403Webshell
Server IP : 104.21.21.239  /  Your IP : 216.73.216.55
Web Server : Apache/2.4.68 (Amazon Linux) OpenSSL/3.5.7
System : Linux ip-172-31-69-123.ec2.internal 6.1.177-224.371.amzn2023.x86_64 #1 SMP PREEMPT_DYNAMIC Mon Jul 27 20:28:29 UTC 2026 x86_64
User : ec2-user ( 1000)
PHP Version : 8.4.24
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /lib/python3.9/site-packages/awscli/botocore/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /lib/python3.9/site-packages/awscli/botocore/__pycache__/utils.cpython-39.pyc
a

wA�i�\�7@s<ddlZddlZddlZddlZddlZddlZddlZddlZddl	Z	ddl
Z
ddlZddlZddl
Z
ddlZddlZddlZddlZddlZddlZddlmZddlmZddlmZddlmZddlmZmZddlZddlZddlZddl Z!ddl"m#Z#ddl$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-m.Z.dd	l/m0Z0m1Z1m2Z2m3Z3m4Z4m5Z5m6Z6m7Z7m8Z8m9Z9m:Z:m;Z;m<Z<m=Z=m>Z>m?Z?m@Z@mAZAmBZBmCZCmDZDmEZEmFZFmGZGdd
lHmIZIddlJmKZKe	�LeM�ZNdZOd
ZPdZQdZRdZSe�Td�ZUe@e5e3e4fZVdgZWdZXe�TdeXd�ZYdZZdeZ�deZ�deX�d�Z[eZe[d�Z\gd�Z]dZ^dd�_dd�e]D��dZ`d e^d!Zad"e`dead#Zbe�Tdebd�Zcedd$�ZeejTd%ejfd&�Zgd'Zhd(d)�Zid*d+�Zjd,d-�Zkd.d/�Zld0d1�Zmd2d3�Znd4d5�Zod6d7�Zpd8d9�Zq�dd;d<�Zrd=d>�ZsGd?d@�d@et�ZuGdAdB�dBet�ZvGdCdD�dD�ZwGdEdF�dFew�Zx�ddHdI�ZydJdK�Zze{fdLdM�Z|dNdO�Z}eSfdPdQ�Z~eSfdRdS�ZdTdU�Z�dVdW�Z�dXdY�Z�dZd[�Z��d d\d]�Z��d!d^d_�Z�d`da�Z�dbdc�Z�Gddde�de�Z�Gdfdg�dg�Z�dhdi�Z�djdk�Z�dldm�Z�dndo�Z�dpdq�Z�drds�Z��d"dtdu�Z��d#dvdw�Z�dxdy�Z�dzd{�Z�d|d}�Z�d~d�Z�d�d��Z��d$d�d��Z��d%d�d��Z�d�d��Z�d�d��Z�Gd�d��d��Z�Gd�d��d�e��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d��d�e��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d��d�e��Z�Gd�d��d��Z�d�d��Z�d�d��Z�d�d��Z��d&d�d��Z�d�d��Z�d�d��Z�d�d��Z�d�d��Z�d�d��Z�d�d��Z�d�d��Z�d�d��Z�Gd�d��d��Z�Gd�d��d��Z�Gd�d„d�e��Z�Gd�dĄd�e��Z�Gd�dƄdƃZ�ej��d'd�dȄ�Z�Gd�dʄdʃZ�Gd�d̄d̃Z��d(d�d΄Z�d�dЄZ�d�d҄Z�d�dԄZ�d�dքZd)d�d؄Z�d�dڄZ�d�d�iZ�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d�d��d�d�d�d�d�d�d�d�d�d	�d
�d�d�d
�d�d�d�d�d�d�6ZƐd�d�Z�G�d�d��d�ZȐd�d�Zɐd*�d�d�Zʐd�d�Z�dS(+�N)�datetime)�partial)�
ip_address)�Path)�
getproxies�proxy_bypass)�EC)
�
MD5_AVAILABLE�get_md5�get_tzinfo_options�json�quote�
total_seconds�urlparse�urlsplit�
urlunsplit�zip_longest)�AuthorizationCodeLoadError�ClientError�ConfigNotFound�ConnectionClosedError�ConnectTimeoutError�EndpointConnectionError�HTTPClientError�InvalidDNSNameError�!InvalidEndpointConfigurationError�InvalidExpressionError�InvalidHostLabelError�InvalidIMDSEndpointError�InvalidIMDSEndpointModeError�InvalidRegionError�MetadataRetrievalError� PendingAuthorizationExpiredError�ReadTimeoutError�SSOTokenLoadError�UnsupportedOutpostResourceError�*UnsupportedS3AccesspointConfigurationError�UnsupportedS3ArnError�UnsupportedS3ConfigurationError�UnsupportedS3ControlArnError�&UnsupportedS3ControlConfigurationError)�tzutc)�LocationParseError�zhttp://169.254.169.254/zhttp://[fd00:ec2::254]/)�ipv4�ipv6�-._~z-z0-9][a-z0-9\-]*[a-z0-9]�	dualstackz(?:[0-9]{1,3}\.){3}[0-9]{1,3}�^�$z[0-9A-Fa-f]{1,4}z(?:�:�|�))�hexZls32)	z(?:%(hex)s:){6}%(ls32)sz::(?:%(hex)s:){5}%(ls32)sz%(?:%(hex)s)?::(?:%(hex)s:){4}%(ls32)sz2(?:(?:%(hex)s:)?%(hex)s)?::(?:%(hex)s:){3}%(ls32)sz6(?:(?:%(hex)s:){0,2}%(hex)s)?::(?:%(hex)s:){2}%(ls32)sz/(?:(?:%(hex)s:){0,3}%(hex)s)?::%(hex)s:%(ls32)sz'(?:(?:%(hex)s:){0,4}%(hex)s)?::%(ls32)sz&(?:(?:%(hex)s:){0,5}%(hex)s)?::%(hex)sz(?:(?:%(hex)s:){0,6}%(hex)s)?::zDABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789._!\-~cCsg|]}|t�qS�)�_subs)�.0�xr8r8�9/usr/lib/python3.9/site-packages/awscli/botocore/utils.py�
<listcomp>��r=z
(?:%25|%)(?:[z]|%[a-fA-F0-9]{2})+z\[z)?\]z	
z^X-Amz-Checksum-([a-z0-9]*)$)�flags)rz	rest-jsonzrest-xmlzsmithy-rpc-v2-cbor�queryZec2cCs,t|t�r|St|t�r$|��dkSdSdS)z~Ensures a boolean value if a string or boolean is provided

    For strings, the value for True/False is case insensitive
    �trueFN)�
isinstance�bool�str�lower��valr8r8r<�ensure_boolean�s


rHcCsP|�d�}|dur>|��}|tvr:|td�}tfi|���|S|�d�rLdSdS)z�Resolving IMDS endpoint mode to either IPv6 or IPv4.

    ec2_metadata_service_endpoint_mode takes precedence over imds_use_ipv6.
    �"ec2_metadata_service_endpoint_modeN)�modeZvalid_modesZ
imds_use_ipv6r/r.)Zget_config_variablerE�METADATA_ENDPOINT_MODESr)�sessionZ
endpoint_modeZlendpoint_modeZerror_msg_kwargsr8r8r<�resolve_imds_endpoint_mode�s��
rMcCs2t|d�o0|j�dd�o0|j�d�dko0|jdkS)z�Determines if the provided shape is the special header type jsonvalue.

    :type shape: botocore.shape
    :param shape: Shape to be inspected for the jsonvalue trait.

    :return: True if this type is a jsonvalue, False otherwise
    :rtype: Bool
    �
serializationZ	jsonvalueF�location�header�string)�hasattrrN�get�	type_name)�shaper8r8r<�is_json_value_header�s

���rVcCs@|durdSt|tjj�r"||vS|��dd�|��D�vSdS)z&Case-insensitive check for header key.NFcSsg|]}|���qSr8�rE)r:�keyr8r8r<r=�r>zhas_header.<locals>.<listcomp>)rB�botocore�
awsrequestZHeadersDictrE�keys)Zheader_name�headersr8r8r<�
has_header�s
r]cCsD|j�d|j�d|j��}|�dd�}|�dd�}t�dd|�}|S)zvReturns the module name for a service

    This is the value used in both the documentation and client class name
    ZserviceAbbreviationZserviceFullNameZAmazon�ZAWSz\W+)�metadatarSZservice_name�replace�re�sub)Z
service_model�namer8r8r<�get_service_module_name�s��rdcCs|sdSt|�S)N�/)�remove_dot_segments��pathr8r8r<�normalize_url_path�sricCs|dur|St|�SdS)zLReturns None if val is None, otherwise ensure value
    converted to booleanN)rHrFr8r8r<�normalize_boolean�srjcCs�|sdS|�d�}g}|D]0}|r|dkr|dkr@|rJ|��q|�|�q|ddkr^d}nd}|ddkrx|rxd}nd}|d�|�|S)Nr^re�.z..r���)�split�pop�append�join)�urlZ	input_urlZoutput_listr;�first�lastr8r8r<rf�s"

rfcCs6|r|dkrt|d��dD]}||vrt|d��qdS)Nrk��
expression)�[�]�*)r)ruZinvalidr8r8r<�validate_jmespath_for_sets

ryTcCs||rt|�|�dd�}|dt|�dkr2|dnd}}|sHt|d��|rp||vr\i||<t||||dd�S|||<dS)Nrkr-rr^rtF)�is_first)ryrm�lenr�set_value_from_jmespath)�sourceru�valuerz�bitsZcurrent_keyZ	remainderr8r8r<r|!s"
�r|cCs|�di�}|�d�dk}|S)z9Determine if request is intended for an MRAP accesspoint.�s3_accesspoint�regionr^�rS)�contextr��	is_globalr8r8r<�is_global_accesspoint?sr�c@seZdZdZdS)�_RetriesExceededErrorz@Internal exception used when the number of retries are exceeded.N)�__name__�
__module__�__qualname__�__doc__r8r8r8r<r�Fsr�c@seZdZdd�ZdS)�BadIMDSRequestErrorcCs
||_dS�N��request��selfr�r8r8r<�__init__MszBadIMDSRequestError.__init__N)r�r�r�r�r8r8r8r<r�Lsr�c@s�eZdZeZdZdZededddfdd�Z	dd�Z
d	d
�Zdd�Zd
d�Z
d dd�Zdd�Zdd�Zdd�Zdd�Zdd�Zdd�Zd!dd�ZdS)"�IMDSFetcherzlatest/api/tokenZ21600r-NcCs�||_||_|duri}|�||�|_||_|dur>tj��}|�dd��	�dk|_
|�d�|_||_t
jj|jt|j�d�|_dS)NZAWS_EC2_METADATA_DISABLEDZfalserAZec2_metadata_v1_disabled)�timeoutZproxies)Z_timeout�
_num_attempts�_select_base_url�	_base_url�_config�os�environ�copyrSrE�	_disabled�_imds_v1_disabled�_user_agentrY�httpsession�URLLib3Session�get_environ_proxies�_session)r�r�Znum_attempts�base_url�envZ
user_agent�configr8r8r<r�Vs 	
��zIMDSFetcher.__init__cCs|jSr�)r��r�r8r8r<�get_base_urlrszIMDSFetcher.get_base_urlcCsz|�d�dk}|�d�}|r*|r*t�d�d}|tkr<|}n|rF|}n|rPt}nt}t�d|���t|�svt|d��|S)NrIr/Zec2_metadata_service_endpointzFCustom endpoint and IMDS_USE_IPV6 are both set. Using custom endpoint.zIMDS ENDPOINT: )�endpoint)rS�loggerZwarning�METADATA_BASE_URL�METADATA_BASE_URL_IPv6�debug�is_valid_urir)r�r�r�Z
requires_ipv6Zcustom_metadata_endpointZchosen_base_urlr8r8r<r�us&�
�
zIMDSFetcher._select_base_urlcCs,d}|jr|j�d�sd}|j�|�|��S)Nr^re)r��endswith)r�rh�sepr8r8r<�_construct_url�szIMDSFetcher._construct_urlcCs0|��|�|j�}d|ji}|�|�tjjd||d�}t|j	�D]�}zN|j
�|���}|j
dkrp|jWS|j
dvr�WdS|j
dvr�t|��WqDty�YdSty�}ztjd||dd	�WYd}~qDd}~0t�y(}z0t|j�d
�t��rt||d��n�WYd}~qDd}~00qDdS)Nz$x-aws-ec2-metadata-token-ttl-secondsZPUT��methodrqr\��)i�i�i�)i��OCaught retryable HTTP exception while making metadata service request to %s: %sT��exc_info�error)r�r�)�_assert_enabledr��_TOKEN_PATH�
_TOKEN_TTL�_add_user_agentrYrZ�
AWSRequest�ranger�r��send�prepare�status_code�textr�r#�RETRYABLE_HTTP_ERRORSr�r�rrB�kwargsrSr,r)r�rqr\r��i�response�er8r8r<�_fetch_metadata_token�s>�
�


�z!IMDSFetcher._fetch_metadata_tokenc
Cs�|��|s|��|dur"|j}|�|�}i}|dur@||d<|�|�t|j�D]t}z8tjj	d||d�}|j
�|���}||�s�|WSWqTt
y�}	ztjd||	dd�WYd}	~	qTd}	~	00qT|���dS)aZMake a get request to the Instance Metadata Service.

