Ë
    £ªði×†  ã                   ó   — d dl Z d dlZd dlZd dlZd dlZd dlZd dlmZmZ d dl	m
Z
mZ d dlmZmZmZmZ d dlmZ d dlmZmZmZ  G d„ d«      Z G d	„ d
«      Zd„ Zd„ Zdd„Z	 dd„Z	 dd„Z	 dd„Z G d„ d«      Zd„ Z 	 dd„Z!d„ Z"	 dd„Z#d„ Z$y)é    N)Úcreate_request_objectÚprepare_request_dict)ÚOrderedDictÚget_current_datetime)ÚParamValidationErrorÚUnknownClientMethodErrorÚUnknownSignatureVersionErrorÚ UnsupportedSignatureVersionError)ÚFrozenAuthToken)Ú	ArnParserÚdatetime2timestampÚfix_s3_hostc                   óŒ   — e Zd ZdZ	 dd„Zed„ «       Zed„ «       Zed„ «       Zdd„Z		 	 	 	 dd„Z
d	„ Zd
„ Z	 	 dd„ZeZ	 	 	 dd„Zy)ÚRequestSignera0  
    An object to sign requests before they go out over the wire using
    one of the authentication mechanisms defined in ``auth.py``. This
    class fires two events scoped to a service and operation name:

    * choose-signer: Allows overriding the auth signer name.
    * before-sign: Allows mutating the request before signing.

    Together these events allow for customization of the request
    signing pipeline, including overrides, request path manipulation,
    and disabling signing per operation.


    :type service_id: botocore.model.ServiceId
    :param service_id: The service id for the service, e.g. ``S3``

    :type region_name: string
    :param region_name: Name of the service region, e.g. ``us-east-1``

    :type signing_name: string
    :param signing_name: Service signing name. This is usually the
                         same as the service name, but can differ. E.g.
                         ``emr`` vs. ``elasticmapreduce``.

    :type signature_version: string
    :param signature_version: Signature name like ``v4``.

    :type credentials: :py:class:`~botocore.credentials.Credentials`
    :param credentials: User credentials with which to sign requests.

    :type event_emitter: :py:class:`~botocore.hooks.BaseEventHooks`
    :param event_emitter: Extension mechanism to fire events.
    Nc                 óŒ   — || _         || _        || _        || _        || _        || _        t        j                  |«      | _        y ©N)	Ú_region_nameÚ_signing_nameÚ_signature_versionÚ_credentialsÚ_auth_tokenÚ_service_idÚweakrefÚproxyÚ_event_emitter)ÚselfÚ
service_idÚregion_nameÚsigning_nameÚsignature_versionÚcredentialsÚevent_emitterÚ
auth_tokens           úg/var/www/acinvestment.org/public_html/aci/backend/venv/lib/python3.12/site-packages/botocore/signers.pyÚ__init__zRequestSigner.__init__G   sG   € ð (ˆÔØ)ˆÔØ"3ˆÔØ'ˆÔØ%ˆÔØ%ˆÔô &Ÿm™m¨MÓ:ˆÕó    c                 ó   — | j                   S r   )r   ©r   s    r$   r   zRequestSigner.region_name[   s   € à× Ñ Ð r&   c                 ó   — | j                   S r   )r   r(   s    r$   r    zRequestSigner.signature_version_   s   € à×&Ñ&Ð&r&   c                 ó   — | j                   S r   )r   r(   s    r$   r   zRequestSigner.signing_namec   s   € à×!Ñ!Ð!r&   c                 ó&   — | j                  ||«      S r   )Úsign)r   Úoperation_nameÚrequestÚkwargss       r$   ÚhandlerzRequestSigner.handlerg   s   € ð
 �y‰y˜¨Ó1Ð1r&   c           	      ó  — |}|€| j                   }|€| j                  }| j                  |||j                  «      }| j                  j                  d| j                  j                  «       › d|› �||| j                   || |¬«       |t        j                  k7  rÅ|||dœ}	|�||	d<   |j                  j                  di «      }
|s|
j                  d«      r|
d   |	d	<   |
j                  d
«      r|
d
   |	d
<   |
j                  d«      r|
d   |	d<   |
j                  d«      �| j                  |	|
d   |
d   «       	  | j                  di |	¤Ž}|j                  |«       yy# t        $ r}|dk7  rt        |¬«      ‚|‚d}~ww xY w)a<  Sign a request before it goes out over the wire.

        :type operation_name: string
        :param operation_name: The name of the current operation, e.g.
                               ``ListBuckets``.
        :type request: AWSRequest
        :param request: The request object to be sent over the wire.

