ó
    Ú°›j¨ˆ  ã                   ó,  • S SK r S SKrS SKrS SKrS SKrS SKrS SKJrJr  S SK	J
r
Jr  S SKJrJrJrJr  S SKJr  S SKJrJrJr   " S S5      r " S	 S
5      rS rS rSS jr SS jr SS jr SS jr " S S5      rS r  SS jr!S r" SS jr#S r$g)é    N)Úcreate_request_objectÚprepare_request_dict)ÚOrderedDictÚget_current_datetime)ÚParamValidationErrorÚUnknownClientMethodErrorÚUnknownSignatureVersionErrorÚ UnsupportedSignatureVersionError)ÚFrozenAuthToken)Ú	ArnParserÚdatetime2timestampÚfix_s3_hostc                   óž   • \ rS rSrSr SS jr\S 5       r\S 5       r\S 5       r	SS jr
    SS	 jrS
 rS r  SS jr\r   SS jrSrg)ÚRequestSigneré$   aÔ  
An object to sign requests before they go out over the wire using
one of the authentication mechanisms defined in ``auth.py``. This
class fires two events scoped to a service and operation name:

* choose-signer: Allows overriding the auth signer name.
* before-sign: Allows mutating the request before signing.

Together these events allow for customization of the request
signing pipeline, including overrides, request path manipulation,
and disabling signing per operation.


:type service_id: botocore.model.ServiceId
:param service_id: The service id for the service, e.g. ``S3``

:type region_name: string
:param region_name: Name of the service region, e.g. ``us-east-1``

:type signing_name: string
:param signing_name: Service signing name. This is usually the
                     same as the service name, but can differ. E.g.
                     ``emr`` vs. ``elasticmapreduce``.

:type signature_version: string
:param signature_version: Signature name like ``v4``.

:type credentials: :py:class:`~botocore.credentials.Credentials`
:param credentials: User credentials with which to sign requests.

:type event_emitter: :py:class:`~botocore.hooks.BaseEventHooks`
:param event_emitter: Extension mechanism to fire events.
Nc                 ó‚   • X l         X0l        X@l        XPl        Xpl        Xl        [        R                  " U5      U l        g ©N)	Ú_region_nameÚ_signing_nameÚ_signature_versionÚ_credentialsÚ_auth_tokenÚ_service_idÚweakrefÚproxyÚ_event_emitter)ÚselfÚ
service_idÚregion_nameÚsigning_nameÚsignature_versionÚcredentialsÚevent_emitterÚ
auth_tokens           ÚM/home/mande/repo/quber/.venv/lib/python3.13/site-packages/botocore/signers.pyÚ__init__ÚRequestSigner.__init__G   s;   € ð (ÔØ)ÔØ"3ÔØ'ÔØ%ÔØ%Ôô &Ÿmšm¨MÓ:ˆÕó    c                 ó   • U R                   $ r   )r   ©r   s    r%   r   ÚRequestSigner.region_name[   s   € à× Ñ Ð r(   c                 ó   • U R                   $ r   )r   r*   s    r%   r!   ÚRequestSigner.signature_version_   s   € à×&Ñ&Ð&r(   c                 ó   • U R                   $ r   )r   r*   s    r%   r    ÚRequestSigner.signing_namec   s   € à×!Ñ!Ð!r(   c                 ó$   • U R                  X5      $ r   )Úsign)r   Úoperation_nameÚrequestÚkwargss       r%   ÚhandlerÚRequestSigner.handlerg   s   € ð
 �y‰y˜Ó1Ð1r(   c           
      ó,  • UnUc  U R                   nUc  U R                  nU R                  XUR                  5      nU R                  R                  SU R                  R                  5        SU 3UUU R                   UU US9  U[        R                  :w  aÚ  UUUS.n	Ub  XYS'   UR                  R                  S0 5      n
U(       d  U
R                  S5      (       a  U
S   U	S	'   U
R                  S
5      (       a  U
S
   U	S
'   U
R                  S5      (       a  U
S   U	S'   U
R                  S5      b  U R                  U	U
S   U
S   5         U R                  " S0 U	D6nUR                  U5        gg! [         a  nUS:w  a	  [        US9eUeSnAff = f)a¤  Sign a request before it goes out over the wire.

:type operation_name: string
:param operation_name: The name of the current operation, e.g.
                       ``ListBuckets``.
:type request: AWSRequest
:param request: The request object to be sent over the wire.

:type region_name: str
:param region_name: The region to sign the request for.