        :type url_path: str
        :param url_path: The path component of the URL to make a get request.
            This arg is appended to the base_url that was provided in the
            initializer.

        :type retry_func: callable
        :param retry_func: A function that takes the response as an argument
             and determines if it needs to retry. By default empty and non
             200 OK responses are retried.

        :type token: str
        :param token: Metadata token to send along with GET requests to IMDS.
        Nzx-aws-ec2-metadata-token�GETr�r�Tr�)r��_assert_v1_enabled�_default_retryr�r�r�r�rYrZr�r�r�r�r�r�r��_RETRIES_EXCEEDED_ERROR_CLS)
r��url_path�
retry_func�tokenrqr\r�r�r�r�r8r8r<�_get_request�s4

��zIMDSFetcher._get_requestcCs|jdur|j|d<dS)Nz
User-Agent)r�)r�r\r8r8r<r��s
zIMDSFetcher._add_user_agentcCs|jrt�d�|���dS)Nz)Access to EC2 metadata has been disabled.)r�r�r�r�r�r8r8r<r��s
zIMDSFetcher._assert_enabledcCs|jrtdd��dS)NzLUnable to retrieve token for use in IMDSv2 call and IMDSv1 has been disabled��	error_msg)r�r!r�r8r8r<r��s�zIMDSFetcher._assert_v1_enabledcCs|�|�p|�|�Sr���_is_non_ok_response�	_is_empty�r�r�r8r8r<r��szIMDSFetcher._default_retrycCs"|jdkr|j|ddd�dSdS)Nr�znon-200T��log_bodyF)r��_log_imds_responser�r8r8r<r��s
zIMDSFetcher._is_non_ok_responsecCs|js|j|ddd�dSdS)Nzno bodyTr�F)�contentr�r�r8r8r<r��szIMDSFetcher._is_emptyFcCs@d}||j|jg}|r*|d7}|�|j�tj|g|�R�dS)NzHMetadata service returned %s response with status code of %s for url: %sz, content body: %s)r�rqror�r�r�)r�r�Z
reason_to_logr�Z	statementZlogger_argsr8r8r<r�s�zIMDSFetcher._log_imds_response)N)F)r�r�r�r�r�r�r�� DEFAULT_METADATA_SERVICE_TIMEOUTr�r�r�r�r�r�r�r�r�r�r�r�r�r�r8r8r8r<r�Qs,�
$
,r�c@s\eZdZdZgd�Zdd�Zddd�Zddd	�Zd
d�Zdd
�Z	dd�Z
dd�Zdd�ZdS)�InstanceMetadataFetcherz*latest/meta-data/iam/security-credentials/)�AccessKeyId�SecretAccessKey�Token�
Expirationc
Cs�z~|��}|�|�}|�||�}|�|�rZ||d|d|d|dd�}|�|�|WSd|vrvd|vrvt�d|�iWSWnR|jy�t�d	|j�Yn2t	y�}zt�d
|j
�WYd}~n
d}~00iS)Nr�r�r�r�)�	role_name�
access_key�
secret_keyr��expiry_time�Code�Messagez7Error response received when retrievingcredentials: %s.z\Max number of attempts exceeded (%s) when attempting to retrieve data from metadata service.zBad IMDS request: %s)r��
_get_iam_role�_get_credentials�_contains_all_credential_fields�_evaluate_expirationr�r�r�r�r�r�)r�r�r��credentialsr�r8r8r<�retrieve_iam_role_credentialss6

�

�
�$z5InstanceMetadataFetcher.retrieve_iam_role_credentialsNcCs|j|j|j|d�jS�N)r�r�r�)r��	_URL_PATH�_needs_retry_for_role_namer�)r�r�r8r8r<r�Cs
�z%InstanceMetadataFetcher._get_iam_rolecCs$|j|j||j|d�}t�|j�Sr�)r�r��_needs_retry_for_credentialsr�loadsr�)r�r�r��rr8r8r<r�Js�z(InstanceMetadataFetcher._get_credentialscCs8zt�|j�WdSty2|�|d�YdS0dS)NFzinvalid jsonT)rr�r��
ValueErrorr�r�r8r8r<�_is_invalid_jsonRsz(InstanceMetadataFetcher._is_invalid_jsoncCs|�|�p|�|�Sr�r�r�r8r8r<r�Zsz2InstanceMetadataFetcher._needs_retry_for_role_namecCs|�|�p|�|�p|�|�Sr�)r�r�r�r�r8r8r<r�]s

��z4InstanceMetadataFetcher._needs_retry_for_credentialscCs*|jD]}||vrt�d|�dSqdS)Nz3Retrieved credentials is missing required field: %sFT)�_REQUIRED_CREDENTIAL_FIELDSr�r�)r�r�Zfieldr8r8r<r�ds
�z7InstanceMetadataFetcher._contains_all_credential_fieldsc	Cs�|�d�}|durdSz�tj�|d�}|j�dd�}|t�dd�}tj��}tj|d�}||}||kr�||}|�d�|d<t	�
d|dd	�d
��Wn&ty�t	�d|d���Yn0dS)Nr�z%Y-%m-%dT%H:%M:%SZZec2_credential_refresh_windowiX�x��secondsz�Attempting credential expiration extension due to a credential service availability issue. A refresh of these credentials will be attempted again within the next �<z.0fz	 minutes.zUnable to parse expiry_time in )
rSr�strptimer��randomZrandintZutcnow�	timedelta�strftimer��infor�r�)	r�r��
expirationZrefresh_intervalZrefresh_interval_with_jitterZcurrent_timeZrefresh_offsetZextension_timeZnew_timer8r8r<r�ns@
���
�����z,InstanceMetadataFetcher._evaluate_expiration)N)N)
r�r�r�r�r�r�r�r�r�r�r�r�r�r8r8r8r<r�s)


r�FcCs�|D]�}t||t�rH||vr:||vr:t||||�q�||||<qt||t�r�|r�||vr�t||t�r�||�||�q�||||<q||||<qdS)z�Given two dict, merge the second dict into the first.

    The dicts can have arbitrary nesting.

    :param append_lists: If true, instead of clobbering a list with the new
        value, append all of the new values onto the original list.
    N)rB�dict�merge_dicts�list�extend)Zdict1Zdict2Zappend_listsrXr8r8r<r��sr�cCs"i}|D]}||||��<q|S)zDCopies the given dictionary ensuring all keys are lowercase strings.rW)�originalr�rXr8r8r<�lowercase_dict�srcCs`z>||��"}|��}t|�Wd�WS1s20YWntyZt|d��Yn0dS)Nrg)�read�parse_key_val_file_contents�OSErrorr)�filename�_open�f�contentsr8r8r<�parse_key_val_file�s
,rcCsHi}|��D]6}d|vrq|�dd�\}}|��}|��}|||<q|S)N�=r-)�
splitlinesrm�strip)r
�final�linerXrGr8r8r<r�s
rcCs�g}t|d�r|��}n|}|D]V\}}t|t�rZ|D] }|�t|��dt|����q6q |�t|��dt|����q d�|�S)afUrlencode a dict or list into a string.

    This is similar to urllib.urlencode except that:

    * It uses quote, and not quote_plus
    * It has a default list of safe chars that don't need
      to be encoded, which matches what AWS services expect.

    If any value in the input ``mapping`` is a list type,
    then each list element wil be serialized.  This is the equivalent
    to ``urlencode``'s ``doseq=True`` argument.

    This function should be preferred over the stdlib
    ``urlencode()`` function.

    :param mapping: Either a dict to urlencode or a list of
        ``(key, value)`` pairs.

    �itemsr�&)rRrrBrro�percent_encoderp)�mapping�safeZ
encoded_pairs�pairsrXr~Zelementr8r8r<�percent_encode_sequence�s


��rcCs6t|ttf�st|�}t|t�s*|�d�}t||d�S)a�Urlencodes a string.

    Whereas percent_encode_sequence handles taking a dict/sequence and
    producing a percent encoded string, this function deals only with
    taking a string (not a dict/sequence) and percent encoding it.

    If given the binary type, will simply URL encode it. If given the
    text type, will produce the binary type by UTF-8 encoding the
    text. If given something else, will convert it to the text type
    first.
    �utf-8)r)rB�bytesrD�encoder
)�	input_strrr8r8r<r�s



rc	Cs6tjddddddt�d�}|�|��}|tj|d�S)a�Parse numerical epoch timestamps (seconds since 1970) into a
    ``datetime.datetime`` in UTC using ``datetime.timedelta``. This is intended
    as fallback when ``fromtimestamp`` raises ``OverflowError`` or ``OSError``.

    :type value: float or int
    :param value: The Unix timestamps as number.

    :type tzinfo: callable
    :param tzinfo: A ``datetime.tzinfo`` class or compatible callable.
    �r-r��tzinfor�)rr+�
astimezoner�)r~rZ
epoch_zeroZepoch_zero_localizedr8r8r<�_epoch_seconds_to_datetime
sr c
Cs�t|ttf�rtj�||��Sztj�t|�|��WSttfyJYn0ztjj	|dt
�id�WSttfy�}z td|�d|����WYd}~n
d}~00dS)z.Parse timestamp with pluggable tzinfo options.ZGMT)ZtzinfoszInvalid timestamp "z": N)rB�int�floatr�
fromtimestamp�	TypeErrorr��dateutil�parser�parser+)r~rr�r8r8r<�_parse_timestamp_with_tzinfosr(cCs�t�}|D]P}zt||�WSttfyX}ztjd|j|d�WYd}~q
d}~00q
zt|�}Wntt	fy~Yn\0z|D]}t
||d�WSWn:ttfy�}ztjd|j|d�WYd}~n
d}~00td|�d���dS)z�Parse a timestamp into a datetime object.

    Supported formats:

        * iso8601
        * rfc822
        * epoch (value is an integer)

    This will return a ``datetime.datetime`` object.

    z2Unable to parse timestamp with "%s" timezone info.r�NrzHUnable to parse timestamp using fallback method with "%s" timezone info.z1Unable to calculate correct timezone offset for "�")rr(r�
OverflowErrorr�r�r�r"r$r�r �RuntimeError)r~Ztzinfo_optionsrr�Z
numeric_valuer8r8r<�parse_timestamp-s4��
�r,cCsBt|t�r|}nt|�}|jdur2|jt�d�}n|�t��}|S)a�Converted the passed in value to a datetime object with tzinfo.

    This function can be used to normalize all timestamp inputs.  This
    function accepts a number of different types of inputs, but
    will always return a datetime.datetime object with time zone
    information.

    The input param ``value`` can be one of several types:

        * A datetime object (both naive and aware)
        * An integer representing the epoch time (can also be a string
          of the integer, i.e '0', instead of 0).  The epoch time is
          considered to be UTC.
        * An iso8601 formatted timestamp.  This does not need to be
          a complete timestamp, it can contain just the date portion
          without the time component.

    The returned value will be a datetime object that will have tzinfo.
    If no timezone info was provided in the input value, then UTC is
    assumed, not local time.

    Nr)rB�_DatetimeClassr,rr`r+r)r~Zdatetime_objr8r8r<�parse_to_aware_datetime]s

r.cCs~t�ddd�}|jdur2|dur&t�}|j|d�}|jdd�|��|}t|d�r\|��S|j|j|j	ddddS)	awCalculate the timestamp based on the given datetime instance.

    :type dt: datetime
    :param dt: A datetime object to be converted into timestamp
    :type default_timezone: tzinfo
    :param default_timezone: If it is provided as None, we treat it as tzutc().
                             But it is only used when dt is a naive datetime.
    :returns: The timestamp
    rr-Nrr�ii@B)
rrr+r`Z	utcoffsetrRrZmicrosecondsr�Zdays)ZdtZdefault_timezoneZepoch�dr8r8r<�datetime2timestamp�s


r1csBt��}t�fdd�d�D]}|�|�q|r6|��S|��SdS)a�Calculate a sha256 checksum.

    This method will calculate the sha256 checksum of a file like
    object.  Note that this method will iterate through the entire
    file contents.  The caller is responsible for ensuring the proper
    starting position of the file and ``seek()``'ing the file back
    to its starting location if other consumers need to read from
    the file like object.

    :param body: Any file like object.  The file must be opened
        in binary mode such that a ``.read()`` call returns bytes.
    :param as_hex: If True, then the hex digest is returned.
        If False, then the digest (as binary bytes) is returned.

    :returns: The sha256 checksum

    cs
��d�S�N��rr8��bodyr8r<�<lambda>�r>z"calculate_sha256.<locals>.<lambda>r>N)�hashlib�sha256�iter�update�	hexdigest�digest)r6Zas_hex�checksum�chunkr8r5r<�calculate_sha256�sr@cs�g}d�tj}t��fdd�d�D]}|�||����q"|sJ|d���St|�dkr�g}t|�D]2\}}|dur�|�|||����qb|�|�qb|}qJt�	|d��
d�S)	a\Calculate a tree hash checksum.

    For more information see:

    http://docs.aws.amazon.com/amazonglacier/latest/dev/checksum-calculations.html

    :param body: Any file like object.  This has the same constraints as
        the ``body`` param in calculate_sha256

    :rtype: str
    :returns: The hex version of the calculated tree hash

    r3cs
����Sr�r4r8�r6Zrequired_chunk_sizer8r<r7�r>z%calculate_tree_hash.<locals>.<lambda>r>r-Nr�ascii)r8r9r:ror=r<r{�	_in_pairs�binasciiZhexlify�decode)r6�chunksr9r?Z
new_chunksrr�secondr8rAr<�calculate_tree_hash�srHcCst|�}t||�Sr�)r:r)�iterableZshared_iterr8r8r<rC�s	rCc@s eZdZdZdd�Zdd�ZdS)�CachedPropertyz�A read only property that caches the initially computed value.

