3 L(ÌYXã@s’dZddlZddlmZddlmZddlmZyddlmZWnek rXdZYnXGdd„dej ƒZ d d „Z Gd d „d ej ej ej ƒZ dS) aGoogle App Engine standard environment support. This module provides authentication and signing for applications running on App Engine in the standard environment using the `App Identity API`_. .. _App Identity API: https://cloud.google.com/appengine/docs/python/appidentity/ éN)Ú_helpers)Ú credentials)Úcrypt)Ú app_identityc@s0eZdZdZedd„ƒZejej ƒdd„ƒZ dS)ÚSignerz»Signs messages using the App Engine App Identity service. This can be used in place of :class:`google.auth.crypt.Signer` when running in the App Engine standard environment. cCsdS)zÖOptional[str]: The key ID used to identify this private key. .. warning:: This is always ``None``. The key ID used by App Engine can not be reliably determined ahead of time. N©)ÚselfrrúE/private/tmp/pip-build-nl73fm5q/google-auth/google/auth/app_engine.pyÚkey_id,sz Signer.key_idcCstj|ƒ}tj|ƒ\}}|S)N)rÚto_bytesrZ sign_blob)rÚmessageÚ_Ú signaturerrr Úsign6s z Signer.signN) Ú__name__Ú __module__Ú __qualname__Ú__doc__Úpropertyr rÚcopy_docstringrrrrrrr r%s rcCstdkrtdƒ‚tjƒS)z¹Gets the project ID for the current App Engine application. Returns: str: The project ID Raises: EnvironmentError: If the App Engine APIs are unavailable. Nz&The App Engine APIs are not available.)rÚEnvironmentErrorZget_application_idrrrr Úget_project_id=s rcs¦eZdZdZd‡fdd„ Zejejƒdd„ƒZ e dd„ƒZ e d d „ƒZ ejej ƒd d „ƒZejejƒd d„ƒZe ejejƒdd„ƒƒZe ejejƒdd„ƒƒZ‡ZS)Ú Credentialsz‰App Engine standard environment credentials. These credentials use the App Engine App Identity API to obtain access tokens. Ncs6tdkrtdƒ‚tt|ƒjƒ||_||_tƒ|_dS)aÏ Args: scopes (Sequence[str]): Scopes to request from the App Identity API. service_account_id (str): The service account ID passed into :func:`google.appengine.api.app_identity.get_access_token`. If not specified, the default application service account ID will be used. Raises: EnvironmentError: If the App Engine APIs are unavailable. Nz&The App Engine APIs are not available.) rrÚsuperrÚ__init__Ú_scopesÚ_service_account_idrÚ_signer)rÚscopesÚservice_account_id)Ú __class__rr rWszCredentials.__init__cCs2tj|j|jƒ\}}tjj|ƒ}|||_|_dS)N)rZget_access_tokenrrÚdatetimeÚutcfromtimestampÚtokenÚexpiry)rÚrequestr#Zttlr$rrr Úrefreshps zCredentials.refreshcCs|jdkrtjƒ|_|jS)zThe service account email.N)rrZget_service_account_name)rrrr Úservice_account_emailys  z!Credentials.service_account_emailcCs|j S)zˆChecks if the credentials requires scopes. Returns: bool: True if there are no scopes set otherwise False. )r)rrrr Úrequires_scopes€szCredentials.requires_scopescCst||jd�S)N)rr)rr)rrrrr Ú with_scopes‰szCredentials.with_scopescCs |jj|ƒS)N)rr)rr rrr Ú sign_bytesŽszCredentials.sign_bytescCs|jS)N)r')rrrr Ú signer_email’szCredentials.signer_emailcCs|jS)N)r)rrrr Úsigner—szCredentials.signer)NN)rrrrrrrrrr&rr'r(ÚScopedr)ÚSigningr*r+r,Ú __classcell__rr)r r rOs  r)rr!Z google.authrrrZgoogle.appengine.apirÚ ImportErrorrrr-r.rrrrr Ús