Ë
    v»•jû]  ã                   ó  — d Z ddlZddlZddlZddlZddlZddlZddlZddlm	Z	m
Z
mZ ddlmZ erddlZddlZ ej"                  e«      Z ej(                  d¬«      Z ej(                  d¬«      Z ej(                  d¬	«      Z ej(                  d¬«      Zd
Z G d„ de	«      Z G d„ de«      Z G d„ dej:                  «      Z G d„ de«      Zd„ Z d„ Z! G d„ de«      Z"de#fd„Z$de#de#fd„Z%de#de#fd„Z&de#de#de#fd„Z'y)z2Utilities for Regional Access Boundary management.é    N)Ú
NamedTupleÚOptionalÚTYPE_CHECKING)Ú_helpersé   )Úhoursé   é   )Úminuteszx-allowed-locationsc                   óˆ   — e Zd ZU dZee   ed<   eej                     ed<   eej                     ed<   ej                  ed<   y)Ú_RegionalAccessBoundaryDataaÎ  Data container for a Regional Access Boundary snapshot.

    Attributes:
        encoded_locations (Optional[str]): The encoded Regional Access Boundary string.
        expiry (Optional[datetime.datetime]): The hard expiration time of the boundary data.
        cooldown_expiry (Optional[datetime.datetime]): The time until which further lookups are skipped.
        cooldown_duration (datetime.timedelta): The current duration for the exponential cooldown.
    Úencoded_locationsÚexpiryÚcooldown_expiryÚcooldown_durationN)	Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   ÚstrÚ__annotations__ÚdatetimeÚ	timedelta© ó    ú^/var/www/html/venv/lib/python3.12/site-packages/google/auth/_regional_access_boundary_utils.pyr   r   5   sA   … ñð   ‘}Ó$Ø�X×&Ñ&Ñ'Ó'Ø˜h×/Ñ/Ñ0Ó0Ø×)Ñ)Ô)r   r   c                   ó`   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zd„ Zdd„Z	d	„ Z
d
„ Zd„ Zd„ Zd„ Zd„ Zd„ Zy)Ú_RegionalAccessBoundaryManagerzãManages the Regional Access Boundary state and its background refresh.

    The actual data is held in an immutable `_RegionalAccessBoundaryData` object
    and is swapped atomically to ensure thread-safe, lock-free reads.
    c                 ó’   — t        d d d t        ¬«      | _        t        «       | _        t        j                  «       | _        d| _        y )N©r   r   r   r   F)	r   Ú)DEFAULT_REGIONAL_ACCESS_BOUNDARY_COOLDOWNÚ_dataÚ%_RegionalAccessBoundaryRefreshManagerÚrefresh_managerÚ	threadingÚLockÚ_update_lockÚ-_use_blocking_regional_access_boundary_lookup©Úselfs    r   Ú__init__z'_RegionalAccessBoundaryManager.__init__L   s?   € Ü0Ø"ØØ ÜGô	
ˆŒ
ô  EÓFˆÔÜ%ŸN™NÓ,ˆÔØ=BˆÕ:r   c                 óD   — | j                   j                  «       }d|d<   |S )z9Pickle helper that serializes the _update_lock attribute.Nr'   ©Ú__dict__Úcopy©r*   Ústates     r   Ú__getstate__z+_RegionalAccessBoundaryManager.__getstate__W   s#   € à—‘×"Ñ"Ó$ˆØ $ˆˆnÑØˆr   c                 ól   — | j                   j                  |«       t        j                  «       | _        y)z;Pickle helper that deserializes the _update_lock attribute.N)r.   Úupdater%   r&   r'   r0   s     r   Ú__setstate__z+_RegionalAccessBoundaryManager.__setstate__]   s#   € à�‰×Ñ˜UÔ#Ü%ŸN™NÓ,ˆÕr   c                 ó–   — t        |t        «      st        S | j                  |j                  k(  xr | j                  |j                  k(  S )z!Checks if two managers are equal.)Ú
isinstancer   ÚNotImplementedr"   r(   )r*   Úothers     r   Ú__eq__z%_RegionalAccessBoundaryManager.__eq__b   sF   € ä˜%Ô!?Ô@Ü!Ð!à�J‰J˜%Ÿ+™+Ñ%ò CØ×BÑBØ×BÑBñCð	
r   c                 ó   — d| _         y)zíEnables blocking Regional Access Boundary lookup.