        :type region_name: str
        :param region_name: The region to sign the request for.

        :type signing_type: str
        :param signing_type: The type of signing to perform. This can be one of
            three possible values:

            * 'standard'     - This should be used for most requests.
            * 'presign-url'  - This should be used when pre-signing a request.
            * 'presign-post' - This should be used when pre-signing an S3 post.

        :type expires_in: int
        :param expires_in: The number of seconds the presigned url is valid
            for. This parameter is only valid for signing type 'presign-url'.

        :type signing_name: str
        :param signing_name: The name to use for the service when signing.
        Nzbefore-sign.ú.)r.   r   r   r    Úrequest_signerr-   )r   r   r    ÚexpiresÚsigningÚregionr   r   Úrequest_credentialsÚidentity_cacheÚ	cache_keyÚstandard©r    © )r   r   Ú_choose_signerÚcontextr   Úemitr   Ú	hyphenizeÚbotocoreÚUNSIGNEDÚgetÚ_resolve_identity_cacheÚget_auth_instancer	   r
   Úadd_auth)r   r-   r.   r   Úsigning_typeÚ
expires_inr   Úexplicit_region_namer    r/   Úsigning_contextÚauthÚes                r$   r,   zRequestSigner.signn   sØ  € ðF  +ÐØÐØ×+Ñ+ˆKàÐØ×-Ñ-ˆLà ×/Ñ/Ø˜L¨'¯/©/ó
Ðð
 	×Ñ× Ñ Ø˜4×+Ñ+×5Ñ5Ó7Ð8¸¸.Ð9IÐJØØ%Ø×)Ñ)Ø/ØØ)ð 	!ô 	
ð ¤× 1Ñ 1Ò1à ,Ø*Ø%6ñˆFð
 Ð%Ø$.��yÑ!Ø%Ÿo™o×1Ñ1°)¸RÓ@ˆOÙ'¨O×,?Ñ,?ÀÔ,IØ(7¸Ñ(A��}Ñ%Ø×"Ñ" >Ô2Ø)8¸Ñ)H��~Ñ&Ø×"Ñ"Ð#8Ô9Ø0?Ø)ñ1�Ð,Ñ-ð ×"Ñ"Ð#3Ó4Ð@Ø×,Ñ,ØØ#Ð$4Ñ5Ø# KÑ0ôð
Ø-�t×-Ñ-Ñ7°Ñ7�ð �M‰M˜'Õ"ðC 2øô2 0ò Ø :Ò-Ü:Ø*;ôð ð �Gûðús   Ä:E Å	F Å(E;Å;F c                 ó   — ||d<   ||d<   y )Nr8   r9   r<   )r   r/   Úcacher9   s       r$   rD   z%RequestSigner._resolve_identity_cacheÊ   s   € Ø#(ˆÐÑ Ø'ˆˆ{Òr&   c                 ó0  — dddœ}|j                  |d«      }|j                  d«      xs | j                  }|j                  di «      }|j                  d| j                  «      }|j                  d| j                  «      }	|t        j
                  ur|j                  |«      s||z  }| j                  j                  d	| j                  j                  «       › d
|› �||	||¬«      \  }
}|�*|}|t        j
                  ur|j                  |«      s||z  }|S )ai  
        Allow setting the signature version via the choose-signer event.
        A value of `botocore.UNSIGNED` means no signing will be performed.

        :param operation_name: The operation to sign.
        :param signing_type: The type of signing that the signer is to be used
            for.
        :return: The signature version to sign with.
        z-presign-postz-query)úpresign-postúpresign-urlÚ Ú	auth_typer5   r   r6   zchoose-signer.r2   )r   r   r    r>   )rC   r   r   r   rA   rB   Úendswithr   Úemit_until_responser   r@   )r   r-   rG   r>   Úsigning_type_suffix_mapÚsuffixr    r5   r   r   r0   Úresponses               r$   r=   zRequestSigner._choose_signerÎ   s0  € ð ,Ø#ñ#
Ðð )×,Ñ,¨\¸2Ó>ˆð $ŸK™K¨Ó4ÒO¸×8OÑ8OÐØ—+‘+˜i¨Ó,ˆØ—{‘{ >°4×3EÑ3EÓFˆØ—k‘k (¨D×,=Ñ,=Ó>ˆà¤X×%6Ñ%6Ñ6Ø%×.Ñ.¨vÔ6à Ñ'Ðà ×/Ñ/×CÑCØ˜T×-Ñ-×7Ñ7Ó9Ð:¸!¸NÐ;KÐLØ%Ø#Ø/Øð Dó 
Ñˆ�ð ÐØ (Ðð "¬×):Ñ):Ñ:Ø)×2Ñ2°6Ô:à! VÑ+Ð!à Ð r&   c                 ó–  — |€| j                   }t        j                  j                  j	                  |«      }|€t        |¬«      ‚|j                  du rW| j                  r5t        | j                  t        «      s| j                  j                  «       }n| j                  } ||«      }|S |xs | j                  }	t        |dd«      du r|d   }
|d   }|
j                  |«      }	|d= d}|	�|	j                  «       }||d<   |j                  r4| j                   €t        j"                  j%                  «       ‚||d<   ||d	<    |d
i |¤Ž}|S )a©  
        Get an auth instance which can be used to sign a request
        using the given signature version.

