<html><body>
<style>

body, h1, h2, h3, div, span, p, pre, a {
  margin: 0;
  padding: 0;
  border: 0;
  font-weight: inherit;
  font-style: inherit;
  font-size: 100%;
  font-family: inherit;
  vertical-align: baseline;
}

body {
  font-size: 13px;
  padding: 1em;
}

h1 {
  font-size: 26px;
  margin-bottom: 1em;
}

h2 {
  font-size: 24px;
  margin-bottom: 1em;
}

h3 {
  font-size: 20px;
  margin-bottom: 1em;
  margin-top: 1em;
}

pre, code {
  line-height: 1.5;
  font-family: Monaco, 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Lucida Console', monospace;
}

pre {
  margin-top: 0.5em;
}

h1, h2, h3, p {
  font-family: Arial, sans serif;
}

h1, h2, h3 {
  border-bottom: solid #CCC 1px;
}

.toc_element {
  margin-top: 0.5em;
}

.firstline {
  margin-left: 2 em;
}

.method  {
  margin-top: 1em;
  border: solid 1px #CCC;
  padding: 1em;
  background: #EEE;
}

.details {
  font-weight: bold;
  font-size: 14px;
}

</style>

<h1><a href="storage_v1.html">Cloud Storage JSON API</a> . <a href="storage_v1.objects.html">objects</a></h1>
<h2>Instance Methods</h2>
<p class="toc_element">
  <code><a href="#compose">compose(destinationBucket, destinationObject, body=None, destinationPredefinedAcl=None, ifGenerationMatch=None, ifMetagenerationMatch=None, kmsKeyName=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Concatenates a list of existing objects into a new object in the same bucket.</p>
<p class="toc_element">
  <code><a href="#copy">copy(sourceBucket, sourceObject, destinationBucket, destinationObject, body=None, destinationKmsKeyName=None, destinationPredefinedAcl=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, ifSourceGenerationMatch=None, ifSourceGenerationNotMatch=None, ifSourceMetagenerationMatch=None, ifSourceMetagenerationNotMatch=None, projection=None, provisionalUserProject=None, sourceGeneration=None, userProject=None)</a></code></p>
<p class="firstline">Copies a source object to a destination object. Optionally overrides metadata.</p>
<p class="toc_element">
  <code><a href="#delete">delete(bucket, object, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Deletes an object and its metadata. Deletions are permanent if versioning is not enabled for the bucket, or if the generation parameter is used.</p>
<p class="toc_element">
  <code><a href="#get">get(bucket, object, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, projection=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Retrieves an object or its metadata.</p>
<p class="toc_element">
  <code><a href="#getIamPolicy">getIamPolicy(bucket, object, generation=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Returns an IAM policy for the specified object.</p>
<p class="toc_element">
  <code><a href="#get_media">get_media(bucket, object, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, projection=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Retrieves an object or its metadata.</p>
<p class="toc_element">
  <code><a href="#insert">insert(bucket, body=None, contentEncoding=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, kmsKeyName=None, name=None, predefinedAcl=None, projection=None, provisionalUserProject=None, userProject=None, media_body=None, media_mime_type=None)</a></code></p>
<p class="firstline">Stores a new object and metadata.</p>
<p class="toc_element">
  <code><a href="#list">list(bucket, delimiter=None, endOffset=None, includeTrailingDelimiter=None, maxResults=None, pageToken=None, prefix=None, projection=None, provisionalUserProject=None, startOffset=None, userProject=None, versions=None)</a></code></p>
<p class="firstline">Retrieves a list of objects matching the criteria.</p>
<p class="toc_element">
  <code><a href="#list_next">list_next(previous_request, previous_response)</a></code></p>
<p class="firstline">Retrieves the next page of results.</p>
<p class="toc_element">
  <code><a href="#patch">patch(bucket, object, body=None, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, predefinedAcl=None, projection=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Patches an object's metadata.</p>
<p class="toc_element">
  <code><a href="#rewrite">rewrite(sourceBucket, sourceObject, destinationBucket, destinationObject, body=None, destinationKmsKeyName=None, destinationPredefinedAcl=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, ifSourceGenerationMatch=None, ifSourceGenerationNotMatch=None, ifSourceMetagenerationMatch=None, ifSourceMetagenerationNotMatch=None, maxBytesRewrittenPerCall=None, projection=None, provisionalUserProject=None, rewriteToken=None, sourceGeneration=None, userProject=None)</a></code></p>
<p class="firstline">Rewrites a source object to a destination object. Optionally overrides metadata.</p>
<p class="toc_element">
  <code><a href="#setIamPolicy">setIamPolicy(bucket, object, body=None, generation=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Updates an IAM policy for the specified object.</p>
<p class="toc_element">
  <code><a href="#testIamPermissions">testIamPermissions(bucket, object, permissions, generation=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Tests a set of permissions on the given object to see which, if any, are held by the caller.</p>
<p class="toc_element">
  <code><a href="#update">update(bucket, object, body=None, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, predefinedAcl=None, projection=None, provisionalUserProject=None, userProject=None)</a></code></p>
<p class="firstline">Updates an object's metadata.</p>
<p class="toc_element">
  <code><a href="#watchAll">watchAll(bucket, body=None, delimiter=None, endOffset=None, includeTrailingDelimiter=None, maxResults=None, pageToken=None, prefix=None, projection=None, provisionalUserProject=None, startOffset=None, userProject=None, versions=None)</a></code></p>
<p class="firstline">Watch for changes on all objects in a bucket.</p>
<h3>Method Details</h3>
<div class="method">
    <code class="details" id="compose">compose(destinationBucket, destinationObject, body=None, destinationPredefinedAcl=None, ifGenerationMatch=None, ifMetagenerationMatch=None, kmsKeyName=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Concatenates a list of existing objects into a new object in the same bucket.