        When enabled, the Regional Access Boundary lookup will be performed
        synchronously in the calling thread instead of asynchronously in a
        background thread.
        TN)r(   r)   s    r   Úenable_blocking_lookupz5_RegionalAccessBoundaryManager.enable_blocking_lookupl   s   € ð >BˆÕ:r   Nc                 ó<   — |sd}t        ||dt        ¬«      | _        y)aS  Manually sets the regional access boundary to the client provided initial values.

        Args:
            encoded_locations (Optional[str]): The encoded locations string.
            expiry (Optional[datetime.datetime]): The expiry time for the boundary.
                If encoded_locations is not provided, expiry is ignored.
        Nr    )r   r!   r"   )r*   r   r   s      r   Ú$set_initial_regional_access_boundaryzC_RegionalAccessBoundaryManager.set_initial_regional_access_boundaryu   s$   € ñ !ØˆFä0Ø/ØØ ÜGô	
ˆ�
r   c                 óâ   — | j                   }|j                  rA|j                  �5t        j                  «       |j                  k  r|j                  |t
        <   y|j                  t
        d«       y)a\  Applies the Regional Access Boundary header to the provided dictionary.

        If the boundary is valid, the 'x-allowed-locations' header is added
        or updated. Otherwise, the header is removed to ensure no stale
        data is sent.

        Args:
            headers (MutableMapping[str, str]): The headers dictionary to update.
        N)r"   r   r   r   ÚutcnowÚ _REGIONAL_ACCESS_BOUNDARY_HEADERÚpop)r*   ÚheadersÚrab_datas      r   Úapply_headersz,_RegionalAccessBoundaryManager.apply_headers‡   sR   € ð —:‘:ˆà×%Ò%Ø�O‰OÐ'¬H¯O©OÓ,=ÀÇÁÒ,Oà8@×8RÑ8RˆGÔ4Ò5à�K‰KÔ8¸$Õ?r   c                 óú   — | j                   }|j                  r5|j                  r)t        j                  «       |j                  t
        z
  k  ry|j                  r"t        j                  «       |j                  k  ryy)z°Checks if the Regional Access Boundary data needs a refresh and is not in cooldown.

        Returns:
            bool: True if a refresh is required, False otherwise.
        FT)r"   r   r   r   r@   Ú*REGIONAL_ACCESS_BOUNDARY_REFRESH_THRESHOLDr   )r*   rD   s     r   Ú_should_refreshz._RegionalAccessBoundaryManager._should_refreshš   sf   € ð —:‘:ˆð ×&Ò&Ø—’Ü—‘Ó!Ø�‰Ô!KÑKòMð ð ×#Ò#¬¯©Ó(9¸H×<TÑ<TÒ(TØàr   c                 óž   — | j                  «       sy| j                  r| j                  ||«       y| j                  j	                  ||| «       y)a  Starts a background thread to refresh the Regional Access Boundary if needed.

        Args:
            credentials (google.auth.credentials.Credentials): The credentials to refresh.
            request (google.auth.transport.Request): The object used to make HTTP requests.
        N)rH   r(   Ústart_blocking_refreshr$   Ústart_refresh©r*   ÚcredentialsÚrequests      r   Úmaybe_start_refreshz2_RegionalAccessBoundaryManager.maybe_start_refresh±   sF   € ð ×#Ñ#Ô%Øð ×=Ò=Ø×'Ñ'¨°WÕ=à× Ñ ×.Ñ.¨{¸GÀTÕJr   c              ƒ   óº   K  — | j                  «       sy| j                  r| j                  ||«      ƒ d{  –—†  y| j                  j	                  ||| «       y7 Œ#­w)a  Starts a background refresh or performs a blocking refresh asynchronously.

        Args:
            credentials (google.auth.credentials.Credentials): The credentials to refresh.
            request (google.auth.aio.transport.Request): The object used to make HTTP requests.
        N)rH   r(   Ústart_blocking_refresh_asyncr$   rK   rL   s      r   Úmaybe_start_refresh_asyncz8_RegionalAccessBoundaryManager.maybe_start_refresh_asyncÁ   sV   è ø€ ð ×#Ñ#Ô%Øð ×=Ò=Ø×3Ñ3°KÀÓI×IÑIà× Ñ ×.Ñ.¨{¸GÀTÕJð Jús   ‚3AµA¶$Ac                 ó:  — t        j                  |j                  «      r't        j	                  d«       | j                  d«       y	 |j                  |d¬«      }| j                  |«       y# t        $ r$}t        j	                  d|d¬«       d}Y d}~Œ:d}~ww xY w)aÖ  Initiates a blocking lookup of the Regional Access Boundary.