:type signing_type: str
:param signing_type: The type of signing to perform. This can be one of
    three possible values:

    * 'standard'     - This should be used for most requests.
    * 'presign-url'  - This should be used when pre-signing a request.
    * 'presign-post' - This should be used when pre-signing an S3 post.

:type expires_in: int
:param expires_in: The number of seconds the presigned url is valid
    for. This parameter is only valid for signing type 'presign-url'.

:type signing_name: str
:param signing_name: The name to use for the service when signing.
Nzbefore-sign.Ú.)r3   r    r   r!   Úrequest_signerr2   )r    r   r!   ÚexpiresÚsigningÚregionr   r    Úrequest_credentialsÚidentity_cacheÚ	cache_keyÚstandard©r!   © )r   r   Ú_choose_signerÚcontextr   Úemitr   Ú	hyphenizeÚbotocoreÚUNSIGNEDÚgetÚ_resolve_identity_cacheÚget_auth_instancer	   r
   Úadd_auth)r   r2   r3   r   Úsigning_typeÚ
expires_inr    Úexplicit_region_namer!   r4   Úsigning_contextÚauthÚes                r%   r1   ÚRequestSigner.signn   sÛ  € ðF  +ÐØÑØ×+Ñ+ˆKàÑØ×-Ñ-ˆLà ×/Ñ/Ø¨'¯/©/ó
Ðð
 	×Ñ× Ñ Ø˜4×+Ñ+×5Ñ5Ó7Ð8¸¸.Ð9IÐJØØ%Ø×)Ñ)Ø/ØØ)ð 	!ñ 	
ð ¤× 1Ñ 1Ó1à ,Ø*Ø%6ñˆFð
 Ñ%Ø$.�yÑ!Ø%Ÿo™o×1Ñ1°)¸RÓ@ˆOÞ'¨O×,?Ñ,?À×,IÑ,IØ(7¸Ñ(A��}Ñ%Ø×"Ñ" >×2Ñ2Ø)8¸Ñ)H��~Ñ&Ø×"Ñ"Ð#8×9Ñ9Ø0?Ø)ñ1�Ð,Ñ-ð ×"Ñ"Ð#3Ó4Ñ@Ø×,Ñ,ØØ#Ð$4Ñ5Ø# KÑ0ôð
Ø×-Ò-Ñ7°Ñ7�ð �M‰M˜'Õ"ðC 2øô2 0ó Ø :Ó-Ü:Ø*;ñð ð �Gûðús   ÅE3 Å3
FÅ=FÆFc                 ó   • X!S'   X1S'   g )Nr>   r?   rB   )r   r4   Úcacher?   s       r%   rJ   Ú%RequestSigner._resolve_identity_cacheÊ   s   € Ø#(ÐÑ Ø'ˆ{Òr(   c                 óH  • SSS.nUR                  US5      nUR                  S5      =(       d    U R                  nUR                  S0 5      nUR                  SU R                  5      nUR                  SU R                  5      n	U[        R
                  La  UR                  U5      (       d  Xe-  nU R                  R                  S	U R                  R                  5        S
U 3UU	UUS9u  p«Ub/  UnU[        R
                  La  UR                  U5      (       d  Xe-  nU$ )a1  
Allow setting the signature version via the choose-signer event.
A value of `botocore.UNSIGNED` means no signing will be performed.

:param operation_name: The operation to sign.
:param signing_type: The type of signing that the signer is to be used
    for.
:return: The signature version to sign with.
z-presign-postz-query)úpresign-postúpresign-urlÚ Ú	auth_typer;   r    r<   zchoose-signer.r8   )r    r   r!   rD   )rI   r   r   r   rG   rH   Úendswithr   Úemit_until_responser   rF   )r   r2   rM   rD   Úsigning_type_suffix_mapÚsuffixr!   r;   r    r   r5   Úresponses               r%   rC   ÚRequestSigner._choose_signerÎ   s0  € ð ,Ø#ñ#
Ðð )×,Ñ,¨\¸2Ó>ˆð $ŸK™K¨Ó4×O¸×8OÑ8OÐØ—+‘+˜i¨Ó,ˆØ—{‘{ >°4×3EÑ3EÓFˆØ—k‘k (¨D×,=Ñ,=Ó>ˆà¤X×%6Ñ%6Ò6Ø%×.Ñ.¨v×6Ñ6àÑ'Ðà ×/Ñ/×CÑCØ˜T×-Ñ-×7Ñ7Ó9Ð:¸!¸NÐ;KÐLØ%Ø#Ø/Øð Dð 
Ñˆð ÑØ (Ðð "¬×):Ñ):Ò:Ø)×2Ñ2°6×:Ñ:à!Ñ+Ð!à Ð r(   c                 ó¾  • Uc  U R                   n[        R                  R                  R	                  U5      nUc	  [        US9eUR                  SL aa  U R                  (       a:  [        U R                  [        5      (       d  U R                  R                  5       nOU R                  nU" U5      nU$ U=(       d    U R                  n	[        USS5      SL a  US   n
US   nU
R                  U5      n	US	 SnU	b  U	R                  5       nXÅS'   UR                  (       a3  U R                   c  [        R"                  R%                  5       eX%S'   XS	'   U" S
0 UD6nU$ )aA  
Get an auth instance which can be used to sign a request
using the given signature version.

