Ë
    ö%9jÌe  ã                   ó¦  — d dl Z d dlZd dlZd dlZd dlZd dlZd dlZd dlZd dlZ	d dl
mZ d dlmZ d dlmZ d dlmZmZmZ d dlmZ ej                  j,                  ZdZd„ Zd	„ Zd
„ Zeej                  ej:                  fZd„ Zd„ Z  ejB                  dg d¢«      Z"d„ Z#	 	 	 	 	 	 	 	 	 	 	 	 dd„Z$dZ%dZ&e&ddddddddddddfd„Z'd„ Z(efd„Z)d„ Z*d„ Z+y)é    N)Ú
exceptions)Úrequests)Ú_helpers)Ú_DEFAULT_UNIVERSE_DOMAINÚ_NOWÚ_UTC)ÚDEFAULT_RETRYz[https://googleapis.dev/python/google-api-core/latest/auth.html#setting-up-a-service-accountc                 ó°   — t        | t        j                  j                  j                  «      s(t        dj                  t        | «      t        «      «      ‚y)ai  Raise AttributeError if the credentials are unsigned.

    :type credentials: :class:`google.auth.credentials.Signing`
    :param credentials: The credentials used to create a private key
                        for signing text.

    :raises: :exc:`AttributeError` if credentials is not an instance
            of :class:`google.auth.credentials.Signing`.
    z…you need a private key to sign credentials.the credentials you are currently using {} just contains a token. see {} for more details.N)	Ú
isinstanceÚgoogleÚauthÚcredentialsÚSigningÚAttributeErrorÚformatÚtypeÚSERVICE_ACCOUNT_URL)r   s    úY/var/www/html/truck-me/venv/lib/python3.12/site-packages/google/cloud/storage/_signing.pyÚensure_signed_credentialsr   +   sJ   € ô �k¤6§;¡;×#:Ñ#:×#BÑ#BÔCÜð÷ ‘vœd ;Ó/Ô1DÓEó	
ð 	
ð Dó    c                 ó¦   — t        | «       | j                  |j                  d«      «      }t        j                  |«      }| j
                  }|||dœS )až  Gets query parameters for creating a signed URL.

    :type credentials: :class:`google.auth.credentials.Signing`
    :param credentials: The credentials used to create a private key
                        for signing text.

    :type expiration: int or long
    :param expiration: When the signed URL should expire.

    :type string_to_sign: str
    :param string_to_sign: The string to be signed by the credentials.

    :raises: :exc:`AttributeError` if credentials is not an instance
            of :class:`google.auth.credentials.Signing`.

    :rtype: dict
    :returns: Query parameters matching the signing credentials with a
              signed payload.
    Úascii©ÚGoogleAccessIdÚExpiresÚ	Signature)r   Ú
sign_bytesÚencodeÚbase64Ú	b64encodeÚsigner_email)r   Ú
expirationÚstring_to_signÚsignature_bytesÚ	signatureÚservice_account_names         r   Úget_signed_query_params_v2r'   >   sV   € ô( ˜kÔ*Ø!×,Ñ,¨^×-BÑ-BÀ7Ó-KÓL€OÜ× Ñ  Ó1€IØ&×3Ñ3Ðà.ØØñð r   c                 ó  — t        | t        j                  «      rt        t        «      }|| z   } t        | t        j                  «      rt        j                  | «      }|dz  } t        | t        «      st        dt        | «      z  «      ‚| S )a  Convert 'expiration' to a number of seconds in the future.

    :type expiration: Union[Integer, datetime.datetime, datetime.timedelta]
    :param expiration: Point in time when the signed URL should expire. If
                       a ``datetime`` instance is passed without an explicit
                       ``tzinfo`` set,  it will be assumed to be ``UTC``.

    :raises: :exc:`TypeError` when expiration is not a valid type.

