;iBdZddlZddlmZddlZddlmZddlmZddlm Z ddlm Z ddlm Z ej ej ejejhZdgZd Zd Zd Zd ZGd de jZdS)zTools for using the Google `Cloud Identity and Access Management (IAM) API`_'s auth-related functionality. .. _Cloud Identity and Access Management (IAM) API: https://cloud.google.com/iam/docs/ N)_exponential_backoff)_helpers) credentials)crypt) exceptionsz#https://www.googleapis.com/auth/iamzZhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateAccessTokenzOhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:signBlobzNhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:signJwtzVhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateIdTokencpeZdZdZdZdZedZej e j dZ dS)SigneraSigns messages using the IAM `signBlob API`_. This is useful when you need to sign bytes but do not have access to the credential's private key file. .. _signBlob API: https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts /signBlob c0||_||_||_dS)a Args: request (google.auth.transport.Request): The object used to make HTTP requests. credentials (google.auth.credentials.Credentials): The credentials that will be used to authenticate the request to the IAM API. The credentials must have of one the following scopes: - https://www.googleapis.com/auth/iam - https://www.googleapis.com/auth/cloud-platform service_account_email (str): The service account email identifying which service account to use to sign bytes. Often, this can be the same as the service account email in the given credentials. N)_request _credentials_service_account_email)selfrequestrservice_account_emails CC:\PYTHON\MyICR_Workspace\venv\Lib\site-packages\google/auth/iam.py__init__zSigner.__init__Is!   '&;###c(tj|}d}ttj|jj|j }ddi}tj dtj |did}t!j}|D]}|j|j||||||||}|jt*vrL|jt,jkr,t1jd|jtj|jdcSt1jd) z(Makes a request to the API signBlob API.POSTz Content-Typezapplication/jsonpayloadzutf-8)urlmethodbodyheadersz&Error calling the IAM signBlob API: {}z#exhausted signBlob endpoint retries)rto_bytes_IAM_SIGN_ENDPOINTreplacerDEFAULT_UNIVERSE_DOMAINr universe_domainformatr jsondumpsbase64 b64encodedecodeencoderExponentialBackoffbefore_requestr statusIAM_RETRY_CODES http_clientOKrTransportErrordataloads) rmessagerrrrretries_responses r_make_signing_requestzSigner._make_signing_request]ss#G,, ((  /1B1R  &, - - "#56z (1188AA B  &// '9;; = =A   , ,T]FC Q Q Q}}V$PW}XXH/11+.00 /<CCHMRR:hm227;;<< < < <'(MNNNrcdS)zOptional[str]: The key ID used to identify this private key. .. warning:: This is always ``None``. The key ID used by IAM can not be reliably determined ahead of time. N)rs rkey_idz Signer.key_id{s trc`||}tj|dS)N signedBlob)r4r# b64decode)rr0r3s rsignz Signer.signs+--g66 6777rN) __name__ __module__ __qualname____doc__rr4propertyr7rcopy_docstringrr r;r6rrr r >s<<<(OOO<XXU\**88+*888rr )r?r# http.clientclientr+r! google.authrrrrrINTERNAL_SERVER_ERROR BAD_GATEWAYSERVICE_UNAVAILABLEGATEWAY_TIMEOUTr* _IAM_SCOPE _IAM_ENDPOINTr_IAM_SIGNJWT_ENDPOINT_IAM_IDTOKEN_ENDPOINTr r6rrrMs" !!!!!! ,,,,,, ######""""""%# 4 4 0 % $ 6 J8J8J8J8J8U\J8J8J8J8J8r