-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathappstoreconnect_token_manager.py
79 lines (66 loc) · 2.43 KB
/
appstoreconnect_token_manager.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
import os
import jwt
from datetime import datetime, timezone, timedelta
from uuid import UUID
from cryptography.hazmat.primitives.serialization import load_pem_private_key
from pydantic import BaseModel, constr, root_validator, validator, ValidationError
from pydantic.schema import Optional
class AppStoreConnectAPICredentials(BaseModel):
issuer_id: Optional[UUID] = os.getenv("APPSTORE_ISSUER_ID")
key_id: Optional[constr( # type: ignore[valid-type]
strip_whitespace=True, min_length=10, max_length=10
)] = os.getenv("APPSTORE_API_KEY_ID")
private_key: Optional[str] = os.getenv("APPSTORE_API_PRIVATE_KEY")
password: Optional[str] = ""
@validator("issuer_id")
def issuer_id_not_none(cls, v):
if not v:
raise ValueError("APPSTORE_ISSUER_ID environment variable not set")
return
@validator("key_id")
def key_id_not_none(cls, v):
if not v:
raise ValueError("APPSTORE_API_KEY_ID environment variable not set")
return
@validator("private_key")
def private_key_not_none(cls, v):
if not v:
raise ValueError("APPSTORE_API_PRIVATE_KEY environment variable not set")
return
@validator("password")
def password_is_set(cls, v):
if v:
raise ValueError("password protected api keys not currently supported")
class Config:
extra = "forbid"
class AppStoreConnectTokenManager:
TOKEN_TTL = timedelta(minutes=15)
def __init__(self):
try:
self.credentials = AppStoreConnectAPICredentials()
except ValidationError as e:
print(e)
return
self.is_a_pem_private_key()
def is_a_pem_private_key(self):
try:
load_pem_private_key(
self.credentials.private_key.encode("utf-8"),
password=None,
)
except Exception:
raise ValueError("Not a valid private key")
return
def get_token(self):
return jwt.encode(
{
"iss": self.credentials.issuer_id,
"iat": datetime.now(tz=timezone.utc),
"exp": datetime.now(tz=timezone.utc) + self.TOKEN_TTL,
"aud": "appstoreconnect-v1"
# TODO: define allowed scopes
},
key=self.credentials.private_key,
algorithm="ES256",
headers={"kid": self.credentials.key_id},
)