        If the lookup raises an exception, it is caught and logged as a warning,
        and the lookup is treated as a failure (entering cooldown). Exceptions
        are not propagated to the caller.

        Args:
            credentials (google.auth.credentials.Credentials): The credentials to refresh.
            request (google.auth.transport.Request): The object used to make HTTP requests.
        zPBlocking Regional Access Boundary lookup is not supported for async credentials.NT©Ú	fail_fastz@Blocking Regional Access Boundary lookup raised an exception: %s©Úexc_info)ÚinspectÚiscoroutinefunctionÚ _lookup_regional_access_boundaryÚ_LOGGERÚdebugÚ%process_regional_access_boundary_infoÚ	Exception©r*   rM   rN   Úregional_access_boundary_infoÚes        r   rJ   z5_RegionalAccessBoundaryManager.start_blocking_refreshÑ   sŸ   € ô ×&Ñ& {×'SÑ'SÔTÜ�M‰MØbôð ×6Ñ6°tÔ<Øð	1ð
 ×<Ñ<¸WÐPTÐ<ÓUð *ð 	×2Ñ2Ð3PÕQøô ò 	1Ü�M‰MØRØØð ô ð
 -1Õ)ûð	1ús   ÁA- Á-	BÁ6BÂBc              ƒ   óÊ   K  — 	 |j                  |d¬«      ƒ d{  –—† }| j	                  |«       y7 Œ# t        $ r$}t        j                  d|d¬«       d}Y d}~Œ<d}~ww xY w­w)aé  Initiates a blocking lookup of the Regional Access Boundary asynchronously.

        If the lookup raises an exception, it is caught and logged as a warning,
        and the lookup is treated as a failure (entering cooldown). Exceptions
        are not propagated to the caller.

        Args:
            credentials (google.auth.credentials.Credentials): The credentials to refresh.
            request (google.auth.aio.transport.Request): The object used to make HTTP requests.
        TrT   Nz7Regional Access Boundary lookup raised an exception: %srV   )rZ   r^   r[   r\   r]   r_   s        r   rQ   z;_RegionalAccessBoundaryManager.start_blocking_refresh_asyncõ   sy   è ø€ ð	1ð
 "×BÑBØ tð Có ÷ ð *ð 	×2Ñ2Ð3PÕQðùô ò 	1Ü�M‰MØIØØð ô ð
 -1Õ)ûð	1üs6   ‚A#„3 š1›3 ŸA#±3 ³	A ¼AÁA#ÁA Á A#c                 ón  — | j                   5  | j                  }|rS|j                  d«      }t        |t	        j
                  «       t        z   dt        ¬«      }t        j                  d«       n¬t        j                  d«       t	        j
                  «       |j                  z   }t        |j                  dz  t        «      }|j                  r&t	        j
                  «       |j                  kD  rd}d}n|j                  }|j                  }t        ||||¬«      }|| _        ddd«       y# 1 sw Y   yxY w)záProcesses the regional access boundary info and updates the state.