        :type signing_name: string
        :param signing_name: Service signing name. This is usually the
                             same as the service name, but can differ. E.g.
                             ``emr`` vs. ``elasticmapreduce``.

        :type region_name: string
        :param region_name: Name of the service region, e.g. ``us-east-1``

        :type signature_version: string
        :param signature_version: Signature name like ``v4``.

        :rtype: :py:class:`~botocore.auth.BaseSigner`
        :return: Auth instance to sign a request.
        Nr;   TÚREQUIRES_IDENTITY_CACHEr8   r9   r!   r   Úservice_namer<   )r   rA   rK   ÚAUTH_TYPE_MAPSrC   r	   ÚREQUIRES_TOKENr   Ú
isinstancer   Úget_frozen_tokenr   ÚgetattrÚget_credentialsÚget_frozen_credentialsÚREQUIRES_REGIONr   Ú
exceptionsÚNoRegionError)r   r   r   r    r7   r/   ÚclsÚfrozen_tokenrK   r!   rN   ÚkeyÚfrozen_credentialss                r$   rE   zRequestSigner.get_auth_instanceþ   se  € ð4 Ð$Ø $× 7Ñ 7Ðä�m‰m×*Ñ*×.Ñ.Ð/@ÓAˆØˆ;Ü.Ø"3ôð ð ×Ñ Ñ%Ø×Ò¬
Ø× Ñ ¤/ô)ð  $×/Ñ/×@Ñ@ÓB‘à#×/Ñ/�Ù�|Ó$ˆDØˆKà)Ò>¨T×->Ñ->ˆÜ�3Ð1°4Ó8¸DÑ@ØÐ+Ñ,ˆEØ˜Ñ%ˆCØ×/Ñ/°Ó4ˆKØ�{Ð#ð "ÐØÐ"Ø!,×!CÑ!CÓ!EÐØ 2ˆˆ}ÑØ×ÒØ× Ñ Ð(Ü×)Ñ)×7Ñ7Ó9Ð9Ø$/ˆF�=Ñ!Ø%1ˆF�>Ñ"Ù‰}�V‰}ˆØˆr&   c                 ó|   — t        |«      }| j                  |||d||«       |j                  «        |j                  S )aÍ  Generates a presigned url

        :type request_dict: dict
        :param request_dict: The prepared request dictionary returned by
            ``botocore.awsrequest.prepare_request_dict()``

        :type operation_name: str
        :param operation_name: The operation being signed.

        :type expires_in: int
        :param expires_in: The number of seconds the presigned url is valid
            for. By default it expires in an hour (3600 seconds)

        :type region_name: string
        :param region_name: The region name to sign the presigned url.

        :type signing_name: str
        :param signing_name: The name to use for the service when signing.

        :returns: The presigned url
        rQ   )r   r,   ÚprepareÚurl)r   Úrequest_dictr-   rH   r   r   r.   s          r$   Úgenerate_presigned_urlz$RequestSigner.generate_presigned_urlE  sB   € ô: (¨Ó5ˆØ�	‰	ØØØØØØô	
ð 	�‰ÔØ�{‰{Ðr&   r   ©NN)Nr:   NN)é  NN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r%   Úpropertyr   r    r   r0   r,   rD   r=   rE   Úget_authrn   r<   r&   r$   r   r   $   s™   „ ñ ðT ó;ð( ñ!ó ð!ð ñ'ó ð'ð ñ"ó ð"ó2ð ØØØóZ#òx(ò.!ðh Ø óBðJ !€Hð ØØô(r&   r   c                   ó4   — e Zd ZdZd„ Zdd„Zd„ Z	 dd„Zd„ Zy)	ÚCloudFrontSigneraà  A signer to create a signed CloudFront URL.

