o
    pkj                  	   @   s   d Z ddlZddlZddlZddlZddlmZ ddlmZ ddl	m
Z
 ddlZeeZ	ddededee d	ejfd
dZdd Zdd Z	dddZdddZdS )z<
Helper functions for mTLS in async for discovery of certs.
    N)Optional)
exceptions)secure_cert_key_paths
cert_bytes	key_bytes
passphrasereturnc           	      C   s   z3t | ||d!\}}}ttjj}|r|}|j|||d |W  d   W S 1 s,w   Y  W dS  tjttt	t
tfyL } ztd|d}~ww )a  Creates an SSLContext with the given client certificate and key.
    This function writes the certificate and key to temporary files so that
    ssl.create_default_context can load them, as the ssl module requires
    file paths for client certificates. These temporary files are deleted
    immediately after the SSL context is created.
    Args:
        cert_bytes (bytes): The client certificate content in PEM format.
        key_bytes (bytes): The client private key content in PEM format.
        passphrase (Optional[bytes]): The passphrase for the private key, if any.
    Returns:
        ssl.SSLContext: The configured SSL context with client certificate.

    Raises:
        google.auth.exceptions.TransportError: If there is an error loading the certificate.
    )r   )certfilekeyfilepasswordNz3Failed to load client certificate and key for mTLS.)r   sslcreate_default_contextPurposeSERVER_AUTHload_cert_chainSSLErrorOSErrorIOError
ValueErrorRuntimeError	TypeErrorr   TransportError)	r   r   r   	cert_pathkey_pathpassphrase_valcontextr   exc r   \/home/djax/ivt_ai_plugin/venv/lib/python3.10/site-packages/google/auth/aio/transport/mtls.pymake_client_cert_ssl_context    s.   (r   c                    sR   zt j| g|R  I dH W S  ty(   t  }|jd| g|R  I dH  Y S w )zRun a blocking function in an executor to avoid blocking the event loop.

    This implements the non-blocking execution strategy for disk I/O operations.
    N)asyncio	to_threadAttributeErrorget_running_looprun_in_executor)funcargsloopr   r   r   _run_in_executorG   s   r(   c                  C   s(   t jjjjddstddd } | S )a  Get a callback which returns the default client SSL credentials.

    Returns:
        Awaitable[Callable[[], Tuple[bytes, bytes]]]: A callback which returns the default
            client certificate bytes and private key bytes, both in PEM format.

    Raises:
        google.auth.exceptions.DefaultClientCertSourceError: If the default
            client SSL credentials don't exist or are malformed.
    F)include_context_awarez(Default client cert source doesn't existc               
      sN   zt  I d H \} }}W ||fS  tttfy& } zt|}||d }~ww N)get_client_cert_and_keyr   r   r   r   MutualTLSChannelError)_r   r   
caught_excnew_excr   r   r   callbackg   s   
z,default_client_cert_source.<locals>.callback)googleauth	transportmtlshas_default_client_cert_sourcer   r,   )r0   r   r   r   default_client_cert_sourceU   s   
	r6   c                    s8   t tjjjj| dI dH \}}|r|rd||dfS dS )a  Returns the client side certificate, private key and passphrase.

    We look for certificates and keys with the following order of priority:
        1. Certificate and key specified by certificate_config.json.
               Currently, only X.509 workload certificates are supported.

    Args:
        certificate_config_path (str): The certificate_config.json file path.

    Returns:
        Tuple[bool, bytes, bytes, bytes]:
            A boolean indicating if cert, key and passphrase are obtained, the
            cert bytes and key bytes both in PEM format, and passphrase bytes.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert, key and passphrase.
    FNT)FNNN)r(   r1   r2   r3   _mtls_helper_get_workload_cert_and_key)certificate_config_pathcertkeyr   r   r   get_client_ssl_credentialss   s   
r<   c                    sV   | r|  }t |r|I dH \}}n|\}}d||fS t I dH \}}}}|||fS )a  Returns the client side certificate and private key. The function first
    tries to get certificate and key from client_cert_callback; if the callback
    is None or doesn't provide certificate and key, the function tries application
    default SSL credentials.

    Args:
        client_cert_callback (Optional[Callable[[], (bytes, bytes)]]): An
            optional callback which returns client certificate bytes and private
            key bytes both in PEM format.

    Returns:
        Tuple[bool, bytes, bytes]:
            A boolean indicating if cert and key are obtained, the cert bytes
            and key bytes both in PEM format.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert and key.
    NT)inspectisawaitabler<   )client_cert_callbackresultr:   r;   has_certr-   r   r   r   r+      s   


r+   r*   )__doc__r    r=   loggingr   typingr   google.authr   "google.auth.transport._mtls_helperr   google.auth.transport.mtlsr1   	getLogger__name___LOGGERbytes
SSLContextr   r(   r6   r<   r+   r   r   r   r   <module>   s2   

'
#