        Args:
            regional_access_boundary_info (Optional[Mapping[str, str]]): The regional access
                boundary info to process.
        ÚencodedLocationsNr    z+Regional Access Boundary lookup successful.z:Regional Access Boundary lookup failed. Entering cooldown.é   )r'   r"   Úgetr   r   r@   Ú$DEFAULT_REGIONAL_ACCESS_BOUNDARY_TTLr!   r[   r\   r   ÚminÚ%MAX_REGIONAL_ACCESS_BOUNDARY_COOLDOWNr   r   )	r*   r`   Úcurrent_datar   Úupdated_dataÚnext_cooldown_expiryÚnext_cooldown_durationÚnext_encoded_locationsÚnext_expirys	            r   r]   zD_RegionalAccessBoundaryManager.process_regional_access_boundary_info  s"  € ð ×Ññ /	&àŸ:™:ˆLá,à$A×$EÑ$EØ&ó%Ð!ô  ;Ø&7Ü#Ÿ?™?Ó,Ô/SÑSØ$(Ü&Oô	 �ô —‘ÐKÕLô —‘ØPôô
 —O‘OÓ%¨×(FÑ(FÑFð %ô *-Ø ×2Ñ2°QÑ6Ü9ó*Ð&ð  ×&Ò&¬8¯?©?Ó+<¸|×?RÑ?RÒ+RØ-1Ð*Ø"&‘Kà-9×-KÑ-KÐ*Ø".×"5Ñ"5�Kä:Ø&<Ø&Ø$8Ø&<ô	 �ð &ˆDŒJ÷_/	&÷ /	&ñ /	&ús   �DD+Ä+D4)NN)r   r   r   r   r+   r2   r5   r:   r<   r>   rE   rH   rO   rR   rJ   rQ   r]   r   r   r   r   r   E   sP   „ ñò	Còò-ò

òBó
ò$@ò&ò.Kò Kò "RòHRó<6&r   r   c                   ó6   ‡ — e Zd ZdZ	 	 	 	 	 	 dˆ fd„Zd„ Zˆ xZS )Ú$_RegionalAccessBoundaryRefreshThreadzAThread for background refreshing of the Regional Access Boundary.c                 óZ   •— t         ‰| �  «        d| _        || _        || _        || _        y )NT)Úsuperr+   ÚdaemonÚ_credentialsÚ_requestÚ_rab_manager)r*   rM   rN   Úrab_managerÚ	__class__s       €r   r+   z-_RegionalAccessBoundaryRefreshThread.__init__O  s.   ø€ ô 	‰ÑÔØˆŒØ'ˆÔØˆŒØ'ˆÕr   c                 óæ   — 	 | j                   j                  | j                  «      }| j                  j                  |«       y# t        $ r$}t        j                  d|d¬«       d}Y d}~ŒDd}~ww xY w)aÜ  
        Performs the Regional Access Boundary lookup and updates the state.

        This method is run in a separate thread. It delegates the actual lookup
        to the credentials object's `_lookup_regional_access_boundary` method.
        Based on the lookup's outcome (success or complete failure after retries),
        it updates the cached Regional Access Boundary information,
        its expiry, its cooldown expiry, and its exponential cooldown duration.
        úDAsynchronous Regional Access Boundary lookup raised an exception: %sTrV   N)ru   rZ   rv   r^   r[   r\   rw   r]   )r*   r`   ra   s      r   Úrunz(_RegionalAccessBoundaryRefreshThread.run[  sq   € ð
	1à×!Ñ!×BÑBÀ4Ç=Á=ÓQð *ð 	×Ñ×?Ñ?Ø)õ	
øô ò 	1Ü�M‰MØVØØð ô ð
 -1Õ)ûð	1ús   ‚%A Á	A0ÁA+Á+A0)rM   z=google.auth.credentials.CredentialsWithRegionalAccessBoundaryrN   zgoogle.auth.transport.Requestrx   r   )r   r   r   r   r+   r|   Ú__classcell__)ry   s   @r   rq   rq   L  s,   ø„ ÙKð
(àTð
(ð 1ð
(ð 6õ	
(ö
r   rq   c                   ó(   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zy)r#   zKManages a thread for background refreshing of the Regional Access Boundary.c                 óD   — t        j                  «       | _        d | _        y ©N)r%   r&   Ú_lockÚ_workerr)   s    r   r+   z._RegionalAccessBoundaryRefreshManager.__init__|  s   € Ü—^‘^Ó%ˆŒ
Øˆ�r   c                 óN   — | j                   j                  «       }d|d<   d|d<   |S )z?Pickle helper that serializes the _lock and _worker attributes.Nr�   r‚   r-   r0   s     r   r2   z2_RegionalAccessBoundaryRefreshManager.__getstate__€  s,   € à—‘×"Ñ"Ó$ˆØˆˆg‰ØˆˆiÑØˆr   c                 óz   — | j                   j                  |«       t        j                  «       | _        d| _        y)zAPickle helper that deserializes the _lock and _worker attributes.N)r.   r4   r%   r&   r�   r‚   r0   s     r   r5   z2_RegionalAccessBoundaryRefreshManager.__setstate__‡  s)   € à�‰×Ñ˜UÔ#Ü—^‘^Ó%ˆŒ
Øˆ�r   c                 ó’  — | j                   5  | j                  r$| j                  j                  «       r
	 ddd«       y	 t        j                  |«      }t        |||«      | _        | j                  j                  «        ddd«       y# t
        $ r(}t        j                  d|«       Y d}~ddd«       yd}~ww xY w# 1 sw Y   yxY w)a¶  
        Starts a background thread to refresh the Regional Access Boundary if one is not already running.

