Ë
    £…jq  ã                   óp   — d dl mZmZ d dlmZ ddlmZmZ ddlm	Z	 ddl
mZ ddlmZmZ  G d	„ d
ee	«      Zy)é    )ÚOptionalÚAny)ÚAccessTokenInfoé   )Ú	AadClientÚAsyncContextManager)ÚGetTokenMixiné   )Úget_client_credential)ÚAadClientCertificateÚvalidate_tenant_idc                   ó~   ‡ — e Zd ZdZddededee   deddf
ˆ fd„Zdd	„Zdd
„Z	dededee
   fd„Zdedede
fd„Zˆ xZS )ÚCertificateCredentialaÛ  Authenticates as a service principal using a certificate.

    The certificate must have an RSA private key, because this credential signs assertions using RS256. See
    `Microsoft Entra ID documentation
    <https://learn.microsoft.com/entra/identity-platform/certificate-credentials#register-your-certificate-with-microsoft-identity-platform>`__
    for more information on configuring certificate authentication.

    :param str tenant_id: ID of the service principal's tenant. Also called its 'directory' ID.
    :param str client_id: The service principal's client ID
    :param str certificate_path: Optional path to a certificate file in PEM or PKCS12 format, including the private
        key. If not provided, **certificate_data** is required.

    :keyword str authority: Authority of a Microsoft Entra endpoint, for example 'login.microsoftonline.com',
          the authority for Azure Public Cloud (which is the default). :class:`~azure.identity.AzureAuthorityHosts`
          defines authorities for other clouds.
    :keyword bytes certificate_data: The bytes of a certificate in PEM or PKCS12 format, including the private key.
    :keyword password: The certificate's password. If a unicode string, it will be encoded as UTF-8. If the certificate
          requires a different encoding, pass appropriately encoded bytes instead.
    :paramtype password: str or bytes
    :keyword cache_persistence_options: Configuration for persistent token caching. If unspecified, the credential
          will cache tokens in memory.
    :paramtype cache_persistence_options: ~azure.identity.TokenCachePersistenceOptions
    :keyword List[str] additionally_allowed_tenants: Specifies tenants in addition to the specified "tenant_id"
        for which the credential may acquire tokens. Add the wildcard value "*" to allow the credential to
        acquire tokens for any tenant the application can access.

    .. admonition:: Example:

        .. literalinclude:: ../samples/credential_creation_code_snippets.py
            :start-after: [START create_certificate_credential_async]
            :end-before: [END create_certificate_credential_async]
            :language: python
            :dedent: 4
            :caption: Create a CertificateCredential.
    NÚ	tenant_idÚ	client_idÚcertificate_pathÚkwargsÚreturnc                 óÊ   •— t        |«       t        |fi |¤Ž}t        |d   |j                  d«      ¬«      | _        t        ||fi |¤Ž| _        || _        t        ‰| �%  «        y )NÚprivate_keyÚ
passphrase)Úpassword)
r   r   r   ÚgetÚ_certificater   Ú_clientÚ
_client_idÚsuperÚ__init__)Úselfr   r   r   r   Úclient_credentialÚ	__class__s         €úl/root/aria/tools/markitdown-venv/lib/python3.12/site-packages/azure/identity/aio/_credentials/certificate.pyr   zCertificateCredential.__init__3   sf   ø€ Ü˜9Ô%ä1Ð2BÑMÀfÑMÐä0Ø˜mÑ,Ð7H×7LÑ7LÈ\Ó7Zô
ˆÔô ! ¨IÑ@¸Ñ@ˆŒØ#ˆŒÜ‰ÑÕó    c              ƒ   óV   K  — | j                   j                  «       ƒ d {  –—†  | S 7 Œ­w©N)r   Ú
__aenter__©r   s    r"   r&   z CertificateCredential.__aenter__@   s&   è ø€ Ø�l‰l×%Ñ%Ó'×'Ð'Øˆð 	(ús   ‚) '¡)c              ƒ   óT   K  — | j                   j                  «       ƒ d{  –—†  y7 Œ­w)z)Close the credential's transport session.N)r   Ú	__aexit__r'   s    r"   ÚclosezCertificateCredential.closeD   s   è ø€ ð �l‰l×$Ñ$Ó&×&Ò&ús   ‚( &¡(Úscopesc              �   óD   K  —  | j                   j                  |fi |¤ŽS ­wr%   )r   Úget_cached_access_token©r   r+   r   s      r"   Ú_acquire_token_silentlyz-CertificateCredential._acquire_token_silentlyI   s"   è ø€ Ø3ˆt�|‰|×3Ñ3°FÑE¸fÑEÐEùs   ‚ c              �   ón   K  —  | j                   j                  || j                  fi |¤Žƒ d {  –—† S 7 Œ­wr%   )r   Ú"obtain_token_by_client_certificater   r.   s      r"   Ú_request_tokenz$CertificateCredential._request_tokenL   s1   è ø€ ØD�T—\‘\×DÑDÀVÈT×M^ÑM^ÑiÐbhÑi×iÐiÐiús   ‚,5®3¯5r%   )r   r   )r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ústrr   r   r   r&   r*   r   r/   r2   Ú__classcell__)r!   s   @r"   r   r      s„   ø„ ñ"ñH #ð °#ð ÈÐRUÉð Ðilð Ðquõ óó'ð
F°Sð FÀCð FÈHÐUdÑLeó Fðj¨Cð j¸3ð jÀ?÷ jr#   r   N)Útypingr   r   Úazure.core.credentialsr   Ú	_internalr   r   Ú_internal.get_token_mixinr	   Ú_credentials.certificater   r   r   r   © r#   r"   ú<module>r?      s*   ð÷
 !å 2ß 6Ý 5Ý =ß Aô?jÐ/°õ ?jr#   