Ë
    ö%9jŸ  ã                   ó¬   — d Z ddlmZmZ ddlZddlmZmZmZmZ ddlm	Z	m
Z
mZ ddlmZ dZdefd	„Zdd
edeeef   fd„Z G d„ d«      Z G d„ d«      Zy)zFirebase App Check module.é    )ÚAnyÚDictN)ÚPyJWKClientÚExpiredSignatureErrorÚInvalidTokenErrorÚDecodeError)ÚInvalidAudienceErrorÚInvalidIssuerErrorÚInvalidSignatureError)Ú_utilsÚ
_app_checkÚreturnc                 ó@   — t        j                  | t        t        «      S ©N)r   Úget_app_serviceÚ_APP_CHECK_ATTRIBUTEÚ_AppCheckService)Úapps    úT/var/www/html/truck-me/venv/lib/python3.12/site-packages/firebase_admin/app_check.pyÚ_get_app_check_servicer      s   € Ü×!Ñ! #Ô';Ô=MÓNÐNó    Útokenc                 ó6   — t        |«      j                  | «      S )a¥  Verifies a Firebase App Check token.

    Args:
        token: A token from App Check.
        app: An App instance (optional).

    Returns:
        Dict[str, Any]: The token's decoded claims.

    Raises:
        ValueError: If the app's ``project_id`` is invalid or unspecified,
        or if the token's headers or payload are invalid.
        PyJWKClientError: If PyJWKClient fails to fetch a valid signing key.
    )r   Úverify_token)r   r   s     r   r   r      s   € ô " #Ó&×3Ñ3°EÓ:Ð:r   c                   óŠ   — e Zd ZdZdZdZdZdZdZd e	j                  «       iZd„ Zdedeeef   fd	„Zd
eddfd„Zdedefd„Zy)r   z?Service class that implements Firebase App Check functionality.z(https://firebaseappcheck.googleapis.com/z/https://firebaseappcheck.googleapis.com/v1/jwksNzX-GOOG-API-CLIENTc                 óÊ   — |j                   | _        | j                  st        d«      ‚d|j                   z   | _        t	        | j
                  d| j                  ¬«      | _        y )Nz·A project ID must be specified to access the App Check service. Either set the projectId option, use service account credentials, or set the GOOGLE_CLOUD_PROJECT environment variable.z	projects/i`T  )ÚlifespanÚheaders)Ú
project_idÚ_project_idÚ
ValueErrorÚ_scoped_project_idr   Ú	_JWKS_URLÚ_APP_CHECK_HEADERSÚ_jwks_client)Úselfr   s     r   Ú__init__z_AppCheckService.__init__:   s[   € àŸ>™>ˆÔØ×ÒÜð=ó>ð >ð
 #.°·±Ñ">ˆÔä'Ø�N‰N U°D×4KÑ4KôMˆÕr   r   r   c                 ó\  — t         j                  d|«       	 | j                  j                  |«      }| j	                  t        j                  |«      «       | j                  ||j                  «      }|j                  d«      |d<   |S # t        t        f$ r}t        d|› �«      ‚d}~ww xY w)z$Verifies a Firebase App Check token.zapp check tokenz)Verifying App Check token failed. Error: NÚsubÚapp_id)Ú_ValidatorsÚcheck_stringr%   Úget_signing_key_from_jwtÚ_has_valid_token_headersÚjwtÚget_unverified_headerÚ_decode_and_verifyÚkeyr   r   r!   Úget)r&   r   Úsigning_keyÚverified_claimsÚ	exceptions        r   r   z_AppCheckService.verify_tokenI   s¨   € ä× Ñ Ð!2°EÔ:ð