    :rtype: int
    :returns: a timestamp as an absolute number of seconds since epoch.
    i@B ú=Expected an integer timestamp, datetime, or timedelta. Got %s)
r   ÚdatetimeÚ	timedeltar   r   r   Ú_microseconds_from_datetimeÚintÚ	TypeErrorr   )r"   ÚnowÚmicross      r   Úget_expiration_seconds_v2r1   ]   sƒ   € ô �*œh×0Ñ0Ô1Ü”4‹jˆØ˜:Ñ%ˆ
ô �*œh×/Ñ/Ô0Ü×5Ñ5°jÓAˆØ˜u‘_ˆ
ä�j¤#Ô&Üð Ü"& zÓ"2ñ3ó
ð 	
ð Ðr   c                 óÈ  — t        | t        «      st        dt        | «      z  «      ‚t	        t
        «      }t        | t        «      r| }t        | t        j                  «      r1| j                  € | j                  t        j                  ¬«      } | |z
  } t        | t        j                  «      rt        | j                  «       «      }t        kD  rt        dt        › �«      ‚|S )aV  Convert 'expiration' to a number of seconds offset from the current time.

    :type expiration: Union[Integer, datetime.datetime, datetime.timedelta]
    :param expiration: Point in time when the signed URL should expire. If
                       a ``datetime`` instance is passed without an explicit
                       ``tzinfo`` set,  it will be assumed to be ``UTC``.

    :raises: :exc:`TypeError` when expiration is not a valid type.
    :raises: :exc:`ValueError` when expiration is too large.
    :rtype: Integer
    :returns: seconds in the future when the signed URL will expire
    r)   ©Útzinfoz.Max allowed expiration interval is seven days )r   Ú_EXPIRATION_TYPESr.   r   r   r   r-   r*   r4   Úreplacer   ÚUTCr+   Útotal_secondsÚ
SEVEN_DAYSÚ
ValueError)r"   r/   Úsecondss      r   Úget_expiration_seconds_v4r<      sÈ   € ô �jÔ"3Ô4Üð Ü"& zÓ"2ñ3ó
ð 	
ô
 Œt‹*€Cä�*œcÔ"Øˆä�*œh×/Ñ/Ô0Ø×ÑÐ$Ø#×+Ñ+´8·<±<Ð+Ó@ˆJØ #Ñ%ˆ
ä�*œh×0Ñ0Ô1Ü�j×.Ñ.Ó0Ó1ˆà”ÒÜÐIÌ*ÈÐVÓWÐWà€Nr   c                 óÜ  — | €g } n)t        | t        «      rt        | j                  «       «      } | sg g fS t	        j
                  t        «      }| D ]V  \  }}|j                  «       j                  «       }dj                  |j                  «       «      }||   j                  |«       ŒX t        d„ |j                  «       D «       «      }|D �cg c]  } dj                  |Ž ‘Œ }}||fS c c}w )am  Canonicalize headers for signing.

    See:
    https://cloud.google.com/storage/docs/access-control/signed-urls#about-canonical-extension-headers

    :type headers: Union[dict|List(Tuple(str,str))]
    :param headers:
        (Optional) Additional HTTP headers to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers
        Requests using the signed URL *must* pass the specified header
        (name and value) with each request for the URL.

    :rtype: str
    :returns: List of headers, normalized / sortted per the URL refernced above.
    ú c              3   óH   K  — | ]  \  }}|d j                  |«      f–— Œ y­w)ú,N)Újoin)Ú.0ÚkeyÚvals      r   ú	<genexpr>z(get_canonical_headers.<locals>.<genexpr>Ä   s!   è ø€ ÒU±h°c¸3˜c 3§8¡8¨C£=Ô1ÑUùs   ‚ "z{}:{})r   ÚdictÚlistÚitemsÚcollectionsÚdefaultdictÚlowerÚstriprA   ÚsplitÚappendÚsortedr   )ÚheadersÚ
normalizedrC   rD   Úordered_headersÚitemÚcanonical_headerss          r   Úget_canonical_headersrU   ¥   sÜ   € ð" €Ø‰Ü	�GœTÔ	"Ü�w—}‘}“Ó'ˆáØ�2ˆvˆä×(Ñ(¬Ó.€JØò $‰ˆˆSØ�i‰i‹k×ÑÓ!ˆØ�h‰h�s—y‘y“{Ó#ˆØ�3‰×Ñ˜sÕ#ð$ô
 ÑUÀ*×BRÑBRÓBTÔUÓU€Oà;JÖK°4˜˜Ÿ™¨Ò.ÐKÐÐKØ˜oÐ-Ð-ùò Ls   ÃC)Ú
_Canonical)ÚmethodÚresourceÚquery_parametersrP   c                 ó  — t        |«      \  }}| dk(  rd} |j                  d«       |€t        | |g |«      S t        d„ |j	                  «       D «       «      }t
        j                  j                  |«      }|› d|› �}t        | |||«      S )ah  Canonicalize method, resource per the V2 spec.