:type signing_name: string
:param signing_name: Service signing name. This is usually the
                     same as the service name, but can differ. E.g.
                     ``emr`` vs. ``elasticmapreduce``.

:type region_name: string
:param region_name: Name of the service region, e.g. ``us-east-1``

:type signature_version: string
:param signature_version: Signature name like ``v4``.

:rtype: :py:class:`~botocore.auth.BaseSigner`
:return: Auth instance to sign a request.
NrA   TÚREQUIRES_IDENTITY_CACHEr>   r?   r"   r   Úservice_namerB   )r   rG   rQ   ÚAUTH_TYPE_MAPSrI   r	   ÚREQUIRES_TOKENr   Ú
isinstancer   Úget_frozen_tokenr   ÚgetattrÚget_credentialsÚget_frozen_credentialsÚREQUIRES_REGIONr   Ú
exceptionsÚNoRegionError)r   r    r   r!   r=   r4   ÚclsÚfrozen_tokenrQ   r"   rU   ÚkeyÚfrozen_credentialss                r%   rK   ÚRequestSigner.get_auth_instanceþ   sd  € ð4 Ñ$Ø $× 7Ñ 7Ðä�m‰m×*Ñ*×.Ñ.Ð/@ÓAˆØ‰;Ü.Ø"3ñð ð ×Ñ Ò%Ø××¬
Ø× Ñ ¤/÷)ñ )ð  $×/Ñ/×@Ñ@ÓB‘à#×/Ñ/�Ù�|Ó$ˆDØˆKà)×>¨T×->Ñ->ˆÜ�3Ð1°4Ó8¸DÒ@ØÐ+Ñ,ˆEØ˜Ñ%ˆCØ×/Ñ/°Ó4ˆKØ�{Ð#ð "ÐØÑ"Ø!,×!CÑ!CÓ!EÐØ 2ˆ}ÑØ××Ø× Ñ Ñ(Ü×)Ñ)×7Ñ7Ó9Ð9Ø$/�=Ñ!Ø%1�>Ñ"Ù‰}�V‰}ˆØˆr(   c                 ó|   • [        U5      nU R                  UUUSUU5        UR                  5         UR                  $ )a]  Generates a presigned url

:type request_dict: dict
:param request_dict: The prepared request dictionary returned by
    ``botocore.awsrequest.prepare_request_dict()``

:type operation_name: str
:param operation_name: The operation being signed.

:type expires_in: int
:param expires_in: The number of seconds the presigned url is valid
    for. By default it expires in an hour (3600 seconds)

:type region_name: string
:param region_name: The region name to sign the presigned url.

:type signing_name: str
:param signing_name: The name to use for the service when signing.

:returns: The presigned url
rY   )r   r1   ÚprepareÚurl)r   Úrequest_dictr2   rN   r   r    r3   s          r%   Úgenerate_presigned_urlÚ$RequestSigner.generate_presigned_urlE  sB   € ô: (¨Ó5ˆØ�	‰	ØØØØØØô	
ð 	�‰ÔØ�{‰{Ðr(   )r   r   r   r   r   r   r   r   ©NN)Nr@   NN)é  NN)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r&   Úpropertyr   r!   r    r5   r1   rJ   rC   rK   Úget_authrx   Ú__static_attributes__rB   r(   r%   r   r   $   s™   † ñ ðT ô;ð( ñ!ó ð!ð ñ'ó ð'ð ñ"ó ð"ô2ð ØØØôZ#òx(ò.!ðh Ø ôBðJ !€Hð ØØ÷(r(   r   c                   ó@   • \ rS rSrSrS rS
S jrS r S
S jrS r	S	r
g)ÚCloudFrontSignerip  a¤  A signer to create a signed CloudFront URL.