    This descriptor will only call the provided ``fget`` function once.
    Subsequent access to this property will return the cached value.

    cCs
||_dSr�)�_fget)r��fgetr8r8r<r��szCachedProperty.__init__cCs,|dur|S|�|�}||j|jj<|SdSr�)rK�__dict__r�)r��obj�clsZcomputed_valuer8r8r<�__get__�s

zCachedProperty.__get__N)r�r�r�r�r�rPr8r8r8r<rJ�srJc@sDeZdZdZddd�Zdd�Zddd	�Zd
d�Zdd
�Zdd�Z	dS)�ArgumentGeneratoraGenerate sample input based on a shape model.

    This class contains a ``generate_skeleton`` method that will take
    an input/output shape (created from ``botocore.model``) and generate
    a sample dictionary corresponding to the input/output shape.

    The specific values used are place holder values. For strings either an
    empty string or the member name can be used, for numbers 0 or 0.0 is used.
    The intended usage of this class is to generate the *shape* of the input
    structure.

    This can be useful for operations that have complex input shapes.
    This allows a user to just fill in the necessary data instead of
    worrying about the specific structure of the input arguments.

    Example usage::

        s = botocore.session.get_session()
        ddb = s.get_service_model('dynamodb')
        arg_gen = ArgumentGenerator()
        sample_input = arg_gen.generate_skeleton(
            ddb.operation_model('CreateTable').input_shape)
        print("Sample input for dynamodb.CreateTable: %s" % sample_input)

    FcCs
||_dSr�)�_use_member_names)r�Zuse_member_namesr8r8r<r�szArgumentGenerator.__init__cCsg}|�||�S)z�Generate a sample input.

        :type shape: ``botocore.model.Shape``
        :param shape: The input shape.

        :return: The generated skeleton input corresponding to the
            provided input shape.

        )�_generate_skeleton)r�rU�stackr8r8r<�generate_skeletons
z#ArgumentGenerator.generate_skeletonr^cCsD|�|j��z&|jdkr0|�||�W|��S|jdkrP|�||�W|��S|jdkrp|�||�W|��S|jdkr�|jr�|W|��S|jr�|jdW|��SW|��dS|jdvr�W|��dS|jdvr�W|��d	S|jd
k�rW|��dS|jdk�r*t	�	d
ddddd�W|��SW|��n
|��0dS)NZ	structurer�maprQrr^)ZintegerZlong)r"ZdoublegZbooleanT�	timestamprr-)
rorcrT�_generate_type_structurern�_generate_type_list�_generate_type_maprR�enumr�r�rUrTrcr8r8r<rS+sV
�
�
�

�
�
�
�
���z$ArgumentGenerator._generate_skeletoncCsDi}|�|j�dkr|S|j��D]\}}|j|||d�||<q"|S)Nr-)rc)�countrc�membersrrS)r�rUrTZskeleton�member_nameZmember_shaper8r8r<rXEs�z*ArgumentGenerator._generate_type_structurecCs$d}|jr|jj}|�|j||�gS)Nr^)rR�memberrcrSr\r8r8r<rYOs
�z%ArgumentGenerator._generate_type_listcCs*|j}|j}|jdksJ�d|�||�iS)NrQZKeyName)rXr~rTrS)r�rUrTZ	key_shapeZvalue_shaper8r8r<rZYsz$ArgumentGenerator._generate_type_mapN)F)r^)
r�r�r�r�r�rUrSrXrYrZr8r8r8r<rQs



rQcCs.t�|�rdSdt|�j�d�}t�|�duS)NFrvrw)�UNSAFE_URL_CHARS�intersectionr�hostname�
IPV6_ADDRZ_RE�match��endpoint_urlrcr8r8r<�is_valid_ipv6_endpoint_url`s
rhcCst|�j}t�|�duSr�)rrc�IPV4_RErerfr8r8r<�is_valid_ipv4_endpoint_urlgs
rjcCsht�|�rdSt|�}|j}|dur(dSt|�dkr8dS|ddkrP|dd�}t�dtj�}|�|�S)z�Verify the endpoint_url is valid.

    :type endpoint_url: string
    :param endpoint_url: An endpoint_url.  Must have at least a scheme
        and a hostname.

    :return: True if the endpoint url is valid. False otherwise.

    FN�rlrkz;^((?!-)[A-Z\d-]{1,63}(?<!-)\.)*((?!-)[A-Z\d-]{1,63}(?<!-))$)	rarbrrcr{ra�compile�
IGNORECASEre)rg�partsrcZallowedr8r8r<�is_valid_endpoint_urlls
�rocCst|�pt|�Sr�)rorh)rgr8r8r<r��s
�r�cCs2|durdSt�d�}|�|�}|s.t|d��dS)z0Provided region_name must be a valid host label.Nz)^(?![0-9]+$)(?!-)[a-zA-Z0-9-]{,63}(?<!-)$)�region_name)rarlrer )rpZvalid_host_labelZvalidr8r8r<�validate_region_name�s

rqcCsRd|vrdSt|�}|dks$|dkr(dSt�|�}|dusJ|��t|�krNdSdS)a�
    Check to see if the ``bucket_name`` complies with the
    restricted DNS naming conventions necessary to allow
    access via virtual-hosting style.

    Even though "." characters are perfectly valid in this DNS
    naming scheme, we are going to punt on any name containing a
    "." character because these will cause SSL cert validation
    problems if we try to use virtual-hosting style addressing.
    rkF��?NT)r{�LABEL_REre�end)�bucket_name�nrer8r8r<�check_dns_name�s
rxc
Ksb|j�dd�rd}zt|||�Wn:ty\}z"|jd}t�d|�WYd}~n
d}~00dS)ar
    This handler looks at S3 requests just before they are signed.
    If there is a bucket name on the path (true for everything except
    ListAllBuckets) it checks to see if that bucket name conforms to
    the DNS naming conventions.  If it does, it alters the request to
    use ``virtual hosting`` style addressing rather than ``path-style``
    addressing.

    Zuse_global_endpointFzs3.amazonaws.comrvz2Not changing URI, bucket is not DNS compatible: %sN)r�rS�switch_to_virtual_host_stylerr�r�r�)r��signature_versionrp�default_endpoint_urlr�r�rvr8r8r<�fix_s3_host�s�
�r|cKs|jdurdSt|�r$t�d�dSt|j�}|j|_|j�d�}|durP|j}t	|�dk�r|d}|sndSt�d|j�t
|��rt	|�dkr�|jddkr�|jd7_|�|�d�|�p�d}|}|d|}	|j
|	||jd	f}
t|
�}||_t�d
|�n
t|d��dS)a)
    This is a handler to force virtual host style s3 addressing no matter
    the signature version (which is taken in consideration for the default
    case). If the bucket is not DNS compatible an InvalidDNSName is thrown.

    :param request: A AWSRequest object that is about to be sent.
    :param signature_version: The signature version to sign with
    :param default_endpoint_url: The endpoint to use when switching to a
        virtual style. If None is supplied, the virtual host will be
        constructed from the url of the request.
    NzKRequest is GetBucketLocation operation, not checking for DNS compatibility.rer-z*Checking for DNS compatible bucket for: %s�rlrkr^zURI updated to: %s)rv)Z	auth_path�_is_get_bucket_location_requestr�r�rrqrhrm�netlocr{rx�removerp�schemer@rr)r�rzr{r�rn�
path_partsrvrhZglobal_endpoint�hostZ	new_tupleZnew_urir8r8r<ry�s<
�


rycCs|j�d�S)Nz	?location)rqr�r�r8r8r<r~
sr~cs"�j�t�����fdd��}|S)aMethod decorator for caching method calls to a single instance.

    **This is not a general purpose caching decorator.**

    In order to use this, you *must* provide an ``_instance_cache``
    attribute on the instance.

    This decorator is used to cache method calls.  The cache is only
    scoped to a single instance though such that multiple instances
    will maintain their own cache.  In order to keep things simple,
    this decorator requires that you provide an ``_instance_cache``
    attribute on your instance.

    csb�|f}|r&tt|����}�||f}|j�|�}|dur>|S�|g|�Ri|��}||j|<|Sr�)�tuple�sortedrZ_instance_cacherS)r��argsr��	cache_keyZkwarg_items�result��funcZ	func_namer8r<�_cache_guard"s

z$instance_cache.<locals>._cache_guard)r��	functools�wraps)r�r�r8r�r<�instance_cachesr�cs��fdd�}|S)a
    Version of functools.lru_cache that stores a weak reference to ``self``.
    Serves the same purpose as :py:func:`instance_cache` but uses Python's
    functools implementation which offers ``max_size`` and ``typed`` properties.
    lru_cache is a global cache even when used on a method. The cache's
    reference to ``self`` will prevent garbage collection of the object. This
    wrapper around functools.lru_cache replaces the reference to ``self`` with
    a weak reference to not interfere with garbage collection.
    cs>tj�i����fdd���t����fdd��}�j|_|S)Ncs�|�g|�Ri|��Sr�r8)Zweakref_to_selfr�r�)r�r8r<�func_with_weakref>sz=lru_cache_weakref.<locals>.wrapper.<locals>.func_with_weakrefcsD|��D]\}}t|t�rt|�||<q�t�|�g|�Ri|��Sr�)rrBrr��weakref�ref)r�r�r�Z	kwarg_keyZkwarg_value)r�r8r<�innerBs
z1lru_cache_weakref.<locals>.wrapper.<locals>.inner)r��	lru_cacher��
cache_info)r�r���
cache_args�cache_kwargs)r�r�r<�wrapper=sz"lru_cache_weakref.<locals>.wrapperr8)r�r�r�r8r�r<�lru_cache_weakref2sr�cKsht|j�j�d�}dd�|D�}d}t|�dkrB|d�|�d7}|d7}|dvrVdSt||d	d
�dS)z?Switches the current s3 endpoint with an S3 Accelerate endpointrkcSsg|]}|tvr|�qSr8��S3_ACCELERATE_WHITELIST�r:�pr8r8r<r=Wr>z-switch_host_s3_accelerate.<locals>.<listcomp>zhttps://s3-accelerate.r�
amazonaws.com)ZListBuckets�CreateBucketZDeleteBucketNF)�use_new_scheme)rrqrrmr{rp�
_switch_hosts)r��operation_namer�rnr�r8r8r<�switch_host_s3_accelerateOsr�cCs2t�|j�d��}|�|�r.||}t||�dS)zBSwitches the host using a parameter value from a JSON request bodyrN)rr��datarErSr�)r��
param_nameZrequest_json�new_endpointr8r8r<�switch_host_with_parambs
r�cCst|j||�}||_dSr�)�_get_new_endpointrq)r�r�r��final_endpointr8r8r<r�js�r�cCsVt|�}t|�}|j}|r |j}||j|j|jdf}t|�}t�d|�d|���|S�Nr^zUpdating URI from � to )rr�rrhr@rr�r�)Zoriginal_endpointr�r�Znew_endpoint_componentsZoriginal_endpoint_componentsr�Zfinal_endpoint_componentsr�r8r8r<r�qs�r�cCsR|D]H}||vr@t||t�r@t||t�r@t||||�q||||<qdS)z�Deeply two dictionaries, overriding existing keys in the base.

    :param base: The base dictionary which will be merged into.
    :param extra: The dictionary to merge into the base. Keys from this
        dictionary will take precedence.
    N)rBr��
deep_merge)�baseZextrarXr8r8r<r��s���r�cCs|�dd���S)zcTranslate the form used for event emitters.

    :param service_id: The service_id to convert.
    � �-)r`rE)Z
service_idr8r8r<�hyphenize_service_id�sr�c@s,eZdZdZdZdd�Zdd�Zdd�Zd	S)
�
IdentityCachez�Base IdentityCache implementation for storing and retrieving
    highly accessed credentials.

    This class is not intended to be instantiated in user code.
    Zbase_identity_cachecCs||_||_dSr���_client�_credential_cls�r��client�credential_clsr8r8r<r��szIdentityCache.__init__cKs2|jfi|��}|�}|jj|||jddd�}|S)N�-�
)r_Z
refresh_usingr�Zadvisory_timeoutZmandatory_timeout)�build_refresh_callbackr�Zcreate_from_metadata�METHOD)r�r��callbackr_Zcredential_entryr8r8r<�get_credentials�s�zIdentityCache.get_credentialscKs
t��dS)z�Callback to be implemented by subclasses.

        Returns a set of metadata to be converted into a new
        credential instance.
        N��NotImplementedError�r�r8r8r<r��sz$IdentityCache.build_refresh_callbackN)r�r�r�r�r�r�r�r�r8r8r8r<r��s
r�csJeZdZdZdZdd�Zejdd��fdd��Zd	d
�Z	ddd
�Z
�ZS)�S3ExpressIdentityCachez�S3Express IdentityCache for retrieving and storing
    credentials from CreateSession calls.

