
                identities must have "Service Account Token Creator" capability
                granted to the prceeding identity.  For example, if set to
                [serviceAccountB, serviceAccountC], the source_credential
                must have the Token Creator role on serviceAccountB.
                serviceAccountB must have the Token Creator on
                serviceAccountC.
                Finally, C must have Token Creator on target_principal.
                If left unset, source_credential must have that role on
                target_principal.
            lifetime (int): Number of seconds the delegated credential should
                be valid for (upto 3600).
            quota_project_id (Optional[str]): The project ID used for quota and billing.
                This project may be different from the project used to
                create the credentials.
            iam_endpoint_override (Optiona[str]): The full IAM endpoint override
                with the target_principal embedded. This is useful when supporting
                impersonation with regional endpoints.
        Ú_create_self_signed_jwtN)Úsuperr1   Ú__init__ÚcopyÚ_source_credentialsÚ
isinstancer   ÚScopedÚwith_scopesÚ
_IAM_SCOPEr   Ú_always_use_jwt_accessr3   Ú_target_principalÚ_target_scopesÚ
_delegatesÚ_DEFAULT_TOKEN_LIFETIME_SECSÚ	_lifetimer*   r   Úutcnowr+   Ú_quota_project_idÚ_iam_endpoint_override)	ÚselfÚsource_credentialsÚtarget_principalÚtarget_scopesÚ	delegatesÚlifetimeÚquota_project_idr%   Ú	__class__s	           €r.   r5   zCredentials.__init__·   sÕ   ø€ ôL 	Œk˜4Ñ)Ô+ä#'§9¡9Ð-?Ó#@ˆÔ ô �d×.Ñ.´×0BÑ0BÔCØ'+×'?Ñ'?×'KÑ'KÌJÓ'WˆDÔ$ô ˜×0Ñ0Ð2KÔLØ×,Ñ,×CÒCà×(Ñ(×@Ñ@ÀÔFØ!1ˆÔØ+ˆÔØ#ˆŒØ!ÒAÔ%AˆŒØˆŒ
Ü—o‘oÓ'ˆŒØ!1ˆÔØ&;ˆÕ#ó    c                 ó"   — t         j                  S ©N)r   ÚCRED_TYPE_SA_IMPERSONATE©rE   s    r.   Ú_metric_header_for_usagez$Credentials._metric_header_for_usageõ   s   € Ü×/Ñ/Ð/rM   c                 ó&   — | j                  |«       y rO   )Ú_update_token)rE   r#   s     r.   ÚrefreshzCredentials.refreshø   s   € à×Ñ˜7Õ#rM   c                 óB  — | j                   j                  t        j                  j                  k(  s1| j                   j                  t        j                  j
                  k(  r| j                   j                  |«       | j                  | j                  t        | j                  «      dz   dœ}ddt        j                  t        j                  «       i}| j                   j                  |«       t        || j                   ||| j"                  ¬«      \  | _        | _        y)zòUpdates credentials with a new access_token representing
        the impersonated account.

        Args:
            request (google.auth.transport.requests.Request): Request object
                to use for refreshing credentials.
        Ús)rI   ÚscoperJ   úContent-Typeúapplication/json)r#   r$   r   r   r%   N)r7   Útoken_stater   Ú
TokenStateÚSTALEÚINVALIDrU   r?   r>   ÚstrrA   r   ÚAPI_CLIENT_HEADERÚ&token_request_access_token_impersonateÚapplyr/   r=   rD   r*   r+   )rE   r#   r   r   s       r.   rT   zCredentials._update_tokenü   sé   € ð ×$Ñ$×0Ñ0´K×4JÑ4J×4PÑ4PÒPØ×'Ñ'×3Ñ3´{×7MÑ7M×7UÑ7UÒUà×$Ñ$×,Ñ,¨WÔ5ð Ÿ™Ø×(Ñ(Ü˜DŸN™NÓ+¨cÑ1ñ
ˆð Ð.Ü×%Ñ%¤w×'UÑ'UÓ'Wð
ˆð 	× Ñ ×&Ñ& wÔ/ä"9ØØ×,Ñ,ØØØ"&×"=Ñ"=ô#
ÑˆŒ