First you create a cloudfront signer based on a normalized RSA signer::

    import rsa
    def rsa_signer(message):
        private_key = open('private_key.pem', 'r').read()
        return rsa.sign(
            message,
            rsa.PrivateKey.load_pkcs1(private_key.encode('utf8')),
            'SHA-1')  # CloudFront requires SHA-1 hash
    cf_signer = CloudFrontSigner(key_id, rsa_signer)

To sign with a canned policy::

    signed_url = cf_signer.generate_signed_url(
        url, date_less_than=datetime(2015, 12, 1))

To sign with a custom policy::

    signed_url = cf_signer.generate_signed_url(url, policy=my_policy)
c                 ó   • Xl         X l        g)aV  Create a CloudFrontSigner.

:type key_id: str
:param key_id: The CloudFront Key Pair ID

:type rsa_signer: callable
:param rsa_signer: An RSA signer.
       Its only input parameter will be the message to be signed,
       and its output will be the signed content as a binary string.
       The hash algorithm needed by CloudFront is SHA-1.
N©Úkey_idÚ
rsa_signer)r   rˆ   r‰   s      r%   r&   ÚCloudFrontSigner.__init__ˆ  s   € ð ŒØ$�r(   Nc                 ó.  • USL=(       a    USLnUSL =(       a    USL nU(       d  U(       a  Sn[        U5      eUb  U R                  X5      n[        U[        5      (       a  UR	                  S5      nUb  S[        [        U5      5       3/nO$SU R                  U5      R                  S5       3/nU R                  U5      nUR                  SU R                  U5      R                  S5       3SU R                   3/5        U R                  X5      $ )a\  Creates a signed CloudFront URL based on given parameters.

:type url: str
:param url: The URL of the protected object

:type date_less_than: datetime
:param date_less_than: The URL will expire after that date and time

:type policy: str
:param policy: The custom policy, possibly built by self.build_policy()

:rtype: str
:return: The signed URL.
Nz=Need to provide either date_less_than or policy, but not bothÚutf8zExpires=zPolicy=z
Signature=zKey-Pair-Id=)Ú
ValueErrorÚbuild_policyrg   ÚstrÚencodeÚintr   Ú_url_b64encodeÚdecoder‰   Úextendrˆ   Ú
_build_url)	r   rv   Údate_less_thanÚpolicyÚboth_args_suppliedÚneither_arg_suppliedrR   ÚparamsÚ	signatures	            r%   rx   Ú'CloudFrontSigner.generate_presigned_url—  s  € ð ,°4Ð7×N¸FÈ$Ð<NÐØ-°Ð5×H¸&ÀD¸.ÐÞÖ!5ØOˆAÜ˜Q“-ÐØÑ%à×&Ñ& sÓ;ˆFÜ�fœc×"Ñ"Ø—]‘] 6Ó*ˆFØÑ%Ø ¤Ô%7¸Ó%GÓ!HÐ IÐJÐK‰Fà × 3Ñ 3°FÓ ;× BÑ BÀ6Ó JÐKÐLÐMˆFØ—O‘O FÓ+ˆ	Ø�‰à˜T×0Ñ0°Ó;×BÑBÀ6ÓJÐKÐLØ˜tŸ{™{˜mÐ,ðô	
ð �‰˜sÓ+Ð+r(   c                 óB   • SU;   a  SOSnX-   SR                  U5      -   $ )NÚ?Ú&)Újoin)r   Úbase_urlÚextra_paramsÚ	separators       r%   r•   ÚCloudFrontSigner._build_url½  s&   € Ø (›?‘C°ˆ	ØÑ# c§h¡h¨|Ó&<Ñ<Ð<r(   c                 ó  • [        [        U5      5      n[        SSU005      nU(       a  SU;  a  US-  nSU0US'   U(       a  [        [        U5      5      nSU0US'   SU4S	U4/nS
[        U5      /0n[        R                  " USS9$ )aØ  A helper to build policy.

:type resource: str
:param resource: The URL or the stream filename of the protected object

:type date_less_than: datetime
:param date_less_than: The URL will expire after the time has passed

:type date_greater_than: datetime
:param date_greater_than: The URL will not be valid until this time

:type ip_address: str
:param ip_address: Use 'x.x.x.x' for an IP, or 'x.x.x.x/x' for a subnet