    First you create a cloudfront signer based on a normalized RSA signer::

        import rsa
        def rsa_signer(message):
            private_key = open('private_key.pem', 'r').read()
            return rsa.sign(
                message,
                rsa.PrivateKey.load_pkcs1(private_key.encode('utf8')),
                'SHA-1')  # CloudFront requires SHA-1 hash
        cf_signer = CloudFrontSigner(key_id, rsa_signer)

    To sign with a canned policy::

        signed_url = cf_signer.generate_signed_url(
            url, date_less_than=datetime(2015, 12, 1))

    To sign with a custom policy::

        signed_url = cf_signer.generate_signed_url(url, policy=my_policy)
    c                 ó    — || _         || _        y)a–  Create a CloudFrontSigner.

        :type key_id: str
        :param key_id: The CloudFront Key Pair ID

        :type rsa_signer: callable
        :param rsa_signer: An RSA signer.
               Its only input parameter will be the message to be signed,
               and its output will be the signed content as a binary string.
               The hash algorithm needed by CloudFront is SHA-1.
        N)Úkey_idÚ
rsa_signer)r   rz   r{   s      r$   r%   zCloudFrontSigner.__init__ˆ  s   € ð ˆŒØ$ˆ�r&   Nc                 óü  — |duxr |du}|du xr |du }|s|rd}t        |«      ‚|�| j                  ||«      }t        |t        «      r|j	                  d«      }|�dt        t        |«      «      › �g}n$d| j                  |«      j                  d«      › �g}| j                  |«      }|j                  d| j                  |«      j                  d«      › �d| j                  › �g«       | j                  ||«      S )a¤  Creates a signed CloudFront URL based on given parameters.

        :type url: str
        :param url: The URL of the protected object

        :type date_less_than: datetime
        :param date_less_than: The URL will expire after that date and time

        :type policy: str
        :param policy: The custom policy, possibly built by self.build_policy()

        :rtype: str
        :return: The signed URL.
        Nz=Need to provide either date_less_than or policy, but not bothÚutf8zExpires=zPolicy=z
Signature=zKey-Pair-Id=)Ú
ValueErrorÚbuild_policyr^   ÚstrÚencodeÚintr   Ú_url_b64encodeÚdecoder{   Úextendrz   Ú
_build_url)	r   rl   Údate_less_thanÚpolicyÚboth_args_suppliedÚneither_arg_suppliedrL   ÚparamsÚ	signatures	            r$   rn   z'CloudFrontSigner.generate_presigned_url—  s  € ð ,°4Ð7ÒN¸FÈ$Ð<NÐØ-°Ð5ÒH¸&ÀD¸.ÐÙÑ!5ØOˆAÜ˜Q“-ÐØÐ%à×&Ñ& s¨NÓ;ˆFÜ�fœcÔ"Ø—]‘] 6Ó*ˆFØÐ%Ø ¤Ô%7¸Ó%GÓ!HÐ IÐJÐK‰Fà × 3Ñ 3°FÓ ;× BÑ BÀ6Ó JÐKÐLÐMˆFØ—O‘O FÓ+ˆ	Ø�‰à˜T×0Ñ0°Ó;×BÑBÀ6ÓJÐKÐLØ˜tŸ{™{˜mÐ,ðô	
ð �‰˜s FÓ+Ð+r&   c                 ó@   — d|v rdnd}||z   dj                  |«      z   S )Nú?ú&)Újoin)r   Úbase_urlÚextra_paramsÚ	separators       r$   r†   zCloudFrontSigner._build_url½  s(   € Ø (™?‘C°ˆ	Ø˜)Ñ# c§h¡h¨|Ó&<Ñ<Ð<r&   c                 ó   — t        t        |«      «      }t        dd|ii«      }|rd|vr|dz  }d|i|d<   |rt        t        |«      «      }d|i|d<   d|fd	|fg}d
t        |«      gi}t        j                  |d¬«      S )a0  A helper to build policy.

        :type resource: str
        :param resource: The URL or the stream filename of the protected object

        :type date_less_than: datetime
        :param date_less_than: The URL will expire after the time has passed

        :type date_greater_than: datetime
        :param date_greater_than: The URL will not be valid until this time

        :type ip_address: str
        :param ip_address: Use 'x.x.x.x' for an IP, or 'x.x.x.x/x' for a subnet

