Ë
    õ%9j‘  ã            	       ó  — d Z ddlZddlZddlZddlZddlZddlZddlmZ ddl	m
Z
 ddlZddlZ ej                  e«      Zej"                  defd„«       Z	 ddeded	ee   d
ej(                  fd„Zd„ Zd„ Z	 dd„Zdd„Zy)z<
Helper functions for mTLS in async for discovery of certs.
é    N)ÚOptional)Ú
exceptionsÚcontentc              #   óš  K  — t        j                  «       \  }}	 t        j                  |d«      5 }|j	                  | «       ddd«       |–— t        j
                  j                  |«      rt        j                  |«       yy# 1 sw Y   ŒCxY w# t        j
                  j                  |«      rt        j                  |«       w w xY w­w)zµCreates a temporary file with the given content.

    Args:
        content (bytes): The content to write to the file.

    Yields:
        str: The path to the temporary file.
    ÚwbN)ÚtempfileÚmkstempÚosÚfdopenÚwriteÚpathÚexistsÚremove)r   ÚfdÚ	file_pathÚfs       úZ/var/www/html/truck-me/venv/lib/python3.12/site-packages/google/auth/aio/transport/mtls.pyÚ_create_temp_filer   "   s›   è ø€ ô ×$Ñ$Ó&�M€Bˆ	ð!Ü�Y‰Y�r˜4Ó ð 	 AØ�G‰G�GÔ÷	àŠô �7‰7�>‰>˜)Ô$Ü�I‰I�iÕ ð %÷	ð 	ûô
 �7‰7�>‰>˜)Ô$Ü�I‰I�iÕ ð %üs3   ‚C›B ±BÁB Á6CÂBÂ
B Â7CÃCÚ
cert_bytesÚ	key_bytesÚ
passphraseÚreturnc           	      ó¬  — t        | «      5 }t        |«      5 }	 t        j                  t        j                  j                  «      }|j                  |||¬«       |cddd«       cddd«       S # t        j                  t        t        t        t        f$ r}t        j                  d«      |‚d}~ww xY w# 1 sw Y   nxY wddd«       y# 1 sw Y   yxY w)a  Creates an SSLContext with the given client certificate and key.
    This function writes the certificate and key to temporary files so that
    ssl.create_default_context can load them, as the ssl module requires
    file paths for client certificates. These temporary files are deleted
    immediately after the SSL context is created.
    Args:
        cert_bytes (bytes): The client certificate content in PEM format.
        key_bytes (bytes): The client private key content in PEM format.
        passphrase (Optional[bytes]): The passphrase for the private key, if any.
    Returns:
        ssl.SSLContext: The configured SSL context with client certificate.

    Raises:
        google.auth.exceptions.TransportError: If there is an error loading the certificate.
    )ÚcertfileÚkeyfileÚpasswordNz3Failed to load client certificate and key for mTLS.)r   ÚsslÚcreate_default_contextÚPurposeÚSERVER_AUTHÚload_cert_chainÚSSLErrorÚOSErrorÚIOErrorÚ
ValueErrorÚRuntimeErrorr   ÚTransportError)r   r   r   Ú	cert_pathÚkey_pathÚcontextÚexcs          r   Úmake_client_cert_ssl_contextr,   8   sÈ   € ô$ 
˜:Ó	&ð ¨)Ô5FØó6ð à	ð		Ü×0Ñ0´·±×1HÑ1HÓIˆGØ×#Ñ#Ø"¨H¸zð $ô ð ÷÷ ò øô —‘œg¤w´
¼LÐIò 	Ü×+Ñ+ØEóàðûð	ú÷ð ú÷ ÷ ñ ús@   ŒC
˜B5šAA/Á	C
Á/(B2ÂB-Â-B2Â2B5Â5B>	Â:C
Ã
Cc              ‡   óÌ   K  — 	 t        j                  | g|¢­Ž ƒ d{  –—† S 7 Œ# t        $ r4 t        j                  «       } |j                  d| g|¢­Ž ƒ d{  –—†7  cY S w xY w­w)zŸRun a blocking function in an executor to avoid blocking the event loop.

    This implements the non-blocking execution strategy for disk I/O operations.
    N)ÚasyncioÚ	to_threadÚAttributeErrorÚget_running_loopÚrun_in_executor)ÚfuncÚargsÚloops      r   Ú_run_in_executorr6   Y   sc   è ø€ ð
=ä×&Ñ& tÐ3¨dÒ3×3Ð3Ð3ùÜò =ä×'Ñ'Ó)ˆØ)�T×)Ñ)¨$°Ð<°tÒ<×<Ð<Ò<ð=üs=   ‚A$„$ �"ž$ ¡A$¢$ ¤4A!ÁAÁA!ÁA$Á A!Á!A$c                  óž   — t         j                  j                  j                  j	                  d¬«      st        j                  d«      ‚d„ } | S )a˜  Get a callback which returns the default client SSL credentials.