    :type method: str
    :param method: The HTTP verb that will be used when requesting the URL.
                   Defaults to ``'GET'``. If method is ``'RESUMABLE'`` then the
                   signature will additionally contain the `x-goog-resumable`
                   header, and the method changed to POST. See the signed URL
                   docs regarding this flow:
                   https://cloud.google.com/storage/docs/access-control/signed-urls

    :type resource: str
    :param resource: A pointer to a specific resource
                     (typically, ``/bucket-name/path/to/blob.txt``).

    :type query_parameters: dict
    :param query_parameters:
        (Optional) Additional query parameters to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers#query

    :type headers: Union[dict|List(Tuple(str,str))]
    :param headers:
        (Optional) Additional HTTP headers to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers
        Requests using the signed URL *must* pass the specified header
        (name and value) with each request for the URL.

    :rtype: :class:_Canonical
    :returns: Canonical method, resource, query_parameters, and headers.
    Ú	RESUMABLEÚPOSTzx-goog-resumable:startc              3   ór   K  — | ]/  \  }}|j                  «       |xr |j                  «       xs d f–— Œ1 y­w)Ú N)rK   rL   )rB   rC   Úvalues      r   rE   z"canonicalize_v2.<locals>.<genexpr>ø   s7   è ø€ ò áˆC�ð 
�‰‹�eÒ- §¡£Ò3°Ô4ñùs   ‚57ú?)rU   rN   rV   rO   rH   ÚurllibÚparseÚ	urlencode)rW   rX   rY   rP   Ú_Únormalized_qpÚ
encoded_qpÚcanonical_resources           r   Úcanonicalize_v2rh   Ï   s�   € ô@ ' wÓ/�J€GˆQà�ÒØˆØ�‰Ð/Ô0àÐÜ˜& (¨B°Ó8Ð8äñ à*×0Ñ0Ó2ôó €Mô —‘×'Ñ'¨Ó6€JØ$˜: Q z lÐ3ÐÜ�fÐ0°-ÀÓIÐIr   ÚGETc                 óD  — t        |«      }t        ||||
«      }|j                  |xs d|xs dt        |«      g}|j	                  |j
                  «       |j                  |j                  «       dj                  |«      }|r|rt        ||||«      }|||dœ}nt        | ||«      }|�||d<   |�||d<   |	�|	|d<   |j                  |j                  «       t        |j                  «       «      }dj                  ||t         j"                  j%                  |«      ¬«      S )	a‰  Generate a V2 signed URL to provide query-string auth'n to a resource.

    .. note::

        Assumes ``credentials`` implements the
        :class:`google.auth.credentials.Signing` interface. Also assumes
        ``credentials`` has a ``signer_email`` property which
        identifies the credentials.

    .. note::

        If you are on Google Compute Engine, you can't generate a signed URL.
        If you'd like to be able to generate a signed URL from GCE, you can use a
        standard service account from a JSON file rather than a GCE service account.

    See headers [reference](https://cloud.google.com/storage/docs/reference-headers)
    for more details on optional arguments.

    :type credentials: :class:`google.auth.credentials.Signing`
    :param credentials: Credentials object with an associated private key to
                        sign text.

    :type resource: str
    :param resource: A pointer to a specific resource
                     (typically, ``/bucket-name/path/to/blob.txt``).
                     Caller should have already URL-encoded the value.

    :type expiration: Union[Integer, datetime.datetime, datetime.timedelta]
    :param expiration: Point in time when the signed URL should expire. If
                       a ``datetime`` instance is passed without an explicit
                       ``tzinfo`` set,  it will be assumed to be ``UTC``.

    :type api_access_endpoint: str
    :param api_access_endpoint: (Optional) URI base. Defaults to empty string.