        Args:
            credentials (CredentialsWithRegionalAccessBoundary): The credentials
                to refresh.
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            rab_manager (_RegionalAccessBoundaryManager): The manager container to update.
        Nz�Could not deepcopy transport for background RAB refresh. Skipping background refresh to avoid thread safety issues. Exception: %s)
r�   r‚   Úis_aliver/   Údeepcopyr^   r[   r\   rq   Ústart)r*   rM   rN   rx   Úcopied_requestra   s         r   rK   z3_RegionalAccessBoundaryRefreshManager.start_refresh�  sº   € ð �Z‰Zñ 	!Ø�|Š| §¡× 5Ñ 5Ô 7à÷	!ð 	!ð
	Ü!%§¡¨wÓ!7�ô @Ø˜^¨[óˆDŒLð �L‰L×ÑÔ ÷'	!ð 	!øô ò Ü—‘ð$ð ô	ó ÷	!ð 	!ûðú÷	!ð 	!ús4   �(B=¿B	Á,B=Â		B:ÂB5Â(B=Â5B:Â:B=Â=CN©r   r   r   r   r+   r2   r5   rK   r   r   r   r#   r#   y  s   „ ÙUòòòó!r   r#   c                 ó  — t        | t        j                  «      }|r| j                  n| }t	        |d«      s| |dfS |j                  «       }||u}|r.t        j                  |g| j                  ¢­i | j                  ¤Ž}n|}|||fS )ak  Unwraps a request callable, clones the transport, and returns the new callable.

    Args:
        request: The original request callable (e.g. functools.partial or raw Request).

    Returns:
        Tuple[Callable, Any, bool]: A tuple containing the new lookup callable, the
            underlying request object, and a boolean indicating if it was cloned.
    Ú_cloneF)r7   Ú	functoolsÚpartialÚfuncÚhasattrrŒ   ÚargsÚkeywords)rN   Ú
is_partialÚbase_callableÚcloned_callableÚ	is_clonedÚnew_requests         r   Ú_prepare_async_lookup_callabler˜   ®  s–   € ô ˜G¤Y×%6Ñ%6Ó7€JÙ$.�G—L’L°G€Mä�= (Ô+Ø˜ uÐ,Ð,à#×*Ñ*Ó,€OØ }Ð4€IáÜ×'Ñ'Øð
Ø%Ÿl™lò
Ø.5×.>Ñ.>ñ
‰ð &ˆà˜¨Ð2Ð2r   c              ƒ   ó  K  — |rt        | d«      syd}	 | j                  «       }t        j                  |«      x}r|ƒ d{  –—†  yy7 Œ# t        $ r)}|rdnd}t
        j                  d||d¬«       Y d}~yd}~ww xY w­w)	zÝSafely closes the underlying cloned request transport, if applicable.