Args:
  destinationBucket: string, Name of the bucket containing the source objects. The destination object is stored in this bucket. (required)
  destinationObject: string, Name of the new object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  body: object, The request body.
    The object takes the form of:

{ # A Compose request.
    &quot;destination&quot;: { # An object. # Properties of the resulting object.
      &quot;acl&quot;: [ # Access controls on the object.
        { # An access-control entry.
          &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
          &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
          &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
          &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
              # - user-userId
              # - user-email
              # - group-groupId
              # - group-email
              # - domain-domain
              # - project-team-projectId
              # - allUsers
              # - allAuthenticatedUsers Examples:
              # - The user liz@example.com would be user-liz@example.com.
              # - The group example@googlegroups.com would be group-example@googlegroups.com.
              # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
          &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
          &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
          &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
          &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
          &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
          &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
          &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
            &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
            &quot;team&quot;: &quot;A String&quot;, # The team.
          },
          &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
          &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
        },
      ],
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
      &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
      &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
      &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
      &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
      &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
      &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
      &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
      &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
      &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
        &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
        &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
      },
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
      &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
      &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
      &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
      &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
      &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
      &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
        &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
      },
      &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
      &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
      &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
        &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
      },
      &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
      &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
      &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
      &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
      &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
      &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
      &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
      &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
    },
    &quot;kind&quot;: &quot;storage#composeRequest&quot;, # The kind of item this is.
    &quot;sourceObjects&quot;: [ # The list of source objects that will be concatenated into a single object.
      {
        &quot;generation&quot;: &quot;A String&quot;, # The generation of this object to use as the source.
        &quot;name&quot;: &quot;A String&quot;, # The source object&#x27;s name. All source objects must reside in the same bucket.
        &quot;objectPreconditions&quot;: { # Conditions that must be met for this operation to execute.
          &quot;ifGenerationMatch&quot;: &quot;A String&quot;, # Only perform the composition if the generation of the source object that would be used matches this value. If this value and a generation are both specified, they must be the same value or the call will fail.
        },
      },
    ],
  }

