o
    .&ßaa5  ã                   @   sŽ   d dl Z d dlZd dlZddlmZ d dlmZ d dlmZ d dl	m
Z
 e e¡ZdZdZG d	d
„ d
eƒZG dd„ deƒZG dd„ deƒZdS )é    Né   )Úget_account_id)ÚBasicCommand)Ús3_bucket_exists)ÚClientErrorz6policy/S3/AWSCloudTrail-S3BucketPolicy-2014-12-17.jsonz7policy/SNS/AWSCloudTrail-SnsTopicPolicy-2014-12-17.jsonc                   @   s   e Zd ZdS )ÚCloudTrailErrorN)Ú__name__Ú
__module__Ú__qualname__© r   r   úL/usr/lib/python3/dist-packages/awscli/customizations/cloudtrail/subscribe.pyr      s    r   c                
   @   s¶   e Zd ZdZdZdZdZddddœd	d
dœdddœdddœdddœdddœdddœdddœgZdZdZ	dd„ Z
dd„ Zdd„ Zdd „ Zd,d"d#„Zd,d$d%„Zd&d'„ Zd(d)„ Zd*d+„ Zd!S )-ÚCloudTrailSubscribez©
    Subscribe/update a user account to CloudTrail, creating the required S3 bucket,
    the optional SNS topic, and starting the CloudTrail monitoring and logging.
    zcreate-subscriptionz‚Creates and configures the AWS resources necessary to use CloudTrail, creates a trail using those resources, and turns on logging.znaws cloudtrail create-subscription (--s3-use-bucket|--s3-new-bucket) bucket-name [--sns-new-topic topic-name]
ÚnameTzCloudtrail name)r   ÚrequiredÚ	help_textzs3-new-bucketz%Create a new S3 bucket with this name)r   r   zs3-use-bucketz(Use an existing S3 bucket with this namez	s3-prefixzS3 object prefixzsns-new-topicz%Create a new SNS topic with this namezinclude-global-service-eventsz(Whether to include global service eventszs3-custom-policyz Custom S3 policy template or URLzsns-custom-policyz!Custom SNS policy template or URLFc                 C   s   |   ||¡ |  ||¡ dS )Nr   )Úsetup_servicesÚ_call)ÚselfÚargsÚparsed_globalsr   r   r   Ú	_run_main@   s   zCloudTrailSubscribe._run_mainc                 C   s°   d d dœ}|j d ur|j |d< |jd ur|j|d< t d¡ | jjd
i |¤Ž| _| jjdi |¤Ž| _| jjdi |¤Ž| _| jj	j
| _
|jd urL|j|d< | jjdi |¤Ž| _d S )N)Úregion_nameÚverifyr   r   z&Initializing S3, SNS and CloudTrail...ÚstsÚs3ÚsnsÚendpoint_urlÚ
cloudtrail)r   )r   )r   )r   )ÚregionÚ
verify_sslÚLOGÚdebugÚ_sessionÚcreate_clientr   r   r   Úmetar   r   r   )r   r   r   Úclient_argsr   r   r   r   G   s   þ