    Returns:
        Awaitable[Callable[[], Tuple[bytes, bytes]]]: A callback which returns the default
            client certificate bytes and private key bytes, both in PEM format.

    Raises:
        google.auth.exceptions.DefaultClientCertSourceError: If the default
            client SSL credentials don't exist or are malformed.
    F)Úinclude_context_awarez(Default client cert source doesn't existc               “   ó¬   K  — 	 t        «       ƒ d {  –—† \  } }}||fS 7 Œ# t        t        t        f$ r}t	        j
                  |«      }||‚d }~ww xY w­w©N)Úget_client_cert_and_keyr#   r&   r%   r   ÚMutualTLSChannelError)Ú_r   r   Ú
caught_excÚnew_excs        r   Úcallbackz,default_client_cert_source.<locals>.callbacky   s^   è ø€ ð	*Ü-DÓ-F×'FÑ$ˆAˆz˜9ð
 ˜9Ð$Ð$ð (GùÜœ¤zÐ2ò 	*Ü ×6Ñ6°zÓBˆGØ˜zÐ)ûð	*üs0   ‚A„  ‘’  šAž   A´AÁAÁA)ÚgoogleÚauthÚ	transportÚmtlsÚhas_default_client_cert_sourcer   r<   )r@   s    r   Údefault_client_cert_sourcerF   g   sO   € ô �;‰;× Ñ ×%Ñ%×DÑDØ#ð Eô ô ×.Ñ.Ø6ó
ð 	
ò%ð €Oó    c              ƒ   ó¬   K  — t        t        j                  j                  j                  j
                  | d«      ƒ d{  –—† \  }}|r|rd||dfS y7 Œ­w)a×  Returns the client side certificate, private key and passphrase.

    We look for certificates and keys with the following order of priority:
        1. Certificate and key specified by certificate_config.json.
               Currently, only X.509 workload certificates are supported.

    Args:
        certificate_config_path (str): The certificate_config.json file path.

    Returns:
        Tuple[bool, bytes, bytes, bytes]:
            A boolean indicating if cert, key and passphrase are obtained, the
            cert bytes and key bytes both in PEM format, and passphrase bytes.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert, key and passphrase.
    FNT)FNNN)r6   rA   rB   rC   Ú_mtls_helperÚ_get_workload_cert_and_key)Úcertificate_config_pathÚcertÚkeys      r   Úget_client_ssl_credentialsrN   …   sX   è ø€ ô. 'Ü�‰×Ñ×*Ñ*×EÑEØØó÷ �I€Dˆ#ñ ‘Ø�T˜3 Ð$Ð$à"ðús   ‚=A¿AÁ Ac              ƒ   óª   K  — | r | «       }	 |ƒ d{  –—† \  }}d||fS t        «       ƒ d{  –—† \  }}}}|||fS 7 Œ(# t         $ r |\  }}Y Œ3w xY w7 Œ$­w)a  Returns the client side certificate and private key. The function first
    tries to get certificate and key from client_cert_callback; if the callback
    is None or doesn't provide certificate and key, the function tries application
    default SSL credentials.

    Args:
        client_cert_callback (Optional[Callable[[], (bytes, bytes)]]): An
            optional callback which returns client certificate bytes and private
            key bytes both in PEM format.

    Returns:
        Tuple[bool, bytes, bytes]:
            A boolean indicating if cert and key are obtained, the cert bytes
            and key bytes both in PEM format.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert and key.
    NT)Ú	TypeErrorrN   )Úclient_cert_callbackÚresultrL   rM   Úhas_certr=   s         r   r;   r;   ¨   su   è ø€ ñ( Ù%Ó'ˆð	Ø$Ÿ‰IˆD�#ð �T˜3ˆÐä#=Ó#?×?Ñ€Hˆd�C˜Ø�T˜3ÐÐð %ùÜò 	Ø‰IˆD’#ð	úð @ús;   ‚
A�= ’;“= šA¬A­A»= ½AÁAÁAÁAr:   )Ú__doc__r.   Ú
contextlibÚloggingr
   r   r   Útypingr   Úgoogle.authr   Ú"google.auth.transport._mtls_helperrA   Úgoogle.auth.transport.mtlsÚ	getLoggerÚ__name__Ú_LOGGERÚcontextmanagerÚbytesr   Ú
SSLContextr,   r6   rF   rN   r;   © rG   r   ú<module>rb      s¬   ðñó Û Û Û 	Û 
Û Ý å "Û )Û !à
ˆ'×
Ñ
˜HÓ
%€ð ×Ñð!˜uò !ó ð!ð, HLñØðØ"'ðØ5=¸e±_ðà‡^�^óòB=òð> !ó #ôFrG   