  destinationPredefinedAcl: string, Apply a predefined set of access controls to the destination object.
    Allowed values
      authenticatedRead - Object owner gets OWNER access, and allAuthenticatedUsers get READER access.
      bucketOwnerFullControl - Object owner gets OWNER access, and project team owners get OWNER access.
      bucketOwnerRead - Object owner gets OWNER access, and project team owners get READER access.
      private - Object owner gets OWNER access.
      projectPrivate - Object owner gets OWNER access, and project team members get access according to their roles.
      publicRead - Object owner gets OWNER access, and allUsers get READER access.
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  kmsKeyName: string, Resource name of the Cloud KMS key, of the form projects/my-project/locations/global/keyRings/my-kr/cryptoKeys/my-key, that will be used to encrypt the object. Overrides the object metadata&#x27;s kms_key_name value, if any.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # An object.
    &quot;acl&quot;: [ # Access controls on the object.
      { # An access-control entry.
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
        &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
        &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
        &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
            # - user-userId
            # - user-email
            # - group-groupId
            # - group-email
            # - domain-domain
            # - project-team-projectId
            # - allUsers
            # - allAuthenticatedUsers Examples:
            # - The user liz@example.com would be user-liz@example.com.
            # - The group example@googlegroups.com would be group-example@googlegroups.com.
            # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
        &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
        &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
        &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
          &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
          &quot;team&quot;: &quot;A String&quot;, # The team.
        },
        &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
      },
    ],
    &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
    &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
    &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
    &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
    &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
    &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
    &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
    &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
    &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
    &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
      &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
      &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
    },
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
    &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
    &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
    &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
    &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
    &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
    &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
    &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
    &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
      &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
    },
    &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
    &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
    &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
      &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
    },
    &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
    &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
    &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
    &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
    &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
    &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
    &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
    &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
    &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
  }</pre>
</div>

<div class="method">
    <code class="details" id="copy">copy(sourceBucket, sourceObject, destinationBucket, destinationObject, body=None, destinationKmsKeyName=None, destinationPredefinedAcl=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, ifSourceGenerationMatch=None, ifSourceGenerationNotMatch=None, ifSourceMetagenerationMatch=None, ifSourceMetagenerationNotMatch=None, projection=None, provisionalUserProject=None, sourceGeneration=None, userProject=None)</code>
  <pre>Copies a source object to a destination object. Optionally overrides metadata.

Args:
  sourceBucket: string, Name of the bucket in which to find the source object. (required)
  sourceObject: string, Name of the source object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  destinationBucket: string, Name of the bucket in which to store the new object. Overrides the provided object metadata&#x27;s bucket value, if any.For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  destinationObject: string, Name of the new object. Required when the object metadata is not otherwise provided. Overrides the object metadata&#x27;s name value, if any. (required)
  body: object, The request body.
    The object takes the form of:

{ # An object.
  &quot;acl&quot;: [ # Access controls on the object.
    { # An access-control entry.
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
      &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
      &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
      &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
          # - user-userId
          # - user-email
          # - group-groupId
          # - group-email
          # - domain-domain
          # - project-team-projectId
          # - allUsers
          # - allAuthenticatedUsers Examples:
          # - The user liz@example.com would be user-liz@example.com.
          # - The group example@googlegroups.com would be group-example@googlegroups.com.
          # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
      &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
      &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
      &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
        &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
        &quot;team&quot;: &quot;A String&quot;, # The team.
      },
      &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
    },
  ],
  &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
  &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
  &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
  &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
  &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
  &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
  &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
  &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
  &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
  &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
    &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
    &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
  },
  &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
  &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
  &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
  &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
  &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
  &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
  &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
  &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
  &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
    &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
  },
  &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
  &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
  &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
    &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
    &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
  },
  &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
  &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
  &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
  &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
  &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
  &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
  &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
  &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
  &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
}