    :type method: str
    :param method: The HTTP verb that will be used when requesting the URL.
                   Defaults to ``'GET'``. If method is ``'RESUMABLE'`` then the
                   signature will additionally contain the `x-goog-resumable`
                   header, and the method changed to POST. See the signed URL
                   docs regarding this flow:
                   https://cloud.google.com/storage/docs/access-control/signed-urls


    :type content_md5: str
    :param content_md5: (Optional) The MD5 hash of the object referenced by
                        ``resource``.

    :type content_type: str
    :param content_type: (Optional) The content type of the object referenced
                         by ``resource``.

    :type response_type: str
    :param response_type: (Optional) Content type of responses to requests for
                          the signed URL. Ignored if content_type is set on
                          object/blob metadata.

    :type response_disposition: str
    :param response_disposition: (Optional) Content disposition of responses to
                                 requests for the signed URL.

    :type generation: str
    :param generation: (Optional) A value that indicates which generation of
                       the resource to fetch.

    :type headers: Union[dict|List(Tuple(str,str))]
    :param headers:
        (Optional) Additional HTTP headers to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers
        Requests using the signed URL *must* pass the specified header
        (name and value) with each request for the URL.

    :type service_account_email: str
    :param service_account_email: (Optional) E-mail address of the service account.

    :type access_token: str
    :param access_token: (Optional) Access token for a service account.

    :type query_parameters: dict
    :param query_parameters:
        (Optional) Additional query parameters to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers#query

    :raises: :exc:`TypeError` when expiration is not a valid type.
    :raises: :exc:`AttributeError` if credentials is not an instance
            of :class:`google.auth.credentials.Signing`.

    :rtype: str
    :returns: A signed URL you can use to access the resource
              until expiration.
    r^   ú
r   úresponse-content-typeúresponse-content-dispositionÚ
generationz"{endpoint}{resource}?{querystring})ÚendpointrX   Úquerystring)r1   rh   rW   ÚstrÚextendrP   rN   rX   rA   Ú_sign_messager'   ÚupdaterY   rO   rH   r   ra   rb   rc   )r   rX   r"   Úapi_access_endpointrW   Úcontent_md5Úcontent_typeÚresponse_typeÚresponse_dispositionrn   rP   rY   Úservice_account_emailÚaccess_tokenÚuniverse_domainÚexpiration_stampÚ	canonicalÚelements_to_signr#   r%   Úsigned_query_paramsÚsorted_signed_query_paramss                         r   Úgenerate_signed_url_v2r‚     s]  € ô\ 1°Ó<Ðä ¨Ð2BÀGÓL€Ið 	×ÑØÒ�rØÒ˜ÜÐÓð	Ðð ×Ñ˜I×-Ñ-Ô.Ø×Ñ˜I×.Ñ.Ô/Ø—Y‘YÐ/Ó0€Nñ
 Ñ-Ü!Ø˜LÐ*?Àó
ˆ	ð 4Ø'Ø"ñ
Ñô 9ØÐ)¨>ó
Ðð Ð Ø7DÐÐ3Ñ4ØÐ'Ø>RÐÐ:Ñ;ØÐØ,6Ð˜LÑ)à×Ñ˜y×9Ñ9Ô:Ü!'Ð(;×(AÑ(AÓ(CÓ!DÐð 0×6Ñ6Ø$ØÜ—L‘L×*Ñ*Ð+EÓFð 7ó ð r   i€:	 zhttps://storage.googleapis.comc                 ó<  — t        |«      }|€t        «       \  }}n|}|dd }|}|r|st        | «       | j                  }|› d�}|› d|› �}|
€i }
|�||
d<   |�||
d<   |
D �cg c]  }|j	                  «       ‘Œ }}d|vr,t
        j                  j                  |«      j                  |
d<   |j                  «       d	k(  rd
}d|
d<   t        |
«      \  }}dj                  |«      dz   }dj                  |D ��cg c]  \  }}|‘Œ	 c}}«      }|€i }n'|j                  «       D ��ci c]  \  }}||xs d“Œ }}}d|d<   ||d<   ||d<   ||d<   ||d<   |�||d<   |�||d<   |	�|	|d<   t        |«      }t        |«      }d|v r|d   } nd} |||||| g}!dj                  |!«      }"t        j                   |"j#                  d«      «      j%                  «       }#d|||#g}$dj                  |$«      }%|rJ|rHt'        |%|||«      }&t)        j*                  |&«      }'t-        j.                  |'«      j1                  d«      }&nD| j3                  |%j#                  d«      «      }'t-        j.                  |'«      j1                  d«      }&dj5                  ||||&«      S c c}w c c}}w c c}}w )a/  Generate a V4 signed URL to provide query-string auth'n to a resource.

