
    @wj              	           d Z ddlZddlZddlZddlZddlmZ ddlmZ ddl	m
Z
 ddlZ ej                  e      Z	 ddededee   d	ej"                  fd
Zd Zd Z	 ddZddZy)z<
Helper functions for mTLS in async for discovery of certs.
    N)Optional)
exceptions)secure_cert_key_paths
cert_bytes	key_bytes
passphrasereturnc                 x   	 t        | ||      5 \  }}}t        j                  t        j                  j                        }|r|}|j                  |||       |cddd       S # 1 sw Y   yxY w# t        j                  t        t        t        t        t        f$ r}t        j                  d      |d}~ww xY w)a  Creates an SSLContext with the given client certificate and key.
    This function writes the certificate and key to temporary files so that
    ssl.create_default_context can load them, as the ssl module requires
    file paths for client certificates. These temporary files are deleted
    immediately after the SSL context is created.
    Args:
        cert_bytes (bytes): The client certificate content in PEM format.
        key_bytes (bytes): The client private key content in PEM format.
        passphrase (Optional[bytes]): The passphrase for the private key, if any.
    Returns:
        ssl.SSLContext: The configured SSL context with client certificate.

    Raises:
        google.auth.exceptions.TransportError: If there is an error loading the certificate.
    )r   )certfilekeyfilepasswordNz3Failed to load client certificate and key for mTLS.)r   sslcreate_default_contextPurposeSERVER_AUTHload_cert_chainSSLErrorOSErrorIOError
ValueErrorRuntimeError	TypeErrorr   TransportError)	r   r   r   	cert_pathkey_pathpassphrase_valcontextr   excs	            \/root/dashboard-youtube/.venv/lib/python3.12/site-packages/google/auth/aio/transport/mtls.pymake_client_cert_ssl_contextr        s    $":yZP 	 U
001H1HIG)''&$% ( 
 	 	 	 LL'7JiP ''A
	s5   A1 AA%	A1 %A.*A1 .A1 1-B9B44B9c                    K   	 t        j                  | g|  d{   S 7 # t        $ r4 t        j                         } |j                  d| g|  d{  7  cY S w xY ww)zRun a blocking function in an executor to avoid blocking the event loop.

    This implements the non-blocking execution strategy for disk I/O operations.
    N)asyncio	to_threadAttributeErrorget_running_looprun_in_executor)funcargsloops      r   _run_in_executorr*   G   sc     
=&&t3d3333 =''))T))$<t<<<<=s=   A$$ "$ A$$ 4A!AA!A$ A!!A$c                      t         j                  j                  j                  j	                  d      st        j                  d      d } | S )a  Get a callback which returns the default client SSL credentials.

    Returns:
        Awaitable[Callable[[], Tuple[bytes, bytes]]]: A callback which returns the default
            client certificate bytes and private key bytes, both in PEM format.

    Raises:
        google.auth.exceptions.DefaultClientCertSourceError: If the default
            client SSL credentials don't exist or are malformed.
    F)include_context_awarez(Default client cert source doesn't existc                     K   	 t                d {   \  } }}||fS 7 # t        t        t        f$ r}t	        j
                  |      }||d }~ww xY wwN)get_client_cert_and_keyr   r   r   r   MutualTLSChannelError)_r   r   
caught_excnew_excs        r   callbackz,default_client_cert_source.<locals>.callbackg   s^     	*-D-F'F$Az9
 9$$ (Gz2 	* 66zBGz)	*s0   A    A  AAAA)googleauth	transportmtlshas_default_client_cert_sourcer   r0   )r4   s    r   default_client_cert_sourcer:   U   sO     ;;  %%DD# E  ..6
 	
% O    c                    K   t        t        j                  j                  j                  j
                  | d       d{   \  }}|r|rd||dfS y7 w)a  Returns the client side certificate, private key and passphrase.

    We look for certificates and keys with the following order of priority:
        1. Certificate and key specified by certificate_config.json.
               Currently, only X.509 workload certificates are supported.

    Args:
        certificate_config_path (str): The certificate_config.json file path.

    Returns:
        Tuple[bool, bytes, bytes, bytes]:
            A boolean indicating if cert, key and passphrase are obtained, the
            cert bytes and key bytes both in PEM format, and passphrase bytes.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert, key and passphrase.
    FNT)FNNN)r*   r5   r6   r7   _mtls_helper_get_workload_cert_and_key)certificate_config_pathcertkeys      r   get_client_ssl_credentialsrB   s   sX     . '**EE ID# T3$$"s   =AA Ac                    K   | r4 |        }t        j                  |      r| d{   \  }}n|\  }}d||fS t                d{   \  }}}}|||fS 7 .7 w)a  Returns the client side certificate and private key. The function first
    tries to get certificate and key from client_cert_callback; if the callback
    is None or doesn't provide certificate and key, the function tries application
    default SSL credentials.

    Args:
        client_cert_callback (Optional[Callable[[], (bytes, bytes)]]): An
            optional callback which returns client certificate bytes and private
            key bytes both in PEM format.

    Returns:
        Tuple[bool, bytes, bytes]:
            A boolean indicating if cert and key are obtained, the cert bytes
            and key bytes both in PEM format.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert and key.
    NT)inspectisawaitablerB   )client_cert_callbackresultr@   rA   has_certr1   s         r   r/   r/      sn     ( %'v&$ID#ID#T3#=#??HdCT3 %
 @s!   $AAAAAAr.   )__doc__r"   rD   loggingr   typingr   google.authr   "google.auth.transport._mtls_helperr   google.auth.transport.mtlsr5   	getLogger__name___LOGGERbytes
SSLContextr    r*   r:   rB   r/    r;   r   <module>rU      s       
  " D !
'

H
% HL$$"'$5=e_$^^$N=> ! #Fr;   