    This class is not intended to be instantiated in user code.
    �	s3expresscCs||_||_dSr�r�r�r8r8r<r��szS3ExpressIdentityCache.__init__�d)�maxsizecst�j|d�S)N��bucket)�superr�)r�r���	__class__r8r<r��sz&S3ExpressIdentityCache.get_credentialscs��fdd�}|S)NcsB�jj�d�}|d}�j|ddd�}|d|d|d|d	�S)
N��BucketZCredentialsr�T)�isor�r�ZSessionToken)r�r�r�r�)r�Zcreate_session�_serialize_if_needed)r�Zcredsr��r�r�r8r<�	refresher�s��[email protected]_refresh_callback.<locals>.refresherr8)r�r�r�r8r�r<r��s
z-S3ExpressIdentityCache.build_refresh_callbackFcCs$t|t�r |r|��S|�d�S|S�Nz%Y-%m-%dT%H:%M:%S%Z�rBr-Z	isoformatr��r�r~r�r8r8r<r��s


z+S3ExpressIdentityCache._serialize_if_needed)F)r�r�r�r�r�r�r�r�r�r�r��
__classcell__r8r8r�r<r��s
r�c@s8eZdZddd�Zd
dd�Zdd�Zdd	�Zd
d�ZdS)�S3ExpressIdentityResolverNcCs*t�|�|_|dur t|j|�}||_dSr�)r��proxyr�r��_cache)r�r�r��cacher8r8r<r��sz"S3ExpressIdentityResolver.__init__cCsFt�d�|p|jjj}|�d|j�|�d|j�|�d|j�dS)Nz'Registering S3Express Identity Resolver�before-parameter-build.s3�before-call.s3�before-sign.s3)	r�r�r��meta�events�register�inject_signing_cache_key�apply_signing_cache_key�resolve_s3express_identity�r��
event_emitterZemitterr8r8r<r��s
�z"S3ExpressIdentityResolver.registercKsd|vrd|di|d<dS)Nr�rv�	S3Expressr8)r��paramsr�r�r8r8r<r��sz2S3ExpressIdentityResolver.inject_signing_cache_keycKsV|�di�}|�dd�}|�di��d�}|dkrR|durR|�di�||dd<dS)N�endpoint_properties�backendr�rv�signingr�)rS�
setdefault)r�r�r�r�r�r�rvr8r8r<r�sz1S3ExpressIdentityResolver.apply_signing_cache_keyc	Ks`|j�di�}|�d�}|dkr\|�d�r\|j|d<d|vr\|j�di��di��d	�|d<dS)
Nr��signing_namer�zv4-s3expressZidentity_cacher��s3_redirectr�r�)r�rS�
startswithr�)	r�r�r�rprzZrequest_signerr�r��signing_contextr8r8r<r�
s

�
���z4S3ExpressIdentityResolver.resolve_s3express_identity)N)N)r�r�r�r�r�r�r�r�r8r8r8r<r��s


	
r�c@sLeZdZdZddd�Zddd�Zdd�Zd	d
�Zdd�Zd
d�Z	dd�Z
dS)�S3RegionRedirectorv2a
Updated version of S3RegionRedirector for use when
    EndpointRulesetResolver is in use for endpoint resolution.

    This class is considered private and subject to abrupt breaking changes or
    removal without prior announcement. Please do not use it directly.
    NcCs|pi|_t�|�|_dSr�)r�r�r�r��r�Zendpoint_bridger�r�r8r8r<r�*s
zS3RegionRedirectorv2.__init__cCsFt�d�|p|jjj}|�d|j�|�d|j�|�d|j�dS)Nz(Registering S3 region redirector handler�needs-retry.s3r�zbefore-endpoint-resolution.s3)	r�r�r�r�r�r��redirect_from_error�annotate_request_context�redirect_from_cacher�r8r8r<r�.s
��zS3RegionRedirectorv2.registerc	Ks0|durdS|�di��di�}t�|�d��r>t�d�dS|�d�rVt�d�dS|d�d	i�}|�d
�}|d�di�}|dvo�|jd
k}	|dvo�|jdko�d|�di�v}
|dko�d|v}|dduo�|djdv}|dk}
|dko�|jdk}t|	||
|
||g��sdS|ddd}|d�d�}|�||�}|du�rbt�d|�d|�d��dSt�d|�d|�d|�d��||j	|<|j
j}|j||ddd|dd�}|�
|d |j�|d <d!|ddd<|j�d"�}|du�r,|�|�}|\}}||dd#<i|d�d$i��|�|dd$<dS)%�
        An S3 request sent to the wrong region will return an error that
        contains the endpoint the request should be sent to. This handler
        will add the redirect information to the signing context and then
        redirect the request.
        Nr�r�r�zBS3 request was previously for an Accesspoint ARN, not redirecting.�
redirected�6S3 request was previously redirected, not redirecting.r-�Errorr��ResponseMetadata�Z301Z400�
HeadObject�
HeadBucket�x-amz-bucket-region�HTTPHeaders�AuthorizationHeaderMalformed�Regionr�i-i.i3�PermanentRedirectZ"IllegalLocationConstraintExceptionr��
client_region� S3 client configured for region � but the bucket �S is not in that region and the proper region could not be automatically determined.� is in region �b; Please configure the proper region to avoid multiple unnecessary redirects and signing attempts.r�)Zoperation_modelZ	call_args�request_contextrqTZauthSchemes�	auth_typer�)rS�	ArnParser�is_arnr�r�rcr��any�get_bucket_regionr�r�Z_ruleset_resolver�construct_endpoint�set_request_urlrqZ
propertiesZauth_schemes_to_signing_ctx)r��request_dictr��	operationr�Zredirect_ctxr��
error_code�response_metadata�is_special_head_object�is_special_head_bucket�is_wrong_signing_region�is_redirect_status�is_permanent_redirectZis_opt_in_region_redirectr�r�
new_regionZep_resolverZep_infoZauth_schemesZ	auth_inforr�r8r8r<r�9s��
�
��
��������

���
�
�

��z(S3RegionRedirectorv2.redirect_from_errorc
Cs�|d}|dd}d|vr$|dS|�di��dd�}|durD|Sz|jj|d�}|dd}Wn2ty�}z|jdd}WYd}~n
d}~00|�dd�}|S�	a.
        There are multiple potential sources for the new region to redirect to,
        but they aren't all universally available for use. This will try to
        find region from response elements, but will fall back to calling
        HEAD on the bucket if all else fails.

        :param bucket: The bucket to find the region for. This is necessary if
            the region is not available in the error response.
        :param response: A response representing a service request that failed
            due to incorrect region configuration.
        r-r�r�r�r�r�Nr��rSr�Zhead_bucketrr��r�r�r�Zservice_responseZresponse_headersr�r\r�r8r8r<r�s
$z&S3RegionRedirectorv2.get_bucket_regioncKst||d�S)z�
        Splice a new endpoint into an existing URL. Note that some endpoints
        from the the endpoint provider have a path component which will be
        discarded by this function.
        F)r�)r�Zold_urlr�r�r8r8r<r�sz$S3RegionRedirectorv2.set_request_urlcKs4|�d�}|dur0||jvr0|j�|�}||d<dS)a
        If a bucket name has been redirected before, it is in the cache. This
        handler will update the AWS::Region endpoint resolver builtin param
        to use the region from cache instead of the client region to avoid the
        redirect.
        r�NzAWS::Region)rSr�)r��builtinsr�r�r�rr8r8r<r��s
z(S3RegionRedirectorv2.redirect_from_cachecKs|�d�}d||d�|d<dS)z�Store the bucket name in context for later use when redirecting.
        The bucket name may be an access point ARN or alias.
        r�F)r�r�r�r�Nr�)r�r�r�r�r�r8r8r<r��s

�z-S3RegionRedirectorv2.annotate_request_context)N)N)r�r�r�r�r�r�r�rrr�r�r8r8r8r<r�"s

p!r�c@sLeZdZdZddd�Zddd�Zdd�Zd	d
�Zdd�Zd
d�Z	dd�Z
dS)�S3RegionRedirectorz�This handler has been replaced by S3RegionRedirectorv2. The original
    version remains in place for any third-party libraries that import it.
    NcCs:||_||_|jduri|_t�|�|_tjdtd�dS)Nz�The S3RegionRedirector class has been deprecated for a new internal replacement. A future version of botocore may remove this class.��category)�_endpoint_resolverr�r�r�r��warnings�warn�
FutureWarningr�r8r8r<r��s
�zS3RegionRedirector.__init__cCs<|p|jjj}|�d|j�|�d|j�|�d|j�dS)Nr�r�r�)r�r�r�r�r�rr�r�r8r8r<r��szS3RegionRedirector.registerc	Ks�|durdS|�|�di��r,t�d�dS|�di��d�rLt�d�dS|d�di�}|�d�}|d�d	i�}|d
vo�|jdk}|d
vo�|jdko�d
|�di�v}	|dko�d|v}
|dduo�|djdv}|dk}t||
||	|g�s�dS|ddd}
|d�d�}|�|
|�}|du�rBt�d|�d|
�d��dSt�d|�d|
�d|�d��|j�	d|�}|d}||
|d�}||dd<||j
|
<|�||d�d|dd<dS) r�Nr�z=S3 request was previously to an accesspoint, not redirecting.Z
s3_redirectedr�r-r�r�r�r�r�r�r�r�r�r�rr�rr�r�rrrrrr�s3rg)r�r�r�T)�_is_s3_accesspointrSr�r�rcr�rrr �resolver�r)r�rr�rr�r�rrrrrrrr�rrr�r�r8r8r<r�s���
��
�������	
����
z&S3RegionRedirector.redirect_from_errorc
Cs�|d}|dd}d|vr$|dS|�di��dd�}|durD|Sz|jj|d�}|dd}Wn2ty�}z|jdd}WYd}~n
d}~00|�dd�}|Srrrr8r8r<rcs
$z$S3RegionRedirector.get_bucket_regioncKs4|�di��dd�}|dur0t|d|d�|d<dS)Nr�r�rqF)rSr��r�r�r�r�r�r8r8r<r�sz"S3RegionRedirector.set_request_urlcKsF|�|�rdS|�d�}|j�|�}|dur6||d<nd|i|d<dS)z�
        This handler retrieves a given bucket's signing context from the cache
        and adds it into the request context.
        Nr�r�r�)r%rSr�)r�r�r�r�r�r�r8r8r<r��s


z&S3RegionRedirector.redirect_from_cachecCsd|vS�Nr�r8)r�r�r8r8r<r%�sz%S3RegionRedirector._is_s3_accesspoint)N)N)r�r�r�r�r�r�r�rrr�r%r8r8r8r<r�s

^!rc@seZdZdS)�InvalidArnExceptionN)r�r�r�r8r8r8r<r)�sr)c@s eZdZdd�Zedd��ZdS)r	cCsL|�dd�}t|�dkr(td|�d���|d|d|d|d	|dd
�S)Nr4��zProvided ARN: zE must be of the format: arn:partition:service:region:account:resourcer-r}rr�)�	partition�servicer��account�resource)rmr{r))r��arnZ	arn_partsr8r8r<�	parse_arn�s
��zArnParser.parse_arncCsHt|t�r|�d�sdSt�}z|�|�WdStyBYdS0dS)Nzarn:FT)rBrDr�r	r2r))r~�
arn_parserr8r8r<r
�s
zArnParser.is_arnN)r�r�r�r2�staticmethodr
r8r8r8r<r	�sr	c@s`eZdZe�d�Ze�d�ZdgZddd�Zdd�Z	d	d
�Z
dd�Zd
d�Zdd�Z
dd�ZdS)�S3ArnParamHandlerzA^(?P<resource_type>accesspoint|outpost)[/:](?P<resource_name>.+)$zc^(?P<outpost_name>[a-zA-Z0-9\-]{1,63})[/:]accesspoint[/:](?P<accesspoint_name>[a-zA-Z0-9\-]{1,63}$)r�NcCs||_|durt�|_dSr���_arn_parserr	�r�r3r8r8r<r��szS3ArnParamHandler.__init__cCs|�d|j�dS)Nr��r��
handle_arn�r�r�r8r8r<r��szS3ArnParamHandler.registercKs`|j|jvrdS|�|�}|dur&dS|ddkrB|�|||�n|ddkr\|�|||�dS)N�
resource_type�accesspoint�outpost)rc�_BLACKLISTED_OPERATIONS�"_get_arn_details_from_bucket_param�_store_accesspoint�_store_outpost)r�r��modelr�r��arn_detailsr8r8r<r:�s
zS3ArnParamHandler.handle_arncCsFd|vrBz&|d}|j�|�}|�||�|WSty@Yn0dS)Nr�)r7r2�_add_resource_type_and_namer))r�r�r1rDr8r8r<r@�sz4S3ArnParamHandler._get_arn_details_from_bucket_paramcCs@|j�|d�}|r2|�d�|d<|�d�|d<n
t|d��dS)Nr0r<�
resource_name)r1)�_RESOURCE_REGEXre�groupr')r�r1rDrer8r8r<rE�s
z-S3ArnParamHandler._add_resource_type_and_namecCs8|d|d<|d|d|d|d|dd�|d<dS)	NrFr�r/r-r�r.)rcr/r-r�r.r�r8�r�r�r�rDr8r8r<rA�s�z$S3ArnParamHandler._store_accesspointcCsd|d}|j�|�}|s"t|d��|�d�}||d<|�d�||d|d|d|d	d
�|d<dS)NrF)rF�accesspoint_namer��outpost_namer/r-r�r.)rKrcr/r-r�r.r�)�_OUTPOST_RESOURCE_REGEXrer%rH)r�r�r�rDrFrerJr8r8r<rB�s