        :rtype: str
        :return: The policy in a compact string.
        ÚDateLessThanzAWS:EpochTimeú/z/32zAWS:SourceIpÚ	IpAddressÚDateGreaterThanÚResourceÚ	ConditionÚ	Statement)ú,ú:)Ú
separators)r‚   r   r   ÚjsonÚdumps)	r   Úresourcer‡   Údate_greater_thanÚ
ip_addressÚmomentÚ	conditionÚordered_payloadÚcustom_policys	            r$   r   zCloudFrontSigner.build_policyÁ  s§   € ô: Ô'¨Ó7Ó8ˆÜ °/À6Ð1JÐ KÓLˆ	ÙØ˜*Ñ$Ø˜eÑ#�
Ø&4°jÐ%AˆI�kÑ"ÙÜÔ+Ð,=Ó>Ó?ˆFØ,;¸VÐ+DˆIÐ'Ñ(Ø&¨Ð1°KÀÐ3KÐLˆØ$¤{°?Ó'CÐ&DÐEˆÜ�z‰z˜-°JÔ?Ð?r&   c                 óŒ   — t        j                  |«      j                  dd«      j                  dd«      j                  dd«      S )Nó   +ó   -ó   =ó   _ó   /ó   ~)Úbase64Ú	b64encodeÚreplace)r   Údatas     r$   rƒ   zCloudFrontSigner._url_b64encodeë  s;   € ô ×Ñ˜TÓ"ß‰W�T˜4Ó ß‰W�T˜4Ó ß‰W�T˜4Ó ð		
r&   ro   )	rq   rr   rs   rt   r%   rn   r†   r   rƒ   r<   r&   r$   rx   rx   p  s*   „ ñò.%ó$,òL=ð
 LPó(@óT
r&   rx   c                 ó   — t         | d<   y )NÚgenerate_db_auth_token)r´   ©Úclass_attributesr/   s     r$   Úadd_generate_db_auth_tokenr·   ö  ó   € Ü1GÐÐ-Ò.r&   c                 ó(   — t         | d<   t        | d<   y )NÚgenerate_db_connect_auth_tokenÚ$generate_db_connect_admin_auth_token)Ú#dsql_generate_db_connect_auth_tokenÚ)dsql_generate_db_connect_admin_auth_tokenrµ   s     r$   Ú'add_dsql_generate_db_auth_token_methodsr¾   ú  s    € ä+ð Ð5Ñ6ô 	2ð Ð;Ò<r&   c                 óÚ   — |}|€| j                   j                  }d|dœ}ddi |ddœ}d}|› |› d	|› �}	t        ||	«       | j                  j	                  d||d
d¬«      }
|
t        |«      d S )a  Generates an auth token used to connect to a db with IAM credentials.

    :type DBHostname: str
    :param DBHostname: The hostname of the database to connect to.

    :type Port: int
    :param Port: The port number the database is listening on.

    :type DBUsername: str
    :param DBUsername: The username to log in as.

    :type Region: str
    :param Region: The region the database is in. If None, the client
        region will be used.

    :return: A presigned url which can be used as an auth token.
    NÚconnect)ÚActionÚDBUserr–   rR   ÚGET©Úurl_pathÚquery_stringÚheadersÚbodyÚmethodúhttps://r�   é„  zrds-db©r-   rm   r   rH   r   )Úmetar   r   Ú_request_signerrn   Úlen)r   Ú
DBHostnameÚPortÚ
DBUsernameÚRegionr6   r‹   rm   ÚschemeÚendpoint_urlÚpresigned_urls              r$   r´   r´     s§   € ð$ €FØ€~Ø—‘×&Ñ&ˆð Øñ€Fð ØØØØñ€Lð €FØ�X˜j˜\¨¨4¨&Ð1€LÜ˜ |Ô4Ø×(Ñ(×?Ñ?Ø Ø!ØØØð @ó €Mð œ˜V›˜Ð'Ð'r&   c                 ó  — d}||vr!t        d|› ddj                  |«      › �¬«      ‚|€| j                  j                  }ddi d	|id
dœ}d}|› |› �}t	        ||«       | j
                  j                  ||||d¬«      }	|	t        |«      d S )a&  Generate a DSQL database token for an arbitrary action.

    :type Hostname: str
    :param Hostname: The DSQL endpoint host name.

    :type Action: str
    :param Action: Action to perform on the cluster (DbConnectAdmin or DbConnect).

    :type Region: str
    :param Region: The AWS region where the DSQL Cluster is hosted. If None, the client region will be used.

    :type ExpiresIn: int
    :param ExpiresIn: The token expiry duration in seconds (default is 900 seconds).