    .. note::

        Assumes ``credentials`` implements the
        :class:`google.auth.credentials.Signing` interface. Also assumes
        ``credentials`` has a ``signer_email`` property which
        identifies the credentials.

    .. note::

        If you are on Google Compute Engine, you can't generate a signed URL.
        If you'd like to be able to generate a signed URL from GCE,you can use a
        standard service account from a JSON file rather than a GCE service account.

    See headers [reference](https://cloud.google.com/storage/docs/reference-headers)
    for more details on optional arguments.

    :type credentials: :class:`google.auth.credentials.Signing`
    :param credentials: Credentials object with an associated private key to
                        sign text. That credentials must provide signer_email
                        only if service_account_email and access_token are not
                        passed.

    :type resource: str
    :param resource: A pointer to a specific resource
                     (typically, ``/bucket-name/path/to/blob.txt``).
                     Caller should have already URL-encoded the value.

    :type expiration: Union[Integer, datetime.datetime, datetime.timedelta]
    :param expiration: Point in time when the signed URL should expire. If
                       a ``datetime`` instance is passed without an explicit
                       ``tzinfo`` set,  it will be assumed to be ``UTC``.

    :type api_access_endpoint: str
    :param api_access_endpoint: URI base. Defaults to
                                "https://storage.googleapis.com/"

    :type method: str
    :param method: The HTTP verb that will be used when requesting the URL.
                   Defaults to ``'GET'``. If method is ``'RESUMABLE'`` then the
                   signature will additionally contain the `x-goog-resumable`
                   header, and the method changed to POST. See the signed URL
                   docs regarding this flow:
                   https://cloud.google.com/storage/docs/access-control/signed-urls


    :type content_md5: str
    :param content_md5: (Optional) The MD5 hash of the object referenced by
                        ``resource``.

    :type content_type: str
    :param content_type: (Optional) The content type of the object referenced
                         by ``resource``.

    :type response_type: str
    :param response_type: (Optional) Content type of responses to requests for
                          the signed URL. Ignored if content_type is set on
                          object/blob metadata.

    :type response_disposition: str
    :param response_disposition: (Optional) Content disposition of responses to
                                 requests for the signed URL.

    :type generation: str
    :param generation: (Optional) A value that indicates which generation of
                       the resource to fetch.

    :type headers: dict
    :param headers:
        (Optional) Additional HTTP headers to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers
        Requests using the signed URL *must* pass the specified header
        (name and value) with each request for the URL.

    :type query_parameters: dict
    :param query_parameters:
        (Optional) Additional query parameters to be included as part of the
        signed URLs.  See:
        https://cloud.google.com/storage/docs/xml-api/reference-headers#query

    :type service_account_email: str
    :param service_account_email: (Optional) E-mail address of the service account.

    :type access_token: str
    :param access_token: (Optional) Access token for a service account.

    :raises: :exc:`TypeError` when expiration is not a valid type.
    :raises: :exc:`AttributeError` if credentials is not an instance
            of :class:`google.auth.credentials.Signing`.