  destinationKmsKeyName: string, Resource name of the Cloud KMS key, of the form projects/my-project/locations/global/keyRings/my-kr/cryptoKeys/my-key, that will be used to encrypt the object. Overrides the object metadata&#x27;s kms_key_name value, if any.
  destinationPredefinedAcl: string, Apply a predefined set of access controls to the destination object.
    Allowed values
      authenticatedRead - Object owner gets OWNER access, and allAuthenticatedUsers get READER access.
      bucketOwnerFullControl - Object owner gets OWNER access, and project team owners get OWNER access.
      bucketOwnerRead - Object owner gets OWNER access, and project team owners get READER access.
      private - Object owner gets OWNER access.
      projectPrivate - Object owner gets OWNER access, and project team members get access according to their roles.
      publicRead - Object owner gets OWNER access, and allUsers get READER access.
  ifGenerationMatch: string, Makes the operation conditional on whether the destination object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the destination object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the destination object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the destination object&#x27;s current metageneration does not match the given value.
  ifSourceGenerationMatch: string, Makes the operation conditional on whether the source object&#x27;s current generation matches the given value.
  ifSourceGenerationNotMatch: string, Makes the operation conditional on whether the source object&#x27;s current generation does not match the given value.
  ifSourceMetagenerationMatch: string, Makes the operation conditional on whether the source object&#x27;s current metageneration matches the given value.
  ifSourceMetagenerationNotMatch: string, Makes the operation conditional on whether the source object&#x27;s current metageneration does not match the given value.
  projection: string, Set of properties to return. Defaults to noAcl, unless the object resource specifies the acl property, when it defaults to full.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  sourceGeneration: string, If present, selects a specific revision of the source object (as opposed to the latest version, the default).
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # An object.
    &quot;acl&quot;: [ # Access controls on the object.
      { # An access-control entry.
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
        &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
        &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
        &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
            # - user-userId
            # - user-email
            # - group-groupId
            # - group-email
            # - domain-domain
            # - project-team-projectId
            # - allUsers
            # - allAuthenticatedUsers Examples:
            # - The user liz@example.com would be user-liz@example.com.
            # - The group example@googlegroups.com would be group-example@googlegroups.com.
            # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
        &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
        &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
        &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
          &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
          &quot;team&quot;: &quot;A String&quot;, # The team.
        },
        &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
      },
    ],
    &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
    &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
    &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
    &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
    &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
    &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
    &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
    &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
    &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
    &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
      &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
      &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
    },
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
    &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
    &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
    &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
    &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
    &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
    &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
    &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
    &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
      &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
    },
    &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
    &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
    &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
      &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
    },
    &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
    &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
    &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
    &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
    &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
    &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
    &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
    &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
    &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
  }</pre>
</div>

<div class="method">
    <code class="details" id="delete">delete(bucket, object, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Deletes an object and its metadata. Deletions are permanent if versioning is not enabled for the bucket, or if the generation parameter is used.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  generation: string, If present, permanently deletes a specific revision of this object (as opposed to the latest version, the default).
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration does not match the given value.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.
</pre>
</div>

<div class="method">
    <code class="details" id="get">get(bucket, object, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, projection=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Retrieves an object or its metadata.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration does not match the given value.
  projection: string, Set of properties to return. Defaults to noAcl.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # An object.
    &quot;acl&quot;: [ # Access controls on the object.
      { # An access-control entry.
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
        &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
        &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
        &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
            # - user-userId
            # - user-email
            # - group-groupId
            # - group-email
            # - domain-domain
            # - project-team-projectId
            # - allUsers
            # - allAuthenticatedUsers Examples:
            # - The user liz@example.com would be user-liz@example.com.
            # - The group example@googlegroups.com would be group-example@googlegroups.com.
            # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
        &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
        &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
        &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
          &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
          &quot;team&quot;: &quot;A String&quot;, # The team.
        },
        &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
      },
    ],
    &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
    &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
    &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
    &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
    &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
    &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
    &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
    &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
    &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
    &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
      &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
      &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
    },
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
    &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
    &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
    &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
    &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
    &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
    &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
    &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
    &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
      &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
    },
    &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
    &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
    &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
      &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
    },
    &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
    &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
    &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
    &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
    &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
    &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
    &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
    &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
    &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
  }</pre>
</div>