�z S3ArnParamHandler._store_outpost)N)r�r�r�rarlrGrLr?r�r�r:r@rErArBr8r8r8r<r5�s��
r5c@s�eZdZdZdZd7dd�Zdd�Zd	d
�Zdd�Zd
d�Z	dd�Z
dd�Zdd�Zdd�Z
dd�Zdd�Zdd�Zdd�Zdd �Zd!d"�Zd#d$�Zd%d&�Zd'd(�Zd)d*�Zd+d,�Zd-d.�Zd/d0�Zed1d2��Zed3d4��Zed5d6��ZdS)8�S3EndpointSetter�awsr�NFcCsF||_||_||_||_|dur&i|_||_||_|durB|j|_dSr��r �_region�
_s3_config�_use_fips_endpoint�
_endpoint_url�
_partition�_DEFAULT_PARTITION�r��endpoint_resolverr��	s3_configrgr-�use_fips_endpointr8r8r<r�s
zS3EndpointSetter.__init__cCs.|�d|j�|�d|j�|�d|j�dS)Nr�zchoose-signer.s3z%before-call.s3.WriteGetObjectResponse)r��set_endpoint�
set_signer�#update_endpoint_to_s3_object_lambdar;r8r8r<r�)s�zS3EndpointSetter.registercKsh|jrtdd��|�|d�|jr&dS|j}|�d|j�}dj|d|dd�}t|d|d	�|d<dS)
NzOS3 client does not support accelerate endpoints for S3 Object Lambda operations��msg�s3-object-lambdazhttps://{host_prefix}{hostname}�host_prefixrc)r`rcrqF)	�_use_accelerate_endpointr(�_override_signing_namerSr r
rP�formatr�)r�r�r�r��resolver�resolvedr�r8r8r<r\1s ���z4S3EndpointSetter.update_endpoint_to_s3_object_lambdacKs�|�|�rL|�|�|�|�|�|�|�|�}|�|�|�||�dS|jr~|jrlt	d|j
�d�d��tfd|i|��|jr�|jfd|i|��dS)Nz8Client is configured to use the FIPS psuedo region for "zA", but S3 Accelerate does not have any FIPS compatible endpoints.r]r�)
�_use_accesspoint_endpoint�_validate_accesspoint_supported�_validate_fips_supported�_validate_global_regions�(_resolve_region_for_accesspoint_endpoint�._resolve_signing_name_for_accesspoint_endpoint�_switch_to_accesspoint_endpointrarRr(rPr��_s3_addressing_handler)r�r�r�rpr8r8r<rZLs(



�
��zS3EndpointSetter.set_endpointcCs
d|jvSr(�r�r�r8r8r<rfdsz*S3EndpointSetter._use_accesspoint_endpointcCs�|js
dSd|jddvr(tdhd��d|jdvrJtd|j�d�d��|jdd}||jkr�|j�d	d
�s�td|j�d|�d
�d��dS)N�fipsr�r��,Invalid ARN, FIPS region not allowed in ARN.r]rKz4Client is configured to use the FIPS psuedo-region "z2", but outpost ARNs do not support FIPS endpoints.�use_arn_regionTz8Client is configured to use the FIPS psuedo-region for "z1", but the access-point ARN provided is for the "zn" region. For clients using a FIPS psuedo-region calls to access-point ARNs in another region are not allowed.)rRr�r&rPrQrS�r�r�Zaccesspoint_regionr8r8r<rhgs(��
���z)S3EndpointSetter._validate_fips_supportedcCs4|j�dd�rdS|jdvr0td|j�d�d��dS)NrqT)z
aws-globalz
s3-external-1z6Client is configured to use the global psuedo-region "zJ". When providing access-point ARNs a regional endpoint must be specified.r])rQrSrPr&r�r8r8r<ri�s
��z)S3EndpointSetter._validate_global_regionscCs�|jrtdd��|jdd}||jkrBtd|j�d|�d�d��|jd�d�}|d	krp|j�d
�rptdd��|jd�d�}|r�|j�d
�r�td
d��|�|�dS)NzZClient does not support s3 accelerate configuration when an access-point ARN is specified.r]r�r-�Client is configured for "z3" partition, but access-point ARN provided is for "zE" partition. The client and  access-point partition must be the same.r.r_�use_dualstack_endpointzjClient does not support s3 dualstack configuration when an S3 Object Lambda access point ARN is specified.rKzTClient does not support s3 dualstack configuration when an outpost ARN is specified.)rar&r�rTrSrQ�_validate_mrap_s3_config)r�r�Zrequest_partitionZ
s3_servicerKr8r8r<rg�s0�

�����z0S3EndpointSetter._validate_accesspoint_supportedcCs@t|j�sdS|j�d�r&tdd��n|j�d�r<tdd��dS)NZ$s3_disable_multiregion_access_pointszCInvalid configuration, Multi-Region Access Point ARNs are disabled.r]rtzeClient does not support s3 dualstack configuration when a Multi-Region Access Point ARN is specified.)r�r�rQrSr&r�r8r8r<ru�s
��z)S3EndpointSetter._validate_mrap_s3_configcCsJt|j�r|�|d�n,|j�dd�rD|jdd}|�||�|S|jS)NrxrqTr�r�)r�r��_override_signing_regionrQrSrPrrr8r8r<rj�s
z9S3EndpointSetter._resolve_region_for_accesspoint_endpointcKst|�rdSdS)NZs3v4a)r�)r�r�r�r8r8r<r[�szS3EndpointSetter.set_signercCs |jdd}|�|j|�dS)Nr�r.�r�rb)r�r�Zaccesspoint_servicer8r8r<rk�sz?S3EndpointSetter._resolve_signing_name_for_accesspoint_endpointcCsXt|j�}t|j|�|j|�|�|j|j�|jdf�}t	�
d|j�d|���||_dSr�)rrqrr��_get_netlocr��_get_accesspoint_pathrhr@r�r�)r�r�rp�original_componentsZaccesspoint_endpointr8r8r<rl�s
����z0S3EndpointSetter._switch_to_accesspoint_endpointcCs"t|�r|�|�S|�||�SdSr�)r��_get_mrap_netloc�_get_accesspoint_netloc)r�rrpr8r8r<rx�s
zS3EndpointSetter._get_netloccCs\|d}d}|dg}|jr4t|j�j}|�|�n|d}|�d||�|�g�d�|�S)Nr�z	s3-globalrcr-r=rk)rSrrror�_get_partition_dns_suffixrp)r�rr�rpZmrap_netloc_components�endpoint_url_netlocr-r8r8r<r{�s
��z!S3EndpointSetter._get_mrap_netlocc	Cs�|d}d�|d|d�g}|�d�}|jrT|r<|�|�t|j�j}|�|�n||rl|dg}|�|�n:|ddkr�|�d|�}|�|�n|�d	|�}|�|�|j�d
�r�|�d�|�||�	|�g�d�
|�S)
Nr�z{}-{}rcr/rK�s3-outpostsr.r_zs3-accesspointrtr1rk)rcrSrSrorrr�_inject_fips_if_neededrQ�_get_dns_suffixrp)	r�rrpr�Zaccesspoint_netloc_componentsrKr~Zoutpost_host�	componentr8r8r<r|	s6�

��

�z(S3EndpointSetter._get_accesspoint_netloccCs|jr|�d�S|S)N�-fips�rR)r�r�rr8r8r<r�'	s
z'S3EndpointSetter._inject_fips_if_neededcCs"|dd}|�d|dd�p dS)Nr�rcrer^r-)r`)r�Z
original_pathrrcr8r8r<ry,	sz&S3EndpointSetter._get_accesspoint_pathcCs|j�|�}|dur|j}|Sr�)r �get_partition_dns_suffix�_DEFAULT_DNS_SUFFIX)r�Zpartition_name�
dns_suffixr8r8r<r}5	s�z*S3EndpointSetter._get_partition_dns_suffixcCs,|j�d|�}|j}|r(d|vr(|d}|S�Nr$Z	dnsSuffix�r r
r��r�rprer�r8r8r<r�=	s�z S3EndpointSetter._get_dns_suffixcCs$|j�di�}||d<||jd<dS�Nr�r��r�rS�r�r�rpr�r8r8r<rvF	sz)S3EndpointSetter._override_signing_regioncCs |�di�}||d<||d<dS�Nr�r�r�)r�r�r�r�r8r8r<rbO	sz'S3EndpointSetter._override_signing_namecCs�|j�d�rdS|jdurdSt|j�j}|�d�s8dS|�d�}|ddkrRdS|dd	�}t|�tt|��krvdSt	d
d�|D��S)N�use_accelerate_endpointTFr�rkr�
s3-accelerater-���css|]}|tvVqdSr�r�r�r8r8r<�	<genexpr>y	r>z<S3EndpointSetter._use_accelerate_endpoint.<locals>.<genexpr>)
rQrSrSrrr�rmr{�set�all)r�rrn�
feature_partsr8r8r<raX	s


z)S3EndpointSetter._use_accelerate_endpointcCs"|jr
dS|j�d�}|r|SdS)N�virtualZaddressing_style)rarQrS)r�Zconfigured_addressing_styler8r8r<�_addressing_style{	s
z"S3EndpointSetter._addressing_stylecCsH|jdkrt�d�tS|jdks,|jdur:t�d�dSt�d�tS)Nr�z'Using S3 virtual host style addressing.rhzUsing S3 path style addressing.zSDefaulting to S3 virtual host style addressing with path style addressing fallback.)r�r�r�ryrSr|r�r8r8r<rm�	s


�z'S3EndpointSetter._s3_addressing_handler)NNNNF)r�r�r�rUr�r�r�r\rZrfrhrirgrurjr[rkrlrxr{r|r�ryr}r�rvrbrJrar�rmr8r8r8r<rMsF�
%
 				
"
rMc@s�eZdZdZdZe�d�Zd6dd�Zdd	�Z	d
d�Z
dd
�Zdd�Zdd�Z
dd�Zdd�Zdd�Zdd�Zdd�Zdd�Zdd�Zd d!�Zd"d#�Zd$d%�Zd&d'�Zd(d)�Zd*d+�Zd,d-�Zd.d/�Zd0d1�Zd2d3�Zd4d5�ZdS)7�S3ControlEndpointSetterrNr�z^[a-zA-Z0-9\-]{1,63}$NFcCsF||_||_||_||_|dur&i|_||_||_|durB|j|_dSr�rOrVr8r8r<r��	s	z S3ControlEndpointSetter.__init__cCs|�d|j�dS)Nzbefore-sign.s3-control)r�rZr;r8r8r<r��	sz S3ControlEndpointSetter.registercKs||�|�r@|�|�|�|�}|�|�|�||�|�|�n8|�|�rx|�|�|�|d�|�	|j
�}|�||�dS�Nr)�_use_endpoint_from_arn_details�-_validate_endpoint_from_arn_details_supported� _resolve_region_from_arn_details�&_resolve_signing_name_from_arn_details�"_resolve_endpoint_from_arn_details�_add_headers_from_arn_details�_use_endpoint_from_outpost_id�#_validate_outpost_redirection_validrb�_construct_outpost_endpointrP�_update_request_netloc)r�r�r�rp�
new_netlocr8r8r<rZ�	s





z$S3ControlEndpointSetter.set_endpointcCs
d|jvS)NrDrnr�r8r8r<r��	sz6S3ControlEndpointSetter._use_endpoint_from_arn_detailscCs
d|jvS)N�
outpost_idrnr�r8r8r<r��	sz5S3ControlEndpointSetter._use_endpoint_from_outpost_idcCs�d|jddvr*t|jdddhd��|j�dd�sn|jdd}||jkrnd	|�d
|j�d�}t|d��|jdd
}||jkr�td|j�d|�d�d��|j�d�r�tdd��d|jdvr�|�|�dS)NrorDr�rrp�r1r^rqFzCThe use_arn_region configuration is disabled but received arn for "z(" when the client is configured to use "r)r]r-rsz&" partition, but arn provided is for "z;" partition. The client and arn partition must be the same.r��7S3 control client does not support accelerate endpointsrK)r�r)rQrSrPr*rTr�)r�r��
arn_regionr�Zrequest_partionr8r8r<r��	s8�
���


���zES3ControlEndpointSetter._validate_endpoint_from_arn_details_supportedcCs|j�d�rtdd��dS)NrtzPClient does not support s3 dualstack configuration when an outpost is specified.r])rQrSr*r�r8r8r<r��	s�z;S3ControlEndpointSetter._validate_outpost_redirection_validcCs2|j�dd�r,|jdd}|�||�|S|jS)NrqFrDr�)rQrSr�rvrP)r�r�r�r8r8r<r��	s
z8S3ControlEndpointSetter._resolve_region_from_arn_detailscCs|jdd}|�||�|S)NrDr.rw)r�r�Zarn_servicer8r8r<r�
sz>S3ControlEndpointSetter._resolve_signing_name_from_arn_detailscCs|�||�}|�||�dSr�)� _resolve_netloc_from_arn_detailsr�)r�r�rpr�r8r8r<r�
s�z:S3ControlEndpointSetter._resolve_endpoint_from_arn_detailscCsDt|j�}t|j||j|jdf�}t�d|j�d|���||_dSr�)rrqrr�rhr@r�r�)r�r�r�rzZarn_details_endpointr8r8r<r�
s
��	�z.S3ControlEndpointSetter._update_request_netloccCs0|jd}d|vr|�|�S|d}|�||�S)NrDrKr/)r�r��_construct_s3_control_endpoint)r�r�rprDr/r8r8r<r�
s


z8S3ControlEndpointSetter._resolve_netloc_from_arn_detailscCs|j�|�Sr�)�_HOST_LABEL_REGEXre)r��labelr8r8r<�_is_valid_host_label"
sz,S3ControlEndpointSetter._is_valid_host_labelcGs"|D]}|�|�st|d��qdS)N)r�)r�r)r��labelsr�r8r8r<�_validate_host_labels%
s
z-S3ControlEndpointSetter._validate_host_labelscCs\|�||�|jr(t|j�j}||g}n*|dg}|�|�|�|�}|�||g�|�|�S)N�
s3-control)r�rSrr�_add_dualstackr�r�_construct_netloc)r�rpr/r~rr�r8r8r<r�*
s
�

z6S3ControlEndpointSetter._construct_s3_control_endpointcCs@|�|�|jrt|j�jSd||�|�g}|�|�|�|�Sr�)r�rSrrr��	_add_fipsr�)r�rprr8r8r<r�9
s
�
z3S3ControlEndpointSetter._construct_outpost_endpointcCs
d�|�S)Nrk)rp�r�rr8r8r<r�F
sz)S3ControlEndpointSetter._construct_netloccCs|jr|dd|d<dS)Nrr�r�r�r8r8r<r�I
sz!S3ControlEndpointSetter._add_fipscCs|j�d�r|�d�dS)Nrtr1)rQrSror�r8r8r<r�M
sz&S3ControlEndpointSetter._add_dualstackcCs,|j�d|�}|j}|r(d|vr(|d}|Sr�r�r�r8r8r<r�Q
s�z'S3ControlEndpointSetter._get_dns_suffixcCs$|j�di�}||d<||jd<dSr�r�r�r8r8r<rvZ
sz0S3ControlEndpointSetter._override_signing_regioncCs$|j�di�}||d<||jd<dSr�r�)r�r�r�r�r8r8r<rbc
sz.S3ControlEndpointSetter._override_signing_namecCs(|jd}|�d�}|r$|�||�dS)NrDrK)r�rS�_add_outpost_id_header)r�r�rDrKr8r8r<r�l
s

z5S3ControlEndpointSetter._add_headers_from_arn_detailscCs||jd<dS)Nzx-amz-outpost-id)r\)r�r�rKr8r8r<r�r
sz.S3ControlEndpointSetter._add_outpost_id_header)NNNNF) r�r�r�rUr�rarlr�r�r�rZr�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r�rvrbr�r�r8r8r8r<r��	s@
�

		
			r�c@s�eZdZdZe�d�Zddd�Zdd�Zdd	�Z	d
d�Z
dd
�Zdd�Zdd�Z
dd�Zdd�Zdd�Zdd�Zdd�Zdd�ZdS)�S3ControlArnParamHandlerz�This handler has been replaced by S3ControlArnParamHandlerv2. The
    original version remains in place for any third-party importers.
    z[/:]NcCs(||_|durt�|_tjdtd�dS)Nz�The S3ControlArnParamHandler class has been deprecated for a new internal replacement. A future version of botocore may remove this class.r)r7r	r!r"r#r8r8r8r<r�}
s�z!S3ControlArnParamHandler.__init__cCs|�d|j�dS)Nz!before-parameter-build.s3-controlr9r;r8r8r<r��
s�z!S3ControlArnParamHandler.registercKs:|jdvr|�|||�n|�|||�|�|||�dS)N)r�ZListRegionalBuckets)rc�_handle_outpost_id_param�_handle_name_param�_handle_bucket_param)r�r�rCr�r�r8r8r<r:�
s
z#S3ControlArnParamHandler.handle_arncCsV||vrdSz0||}|j�|�}||d<|�|�|d<|WStyPYdS0dS)Nr�	resources)r7r2�_split_resourcer))r�r�r�r1rDr8r8r<�_get_arn_details_from_param�
sz4S3ControlArnParamHandler._get_arn_details_from_paramcCs|j�|d�S)Nr0)�_RESOURCE_SPLIT_REGEXrm)r�rDr8r8r<r��
sz(S3ControlArnParamHandler._split_resourcecCsF|d}d|vr:|d|kr:d�|d�}t|d|d��||d<dS)Nr/Z	AccountIdzGAccount ID in arn does not match the AccountId parameter provided: "{}"rr�)rcr))r�r�rDZ
account_idr�r8r8r<�_override_account_id_param�
s���z3S3ControlArnParamHandler._override_account_id_paramcCsd|vrdS|d|d<dS)NZ	OutpostIdr�r8)r�r�rCr�r8r8r<r��
sz1S3ControlArnParamHandler._handle_outpost_id_paramcCsX|jdkrdS|�|d�}|dur&dS|�|�r@|�|||�nd}t|d|d��dS�NZCreateAccessPoint�Namez4The Name parameter does not support the provided ARNrr�)rcr��_is_outpost_accesspoint�_store_outpost_accesspointr)�r�r�rCr�rDr�r8r8r<r��
s

�z+S3ControlArnParamHandler._handle_name_paramcCs@|ddkrdS|d}t|�dkr(dS|ddko>|dd	kS)
Nr.rFr�r,rr>r}r=�r{�r�rDr�r8r8r<r��
sz0S3ControlArnParamHandler._is_outpost_accesspointcCsD|�||�|dd}||d<||d<|dd|d<||d<dS)Nr�rrr�rJr-rKrD�r�)r�r�r�rDrJr8r8r<r��
sz3S3ControlArnParamHandler._store_outpost_accesspointcCsJ|�|d�}|durdS|�|�r2|�|||�nd}t|d|d��dS�Nr�z6The Bucket parameter does not support the provided ARNrr�)r��_is_outpost_bucket�_store_outpost_bucketr)r�r8r8r<r��
s
��z-S3ControlArnParamHandler._handle_bucket_paramcCs@|ddkrdS|d}t|�dkr(dS|ddko>|dd	kS)
Nr.rFr�r,rr>r}r�r�r�r8r8r<r��
sz+S3ControlArnParamHandler._is_outpost_bucketcCsD|�||�|dd}||d<||d<|dd|d<||d<dS)Nr�rrr�rvr-rKrDr�)r�r�r�rDrvr8r8r<r��
sz.S3ControlArnParamHandler._store_outpost_bucket)N)r�r�r�r�rarlr�r�r�r:r�r�r�r�r�r�r�r�r�r�r8r8r8r<r�v
s



		r�c@sReZdZdZddd�Zdd�Zdd�Zd	d
�Zdd�Zd
d�Z	dd�Z
dd�ZdS)�S3ControlArnParamHandlerv2aUpdated version of S3ControlArnParamHandler for use when
    EndpointRulesetResolver is in use for endpoint resolution.

    This class is considered private and subject to abrupt breaking changes or
    removal without prior announcement. Please do not use it directly.
    NcCs||_|durt�|_dSr�r6r8r8r8r<r�sz#S3ControlArnParamHandlerv2.__init__cCs|�d|j�dS)Nz%before-endpoint-resolution.s3-controlr9r;r8r8r<r�s�z#S3ControlArnParamHandlerv2.registercCsl|jdkrdS|�|d�}|dur&dS|�|�|�|�|�|�rT|�|||�nd}t|d|d��dSr�)rcr��_raise_for_fips_pseudo_region�_raise_for_accelerate_endpointr�r�r)r�r8r8r<r�s



�z-S3ControlArnParamHandlerv2._handle_name_paramcCs|�||�dSr�r�rIr8r8r<r� sz5S3ControlArnParamHandlerv2._store_outpost_accesspointcCs^|�|d�}|durdS|�|�|�|�|�|�rF|�|||�nd}t|d|d��dSr�)r�r�r�r�r�r)r�r8r8r<r�#s


��z/S3ControlArnParamHandlerv2._handle_bucket_paramcCs|�||�dSr�r�rIr8r8r<r�4sz0S3ControlArnParamHandlerv2._store_outpost_bucketcCs0|d}|�d�s|�d�r,t|ddd��dS)Nr�zfips-rrpr�)r�r�r))r�rDr�r8r8r<r�7s�z8S3ControlArnParamHandlerv2._raise_for_fips_pseudo_regioncCs&|djpi}|�d�r"tdd��dS)N�
client_configr�r�r])r$rSr*)r�r�rXr8r8r<r�@s

�z9S3ControlArnParamHandlerv2._raise_for_accelerate_endpoint)N)r�r�r�r�r�r�r�r�r�r�r�r�r8r8r8r<r��
s
	r�c@s|eZdZdZdZdZdZedddgZdej	fd	d
�Z
ddd�Zd
d�Zdd�Z
dd�Zdd�Zddd�Zdd�Zdd�ZdS)�ContainerMetadataFetcherr}rrr-z
169.254.170.2z169.254.170.23zfd00:ec2::23Z	localhostNcCs(|durtjj|jd�}||_||_dS)N)r�)rYr�r��TIMEOUT_SECONDSr��_sleep)r�rL�sleepr8r8r<r�Ts�z!ContainerMetadataFetcher.__init__cCs|�|�|�||�S)z�Retrieve JSON metadata from container metadata.

        :type full_url: str
        :param full_url: The full URL of the metadata service.
            This should include the scheme as well, e.g
            "http://localhost:123/foo"

        )�_validate_allowed_url�_retrieve_credentials)r��full_urlr\r8r8r<�retrieve_full_uri\s	
z*ContainerMetadataFetcher.retrieve_full_uricCs\tj�|�}|jdkrdS|�|j�r*dS|�|j�}|sXtd|j�dd�|j	�����dS)N�httpszUnsupported host 'zN'.  Can only retrieve metadata from a loopback address or one of these hosts: z, )
rY�compatrr��_is_loopback_addressrc�_check_if_whitelisted_hostr�rp�_ALLOWED_HOSTS)r�r��parsedZis_whitelisted_hostr8r8r<r�hs


��z.ContainerMetadataFetcher._validate_allowed_urlcCs*zt|�}|jWSty$YdS0dS)NF)r�is_loopbackr�)r�rc�ipr8r8r<r�vs
z-ContainerMetadataFetcher._is_loopback_addresscCs||jvrdSdS)NTF)r�)r�r�r8r8r<r�}s
z3ContainerMetadataFetcher._check_if_whitelisted_hostcCs|�|�}|�|�S)z�Retrieve JSON metadata from container metadata.

        :type relative_uri: str
        :param relative_uri: A relative URI, e.g "/foo/bar?id=123"

        :return: The parsed JSON response.

        )r�r�)r��relative_urir�r8r8r<�retrieve_uri�s	
z%ContainerMetadataFetcher.retrieve_uric
Cs�ddi}|dur|�|�d}z|�|||j�WSty�}z<tjd|dd�|�|j�|d7}||jkrp�WYd}~qd}~00qdS)NZAcceptzapplication/jsonrzAReceived error when attempting to retrieve container metadata: %sTr�r-)	r;�
_get_responser�r!r�r�r��
SLEEP_TIME�RETRY_ATTEMPTS)r�r�Z
extra_headersr\Zattemptsr�r8r8r<r��s$
��
z.ContainerMetadataFetcher._retrieve_credentialsc

Cs�z�tjj}|d||d�}|j�|���}|j�d�}|jdkrVt	d|j�d|��d��zt
�|�WWSty�d}t
�d	||�t	|d��Yn0Wn8ty�}	z d
|	��}t	|d��WYd}	~	n
d}	~	00dS)Nr�r�rr�zReceived non 200 response z from container metadata: r�z>Unable to parse JSON returned from container metadata servicesz%s:%sz?Received error when attempting to retrieve container metadata: )rYrZr�r�r�r�r�rEr�r!rr�r�r�r�r�)
r�r�r\r�r�r�r�Z
response_textr�r�r8r8r<r��s.

����z&ContainerMetadataFetcher._get_responsecCsd|j�|��S)Nzhttp://)�
IP_ADDRESS)r�r�r8r8r<r��sz!ContainerMetadataFetcher.full_url)N)N)r�r�r�r�r�r�r�r��timer�r�r�r�r�r�r�r�r�r�r8r8r8r<r�Hs$�

r�cCst|�riSt�SdSr�)�should_bypass_proxiesr�rqr8r8r<r��sr�c	Cs6ztt|�j�rWdSWnttjfy0Yn0dS)z:
    Returns whether we should bypass proxies or not.
    TF)rrrr$�socketZgaierrorr�r8r8r<r��s
r�c	Cs�|sdSz
t|�WSttfy(Yn0t|d�r�t|d�r�z0|��}|�dd�|��}|�|�||WStjy�Yn0dS)Nr�seek�tellr})r{�AttributeErrorr$rRr�r��io�UnsupportedOperation)r6Zorig_posZend_file_posr8r8r<�determine_content_length�s 


r��
ISO-8859-1cCsJ|�d�}|sdStj��}||d<|�d�}|dur:|Sd|vrF|SdS)z�Returns encodings from given HTTP Header Dict.