    :return: A presigned url which can be used as an auth token.
    )Ú	DbConnectÚDbConnectAdminz	Received z! for action but expected one of: z, )ÚreportNr–   rR   rÁ   rÃ   rÄ   rÊ   ÚdsqlrÌ   )r   r�   rÍ   r   r   rÎ   rn   rÏ   )
r   ÚHostnamerÁ   rÓ   Ú	ExpiresInÚpossible_actionsrm   rÔ   rÕ   rÖ   s
             r$   Ú_dsql_generate_db_auth_tokenrß   9  sÐ   € ð& 7ÐàÐ%Ñ%Ü"Ø˜v˜hÐ&GÈÏ	É	ÐRbÓHcÐGdÐeô
ð 	
ð €~Ø—‘×&Ñ&ˆð ØØà�fð
ð ñ€Lð €FØ�X˜h˜ZÐ(€LÜ˜ |Ô4Ø×(Ñ(×?Ñ?ØØ!ØØØð @ó €Mð œ˜V›˜Ð'Ð'r&   c                 ó    — t        | |d||«      S )a¿  Generate a DSQL database token for the "DbConnect" action.

    :type Hostname: str
    :param Hostname: The DSQL endpoint host name.

    :type Region: str
    :param Region: The AWS region where the DSQL Cluster is hosted. If None, the client region will be used.

    :type ExpiresIn: int
    :param ExpiresIn: The token expiry duration in seconds (default is 900 seconds).

    :return: A presigned url which can be used as an auth token.
    rØ   ©rß   ©r   rÜ   rÓ   rÝ   s       r$   r¼   r¼   l  s   € ô  (Øˆh˜ V¨Yóð r&   c                 ó    — t        | |d||«      S )aÄ  Generate a DSQL database token for the "DbConnectAdmin" action.

    :type Hostname: str
    :param Hostname: The DSQL endpoint host name.

    :type Region: str
    :param Region: The AWS region where the DSQL Cluster is hosted. If None, the client region will be used.

    :type ExpiresIn: int
    :param ExpiresIn: The token expiry duration in seconds (default is 900 seconds).

    :return: A presigned url which can be used as an auth token.
    rÙ   rá   râ   s       r$   r½   r½   �  s   € ô  (ØˆhÐ(¨&°)óð r&   c                   ó"   — e Zd Zd„ Z	 	 	 	 dd„Zy)ÚS3PostPresignerc                 ó   — || _         y r   )rÎ   )r   r3   s     r$   r%   zS3PostPresigner.__init__—  s
   € Ø-ˆÕr&   Nc                 ó   — |€i }|€g }i }t        «       }|t        j                  |¬«      z   }|j                  t        j
                  j                  «      |d<   g |d<   |D ]  }	|d   j                  |	«       Œ t        |«      }
||
j                  d<   ||
j                  d<   | j                  j                  d|
|d«       |
j                  |dœS )	a…  Generates the url and the form fields used for a presigned s3 post

        :type request_dict: dict
        :param request_dict: The prepared request dictionary returned by
            ``botocore.awsrequest.prepare_request_dict()``

        :type fields: dict
        :param fields: A dictionary of prefilled form fields to build on top
            of.

        :type conditions: list
        :param conditions: A list of conditions to include in the policy. Each
            element can be either a list or a structure. For example:

            .. code:: python

                [
                    {"acl": "public-read"},
                    {"bucket": "amzn-s3-demo-bucket"},
                    ["starts-with", "$key", "mykey"]
                ]

        :type expires_in: int
        :param expires_in: The number of seconds the presigned post is valid
            for.

        :type region_name: string
        :param region_name: The region name to sign the presigned post to.

        :rtype: dict
        :returns: A dictionary with two elements: ``url`` and ``fields``.
            Url is the url to post to. Fields is a dictionary filled with
            the form fields and respective values to use when submitting the
            post. For example:

            .. code:: python

                {
                    'url': 'https://amzn-s3-demo-bucket.s3.amazonaws.com',
                    'fields': {
                        'acl': 'public-read',
                        'key': 'mykey',
                        'signature': 'mysignature',
                        'policy': 'mybase64 encoded policy'
                    }
                }
        )ÚsecondsÚ
expirationÚ
conditionszs3-presign-post-fieldszs3-presign-post-policyÚ	PutObjectrP   )rl   Úfields)r   ÚdatetimeÚ	timedeltaÚstrftimerA   rK   ÚISO8601Úappendr   r>   rÎ   r,   rl   )r   rm   rì   rê   rH   r   rˆ   Údatetime_nowÚexpire_dater¥   r.   s              r$   Úgenerate_presigned_postz'S3PostPresigner.generate_presigned_postš  så   € ðn ˆ>ØˆFàÐØˆJð ˆô ,Ó-ˆØ"¤X×%7Ñ%7À
Ô%KÑKˆØ*×3Ñ3´H·M±M×4IÑ4IÓJˆˆ|Ñð  "ˆˆ|ÑØ#ò 	3ˆIØ�<Ñ ×'Ñ'¨	Õ2ð	3ô (¨Ó5ˆØ4:ˆ�‰Ð0Ñ1Ø4:ˆ�‰Ð0Ñ1à×Ñ×!Ñ!Ø˜ +¨~ô	
ð —{‘{¨fÑ5Ð5r&   )NNrp   N)rq   rr   rs   r%   rô   r<   r&   r$   rå   rå   –  s   „ ò.ð ØØØôS6r&   rå   c                 ó   — t         | d<   y )Nrn   )rn   rµ   s     r$   Úadd_generate_presigned_urlrö   ð  r¸   r&   c                 óô  — |}|}|€i }|}|}dt        | «      dœ}	| j                  }
	 | j                  |   }| j
                  j                  j                  |«      }| j                  |||	¬«      }t        j                  |j                  dd«      «      }| j                  |||	| ¬«      \  }}}| j                  ||||	|d¬	«      }|�||d
<   |
j                  |||¬«      S # t        $ r t	        |¬«      ‚w xY w)ax  Generate a presigned url given a client, its method, and arguments

