import json
import base64
import time
import urllib.request
import subprocess
import os

def base64url_encode(data):
    return base64.urlsafe_b64encode(data).decode('utf-8').replace('=', '')

def edit_google_doc_raw():
    # Load credentials
    with open('/home/openclaw/.openclaw/workspace/google_service_account.json') as f:
        creds = json.load(f)
    
    private_key_str = creds['private_key']
    client_email = creds['client_email']
    token_uri = creds['token_uri']
    
    # JWT Header
    header = {"alg": "RS256", "typ": "JWT"}
    header_b64 = base64url_encode(json.dumps(header).encode())
    
    # JWT Payload
    now = int(time.time())
    payload = {
        "iss": client_email,
        "scope": "https://www.googleapis.com/auth/documents",
        "aud": token_uri,
        "iat": now,
        "exp": now + 3600
    }
    payload_b64 = base64url_encode(json.dumps(payload).encode())
    
    content = f"{header_b64}.{payload_b64}"
    
    # Write private key to a temporary file for OpenSSL
    key_file = '/tmp/priv.pem'
    with open(key_file, 'w') as f:
        f.write(private_key_str)
    
    try:
        # Use openssl CLI to sign
        process = subprocess.Popen(
            ['openssl', 'dgst', '-sha256', '-sign', key_file],
            stdin=subprocess.PIPE, stdout=subprocess.PIPE, stderr=subprocess.PIPE
        )
        signature, err = process.communicate(input=content.encode())
        if process.returncode != 0:
            raise Exception(f"OpenSSL error: {err.decode()}")
    finally:
        if os.path.exists(key_file):
            os.remove(key_file)
    
    signature_b64 = base64url_encode(signature)
    jwt = f"{content}.{signature_b64}"
    
    # Exchange JWT for access token
    data = urllib.parse.urlencode({
        "grant_type": "urn:ietf:params:oauth:grant-type:jwt-bearer",
        "assertion": jwt
    }).encode()
    
    req = urllib.request.Request(token_uri, data=data)
    with urllib.request.urlopen(req) as f:
        res = json.loads(f.read().decode())
    
    access_token = res['access_token']
    
    # Batch Update Request
    doc_id = "1Ymh60_Qe2yX6TgfznwOHwlphv8YMoz3SscJNg_HZtO0"
    update_uri = f"https://docs.googleapis.com/v1/documents/{doc_id}:batchUpdate"
    
    body = {
        "requests": [
            {
                "insertText": {
                    "location": {"index": 1},
                    "text": "Trợ lý Zen vừa sửa bài\n"
                }
            }
        ]
    }
    
    req = urllib.request.Request(
        update_uri, 
        data=json.dumps(body).encode(),
        headers={
            "Authorization": f"Bearer {access_token}",
            "Content-Type": "application/json"
        },
        method='POST'
    )
    
    try:
        with urllib.request.urlopen(req) as f:
            final_res = json.loads(f.read().decode())
        print(json.dumps(final_res, indent=2))
    except urllib.error.HTTPError as e:
        print(f"Error Status: {e.code}")
        print(f"Error Body: {e.read().decode()}")

if __name__ == "__main__":
    try:
        edit_google_doc_raw()
    except Exception as e:
        print(f"Error: {e}")