    :rtype: str
    :returns: A signed URL you can use to access the resource
              until expiration.
    Né   z/auto/storage/goog4_requestú/zContent-TypezContent-MD5ÚhostÚHostr[   r\   Ústartzx-goog-resumablerk   ú;r^   zGOOG4-RSA-SHA256zX-Goog-AlgorithmzX-Goog-CredentialzX-Goog-DatezX-Goog-ExpireszX-Goog-SignedHeadersrl   rm   rn   zx-goog-content-sha256zUNSIGNED-PAYLOADr   z{}{}?{}&X-Goog-Signature={})r<   Úget_v4_now_dtstampsr   r!   rK   ra   rb   ÚurlparseÚnetlocÚupperrU   rA   rH   Ú_url_encoderF   ÚhashlibÚsha256r   Ú	hexdigestrs   r   Ú	b64decodeÚbinasciiÚhexlifyÚdecoder   r   )(r   rX   r"   ru   rW   rv   rw   rx   ry   rn   rP   rY   rz   r{   r|   Ú_request_timestampÚexpiration_secondsÚrequest_timestampÚ	datestampÚclient_emailÚcredential_scopeÚ
credentialrC   Úheader_namesrT   rR   Úcanonical_header_stringrd   Úsigned_headersr_   Úcanonical_query_stringÚlowercased_headersÚpayloadÚcanonical_elementsÚcanonical_requestÚcanonical_request_hashÚstring_elementsr#   r%   r$   s(                                           r   Úgenerate_signed_url_v4r§   ¥  s?  € ôd 3°:Ó>ÐàÐ!Ü':Ó'<Ñ$Ð™9à.ÐØ& r¨Ð*ˆ	ð )€LÙÑ4Ü! +Ô.Ø"×/Ñ/ˆà#˜Ð$?Ð@ÐØ �> Ð#3Ð"4Ð5€Jà€ØˆàÐØ".ˆ�ÑàÐØ!,ˆ�Ñà+2Ö3 C�C—I‘I•KÐ3€LÐ3Ø�\Ñ!Ü Ÿ,™,×/Ñ/Ð0CÓD×KÑKˆ�‰à‡|�|ƒ~˜Ò$ØˆØ&-ˆÐ"Ñ#ä)>¸wÓ)GÑ&Ð�à�	‰	Ð#Ó$ tÑ+ð ð —X‘X°×A¡v s¨AšsÓAÓB€NàÐØÑà?O×?UÑ?UÓ?W×X±°°e˜C ¢¨"Ñ,ÐXÐÑXà+=ÐÐ'Ñ(Ø,6ÐÐ(Ñ)Ø&7Ð�]Ñ#Ø);ÐÐ%Ñ&Ø/=ÐÐ+Ñ,àÐ Ø4AÐÐ0Ñ1àÐ'Ø;OÐÐ7Ñ8àÐØ)3Ð˜Ñ&ä(Ð)9Ó:Ðä˜oÓ.ÐàÐ"4Ñ4Ø$Ð%<Ñ=‰à$ˆð 	ØØØØØðÐð Ÿ	™	Ð"4Ó5Ðä$Ÿ^™^Ø× Ñ  Ó)óç�iƒkð ð
 	ØØØð	€Oð —Y‘Y˜Ó/€NáÑ-Ü!Ø˜LÐ*?Àó
ˆ	ô !×*Ñ*¨9Ó5ˆÜ×$Ñ$ _Ó5×<Ñ<¸WÓE‰	à%×0Ñ0°×1FÑ1FÀwÓ1OÓPˆÜ×$Ñ$ _Ó5×<Ñ<¸WÓEˆ	à(×/Ñ/Ø˜XÐ'=¸yóð ùòW 4ùó Bùó
 Ys   Á"JÃ7J
Ä#Jc                  ó¨   — t        t        «      j                  d¬«      } | j                  d«      }| j	                  «       j                  d«      }||fS )z~Get current timestamp and datestamp in V4 valid format.

    :rtype: str, str
    :returns: Current timestamp, datestamp.
    Nr3   z%Y%m%dT%H%M%SZz%Y%m%d)r   r   r6   ÚstrftimeÚdate)r/   Ú	timestampr™   s      r   rŠ   rŠ   ‚  sK   € ô Œt‹*×
Ñ
 DÐ
Ó
)€CØ—‘Ð-Ó.€IØ—‘“
×#Ñ# HÓ-€IØ�iÐÐr   c                 ó*  ‡	‡
‡‡‡— t        j                  | «      } dŠd|› d|› d�Šd|z   ddœŠ
t        j                  dt	        j
                  | «      j                  d	«      i«      Š	t        j                  «       Šˆ	ˆ
ˆˆˆfd
„}t        } ||«      } |«       }|j                  t        j                  j                  k7  r"t        j                  d|j                   › �«      ‚t        j"                  |j                   j                  d	«      «      }|d   S )a­  Signs a message.

    :type message: str
    :param message: The message to be signed.

    :type access_token: str
    :param access_token: Access token for a service account.


    :type service_account_email: str
    :param service_account_email: E-mail address of the service account.