    Args:
        lookup_request (Any): The request object/transport to close.
        is_cloned (bool): Whether the request was actually cloned.
    ÚcloseNFz asynchronous ú z5Failed to cleanly close cloned%srequest transport: %sTrV   )r�   rš   rX   Úisawaitabler^   r[   r\   )Úlookup_requestr–   Úis_asyncÚ
maybe_corora   Úadapter_types         r   Ú_close_cloned_requestr¡   Ë  s‘   è ø€ ñ œG N°GÔ<Øà€Hð
Ø#×)Ñ)Ó+ˆ
Ü×*Ñ*¨:Ó6Ð6ˆ8Ð6Ø×Ñð 7ØùÜò 
Ù+3Ñ'¸ˆÜ�‰ØCØØØð	 	÷ 	
ñ 	
ûð
üs@   ‚A?•,A
 ÁAÁA
 ÁA?ÁA
 Á
	A<ÁA7Á2A?Á7A<Á<A?c                   ó(   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zy)Ú*_AsyncRegionalAccessBoundaryRefreshManagerzXManages a task for background refreshing of the Regional Access Boundary in async flows.c                 óD   — t        j                  «       | _        d | _        y r€   )r%   r&   r�   Ú_worker_taskr)   s    r   r+   z3_AsyncRegionalAccessBoundaryRefreshManager.__init__ç  s   € Ü—^‘^Ó%ˆŒ
Ø ˆÕr   c                 óN   — | j                   j                  «       }d|d<   d|d<   |S )zbPickle helper that excludes the un-picklable _lock and _worker_task attributes from serialization.Nr�   r¥   r-   r0   s     r   r2   z7_AsyncRegionalAccessBoundaryRefreshManager.__getstate__ë  s,   € à—‘×"Ñ"Ó$ˆØˆˆg‰Ø $ˆˆnÑØˆr   c                 óz   — | j                   j                  |«       t        j                  «       | _        d| _        y)z[Pickle helper that restores state and re-initializes the _lock and _worker_task attributes.N)r.   r4   r%   r&   r�   r¥   r0   s     r   r5   z7_AsyncRegionalAccessBoundaryRefreshManager.__setstate__ò  s*   € à�‰×Ñ˜UÔ#Ü—^‘^Ó%ˆŒ
Ø ˆÕr   c                 ó�  ‡‡‡‡‡	— | j                   5  | j                  r$| j                  j                  «       s
	 ddd«       y	 t        |«      \  ŠŠ	Šˆˆˆˆ	ˆfd„} |«       }	 t        j                  |«      | _        	 ddd«       y# t        $ r;}t
        j                  d|d¬«       ‰j                  d«       Y d}~ddd«       yd}~ww xY w# t        $ ra |j                  «        	 t        j                  «       j                  t        ‰	‰«      «       n# t        $ r Y nw xY w‰j                  d«       ‚ w xY w# 1 sw Y   yxY w)a¸  
        Starts a background task to refresh the Regional Access Boundary if one is not already running.

        Args:
            credentials (CredentialsWithRegionalAccessBoundary): The credentials
                to refresh.
            request (google.auth.aio.transport.Request): The object used to make
                HTTP requests.
            rab_manager (_RegionalAccessBoundaryManager): The manager container to update.
        NzMSynchronous cloning of request for Regional Access Boundary lookup failed: %sTrV   c               “   ó(  •K  — 	 ‰j                  ‰«      ƒ d {  –—† } t	        ‰‰«      ƒ d {  –—†  ‰j                  | «       y 7 Œ*# t        $ r$}t        j                  d|d¬«       d } Y d }~ŒPd }~ww xY w7 ŒH# t	        ‰‰«      ƒ d {  –—†7   w xY w­w)Nr{   TrV   )rZ   r^   r[   r\   r¡   r]   )r`   ra   rM   r–   Úlookup_callabler�   rx   s     €€€€€r   r‚   zI_AsyncRegionalAccessBoundaryRefreshManager.start_refresh.<locals>._worker  s›   øè ø€ ðKà)×JÑJØ+ó÷ ð 2ô 0°À	ÓJ×JÐJà×AÑAØ1õðùô !ò 9Ü—M‘MØ^ØØ!%ð "ô ð
 59Õ1ûð9úð KùÔ/°À	ÓJ×JÒJüse   ƒB…A ™AšA žB­A6®BÁA Á	A3ÁA.Á)A8 Á.A3Á3A8 Á6BÁ8BÂBÂ	BÂB)r�   r¥   Údoner˜   r^   r[   r\   r]   ÚasyncioÚcreate_taskrš   Úget_running_loopr¡   ÚRuntimeError)
r*   rM   rN   rx   ra   r‚   Úcoror–   rª   r�   s
    ` `   @@@r   rK   z8_AsyncRegionalAccessBoundaryRefreshManager.start_refreshø  sE  ü€ ð �Z‰Zñ 6	Ø× Ò ¨×):Ñ):×)?Ñ)?Ô)Aà÷6	ð 6	ð
ô
 3°7Ó;ñ	Ø#Ø"Ø÷ð ñ* “9ˆDðÜ$+×$7Ñ$7¸Ó$=�Õ!÷W6	ð 6	øô ò Ü—‘ØcØØ!ð ô ð
 ×AÑAÀ$ÔGÛ÷%6	ð 6	ûðûôB ò 
à—
‘
”ðÜ×,Ñ,Ó.×:Ñ:Ü-¨n¸iÓHõøô $ò Ùðúà×AÑAÀ$ÔGØð
ú÷Y6	ð 6	úsk   ’(D<ÁBÁD<Á$CÂ	CÂ)CÂ:D<ÃCÃD<ÃD9Ã)-DÄD9Ä	D#Ä D9Ä"D#Ä#D9Ä9D<Ä<ENrŠ   r   r   r   r£   r£   ä  s   „ Ùbò!òò!óAr   r£   Úreturnc                  ó’   — ddl m}  t        | d«      r#| j                  «       rdt        j
                  › �S dt        j
                  › �S )z”Dynamically determines the domain for IAM credentials based on active mTLS configuration.