�D•KrM   c                 ó8  — ddl m} t        j                  | j                  «      }t        j                  |«      j                  d«      | j                  dœ}ddi} || j                  «      }	 |j                  |||¬«      }|j                  «        |j                  t        j                  k7  r2t        j                   dj                  |j#                  «       «      «      ‚t        j$                  |j#                  «       d	   «      S # |j                  «        w xY w)
Nr   ©ÚAuthorizedSessionr
   )ÚpayloadrI   rY   rZ   )r   r   r   zError calling sign_bytes: {}Ú
signedBlob)Úgoogle.auth.transport.requestsre   Ú_IAM_SIGN_ENDPOINTr   r=   Úbase64Ú	b64encoder   r?   r7   ÚpostÚcloseÚstatus_coder   r   r   ÚTransportErrorr   Ú	b64decode)rE   Úmessagere   Úiam_sign_endpointr   r   Úauthed_sessionr'   s           r.   Ú
sign_byteszCredentials.sign_bytes"  sø   € ÝDä.×5Ñ5°d×6LÑ6LÓMÐô ×'Ñ'¨Ó0×7Ñ7¸Ó@ØŸ™ñ
ˆð
 "Ð#5Ð6ˆá*¨4×+CÑ+CÓDˆð	#Ø%×*Ñ*Ø%¨w¸Tð +ó ˆHð × Ñ Ô"à×Ñ¤;§>¡>Ò1Ü×+Ñ+Ø.×5Ñ5°h·m±m³oÓFóð ô ×Ñ §¡£°Ñ =Ó>Ð>øð × Ñ Õ"ús   Á.D ÄDc                 ó   — | j                   S rO   ©r=   rQ   s    r.   Úsigner_emailzCredentials.signer_email>  ó   € à×%Ñ%Ð%rM   c                 ó   — | j                   S rO   rv   rQ   s    r.   Úservice_account_emailz!Credentials.service_account_emailB  rx   rM   c                 ó   — | S rO   © rQ   s    r.   ÚsignerzCredentials.signerF  s   € àˆrM   c                 ó   — | j                    S rO   )r>   rQ   s    r.   Úrequires_scopeszCredentials.requires_scopesJ  s   € à×&Ñ&Ð&Ð&rM   c           	      óª   — | j                  | j                  | j                  | j                  | j                  | j
                  || j                  ¬«      S ©N)rG   rH   rI   rJ   rK   r%   )rL   r7   r=   r>   r?   rA   rD   ©rE   rK   s     r.   Úwith_quota_projectzCredentials.with_quota_projectN  sM   € à�~‰~Ø×$Ñ$Ø!×3Ñ3Ø×-Ñ-Ø—o‘oØ—^‘^Ø-Ø"&×"=Ñ"=ð ó 
ð 	
rM   c           	      ó²   — | j                  | j                  | j                  |xs || j                  | j                  | j
                  | j                  ¬«      S r�   )rL   r7   r=   r?   rA   rC   rD   )rE   ÚscopesÚdefault_scopess      r.   r:   zCredentials.with_scopesZ  sR   € à�~‰~Ø×$Ñ$Ø!×3Ñ3Ø Ò2 NØ—o‘oØ—^‘^Ø!×3Ñ3Ø"&×"=Ñ"=ð ó 
ð 	
rM   rO   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r@   r5   rR   r   Úcopy_docstringr   r1   rU   rT   rt   Úpropertyrw   rz   r}   r   ÚCredentialsWithQuotaProjectrƒ   r9   r:   Ú__classcell__©rL   s   @r.   r1   r1   w   só   ø„ ñ;ðD Ø-ØØ"õ<<ò|0ð €X×Ñ˜[×4Ñ4Ó5ñ$ó 6ð$ò$
òL?ð8 ñ&ó ð&ð ñ&ó ð&ð ñó ðð ñ'ó ð'ð €X×Ñ˜[×DÑDÓEñ	
ó Fð	
ð €X×Ñ˜[×/Ñ/Ó0ò	
ó 1ô	
rM   r1   c                   óÆ   ‡ — e Zd ZdZ	 	 	 dˆ fd„	Zd	d„Zd„ Zd„ Z ej                  e
j                  «      d„ «       Z ej                  e
j                  «      d„ «       Zˆ xZS )
ÚIDTokenCredentialszAOpen ID Connect ID Token-based service account credentials.

    c                 ó¬   •— t         t        | �  «        t        |t        «      st        j                  d«      ‚|| _        || _        || _	        || _
        y)a‰  
        Args:
            target_credentials (google.auth.Credentials): The target
                credential used as to acquire the id tokens for.
            target_audience (string): Audience to issue the token for.
            include_email (bool): Include email in IdToken
            quota_project_id (Optional[str]):  The project ID used for
                quota and billing.