:rtype: str
:return: The policy in a compact string.
ÚDateLessThanzAWS:EpochTimeÚ/z/32zAWS:SourceIpÚ	IpAddressÚDateGreaterThanÚResourceÚ	ConditionÚ	Statement)Ú,Ú:)Ú
separators)r‘   r   r   ÚjsonÚdumps)	r   Úresourcer–   Údate_greater_thanÚ
ip_addressÚmomentÚ	conditionÚordered_payloadÚcustom_policys	            r%   rŽ   ÚCloudFrontSigner.build_policyÁ  s§   € ô: Ô'¨Ó7Ó8ˆÜ °/À6Ð1JÐ KÓLˆ	ÞØ˜*Ó$Ø˜eÑ#�
Ø&4°jÐ%AˆI�kÑ"ÞÜÔ+Ð,=Ó>Ó?ˆFØ,;¸VÐ+DˆIÐ'Ñ(Ø&¨Ð1°KÀÐ3KÐLˆØ$¤{°?Ó'CÐ&DÐEˆÜ�zŠz˜-°JÑ?Ð?r(   c                 óŽ   • [         R                  " U5      R                  SS5      R                  SS5      R                  SS5      $ )Nó   +ó   -ó   =ó   _ó   /ó   ~)Úbase64Ú	b64encodeÚreplace)r   Údatas     r%   r’   ÚCloudFrontSigner._url_b64encodeë  s;   € ô ×Ò˜TÓ"ß‰W�T˜4Ó ß‰W�T˜4Ó ß‰W�T˜4Ó ð		
r(   r‡   rz   )r|   r}   r~   r   r€   r&   rx   r•   rŽ   r’   rƒ   rB   r(   r%   r…   r…   p  s*   † ñò.%ô$,òL=ð
 LPô(@õT
r(   r…   c                 ó   • [         U S'   g )NÚgenerate_db_auth_token)rÇ   ©Úclass_attributesr4   s     r%   Úadd_generate_db_auth_tokenrÊ   ö  ó   € Ü1GÐÐ-Ò.r(   c                 ó(   • [         U S'   [        U S'   g )NÚgenerate_db_connect_auth_tokenÚ$generate_db_connect_admin_auth_token)Ú#dsql_generate_db_connect_auth_tokenÚ)dsql_generate_db_connect_admin_auth_tokenrÈ   s     r%   Ú'add_dsql_generate_db_auth_token_methodsrÑ   ú  s    € ä+ð Ð5Ñ6ô 	2ð Ð;Ò<r(   c                 óÔ   • UnUc  U R                   R                  nSUS.nSS0 USS.nSnU U S	U 3n	[        Xy5        U R                  R	                  SUUS
SS9n
U
[        U5      S $ )aÙ  Generates an auth token used to connect to a db with IAM credentials.

:type DBHostname: str
:param DBHostname: The hostname of the database to connect to.

:type Port: int
:param Port: The port number the database is listening on.

:type DBUsername: str
:param DBUsername: The username to log in as.

:type Region: str
:param Region: The region the database is in. If None, the client
    region will be used.

:return: A presigned url which can be used as an auth token.
NÚconnect)ÚActionÚDBUserr§   rZ   ÚGET©Úurl_pathÚquery_stringÚheadersÚbodyÚmethodúhttps://r®   é„  zrds-db©r2   rw   r   rN   r    )Úmetar   r   Ú_request_signerrx   Úlen)r   Ú
DBHostnameÚPortÚ
DBUsernameÚRegionr<   rš   rw   ÚschemeÚendpoint_urlÚpresigned_urls              r%   rÇ   rÇ     s¥   € ð$ €FØ�~Ø—‘×&Ñ&ˆð Øñ€Fð ØØØØñ€Lð €FØ�X˜j˜\¨¨4¨&Ð1€LÜ˜Ô4Ø×(Ñ(×?Ñ?Ø Ø!ØØØð @ð €Mð œ˜V›˜Ð'Ð'r(   c                 ó  • SnX%;  a  [        SU SSR                  U5       3S9eUc  U R                  R                  nSS0 S	U0S
S.nSnU U 3n[	        Xh5        U R
                  R                  UUUUSS9n	U	[        U5      S $ )aþ  Generate a DSQL database token for an arbitrary action.

:type Hostname: str
:param Hostname: The DSQL endpoint host name.

:type Action: str
:param Action: Action to perform on the cluster (DbConnectAdmin or DbConnect).

:type Region: str
:param Region: The AWS region where the DSQL Cluster is hosted. If None, the client region will be used.

:type ExpiresIn: int
:param ExpiresIn: The token expiry duration in seconds (default is 900 seconds).

:return: A presigned url which can be used as an auth token.
)Ú	DbConnectÚDbConnectAdminz	Received z! for action but expected one of: z, )ÚreportNr§   rZ   rÔ   rÖ   r×   rÝ   Údsqlrß   )r   r    rà   r   r   rá   rx   râ   )
r   ÚHostnamerÔ   ræ   Ú	ExpiresInÚpossible_actionsrw   rç   rè   ré   s
             r%   Ú_dsql_generate_db_auth_tokenrò   9  sË   € ð& 7ÐàÓ%Ü"Ø˜v˜hÐ&GÈÏ	É	ÐRbÓHcÐGdÐeñ
ð 	
ð �~Ø—‘×&Ñ&ˆð ØØà�fð
ð ñ€Lð €FØ�X˜h˜ZÐ(€LÜ˜Ô4Ø×(Ñ(×?Ñ?ØØ!ØØØð @ð €Mð œ˜V›˜Ð'Ð'r(   c                 ó   • [        XSX#5      $ )aŸ  Generate a DSQL database token for the "DbConnect" action.

