3 f÷ÔY2*ã@s¨dZddlZddlZddlZddlZddlmZddlmZddlZ ej e ƒZ dZ dZe efZdjejd�jƒZd d „Zd d „Zd d„Zdd„Zddd„Zddd„ZdS)zgApplication default credentials. Implements application default credentials and project ID detection. éN)Úenvironment_vars)Ú exceptionsZauthorized_userÚservice_accountzë Could not automatically determine credentials. Please set {env} or explicitly create credential and re-run the application. For more information, please see https://developers.google.com/accounts/docs/application-default-credentials. )Úenvc&Cshtjj|ƒstjdj|ƒƒ‚tj|dƒ�J}ytj |ƒ}Wn4t k rl}ztjdj|ƒ|ƒ‚WYdd}~XnXWdQRX|j dƒ}|t krâddl m}y|j|ƒ}Wn4t k rØ}ztjdj|ƒ|ƒ‚WYdd}~XnX|dfS|tk�rNdd lm}y|jj|ƒ}Wn6t k �r>}ztjd j|ƒ|ƒ‚WYdd}~XnX||j d ƒfStjd j||td �ƒ‚dS)a'Loads credentials from a file. The credentials file must be a service account key or stored authorized user credentials. Args: filename (str): The full path to the credentials file. Returns: Tuple[google.auth.credentials.Credentials, Optional[str]]: Loaded credentials and the project ID. Authorized user credentials do not have the project ID information. Raises: google.auth.exceptions.DefaultCredentialsError: if the file is in the wrong format or is missing. zFile {} was not found.Úrz!File {} is not a valid json file.NÚtyper)Ú _cloud_sdkz2Failed to load authorized user credentials from {})rz2Failed to load service account credentials from {}Ú project_idzZThe file {file} does not have a valid type. Type is {type}, expected one of {valid_types}.)ÚfilerÚ valid_types)ÚosÚpathÚexistsrÚDefaultCredentialsErrorÚformatÚioÚopenÚjsonÚloadÚ ValueErrorÚgetÚ_AUTHORIZED_USER_TYPEÚ google.authrZ load_authorized_user_credentialsÚ_SERVICE_ACCOUNT_TYPEZ google.oauth2rÚ CredentialsZfrom_service_account_infoÚ _VALID_TYPES)ÚfilenameZfile_objÚinfoÚexcZcredential_typerÚ credentialsr©r úE/Users/olari/OneDrive/sandbox/awsBlog2/lambda/google/auth/_default.pyÚ_load_credentials_from_file-s>  *    r"cCsVddlm}|jƒ}tjj|ƒs$dSt|ƒ\}}|s<|jƒ}|sNtj dt j ƒ||fS)z7Gets the credentials and project ID from the Cloud SDK.r)rNz—No project ID could be determined from the Cloud SDK configuration. Consider running `gcloud config set project` or setting the %s environment variable)NN) rrZ(get_application_default_credentials_pathr r Úisfiler"Úget_project_idÚ_LOGGERÚwarningrÚPROJECT)rZcredentials_filenamerr r r r!Ú_get_gcloud_sdk_credentialsms   r(cCsPtjjtjƒ}|dk rHttjtjƒ\}}|s@tjdtjtjƒ||fSdSdS)zRGets credentials from the GOOGLE_APPLICATION_CREDENTIALS environment variable.NziNo project ID could be determined from the credentials at %s Consider setting the %s environment variable)NN) r ÚenvironrrÚ CREDENTIALSr"r%r&r')Z explicit_filerr r r r!Ú!_get_explicit_environ_credentials‡s r+c Cs>ddlm}y|jƒ}|jƒ}||fStk r8dSXdS)z?Gets Google App Engine App Identity credentials and project ID.r)Ú app_engineN)NN)rr,rr$ÚEnvironmentError)r,rr r r r!Ú_get_gae_credentialsœs r.c Csˆddlm}ddlm}|dkr.tjjjjƒ}|j |d�r€y|j |d�}Wn(t j k rrt jdtjƒd}YnX|jƒ|fSdSdS)z>Gets credentials and project ID from the GCE Metadata Service.r)Úcompute_engine)Ú _metadataN)ÚrequestzyNo project ID could be determined from the Compute Engine metadata service. Consider setting the %s environment variable.)NN)rr/Zgoogle.auth.compute_enginer0ÚgoogleÚauthÚ transportZ _http_clientÚRequestÚpingr$rZTransportErrorr%r&rr'r)r1r/r0r r r r!Ú_get_gce_credentials¨s     r7cs~ddlm}tjjtjtjjtjƒƒ}tt t ‡fdd„f}x4|D],}|ƒ\}}|dk r@|||ƒ}||ph|fSq@Wt j t ƒ‚dS)ao Gets the default credentials for the current environment. `Application Default Credentials`_ provides an easy way to obtain credentials to call Google APIs for server-to-server or local applications. This function acquires credentials from the environment in the following order: 1. If the environment variable ``GOOGLE_APPLICATION_CREDENTIALS`` is set to the path of a valid service account JSON private key file, then it is loaded and returned. The project ID returned is the project ID defined in the service account file if available (some older files do not contain project ID information). 2. If the `Google Cloud SDK`_ is installed and has application default credentials set they are loaded and returned. To enable application default credentials with the Cloud SDK run:: gcloud auth application-default login If the Cloud SDK has an active project, the project ID is returned. The active project can be set using:: gcloud config set project 3. If the application is running in the `App Engine standard environment`_ then the credentials and project ID from the `App Identity Service`_ are used. 4. If the application is running in `Compute Engine`_ or the `App Engine flexible environment`_ then the credentials and project ID are obtained from the `Metadata Service`_. 5. If no credentials are found, :class:`~google.auth.exceptions.DefaultCredentialsError` will be raised. .. _Application Default Credentials: https://developers.google.com /identity/protocols/application-default-credentials .. _Google Cloud SDK: https://cloud.google.com/sdk .. _App Engine standard environment: https://cloud.google.com/appengine .. _App Identity Service: https://cloud.google.com/appengine/docs/python /appidentity/ .. _Compute Engine: https://cloud.google.com/compute .. _App Engine flexible environment: https://cloud.google.com /appengine/flexible .. _Metadata Service: https://cloud.google.com/compute/docs /storing-retrieving-metadata Example:: import google.auth credentials, project_id = google.auth.default() Args: scopes (Sequence[str]): The list of scopes for the credentials. If specified, the credentials will automatically be scoped if necessary. request (google.auth.transport.Request): An object used to make HTTP requests. This is used to detect whether the application is running on Compute Engine. If not specified, then it will use the standard library http client to make requests. Returns: Tuple[~google.auth.credentials.Credentials, Optional[str]]: the current environment's credentials and project ID. Project ID may be None, which indicates that the Project ID could not be ascertained from the environment. Raises: ~google.auth.exceptions.DefaultCredentialsError: If no credentials were found, or if the credentials found were invalid. r)Úwith_scopes_if_requiredcstˆƒS)N)r7r )r1r r!Úszdefault..N)Zgoogle.auth.credentialsr8r r)rrr'ZLEGACY_PROJECTr+r(r.rrÚ _HELP_MESSAGE)Úscopesr1r8Zexplicit_project_idÚcheckersÚcheckerrr r )r1r!ÚdefaultÄsH    r>)N)NN)Ú__doc__rrÚloggingr rrrZ"google.auth.transport._http_clientr2Ú getLoggerÚ__name__r%rrrrr*Ústripr:r"r(r+r.r7r>r r r r!Ús$   @