    :type ClientMethod: string
    :param ClientMethod: The client method to presign for

    :type Params: dict
    :param Params: The parameters normally passed to
        ``ClientMethod``.

    :type ExpiresIn: int
    :param ExpiresIn: The number of seconds the presigned url is valid
        for. By default it expires in an hour (3600 seconds)

    :type HttpMethod: string
    :param HttpMethod: The http method to use on the generated url. By
        default, the http method is whatever is used in the method's model.

    :returns: The presigned url
    T©Úis_presign_requestÚuse_global_endpoint)Úmethod_name©Ú
api_paramsÚoperation_modelr>   ÚBucketrR   ©Úignore_signing_regionF©rý   rþ   rÕ   r>   rÇ   Úset_user_agent_headerrÉ   )rm   rH   r-   )Ú_should_use_global_endpointrÎ   Ú_PY_TO_OP_NAMEÚKeyErrorr   rÍ   Úservice_modelrþ   Ú_emit_api_paramsr   Úis_arnrC   Ú_resolve_endpoint_rulesetÚ_convert_to_request_dictrn   )r   ÚClientMethodÚParamsrÝ   Ú
HttpMethodÚclient_methodr‹   rH   Úhttp_methodr>   r3   r-   rþ   Úbucket_is_arnrÕ   Úadditional_headersÚ
propertiesrm   s                     r$   rn   rn   ô  s]  € ð, !€MØ€FØ€~ØˆØ€JØ€Kà"Ü:¸4Ó@ñ€Gð
 ×)Ñ)€NðBØ×,Ñ,¨]Ñ;ˆð —i‘i×-Ñ-×=Ñ=¸nÓM€OØ×"Ñ"ØØ'Øð #ó €Fô
 ×$Ñ$ V§Z¡Z°¸"Ó%=Ó>€Mð
 	×&Ñ&ØØØØ#0Ð0ð	 	'ó 	ñ	ØØØð ×0Ñ0ØØ'Ø!ØØ"Ø#ð 1ó €Lð ÐØ!,ˆ�XÑð ×0Ñ0Ø!ØØ%ð 1ó ð øôG ò BÜ&°=ÔAÐAðBús   ¨C! Ã!C7c                 ó   — t         | d<   y )Nrô   )rô   rµ   s     r$   Úadd_generate_presigned_postr  C  s   € Ü2IÐÐ.Ò/r&   c           	      ó–  — |}|}|}|}	|}
|€i }n|j                  «       }|	€g }	dt        | «      dœ}t        | j                  «      }| j                  j
                  j                  d«      }| j                  d|i||¬«      }t        j                  |j                  dd«      «      }| j                  |||| ¬«      \  }}}| j                  |||||d	¬
«      }|	j                  d|i«       |j                  d«      r"|	j                  dd|dt        d«        g«       n|	j                  d|i«       ||d<   |j!                  |||	|
¬«      S )aw
  Builds the url and the form fields used for a presigned s3 post

    :type Bucket: string
    :param Bucket: The name of the bucket to presign the post to. Note that
        bucket related conditions should not be included in the
        ``conditions`` parameter.

    :type Key: string
    :param Key: Key name, optionally add ${filename} to the end to
        attach the submitted filename. Note that key related conditions and
        fields are filled out for you and should not be included in the
        ``Fields`` or ``Conditions`` parameter.

    :type Fields: dict
    :param Fields: A dictionary of prefilled form fields to build on top
        of. Elements that may be included are acl, Cache-Control,
        Content-Type, Content-Disposition, Content-Encoding, Expires,
        success_action_redirect, redirect, success_action_status,
        and x-amz-meta-.