        z4Provided Credential must be impersonated_credentialsN)r4   r‘   r5   r8   r1   r   ÚGoogleAuthErrorÚ_target_credentialsÚ_target_audienceÚ_include_emailrC   )rE   Útarget_credentialsÚtarget_audienceÚinclude_emailrK   rL   s        €r.   r5   zIDTokenCredentials.__init__l  sV   ø€ ô  	Ô  $Ñ0Ô2äÐ,¬kÔ:Ü×,Ñ,ØIóð ð $6ˆÔ Ø /ˆÔØ+ˆÔØ!1ˆÕrM   c                 óT   — | j                  ||| j                  | j                  ¬«      S ©N)r—   r˜   r™   rK   )rL   r–   rC   )rE   r—   r˜   s      r.   Úfrom_credentialsz#IDTokenCredentials.from_credentials‡  s0   € Ø�~‰~Ø1Ø+Ø×-Ñ-Ø!×3Ñ3ð	 ó 
ð 	
rM   c                 óh   — | j                  | j                  || j                  | j                  ¬«      S r›   )rL   r”   r–   rC   )rE   r˜   s     r.   Úwith_target_audiencez'IDTokenCredentials.with_target_audience�  s6   € Ø�~‰~Ø#×7Ñ7Ø+Ø×-Ñ-Ø!×3Ñ3ð	 ó 
ð 	
rM   c                 óh   — | j                  | j                  | j                  || j                  ¬«      S r›   )rL   r”   r•   rC   )rE   r™   s     r.   Úwith_include_emailz%IDTokenCredentials.with_include_email—  s6   € Ø�~‰~Ø#×7Ñ7Ø ×1Ñ1Ø'Ø!×3Ñ3ð	 ó 
ð 	
rM   c                 óh   — | j                  | j                  | j                  | j                  |¬«      S r›   )rL   r”   r•   r–   r‚   s     r.   rƒ   z%IDTokenCredentials.with_quota_projectŸ  s6   € à�~‰~Ø#×7Ñ7Ø ×1Ñ1Ø×-Ñ-Ø-ð	 ó 
ð 	
rM   c                 ó4  — ddl m} t        j                  | j                  j
                  «      }| j                  | j                  j                  | j                  dœ}ddt        j                  t        j                  «       i} || j                  j                  |¬«      }	 |j                  ||t        j                  |«      j!                  d«      ¬«      }|j#                  «        |j$                  t&        j(                  k7  r2t+        j,                  d	j                  |j                  «       «      «      ‚|j                  «       d
   }|| _        t1        j2                  t5        j6                  |d¬«      d   «      | _        y # |j#                  «        w xY w)Nr   rd   )ÚaudiencerI   ÚincludeEmailrY   rZ   )Úauth_requestr
   )r   r   r   zError getting ID token: {}r*   F)ÚverifyÚexp)rh   re   Ú_IAM_IDTOKEN_ENDPOINTr   r”   rw   r•   r?   r–   r   r`   Ú"token_request_id_token_impersonater7   rl   r   r   r   rm   rn   r   r   r   r   r*   r   Úutcfromtimestampr   r   r+   )	rE   r#   re   rr   r   r   rs   r'   Úid_tokens	            r.   rU   zIDTokenCredentials.refresh¨  s[  € åDä1×8Ñ8Ø×$Ñ$×1Ñ1ó
Ðð
 ×-Ñ-Ø×1Ñ1×<Ñ<Ø ×/Ñ/ñ
ˆð Ð.Ü×%Ñ%¤w×'QÑ'QÓ'Sð
ˆñ
 +Ø×$Ñ$×8Ñ8Àwô
ˆð	#Ø%×*Ñ*Ø%ØÜ—Z‘Z Ó%×,Ñ,¨WÓ5ð +ó ˆHð × Ñ Ô"à×Ñ¤;§>¡>Ò1Ü×)Ñ)Ø,×3Ñ3°H·M±M³OÓDóð ð —=‘=“? 7Ñ+ˆØˆŒ
Ü×/Ñ/Ü�J‰J�x¨Ô.¨uÑ5ó
ˆ�øð × Ñ Õ"ús   Â#6F ÆF)NFNrO   )r‡   rˆ   r‰   rŠ   r5   rœ   rž   r    r   r‹   r   r�   rƒ   r1   rU   rŽ   r�   s   @r.   r‘   r‘   g  sv   ø„ ñð ØØõ2ó6
ò
ò
ð €X×Ñ˜[×DÑDÓEñ
ó Fð
ð €X×Ñ˜[×4Ñ4Ó5ñ(
ó 6ô(
rM   r‘   rO   )rŠ   rj   r6   r   Úhttp.clientÚclientr   r   Úgoogle.authr   r   r   r   r   r;   r   ri   r¨   r   r@   Ú_DEFAULT_TOKEN_URIr/   r9   r�   ÚSigningr1   r‘   r|   rM   r.   ú<module>r±      s©   ðñó Û Ý Ý !Û å  Ý #Ý "Ý Ý à3Ð4€
ð0ð ð%ð ð6ð ð
 >€à#Ð à:Ð ð >Bó4&ônm
Ø×Ñ˜×?Ñ?À×ATÑATôm
ô`j
˜×@Ñ@õ j
rM   