z"CloudTrailSubscribe.setup_servicesc           	      C   s´  |j }|r| ¡ dkrd}n| ¡ dkrd}ntdƒ‚|j}|jrX|j}| jrN|jdu rN| jj|j	gd�}|d d	 }d
|v rNt
 d |d
 ¡¡ |d
 |_|  ||j|j¡ n	|sa| jsatdƒ‚|jr‚z
|  |j|j¡}W n ty�   |jr€| jj|jd� ‚ w z|  |j	||j|j|¡}W n ty¯   |jr¢| jj|jd� |jr®| jj|d d� ‚ w tj djtj|dd�d�¡ | jsØ|  |j	¡ tj dj||jpÒdd�¡ dS dS )zˆ
        Run the command. Calls various services based on input options and
        outputs the final CloudTrail configuration.
        ÚtrueTÚfalseFzFYou must pass either true or false to --include-global-service-events.N)ÚtrailNameListÚ	trailListr   ÚS3KeyPrefixzSetting S3 prefix to {0}zBYou must pass either --s3-use-bucket or --s3-new-bucket to create.©ÚBucketÚTopicArn©r-   z#CloudTrail configuration:
{config}
é   )Úindent)Úconfigz,Logs will be delivered to {bucket}:{prefix}
Ú )ÚbucketÚprefix)Úinclude_global_service_eventsÚlowerÚ
ValueErrorÚs3_use_bucketÚs3_new_bucketÚUPDATEÚ	s3_prefixr   Údescribe_trailsr   r    r!   ÚformatÚsetup_new_bucketÚs3_custom_policyÚsns_new_topicÚsetup_new_topicÚsns_custom_policyÚ	Exceptionr   Údelete_bucketÚupsert_cloudtrail_configr   Údelete_topicÚsysÚstdoutÚwriteÚjsonÚdumpsÚstart_cloudtrail)	r   Úoptionsr   Úgser3   ÚresÚ
trail_infoÚtopic_resultÚcloudtrail_configr   r   r   r   ^   sz   ÿÿ

ÿ
ÿüûú
ÿ
ÿÿûzCloudTrailSubscribe._callc              
   C   sT   z| j jd| j |d�}|d  ¡  d¡W S  ty) } ztd| j||ƒ‚d }~ww )Nzawscloudtrail-policy-)r,   ÚKeyÚBodyzutf-8zCUnable to get regional policy template for region %s: %s. Error: %s)r   Ú
get_objectr   ÚreadÚdecoderC   r   )r   Úkey_nameÚdataÚer   r   r   Ú_get_policy«   s   þþ€ÿzCloudTrailSubscribe._get_policyNc           
      C   s&  t j dj|d�¡ t| jƒ}|r| d¡s|d7 }|dur!|}n|  t¡}| 	d|¡ 	d|¡}d|v r=| 	d|p:d¡}n| 	d	|pCd¡}t
 d
 |¡¡ t| j|ƒ}|r]tdj|d�ƒ‚d|i}| jdkrod| ji}||d< | jjdi |¤Ž}	z| jj||d� W |	S  ty’   | jj|d� ‚ w )zx
        Creates a new S3 bucket with an appropriate policy to let CloudTrail
        write to the prefix path.
        z%Setting up new S3 bucket {bucket}...
)r3   ú/Nz<BucketName>z<CustomerAccountID>z	<Prefix>/r2   z<Prefix>zBucket policy:
{0}zBucket {bucket} already exists.r,   z	us-east-1ÚLocationConstraintÚCreateBucketConfiguration)r,   ÚPolicyr+   r   )rG   rH   rI   r=   r   r   Úendswithr[   ÚS3_POLICY_TEMPLATEÚreplacer    r!   r   r   rC   r   Úcreate_bucketÚput_bucket_policyr   rD   )
r   r3   r4   Úcustom_policyÚ
account_idÚpolicyÚbucket_existsÚparamsÚbucket_configrY   r   r   r   r>   ¶   sB   
ÿ