    :raises: :exc:`TransportError` if an `access_token` is unauthorized.

    :rtype: str
    :returns: The signature of the message.

    r\   zhttps://iamcredentials.z/v1/projects/-/serviceAccounts/z:signBlob?alt=jsonzBearer zapplication/json)ÚAuthorizationzContent-typer¢   zutf-8c                  ó    •—  ‰‰‰‰‰¬«      } | S )N)ÚurlrW   ÚbodyrP   © )Úresponser°   rP   rW   Úrequestr¯   s    €€€€€r   Úretriable_requestz(_sign_message.<locals>.retriable_request±  s   ø€ Ù˜s¨6¸ÀgÔNˆØˆr   z%Error calling the IAM signBytes API: Ú
signedBlob)r   Ú	_to_bytesÚjsonÚdumpsr   r    r•   r   ÚRequestr	   ÚstatusÚhttpÚclientÚOKr   ÚTransportErrorÚdataÚloads)Úmessager{   rz   r|   r´   ÚretryÚcallr²   r¿   r°   rP   rW   r³   r¯   s            @@@@@r   rs   rs   Ž  s   ü€ ô0 × Ñ  Ó)€Gà€FØ# OÐ#4Ð4SÐTiÐSjÐj|Ð
}€Cà" \Ñ1Ø*ñ€Gô �:‰:�y¤&×"2Ñ"2°7Ó";×"BÑ"BÀ7Ó"KÐLÓM€DÜ×ÑÓ €G÷ð ô
 €EÙÐ"Ó#€DÙ‹v€Hà‡�œ$Ÿ+™+Ÿ.™.Ò(Ü×'Ñ'Ø3°H·M±M°?ÐCó
ð 	
ô �:‰:�h—m‘m×*Ñ*¨7Ó3Ó4€DØ�ÑÐr   c           	      ó´   — | j                  «       D ��cg c]  \  }}t        |«      › dt        |«      › �‘Œ  }}}dj                  t        |«      «      S c c}}w )z®Encode query params into URL.

    :type query_params: dict
    :param query_params: Query params to be encoded.

    :rtype: str
    :returns: URL encoded query params.
    ú=ú&)rH   Ú_quote_paramrA   rO   )Úquery_paramsÚnamer_   Úparamss       r   rŽ   rŽ   Ã  s_   € ð (×-Ñ-Ó/÷áˆD�%ô ˜ÓÐ
˜a¤¨UÓ 3Ð4Ò5ð€Fñ ð
 �8‰8”F˜6“NÓ#Ð#ùós   ”#Ac                 óz   — t        | t        «      st        | «      } t        j                  j                  | d¬«      S )z’Quote query param.

    :type param: Any
    :param param: Query param to be encoded.

    :rtype: str
    :returns: URL encoded query param.
    ú~)Úsafe)r   Úbytesrq   ra   rb   Úquote)Úparams    r   rÇ   rÇ   Ô  s1   € ô �eœUÔ#Ü�E“
ˆÜ�<‰<×Ñ˜e¨#ÐÓ.Ð.r   )r^   ri   NNNNNNNNNN),r   r“   rI   r*   r�   r»   r·   ra   Úgoogle.auth.credentialsr   Úgoogle.authr   Úgoogle.auth.transportr   Úgoogle.cloudr   Úgoogle.cloud.storage._helpersr   r   r   Úgoogle.cloud.storage.retryr	   ÚutcnowÚNOWr   r   r'   r1   r-   r+   r5   r<   rU   Ú
namedtuplerV   rh   r‚   r9   ÚDEFAULT_ENDPOINTr§   rŠ   rs   rŽ   rÇ   r±   r   r   ú<module>rÛ      s,  ðó  Û Û Û Û Û Û Û ã Ý "Ý *å !ß NÑ NÝ 4ð ×Ñ×Ñ€ð-ð ò
ò&ò>ð> ˜(×+Ñ+¨X×-?Ñ-?Ð@Ð ò#òL".ðJ $ˆ[×#Ñ#ØÒGó€
ò
/Jðl ØØØØØØØØØØØó]ð@ €
Ø3Ð ð )ØØØØØØØØØØØØó!Zòz	 ð  -ó	2òj$ó"/r   