:type Hostname: str
:param Hostname: The DSQL endpoint host name.

:type Region: str
:param Region: The AWS region where the DSQL Cluster is hosted. If None, the client region will be used.

:type ExpiresIn: int
:param ExpiresIn: The token expiry duration in seconds (default is 900 seconds).

:return: A presigned url which can be used as an auth token.
rë   ©rò   ©r   rï   ræ   rð   s       r%   rÏ   rÏ   l  s   € ô  (Ø˜ Vóð r(   c                 ó   • [        XSX#5      $ )a¤  Generate a DSQL database token for the "DbConnectAdmin" action.

:type Hostname: str
:param Hostname: The DSQL endpoint host name.

:type Region: str
:param Region: The AWS region where the DSQL Cluster is hosted. If None, the client region will be used.

:type ExpiresIn: int
:param ExpiresIn: The token expiry duration in seconds (default is 900 seconds).

:return: A presigned url which can be used as an auth token.
rì   rô   rõ   s       r%   rÐ   rÐ   �  s   € ô  (ØÐ(¨&óð r(   c                   ó,   • \ rS rSrS r    SS jrSrg)ÚS3PostPresigneri–  c                 ó   • Xl         g r   ©rá   )r   r9   s     r%   r&   ÚS3PostPresigner.__init__—  s   € Ø-Õr(   Nc                 óž  • Uc  0 nUc  / n0 n[        5       nU[        R                  " US9-   nUR                  [        R
                  R                  5      US'   / US'   U H  n	US   R                  U	5        M     [        U5      n
X*R                  S'   XjR                  S'   U R                  R                  SX¥S5        U
R                  US.$ )	ae  Generates the url and the form fields used for a presigned s3 post

:type request_dict: dict
:param request_dict: The prepared request dictionary returned by
    ``botocore.awsrequest.prepare_request_dict()``

:type fields: dict
:param fields: A dictionary of prefilled form fields to build on top
    of.

:type conditions: list
:param conditions: A list of conditions to include in the policy. Each
    element can be either a list or a structure. For example:

    .. code:: python

        [
            {"acl": "public-read"},
            {"bucket": "amzn-s3-demo-bucket"},
            ["starts-with", "$key", "mykey"]
        ]

:type expires_in: int
:param expires_in: The number of seconds the presigned post is valid
    for.

:type region_name: string
:param region_name: The region name to sign the presigned post to.

:rtype: dict
:returns: A dictionary with two elements: ``url`` and ``fields``.
    Url is the url to post to. Fields is a dictionary filled with
    the form fields and respective values to use when submitting the
    post. For example:

    .. code:: python

        {
            'url': 'https://amzn-s3-demo-bucket.s3.amazonaws.com',
            'fields': {
                'acl': 'public-read',
                'key': 'mykey',
                'signature': 'mysignature',
                'policy': 'mybase64 encoded policy'
            }
        }
)ÚsecondsÚ
expirationÚ
conditionszs3-presign-post-fieldszs3-presign-post-policyÚ	PutObjectrX   )rv   Úfields)r   ÚdatetimeÚ	timedeltaÚstrftimerG   rQ   ÚISO8601Úappendr   rD   rá   r1   rv   )r   rw   r  rÿ   rN   r   r—   Údatetime_nowÚexpire_dater¶   r3   s              r%   Úgenerate_presigned_postÚ'S3PostPresigner.generate_presigned_postš  sÚ   € ðn ‰>ØˆFàÑØˆJð ˆô ,Ó-ˆØ"¤X×%7Ò%7À
Ñ%KÑKˆØ*×3Ñ3´H·M±M×4IÑ4IÓJˆˆ|Ñð  "ˆˆ|ÑÛ#ˆIØ�<Ñ ×'Ñ'¨	Ö2ñ $ô (¨Ó5ˆØ4:�‰Ð0Ñ1Ø4:�‰Ð0Ñ1à×Ñ×!Ñ!Ø˜¨~ô	
ð —{‘{¨fÑ5Ð5r(   rú   )NNr{   N)r|   r}   r~   r   r&   r	  rƒ   rB   r(   r%   rø   rø   –  s   † ò.ð ØØØ÷S6r(   rø   c                 ó   • [         U S'   g )Nrx   )rx   rÈ   s     r%   Úadd_generate_presigned_urlr  ð  rË   r(   c           	      óæ  • UnUnUc  0 nUnUnS[        U 5      S.n	U R                  n
 U R                  U   nU R
                  R                  R                  U5      nU R                  UUU	S9n[        R                  " UR                  SS5      5      nU R                  UUU	U(       + S9u  nnnU R                  UUUU	USS	9nUb  UUS
'   U
R                  UUUS9$ ! [         a
    [	        US9ef = f)aõ  Generate a presigned url given a client, its method, and arguments