    Returns:
        str: The dynamic domain string.
    r   ©Ú_mtls_helperÚcheck_use_client_certziamcredentials.mtls.ziamcredentials.)Úgoogle.auth.transportr´   r�   rµ   r   ÚDEFAULT_UNIVERSE_DOMAINr³   s    r   Ú_get_domainr¸   <  sH   € õ 3ô 	�Ð5Ô6Ø×.Ñ.Ô0à%¤h×&FÑ&FÐ%GÐHÐHà ¤×!AÑ!AÐ BÐCÐCr   Úservice_account_emailc                 ó$   — dt        «       › d| › d�S )zÂBuilds the Regional Access Boundary lookup URL for service accounts.

    Args:
        service_account_email: The service account email.

    Returns:
        str: The complete lookup URL.
    úhttps://z/v1/projects/-/serviceAccounts/ú/allowedLocations©r¸   )r¹   s    r   Ú get_service_account_rab_endpointr¾   M  s   € ð ”k“m�_Ð$CÐDYÐCZÐZkÐlÐlr   Úpool_idc                 ó$   — dt        «       › d| › d�S )z¯Builds the Regional Access Boundary lookup URL for workforce pools.

    Args:
        pool_id: The workforce pool ID.

    Returns:
        str: The complete lookup URL.
    r»   z$/v1/locations/global/workforcePools/r¼   r½   )r¿   s    r   Úget_workforce_pool_rab_endpointrÁ   Y  s   € ð ”k“m�_Ð$HÈÈ	ÐQbÐcÐcr   Úproject_numberc                 ó*   — dt        «       › d| › d|› d�S )zøBuilds the Regional Access Boundary lookup URL for workload identity pools.

    Args:
        project_number: The Google Cloud project number.
        pool_id: The workload identity pool ID.

    Returns:
        str: The complete lookup URL.
    r»   z/v1/projects/z(/locations/global/workloadIdentityPools/r¼   r½   )rÂ   r¿   s     r   Ú'get_workload_identity_pool_rab_endpointrÄ   e  s0   € ð ”k“m�_ M°.Ð1AÐAiÐjqÐirð  sDð  Eð  Er   )(r   r¬   r/   r   r�   rX   Úloggingr%   Útypingr   r   r   Úgoogle.authr   Úgoogle.auth.credentialsÚgoogler¶   Ú	getLoggerr   r[   r   rg   rG   r!   ri   rA   r   Úobjectr   ÚThreadrq   r#   r˜   r¡   r£   r   r¸   r¾   rÁ   rÄ   r   r   r   ú<module>rÍ      sM  ðñ 9ã Û Û Û Û Û Û ß 6Ñ 6å  áÛ"Û à
ˆ'×
Ñ
˜HÓ
%€ð (: x×'9Ñ'9ÀÔ'BÐ $ð .@¨X×-?Ñ-?ÀaÔ-HÐ *ð -?¨H×,>Ñ,>ÀrÔ,JÐ )ð );¨×(:Ñ(:ÀÔ(CÐ %ð $9Ð  ô* *ô *ô D& Vô D&ôN*
¨9×+;Ñ+;ô *
ôZ2!¨Fô 2!òj3ò:
ô2U°ô UðpD�Só Dð"	m¸Cð 	mÀCó 	mð	d¨Sð 	d°Só 	dð
E¸Cð 
EÈ#ð 
EÐRUô 
Er   