    :param headers: dictionary to extract encoding from.
    :param default: default encoding if the content-type is text
    zcontent-typeN�charsetr�)rS�email�messager�Z	get_param)r\�defaultZcontent_typer�r�r8r8r<�get_encoding_from_headers�s


r�cKs0t|ttf�rt|�}nt|�}t�|��d�S)�KThis function has been deprecated, but is kept for backwards compatibility.rB)rBr�	bytearray�_calculate_md5_from_bytes�_calculate_md5_from_file�base64Z	b64encoderE)r6r�Z
binary_md5r8r8r<�
calculate_md5s
r�cCst|�}|��S)r�)r
r=)Z
body_bytes�md5r8r8r<r�sr�csB���}t�}t�fdd�d�D]}|�|�q ��|�|��S)r�cs
��d�Sr2r4r8��fileobjr8r<r7%r>z*_calculate_md5_from_file.<locals>.<lambda>r>)r�r
r:r;r�r=)r�Zstart_positionr�r?r8r�r<r�!s
r�cCs"|�di��di�}|�d�dkS)Nr�r�r�r�r�)r�r�r8r8r<�_is_s3express_request+s�r�cCs&|d}|D]}t�|�rdSqdS)z�
    Checks if a header starting with "x-amz-checksum-" is provided in a request.

    This function is considered private and subject to abrupt breaking changes or
    removal without prior announcement. Please do not use it directly.
    r\TF)�CHECKSUM_HEADER_PATTERNre)r�r\rPr8r8r<�has_checksum_header2s

r�cKs,t|�s(t|fi|��t|fi|��dS)r�N)r��conditionally_calculate_md5�conditionally_enable_crc32)r�r�r8r8r<� conditionally_calculate_checksumDsrcKsV|�di��di�}|�d�}t|�rR|ddurR|dvrRdddd	d
�i|dd<dS)r�r�r>�request_algorithmr6N)N�conditional-md5Zcrc32rPzx-amz-checksum-crc32)�	algorithm�inrc)rSr�)r�r��checksum_context�checksum_algorithmr8r8r<rKs
�
����rcKsz|d}|�di��di�}|�d�}|r6|dkr6dSt|�rBdSt|�rNdStrv|durvt|fi|��}||dd<dS)	z�Only add a Content-MD5 if the system supports it.

    This function has been deprecated, but is kept for backwards compatibility.
    r6r�r>rrNr\zContent-MD5)rSr�r�r	r�)r�r�r6rrZ
md5_digestr8r8r<r]s
rc@s eZdZefdd�Zdd�ZdS)�FileWebIdentityTokenLoadercCs||_||_dSr�)�_web_identity_token_pathr)r�Zweb_identity_token_pathrr8r8r<r�wsz#FileWebIdentityTokenLoader.__init__cCs8|�|j��}|��Wd�S1s*0YdSr�)rr
r)r�Z
token_filer8r8r<�__call__{sz#FileWebIdentityTokenLoader.__call__N)r�r�r��openr�rr8r8r8r<r	vsr	c@sreZdZdZdZdZdZddd�Zdd�Zd	d
�Z	dd�Z
d
d�Zdd�Ze
dd��Zdd�Zdd�Zdd�ZdS)�BaseSSOTokenFetcherz{Base class for SSO token fetchers, for functionality
    shared between the device and authorization code grant flows.
    ��publicNcCsB||_||_||_||_|dur&|j}||_|dur8i}||_dSr�)�_sso_region�_client_creator�_parsed_globals�_on_pending_authorization�_utc_now�
_time_fetcherr�)r��
sso_region�client_creator�parsed_globalsr��on_pending_authorization�time_fetcherr8r8r<r��s	zBaseSSOTokenFetcher.__init__cCstd��dS)NzMust implement fetch_token()r��r��	start_url�
force_refresh�registration_scopes�session_namer8r8r<�fetch_token�szBaseSSOTokenFetcher.fetch_tokencCstj�t��Sr�)rZnowr+r�r8r8r<r�szBaseSSOTokenFetcher._utc_nowcCst|t�r|Stj�|�Sr�)rBr-r%r&r')r�r~r8r8r<�_parse_if_needed�s
z$BaseSSOTokenFetcher._parse_if_neededcCs(|�|d�}t||���}||jkS)N�	expiresAt)r!rr�_EXPIRY_WINDOW)r�r�Zend_timer�r8r8r<�_is_expired�szBaseSSOTokenFetcher._is_expiredcCsd|vrd|dvrdSdS)N�
grantTypes�authorization_codeTFr8)r��registrationr8r8r<�_is_registration_for_auth_code�s�
�z2BaseSSOTokenFetcher._is_registration_for_auth_codecCs,tjj|jtj|jd�}|jd||jjd�S)N)rprzZuser_agent_extrazsso-oidc)r�Zverify)	rYr�ZConfigrZUNSIGNED�_USER_AGENT_EXTRArrZ
verify_ssl)r�r�r8r8r<r��s��zBaseSSOTokenFetcher._clientcCs*|durt|���}t|�}dt|���S)Nzbotocore-client-)r1rr!rD)r�rrWr8r8r<�_generate_client_name�sz)BaseSSOTokenFetcher._generate_client_namecCs4d||j||d�}tj|dd��d�}t�|���S)NrY)Ztool�startUrlr��scopesrT)Z	sort_keysr)rr�dumpsrr8�sha1r<)r�rrr,r�r�r8r8r<�_registration_cache_key�s�z+BaseSSOTokenFetcher._registration_cache_keycCs$|}|dur|}t�|�d����S�Nr�r8r.rr<�r�rrrr8r8r<�_token_cache_key�sz$BaseSSOTokenFetcher._token_cache_key)NNN)r�r�r�r�r#�_CLIENT_REGISTRATION_TYPEr)r�r rr!r$r(rJr�r*r/r3r8r8r8r<r
�s$�
	
r
csneZdZdZdZdZdZdZd�fdd�	Zdd	�Z	ddd�Z
d
d�Zdd�Zdd�Z
dd�Zddd�Z�ZS)�SSOTokenFetcherz'Performs the device grant OAuth2.0 flowr*rz,urn:ietf:params:oauth:grant-type:device_codeNcs.t��||||||�|dur$tj}||_dSr�)r�r�r�r�r�)r�rrrr�rrr�r�r8r<r��s
�	zSSOTokenFetcher.__init__cCsl|�|�|jd�}|r||d<|jjfi|��}|d}tj�|t��}|d|d|d�}|rh||d<|S)N��
clientName�
clientTyper,�clientSecretExpiresAt�clientId�clientSecret)r:r;r")r*r4r��register_clientrr#r+)r�rr,�register_kwargsr��
expires_atr'r8r8r<�_register_client
s��z SSOTokenFetcher._register_clientFcCsX|�|||�}|s>||jvr>|j|}|�|�s>|�|�s>|S|�||�}||j|<|Sr�)r/r�r$r(r?�r�rrr,rr�r'r8r8r<�
_registration
s&�
���
zSSOTokenFetcher._registrationcCsj|jj|d|d|d�}tj|dd�}|d|d|d|d	|��|d
�}d|vrf|d|d<|S)Nr:r;)r:r;r+�	expiresInr��
deviceCode�userCode�verificationUri�verificationUriComplete)rCrDrErFr"�interval)r�Zstart_device_authorizationrr�r)r�rr'r��
expires_in�
authorizationr8r8r<�_authorize_client9
s�
�z!SSOTokenFetcher._authorize_clientcCs�|�|||�}|�||�}|�d|j�}|�||||�\}}|durH|S|jr^|jfi|��|�||||�\}}|dur~|S|�|�q^dS)NrG)rArJrS�_DEFAULT_INTERVAL�_create_token_attemptrr�)r�rrrr'rIrGr�r8r8r<�_poll_for_tokenN
s(���zSSOTokenFetcher._poll_for_tokencCs�z~|jj|j|d|d|dd�}tj|dd�}||j|d|��||d|d|dd	�}d
|vrv|d
|d
<||fWS|jjjy�||j	7}Yn4|jjj
y�Yn|jjjy�t��Yn0|dfS)Nr:r;rC)�	grantTyper:r;rCrBr��accessTokenr"�r+r�rOr"r:r;ZregistrationExpiresAt�refreshToken)
r��create_token�_GRANT_TYPErr�rr�
exceptionsZSlowDownException�_SLOW_DOWN_DELAYZAuthorizationPendingException�ExpiredTokenExceptionr")r�rr'rIrGr�rHr�r8r8r<rLt
s4�
�

z%SSOTokenFetcher._create_token_attemptcCsN|�||�}|s2||jvr2|j|}|�|�s2|S|�|||�}||j|<|Sr�)r3r�r$rM�r�rrrrr�r�r8r8r<�_token�
s

�
zSSOTokenFetcher._tokencCs|�||||�Sr�)rXrr8r8r<r �
s�zSSOTokenFetcher.fetch_token)NNNN)F)FNN)r�r�r�r�rUrKr#rSr�r?rArJrMrLrXr r�r8r8r�r<r5�s*��
&$�r5csreZdZdZdZdZdZd�fdd�	Zdd	�Zddd�Z	d
d�Z
dd�Zdd�Zdd�Z
dd�Zddd�Z�ZS)�SSOTokenFetcherAuthz=Performs the authorization code grant with PKCE OAuth2.0 flow)r&Z
refresh_tokenzsso:account:accesszmd/sso#authNcsZt��||||||�||_d�dd�td�D��|_t�t�	|j�
�������|_
dS)Nr^css$|]}t�tjtjd�VqdS)r0N)�secretsZchoicerQZ
ascii_lettersZdigits)r:�_r8r8r<r��
s�z/SSOTokenFetcherAuth.__init__.<locals>.<genexpr>�@)r�r��_auth_code_fetcherrpr��
code_verifierr��urlsafe_b64encoder8r9rr=rE�code_challenge)r�rrrZauth_code_fetcherr�rrr�r8r<r��
s
�	
�
�zSSOTokenFetcherAuth.__init__c	Cst|�|�|j|j|g||p |jgd�}|jjfi|��}|d}tj�|t��}|d|d||d|dd�}|S)N)r7r8r%ZredirectUrisZ	issuerUrlr,r9r:r;r,r%)r:r;r"r,r%)	r*r4�_AUTH_GRANT_TYPES�_AUTH_GRANT_DEFAULT_SCOPEr�r<rr#r+)	r�rr,�redirect_uriZ
issuer_urlr=r�r>r'r8r8r<r?�
s"
�	�z$SSOTokenFetcherAuth._register_clientFcCsb|�|||�}|s>||jvr>|j|}|�|�s>|�|�r>|S|�|||j��|�}||j|<|Sr�)r/r�r$r(r?r]Zredirect_uri_without_portr@r8r8r<rA�
s*�
���
z!SSOTokenFetcherAuth._registrationcKs>|dr(t|d�}|j�d|j��|_tj�ddid�ifS)z�Event handler for before-call that will extract the resolved endpoint
        for a given request without actually running it
        rq�://Nr�)rr�r�_base_endpointrYrZ�AWSResponse)r�r�r�r�r8r8r<�_extract_resolved_endpointsz.SSOTokenFetcherAuth._extract_resolved_endpointcCs>|jjj�d|j�|jjddd�|jjj�d|j�|jS)z�Simulates an SSO-OIDC request so that we can extract the "base"
        endpoint for the current client to use for the un-modeled Authorize
        operation
        �before-callZtemprr6)r�r�r�r�rgr<�
unregisterrer�r8r8r<�_get_base_authorization_uri$s
�
�z/SSOTokenFetcherAuth._get_base_authorization_uricCsZd||j��|dd�}|r*d�|�|d<n
|j|d<|���dt|��d|jdd���S)	N�codeZS256)Z
response_type�	client_idrc�stateZcode_challenge_methodr�r,z/authorize?z&code_challenge=rl)r]�redirect_uri_with_portrprbrjrr`)r�rlr�expected_stateZquery_paramsr8r8r<�_get_authorization_uri3s�


���z*SSOTokenFetcherAuth._get_authorization_uric
Cs�|�|||�}t��}|�|d||�}||dd�}|jfi|��|j��\}}	|durdtdd��|	t|�krztdd��|�	|||�S)Nr:)rErFrDz)Failed to retrieve an authorization code.r�z.State parameter does not match expected value.)
rA�uuid�uuid4rprr]Zget_auth_code_and_staterrD�_create_token_)
r�rrrr'roZauthorization_uriZauthorization_args�	auth_codermr8r8r<�_get_new_tokenKs0�
����z"SSOTokenFetcherAuth._get_new_tokencCs�z�|jjd|d|d|j��|j|d�}tj|dd�}||j|d|��||d|d|dd	�}d
|vr||d
|d
<|WS|jj	j
y�t��Yn0dS)Nr&r:r;)rNr:r;ZredirectUriZcodeVerifierrkrBr�rOr"rPrQ)r�rRr]rnr^rr�rrrTrVr")r�rr'rtr�rHr�r8r8r<rsss.�
�
z"SSOTokenFetcherAuth._create_token_cCsN|�||�}|s2||jvr2|j|}|�|�s2|S|�|||�}||j|<|Sr�)r3r�r$rurWr8r8r<r �s

�
zSSOTokenFetcherAuth.fetch_token)NNN)F)FNN)r�r�r�r�rarbr)r�r?rArgrjrprursr r�r8r8r�r<rY�
s(��

(�rYc@s2eZdZd
dd�Zdd�Zddd�Zddd	�ZdS)
�SSOTokenLoaderNcCs|duri}||_dSr��r��r�r�r8r8r<r��szSSOTokenLoader.__init__cCs$|}|dur|}t�|�d����Sr0r1r2r8r8r<�_generate_cache_key�sz"SSOTokenLoader._generate_cache_keycCs|�||�}||j|<dSr�)ryr�)r�rr�rr�r8r8r<�
save_token�szSSOTokenLoader.save_tokencCs�|�||�}t�d|���||jvrL|}|dur6|}d|�d�}t|d��|j|}d|vsfd|vr|d|�d�}t|d��|S)NzChecking for cached token at: z
Token for z does not existr�rOr"z is invalid)ryr�r�r�r$)r�rrr�rcr�r�r8r8r<r�s



zSSOTokenLoader.__call__)N)N)N)r�r�r�r�ryrzrr8r8r8r<rv�s

rvc
cs�|durtj}d}d|vr&d|d<d}|�d�}d|vrF|d|d<n|�dd�z*dVW|durl||d<|r�|�dd�n"|dur�||d<|r�|�dd�0dS)NFZPYINSTALLER_RESET_ENVIRONMENT�1TZLD_LIBRARY_PATHZLD_LIBRARY_PATH_ORIG)r�r�rSrn)r�Z*should_clear_pyinstaller_reset_environmentZvalue_to_put_backr8r8r<�original_ld_library_path�s(
�r|c@s@eZdZdZdZddd�Zdd�Zdd	�Zd
d�Zddd
�Z	dS)�EventbridgeSignerSetterrNr�NcCs||_||_||_dSr�)r rPrS)r�rWr�rgr8r8r<r��sz EventbridgeSignerSetter.__init__cCs |�d|j�|�d|j�dS)Nz,before-parameter-build.eventbridge.PutEventsz!before-call.eventbridge.PutEvents)r��check_for_global_endpoint�set_endpoint_urlr;r8r8r<r��s��z EventbridgeSignerSetter.registercKs6d|vr2|d}t�d|d�d|���||d<dS)N�eventbridge_endpointzRewriting URL from rqr�)r�r�r'r8r8r<r�sz(EventbridgeSignerSetter.set_endpoint_urlc	Ks�|�d�}|durdSt|�dkr,tdd��|�d�}d}|dur^|jrRtdd��|jr^dg}|jdur�td|���}|j|kr�td	d��|j||d
�}n|j}||d<d|d
<dS)NZ
EndpointIdrz+EndpointId must not be a zero length stringr]r�z>FIPS is not supported with EventBridge multi-region endpoints.r1�https://z-EndpointId is not a valid hostname component.��endpoint_variant_tagsr�Zv4ar)	rSr{rrYrtrSrrc�_get_global_endpoint)	r�r�r�r�r�r�r�rnZresolved_endpointr8r8r<r~s8
�
�

��z1EventbridgeSignerSetter.check_for_global_endpointcCsN|j}|�|j�}|dur |j}|j||d�}|dur<|j}d|�d|�d�S)Nr�r�z.endpoint.events.re)r Zget_partition_for_regionrPrUr�r�)r�r�r�rdr-r�r8r8r<r�(s�z,EventbridgeSignerSetter._get_global_endpoint)NN)N)
r�r�r�rUr�r�r�rr~r�r8r8r8r<r}�s
	%r}c@sreZdZdZej�ej�dddd��Zedfdd�Z	d	d
�Z
dd�Zd
d�Zdd�Z
dd�Zdd�Zddd�ZdS)�
JSONFileCachez�JSON file cache.
    This provides a dict like interface that stores JSON serializable
    objects.
    The objects are serialized to JSON and stored in a file.  These
    values can be retrieved at a later time.
    �~�.awsZbotor�NcCs||_|dur|j}||_dSr�)�_working_dir�_default_dumps�_dumps)r�Zworking_dirZ
dumps_funcr8r8r<r�AszJSONFileCache.__init__cCstj||jd�S)N)r�)rr-r�)r�rNr8r8r<r�GszJSONFileCache._default_dumpscCs|�|�}tj�|�Sr�)�_convert_cache_keyr�rh�isfile)r�r��
actual_keyr8r8r<�__contains__Js
zJSONFileCache.__contains__c	Csf|�|�}z8t|��}t�|�Wd�WS1s60YWnttfy`t|��Yn0dS)z Retrieve value from a cache key.N)r�rr�loadrr��KeyError)r�r�r�r	r8r8r<�__getitem__Ns

.zJSONFileCache.__getitem__cCs>|�|�}zt|�}|��Wnty8t|��Yn0dSr�)r�r�unlink�FileNotFoundErrorr�)r�r�r�Zkey_pathr8r8r<�__delitem__Ws
zJSONFileCache.__delitem__c	Cs�|�|�}z|�|�}Wn$ttfy<td|����Yn0tj�|j�sXt�|j�t�	t�
|tjtjBd�d��"}|�
�|�|�Wd�n1s�0YdS)Nz3Value cannot be cached, must be JSON serializable: i��w)r�r�r$r�r�rh�isdirr��makedirs�fdopenr�O_WRONLY�O_CREAT�truncate�write)r�r�r~Zfull_keyZfile_contentr	r8r8r<�__setitem___s"
��
�zJSONFileCache.__setitem__cCstj�|j|d�}|S)Nz.json)r�rhrpr�)r�r��	full_pathr8r8r<r�psz JSONFileCache._convert_cache_keyFcCs$t|t�r |r|��S|�d�S|Sr�r�r�r8r8r<r�ts


z"JSONFileCache._serialize_if_needed)F)r�r�r�r�r�rh�
expanduserrpZ	CACHE_DIRr�r�r�r�r�r�r�r�r8r8r8r<r�7s	r�cKsL|duri}|dr6t|d�}|j�d|j��|d<tj�ddid�ifS)z~Event handler for before-call that will extract the resolved endpoint
    for a given request without actually running it
    Nrqrd�urir�)rr�rrYrZrf)r�r�r�r�r8r8r<rg|srgcCsJi}tt|d�}|jj�d|�|jddd�d�|jj�d|�|dS)zfSimulates a Sign-In request so that we can extract the "base"
    endpoint for the current client
    )r�rhr�)r:rN)Z
tokenInputr�)rrgr�r�r�Zcreate_o_auth2_tokenri)r�r�Zhandlerr8r8r<�get_base_sign_in_uri�s�r�cCst�|�d����Sr0)r8r9rr<)Zsign_in_session_namer8r8r<�generate_login_cache_key�sr�cCs�|durdSt|�}|j�d�r*|jdvr.dS|j�d�}|ddkrJdS|dd	�}t|�tt|��krndStd
d�|D��S)z�Does the URL match the S3 Accelerate endpoint scheme?

    Virtual host naming style with bucket names in the netloc part of the URL
    are not allowed by this function.
    NFr�)r��httprkrr�r-r�css|]}|tvVqdSr�r�r�r8r8r<r��r>z'is_s3_accelerate_url.<locals>.<genexpr>)rrr�r�rmr{r�r�)rqZ	url_partsrnr�r8r8r<�is_s3_accelerate_url�s ��r�cCs|durdS|�d�S)NFz--x-s3)r�r�r8r8r<�is_s3express_bucket�sr�cCs6t|t�r|��sdS|dur$tj}t|�}|�|�Sr�)rBrDrr�r��_get_bearer_env_var_namerS)r�r�Zenv_varr8r8r<�get_token_from_environment�sr�cCs"|�dd��dd���}d|��S)Nr�r[r�ZAWS_BEARER_TOKEN_)r`�upper)r�Zbearer_namer8r8r<r��sr�zruntime.sagemakerzsagemaker-runtimezapi-gatewayzapplication-auto-scalingzapp-meshzauto-scalingzauto-scaling-plansz
cost-explorerzcloudhsm-v2zcloudsearch-domainzcognito-identity-providerzconfig-servicezcost-and-usage-report-servicez
data-pipelinezdirect-connectzdevice-farmzapplication-discovery-servicezdatabase-migration-servicezdirectory-servicezdirectory-service-datazdynamodb-streamszelastic-beanstalkzelastic-load-balancingzelastic-load-balancing-v2zelasticsearch-serviceZeventbridgezglobal-acceleratorziot-data-planeziot-jobs-data-planeziot-events-dataz
iot-eventsziot-wirelesszkinesis-analyticszkinesis-analytics-v2z
kinesis-videozlex-model-building-servicez
lex-models-v2zlex-runtime-servicezlex-runtime-v2zcloudwatch-logszmachine-learningzmarketplace-commerce-analyticszmarketplace-entitlement-servicezmarketplace-meteringz
migration-hubzresource-groups-tagging-apizroute-53zroute-53-domainsr�Zsimpledbzsecrets-managerZserverlessapplicationrepositoryzservice-catalogzservice-catalog-appregistryZsfnzstorage-gateway)6Z
apigatewayzapplication-autoscalingZappmeshZautoscalingzautoscaling-plansZceZ
cloudhsmv2Zcloudsearchdomainzcognito-idpr�ZcurZdatapipelineZ
directconnectZ
devicefarmZ	discoveryZdmsZdszds-dataZdynamodbstreamsZelasticbeanstalkZelbZelbv2Zesr�Zglobalacceleratorziot-dataz
iot-jobs-dataziotevents-dataZ	ioteventsZiotwirelessZkinesisanalyticsZkinesisanalyticsv2Zkinesisvideoz
lex-modelszlexv2-modelszlex-runtimez
lexv2-runtimeZlogsZmachinelearningZmarketplacecommerceanalyticszmarketplace-entitlementZmeteringmarketplaceZmghZresourcegroupstaggingapiZroute53Zroute53domainsZ	s3controlZsdbZsecretsmanagerZserverlessrepoZservicecatalogzservicecatalog-appregistryZ
stepfunctionsZstoragegatewaycCsJdtjvr,tj�tjd�}tj�|�}|Stj�tj�dddd��SdS)z>Returns which directory contains the login_session token filesZAWS_LOGIN_CACHE_DIRECTORYr�r�Zloginr�N)r�r�rh�
expandvarsr�rprgr8r8r<�get_login_token_cache_directorys

r�c@s*eZdZdZd	dd�Zdd�Zdd�ZdS)
�LoginCredentialsLoaderz+Loads and saves login access tokens to diskNcCs|duri}||_dSr�rwrxr8r8r<r�*szLoginCredentialsLoader.__init__cCst|�}||j|<dSr��r�r�)r�rr�r�r8r8r<rz/sz!LoginCredentialsLoader.save_tokencCs t|�}||jvrdS|j|Sr�r�)r�rr�r8r8r<�
load_token3s
z!LoginCredentialsLoader.load_token)N)r�r�r�r�r�rzr�r8r8r8r<r�'s
r�cCst�|��d��d�S)N�=rB)r�r_�rstriprE)r�r8r8r<�base64_url_encode_no_padding:sr�cCs�|��\}}dt|�t|�dd�}dd|d�}d||p@tt���|pNtt���d�}ttj|d	d
��	��}	ttj|d	d
��	��}
|	�d|
���	�}|�
t�|��
��}tj|dd
�}
t|
�}|	�d|
�d|��S)NrzP-256)Zktyr;�yZcrvzdpop+jwtZES256)�typZalg�jwkZPOST)ZhtmZhtuZiatZjti)�,r4)Z
separatorsrk� )Zpad_to)Zget_public_coordsr�r!r�rDrqrrrr-rZsignr8r9r=rZ#decode_der_signature_to_padded_pair)�private_keyr�ZuidZtsr;r�r�rPZpayloadZ
header_b64Zpayload_b64Z
signing_inputZ	signatureZsignature_bytesZ
signature_b64r8r8r<�build_dpop_header>s8������r�cs�fdd�}|S)zHBuilds a before-call handler for calculating and setting the DPoP headercs"t�|dd�|ddd<dS)Nr�rqr\ZDPoP)r�r��r�r8r<�_add_dpop_header_handlerfs�z?build_add_dpop_header_handler.<locals>._add_dpop_header_handlerr8)r�r�r8r�r<�build_add_dpop_header_handlercsr�)T)F)N)F)N)N)T)T)r�)N)N)N)NN)�r�rD�
contextlibrZ
email.messager�r�r8r�Zloggingr�r�rarZr�rQr�rqr!r�r-r�	ipaddressr�pathlibrZurllib.requestrrrYZbotocore.awsrequestZbotocore.httpsessionZdateutil.parserr%Z
awscrt.cryptorZbotocore.compatr	r
rrr
rrrrrZbotocore.exceptionsrrrrrrrrrrrrrr r!r"r#r$r%r&r'r(r)r*Zdateutil.tzr+Zurllib3.exceptionsr,Z	getLoggerr�r�r�r�r�rKZ
SAFE_CHARSrlrtr�r�ZIPV4_PATriZHEX_PATZLS32_PATr9Z_variationsZUNRESERVED_PATrpZIPV6_PATZZONE_ID_PATZIPV6_ADDRZ_PATrd�	frozensetrarmr�Z$PRIORITY_ORDERED_SUPPORTED_PROTOCOLSrHrMrVr]rdrirjrfryr|r��	Exceptionr�r�r�r�r�rrrrrrr r(r,r.r1r@rHrCrJrQrhrjror�rqrxr|ryr~r�r�r�r�r�r�r�r�r�r�r�r�rr�r)r	r5rMr�r�r�r�r�r�r�r�r�r�r�r�r�rrrr	r
r5rYrv�contextmanagerr|r}r�rgr�r�r�r�r�r�ZSERVICE_NAME_ALIASESZ.CLIENT_NAME_TO_HYPHENIZED_SERVICE_ID_OVERRIDESr�r�r�r�r�r8r8r8r<�<module>
s�0h

�
��


	A	&0-!`
�
�
@!")7I2UWMz	

iVf!&LE!


�;
%

Youez - 2016 - github.com/yon3zu
LinuXploit