	Ø×+Ñ+×DÑDÀUÓKˆKØ×)Ñ)¬#×*CÑ*CÀEÓ*JÔKØ"×5Ñ5°e¸[¿_¹_ÓMˆOð %4×$7Ñ$7¸Ó$>ˆ˜Ñ!ØÐøô "¤;Ð/ò 	ÜØ;¸I¸;ÐGóð ûð	ús   ˜AB	 Â	B+ÂB&Â&B+r   c                 óŒ   — |j                  d«      dk7  rt        d«      ‚|j                  d«      }|dk7  rt        d|› d�«      ‚y)	z9Checks whether the token has valid headers for App Check.ÚtypÚJWTz9The provided App Check token has an incorrect type headerÚalgÚRS256zQThe provided App Check token has an incorrect alg header. Expected RS256 but got ú.N)r3   r!   )r&   r   Ú	algorithms      r   r.   z)_AppCheckService._has_valid_token_headers\   sZ   € ð �;‰;�uÓ Ò&ÜÐXÓYÐYà—K‘K Ó&ˆ	Ø˜ÒÜð*Ø*3¨°Að7óð ð  r   r4   c                 óˆ  — i }	 t        j                  ||dg| j                  ¬«      }|j                  d
«      }t        |t        «      r| j                  |vrt	        d«      ‚|j                  d«      j                  | j                  «      st	        d«      ‚t        j                  d|j                  d«      «       |S # t        $ r t	        d«      ‚t
        $ r t	        d| j                  › d�«      ‚t        $ r t	        d| j                  › �«      ‚t        $ r t	        d«      ‚t        $ r}t	        d|› �«      ‚d	}~ww xY w)z.Decodes and verifies the token from App Check.r;   )Ú
algorithmsÚaudiencez6The provided App Check token has an invalid signature.zbThe provided App Check token has an incorrect "aud" (audience) claim. Expected payload to include r<   z^The provided App Check token has an incorrect "iss" (issuer) claim. Expected claim to include z)The provided App Check token has expired.z(Decoding App Check token failed. Error: NÚaudz>Firebase App Check token has incorrect "aud" (audience) claim.Úissz2Token does not contain the correct "iss" (issuer).z2The provided App Check token "sub" (subject) claimr)   )r/   Údecoder"   r   r!   r	   r
   Ú_APP_CHECK_ISSUERr   r   r3   Ú
isinstanceÚlistÚ
startswithr+   r,   )r&   r   r4   Úpayloadr6   r@   s         r   r1   z#_AppCheckService._decode_and_verifyi   sj  € àˆð	Ü—j‘jØØØ#˜9Ø×0Ñ0ô	ˆGð: —;‘;˜uÓ%ˆÜ˜(¤DÔ)¨T×-DÑ-DÈHÑ-TÜÐ]Ó^Ð^Ø�{‰{˜5Ó!×,Ñ,¨T×-CÑ-CÔDÜÐQÓRÐRÜ× Ñ Ø@Ø�K‰K˜Óô	 ð ˆøôA %ò 	ÜØHóð ô $ò 	Üð/Ø/3×/FÑ/FÐ.GÀqðJóð ô "ò 	Üð-Ø-1×-CÑ-CÐ,DðFóð ô %ò 	ÜØ;óð ô !ò 	ÜØ:¸9¸+ÐFóð ûð	ús   „$B> Â>A0EÄ.D<Ä<E)Ú__name__Ú
__module__Ú__qualname__Ú__doc__rD   r#   r    r"   r%   r   Úget_metrics_headerr$   r'   Ústrr   r   r   r.   r1   © r   r   r   r   -   s‚   „ ÙIàBÐØA€IØ€KØÐØ€Lð 	Ð6˜V×6Ñ6Ó8ðÐòMð #ð ¨$¨s°C¨x©.ó ð&°ð ¸ó ð*¨ð *¸#ô *r   r   c                   ó*   — e Zd ZdZededefd„«       Zy)r+   z‚A collection of data validation utilities.

    Methods provided in this class raise ``ValueErrors`` if any validations fail.
    ÚlabelÚvaluec                 ó”   — |€t        dj                  ||«      «      ‚t        |t        «      st        dj                  ||«      «      ‚y)z&Checks if the given value is a string.Nz%{0} "{1}" must be a non-empty string.z{0} "{1}" must be a string.)r!   ÚformatrE   rN   )ÚclsrQ   rR   s      r   r,   z_Validators.check_string›   sK   € ð ˆ=ÜÐD×KÑKÈEÐSXÓYÓZÐZÜ˜%¤Ô%ÜÐ:×AÑAÀ%ÈÓOÓPÐPð &r   N)rI   rJ   rK   rL   ÚclassmethodrN   r   r,   rO   r   r   r+   r+   •   s-   „ ñð
 ðQ ð Q¨Sò Qó ñQr   r+   r   )rL   Útypingr   r   r/   r   r   r   r   r	   r
   r   Úfirebase_adminr   r   r   rN   r   r   r+   rO   r   r   ú<module>rY      sg   ðñ !ç Û 
ß RÓ Rß OÑ OÝ !à#Ð ðO 3ó Oñ;˜ð ;¨$¨s°C¨x©.ó ;÷"fñ f÷PQò Qr   