ÿÿ

ûýz$CloudTrailSubscribe.setup_new_bucketc           	         s6  t j djˆ d�¡ t| jƒ}z	| j ¡ d }W n ty(   g }t	 
d¡ Y nw ‡ fdd„|D ƒr:tdjˆ d�ƒ‚| jjj}|durF|}n|  t¡}| d	|¡ d
|¡ dˆ ¡}| jjˆ d�}z)| jj|d d�}|  |d d |¡}t	 d |¡¡ | jj|d d|d� W |S  tyš   | jj|d d� ‚ w )zz
        Creates a new SNS topic with an appropriate policy to let CloudTrail
        post messages to the topic.
        z$Setting up new SNS topic {topic}...
©ÚtopicÚTopicsz$Unable to list topics, continuing...c                    s&   g | ]}|d    d¡d ˆ kr|‘qS )r-   ú:éÿÿÿÿ)Úsplit)Ú.0Útrk   r   r   Ú
<listcomp>ý   s   & z7CloudTrailSubscribe.setup_new_topic.<locals>.<listcomp>zTopic {topic} already exists.Nz<Region>z<SNSTopicOwnerAccountId>z<SNSTopicName>©ÚNamer-   r.   Ú
Attributesr_   zTopic policy:
{0})r-   ÚAttributeNameÚAttributeValue)rG   rH   rI   r=   r   r   r   Úlist_topicsrC   r    Úwarnr$   r   r[   ÚSNS_POLICY_TEMPLATErb   Úcreate_topicÚget_topic_attributesÚmerge_sns_policyr!   Úset_topic_attributesrF   )	r   rl   re   rf   Útopicsr   rg   rQ   Ú
topic_attrr   rk   r   rA   ê   sP   
ÿ
þÿ


þÿÿþûýz#CloudTrailSubscribe.setup_new_topicc                 C   s2   t  |¡}t  |¡}|d  |d 7  < t  |¡S )aÞ  
        Merge two SNS topic policy documents. The id information from
        ``left`` is used in the final document, and the statements
        from ``right`` are merged into ``left``.

        http://docs.aws.amazon.com/sns/latest/dg/BasicStructure.html

        :type left: string
        :param left: First policy JSON document
        :type right: string
        :param right: Second policy JSON document
        :rtype: string
        :return: Merged policy JSON
        Ú	Statement)rJ   ÚloadsrK   )r   ÚleftÚrightÚleft_parsedÚright_parsedr   r   r   r~   %  s   


z$CloudTrailSubscribe.merge_sns_policyc                 C   sŠ   t j d¡ d|i}|dur||d< |dur||d< |dur"||d< |dur*||d< | js7| jjdi |¤Ž n	| jjdi |¤Ž | j ¡ S )	z�
        Either create or update the CloudTrail configuration depending on
        whether this command is a create or update command.
        z.Creating/updating CloudTrail configuration...
ru   NÚS3BucketNamer*   ÚSnsTopicNameÚIncludeGlobalServiceEventsr   )rG   rH   rI   r:   r   Úcreate_trailÚupdate_trailr<   )r   r   r3   r4   rl   rN   r1   r   r   r   rE   9  s   ÿ
z,CloudTrailSubscribe.upsert_cloudtrail_configc                 C   s   t j d¡ | jj|d�S )zE
        Start the CloudTrail service, which begins logging.
        zStarting CloudTrail service...
rt   )rG   rH   rI   r   Ústart_logging)r   r   r   r   r   rL   P  s   z$CloudTrailSubscribe.start_cloudtrail)N)r   r	   r
   Ú__doc__ÚNAMEÚDESCRIPTIONÚSYNOPSISÚ	ARG_TABLEr:   Ú_UNDOCUMENTEDr   r   r   r[   r>   rA   r~   rE   rL   r   r   r   r   r       sJ    
ÿÿÿÿÿÿóM

4;r   c                   @   s    e Zd ZdZdZdZdZdZdS )ÚCloudTrailUpdatezF
    Like subscribe above, but the update version of the command.
    zupdate-subscriptionTzlUpdates any of the trail configuration settings, and creates and configures any new AWS resources specified.zpaws cloudtrail update-subscription [(--s3-use-bucket|--s3-new-bucket) bucket-name] [--sns-new-topic topic-name]
N)r   r	   r
   rŽ   r�   r:   r�   r‘   r   r   r   r   r”   X  s    r”   )rJ   ÚloggingrG   Úutilsr   Úawscli.customizations.commandsr   Úawscli.customizations.utilsr   Úbotocore.exceptionsr   Ú	getLoggerr   r    ra   r{   rC   r   r   r”   r   r   r   r   Ú<module>   s   
  :