.. warning::

    For backwards compatibility, S3 presigned URLs use Signature
    Version 2 by default in regions where S3 supports it. As a result,
    some ``Params`` entries are not signed. Some headers, including the
    conditionals and ``Range``, are also silently dropped.

    It is recommended to configure the S3 client with Signature
    Version 4 by setting ``signature_version='s3v4'`` in the client's
    ``Config``.

:type ClientMethod: string
:param ClientMethod: The client method to presign for

:type Params: dict
:param Params: The parameters normally passed to
    ``ClientMethod``.

:type ExpiresIn: int
:param ExpiresIn: The number of seconds the presigned url is valid
    for. By default it expires in an hour (3600 seconds)

:type HttpMethod: string
:param HttpMethod: The http method to use on the generated url. By
    default, the http method is whatever is used in the method's model.

:returns: The presigned url
T©Úis_presign_requestÚuse_global_endpoint)Úmethod_name©Ú
api_paramsÚoperation_modelrD   ÚBucketrZ   ©Úignore_signing_regionF©r  r  rè   rD   rÚ   Úset_user_agent_headerrÜ   )rw   rN   r2   )Ú_should_use_global_endpointrá   Ú_PY_TO_OP_NAMEÚKeyErrorr   rà   Úservice_modelr  Ú_emit_api_paramsr   Úis_arnrI   Ú_resolve_endpoint_rulesetÚ_convert_to_request_dictrx   )r   ÚClientMethodÚParamsrð   Ú
HttpMethodÚclient_methodrš   rN   Úhttp_methodrD   r9   r2   r  Úbucket_is_arnrè   Úadditional_headersÚ
propertiesrw   s                     r%   rx   rx   ô  s^  € ðB !€MØ€FØ�~ØˆØ€JØ€Kà"Ü:¸4Ó@ñ€Gð
 ×)Ñ)€NðBØ×,Ñ,¨]Ñ;ˆð —i‘i×-Ñ-×=Ñ=¸nÓM€OØ×"Ñ"ØØ'Øð #ð €Fô
 ×$Ò$ V§Z¡Z°¸"Ó%=Ó>€Mð
 	×&Ñ&ØØØØ#0Ô0ð	 	'ð 	ñ	ØØØð ×0Ñ0ØØ'Ø!ØØ"Ø#ð 1ð €Lð ÑØ!,ˆ�XÑð ×0Ñ0Ø!ØØ%ð 1ð ð øôG ó BÜ&°=ÑAÐAðBús   ©C ÃC0c                 ó   • [         U S'   g )Nr	  )r	  rÈ   s     r%   Úadd_generate_presigned_postr+  N  s   € Ü2IÐÐ.Ò/r(   c           	      ó”  • UnUnUnUn	Un
Uc  0 nOUR                  5       nU	c  / n	S[        U 5      S.n[        U R                  5      nU R                  R
                  R                  S5      nU R                  SU0UUS9n[        R                  " UR                  SS5      5      nU R                  UUUU(       + S9u  nnnU R                  UUUUUS	S
9nU	R                  SU05        UR                  S5      (       a"  U	R                  SSUS[        S5      *  /5        OU	R                  SU05        XxS'   UR!                  UUU	U
S9$ )a›	  Builds the url and the form fields used for a presigned s3 post

:type Bucket: string
:param Bucket: The name of the bucket to presign the post to. Note that
    bucket related conditions should not be included in the
    ``conditions`` parameter.

:type Key: string
:param Key: Key name, optionally add ${filename} to the end to
    attach the submitted filename. Note that key related conditions and
    fields are filled out for you and should not be included in the
    ``Fields`` or ``Conditions`` parameter.

:type Fields: dict
:param Fields: A dictionary of prefilled form fields to build on top
    of. Elements that may be included are acl, Cache-Control,
    Content-Type, Content-Disposition, Content-Encoding, Expires,
    success_action_redirect, redirect, success_action_status,
    and x-amz-meta-.