        Note that if a particular element is included in the fields
        dictionary it will not be automatically added to the conditions
        list. You must specify a condition for the element as well.

    :type Conditions: list
    :param Conditions: A list of conditions to include in the policy. Each
        element can be either a list or a structure. For example:

        .. code:: python

            [
                {"acl": "public-read"},
                ["content-length-range", 2, 5],
                ["starts-with", "$success_action_redirect", ""]
            ]

        Conditions that are included may pertain to acl,
        content-length-range, Cache-Control, Content-Type,
        Content-Disposition, Content-Encoding, Expires,
        success_action_redirect, redirect, success_action_status,
        and/or x-amz-meta-.

        Note that if you include a condition, you must specify
        a valid value in the fields dictionary as well. A value will
        not be added automatically to the fields dictionary based on the
        conditions.

    :type ExpiresIn: int
    :param ExpiresIn: The number of seconds the presigned post
        is valid for.

    :rtype: dict
    :returns: A dictionary with two elements: ``url`` and ``fields``.
        Url is the url to post to. Fields is a dictionary filled with
        the form fields and respective values to use when submitting the
        post. For example:

        .. code:: python

            {
                'url': 'https://amzn-s3-demo-bucket.s3.amazonaws.com',
                'fields': {
                    'acl': 'public-read',
                    'key': 'mykey',
                    'signature': 'mysignature',
                    'policy': 'mybase64 encoded policy'
                }
            }
    NTrø   ÚCreateBucketrÿ   rü   rR   r   Fr  Úbucketz${filename}zstarts-withz$keyrh   )rm   rì   rê   rH   )Úcopyr  rå   rÎ   rÍ   r  rþ   r  r   r	  rC   r
  r  rñ   rT   rÏ   rô   )r   rÿ   ÚKeyÚFieldsÚ
ConditionsrÝ   r  rh   rì   rê   rH   r>   Úpost_presignerrþ   r‹   r  rÕ   r  r  rm   s                       r$   rô   rô   G  s¤  € ðP €FØ
€CØ€FØ€JØ€Jà€~Ø‰à—‘“ˆàÐØˆ
ð #Ü:¸4Ó@ñ€Gô
 % T×%9Ñ%9Ó:€Nð —i‘i×-Ñ-×=Ñ=¸nÓM€OØ×"Ñ"Ø˜fÐ%Ø'Øð #ó €Fô
 ×$Ñ$ V§Z¡Z°¸"Ó%=Ó>€Mð
 	×&Ñ&ØØØØ#0Ð0ð	 	'ó 	ñ	ØØØð ×0Ñ0ØØ'Ø!ØØ"Ø#ð 1ó €Lð ×Ñ�x Ð(Ô)ð ‡|�|�MÔ"Ø×Ñ˜=¨&°#Ð6K¼¸]Ó9KÐ8KÐ2LÐMÕNà×Ñ˜5 #˜,Ô'ð €Fˆ5�Mà×1Ñ1Ø!ØØØð	 2ó ð r&   c                 ó<  — | j                   j                  dk7  ry| j                   j                  j                  }|r`|j	                  dd«      ry|j	                  d«      dk(  r$| j                   j                  j
                  dk(  ry|j	                  d«      dk(  ryy	)
NÚawsFÚuse_dualstack_endpointÚus_east_1_regional_endpointÚregionalz	us-east-1Úaddressing_styleÚvirtualT)rÍ   Ú	partitionÚconfigÚs3rC   r   )ÚclientÚ	s3_configs     r$   r  r  Ö  s†   € Ø‡{�{×Ñ Ò%ØØ—‘×"Ñ"×%Ñ%€IÙØ�=‰=Ð1°5Ô9Øà�M‰MÐ7Ó8¸JÒFØ—‘×"Ñ"×.Ñ.°+Ò=àØ�=‰=Ð+Ó,°	Ò9ØØr&   r   )NrË   )Nrp   N)NNrp   )%r¯   rí   rŸ   r   rA   Úbotocore.authÚbotocore.awsrequestr   r   Úbotocore.compatr   r   Úbotocore.exceptionsr   r   r	   r
   Úbotocore.tokensr   Úbotocore.utilsr   r   r   r   rx   r·   r¾   r´   rß   r¼   r½   rå   rö   rn   r  rô   r  r<   r&   r$   ú<module>r0     s¼   ðó Û Û Û ã Û ß Kß =÷ó õ ,÷ñ ÷Iñ I÷X
C
ñ C
òLHòó3(ðn 47ó0(ðh ,/óð, ,/ó÷*W6ñ W6òtHð
 AEóLò^Jð
 @DóLó^r&   