    Note that if a particular element is included in the fields
    dictionary it will not be automatically added to the conditions
    list. You must specify a condition for the element as well.

:type Conditions: list
:param Conditions: A list of conditions to include in the policy. Each
    element can be either a list or a structure. For example:

    .. code:: python

        [
            {"acl": "public-read"},
            ["content-length-range", 2, 5],
            ["starts-with", "$success_action_redirect", ""]
        ]

    Conditions that are included may pertain to acl,
    content-length-range, Cache-Control, Content-Type,
    Content-Disposition, Content-Encoding, Expires,
    success_action_redirect, redirect, success_action_status,
    and/or x-amz-meta-.

    Note that if you include a condition, you must specify
    a valid value in the fields dictionary as well. A value will
    not be added automatically to the fields dictionary based on the
    conditions.

:type ExpiresIn: int
:param ExpiresIn: The number of seconds the presigned post
    is valid for.

:rtype: dict
:returns: A dictionary with two elements: ``url`` and ``fields``.
    Url is the url to post to. Fields is a dictionary filled with
    the form fields and respective values to use when submitting the
    post. For example:

    .. code:: python

        {
            'url': 'https://amzn-s3-demo-bucket.s3.amazonaws.com',
            'fields': {
                'acl': 'public-read',
                'key': 'mykey',
                'signature': 'mysignature',
                'policy': 'mybase64 encoded policy'
            }
        }
NTr  ÚCreateBucketr  r  rZ   r  Fr  Úbucketz${filename}zstarts-withz$keyrq   )rw   r  rÿ   rN   )Úcopyr  rø   rá   rà   r  r  r  r   r  rI   r   r!  r  r\   râ   r	  )r   r  ÚKeyÚFieldsÚ
Conditionsrð   r.  rq   r  rÿ   rN   rD   Úpost_presignerr  rš   r'  rè   r(  r)  rw   s                       r%   r	  r	  R  s¥  € ðP €FØ
€CØ€FØ€JØ€Jà�~Ø‰à—‘“ˆàÑØˆ
ð #Ü:¸4Ó@ñ€Gô
 % T×%9Ñ%9Ó:€Nð —i‘i×-Ñ-×=Ñ=¸nÓM€OØ×"Ñ"Ø˜fÐ%Ø'Øð #ð €Fô
 ×$Ò$ V§Z¡Z°¸"Ó%=Ó>€Mð
 	×&Ñ&ØØØØ#0Ô0ð	 	'ð 	ñ	ØØØð ×0Ñ0ØØ'Ø!ØØ"Ø#ð 1ð €Lð ×Ñ�x Ð(Ô)ð ‡|�|�M×"Ñ"Ø×Ñ˜=¨&°#Ð6K¼¸]Ó9KÐ8KÐ2LÐMÕNà×Ñ˜5 #˜,Ô'ð ˆ5�Mà×1Ñ1Ø!ØØØð	 2ð ð r(   c                 óX  • U R                   R                  S:w  a  gU R                   R                  R                  nU(       ah  UR	                  SS5      (       a  gUR	                  S5      S:X  a%  U R                   R                  R
                  S:X  a  gUR	                  S5      S:X  a  gg	)
NÚawsFÚuse_dualstack_endpointÚus_east_1_regional_endpointÚregionalz	us-east-1Úaddressing_styleÚvirtualT)rà   Ú	partitionÚconfigÚs3rI   r   )ÚclientÚ	s3_configs     r%   r  r  á  s‰   € Ø‡{�{×Ñ Ó%ØØ—‘×"Ñ"×%Ñ%€IÞØ�=‰=Ð1°5×9Ñ9Øà�M‰MÐ7Ó8¸JÓFØ—‘×"Ñ"×.Ñ.°+Ó=àØ�=‰=Ð+Ó,°	Ó9ØØr(   r   )NrÞ   )Nr{   N)NNr{   )%rÁ   r  r°   r   rG   Úbotocore.authÚbotocore.awsrequestr   r   Úbotocore.compatr   r   Úbotocore.exceptionsr   r   r	   r
   Úbotocore.tokensr   Úbotocore.utilsr   r   r   r   r…   rÊ   rÑ   rÇ   rò   rÏ   rÐ   rø   r  rx   r+  r	  r  rB   r(   r%   Ú<module>rF     s¼   ðó Û Û Û ã Û ß Kß =÷ó õ ,÷ñ ÷Iñ I÷X
C
ñ C
òLHòô3(ðn 47ô0(ðh ,/ôð, ,/ô÷*W6ñ W6òtHð
 AEôWòtJð
 @DôLó^r(   