<div class="method">
    <code class="details" id="getIamPolicy">getIamPolicy(bucket, object, generation=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Returns an IAM policy for the specified object.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # A bucket/object IAM policy.
    &quot;bindings&quot;: [ # An association between a role, which comes with a set of permissions, and members who may assume that role.
      {
        &quot;condition&quot;: { # Represents an expression text. Example: title: &quot;User account presence&quot; description: &quot;Determines whether the request has a user account&quot; expression: &quot;size(request.user) &gt; 0&quot; # The condition that is associated with this binding. NOTE: an unsatisfied condition will not allow user access via current binding. Different bindings, including their conditions, are examined independently.
          &quot;description&quot;: &quot;A String&quot;, # An optional description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.
          &quot;expression&quot;: &quot;A String&quot;, # Textual representation of an expression in Common Expression Language syntax. The application context of the containing message determines which well-known feature set of CEL is supported.
          &quot;location&quot;: &quot;A String&quot;, # An optional string indicating the location of the expression for error reporting, e.g. a file name and a position in the file.
          &quot;title&quot;: &quot;A String&quot;, # An optional title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.
        },
        &quot;members&quot;: [ # A collection of identifiers for members who may assume the provided role. Recognized identifiers are as follows:
            # - allUsers — A special identifier that represents anyone on the internet; with or without a Google account.
            # - allAuthenticatedUsers — A special identifier that represents anyone who is authenticated with a Google account or a service account.
            # - user:emailid — An email address that represents a specific account. For example, user:alice@gmail.com or user:joe@example.com.
            # - serviceAccount:emailid — An email address that represents a service account. For example,  serviceAccount:my-other-app@appspot.gserviceaccount.com .
            # - group:emailid — An email address that represents a Google group. For example, group:admins@example.com.
            # - domain:domain — A Google Apps domain name that represents all the users of that domain. For example, domain:google.com or domain:example.com.
            # - projectOwner:projectid — Owners of the given project. For example, projectOwner:my-example-project
            # - projectEditor:projectid — Editors of the given project. For example, projectEditor:my-example-project
            # - projectViewer:projectid — Viewers of the given project. For example, projectViewer:my-example-project
          &quot;A String&quot;,
        ],
        &quot;role&quot;: &quot;A String&quot;, # The role to which members belong. Two types of roles are supported: new IAM roles, which grant permissions that do not map directly to those provided by ACLs, and legacy IAM roles, which do map directly to ACL permissions. All roles are of the format roles/storage.specificRole.
            # The new IAM roles are:
            # - roles/storage.admin — Full control of Google Cloud Storage resources.
            # - roles/storage.objectViewer — Read-Only access to Google Cloud Storage objects.
            # - roles/storage.objectCreator — Access to create objects in Google Cloud Storage.
            # - roles/storage.objectAdmin — Full control of Google Cloud Storage objects.   The legacy IAM roles are:
            # - roles/storage.legacyObjectReader — Read-only access to objects without listing. Equivalent to an ACL entry on an object with the READER role.
            # - roles/storage.legacyObjectOwner — Read/write access to existing objects without listing. Equivalent to an ACL entry on an object with the OWNER role.
            # - roles/storage.legacyBucketReader — Read access to buckets with object listing. Equivalent to an ACL entry on a bucket with the READER role.
            # - roles/storage.legacyBucketWriter — Read access to buckets with object listing/creation/deletion. Equivalent to an ACL entry on a bucket with the WRITER role.
            # - roles/storage.legacyBucketOwner — Read and write access to existing buckets with object listing/creation/deletion. Equivalent to an ACL entry on a bucket with the OWNER role.
      },
    ],
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1  Entity tag for the policy.
    &quot;kind&quot;: &quot;storage#policy&quot;, # The kind of item this is. For policies, this is always storage#policy. This field is ignored on input.
    &quot;resourceId&quot;: &quot;A String&quot;, # The ID of the resource to which this policy belongs. Will be of the form projects/_/buckets/bucket for buckets, and projects/_/buckets/bucket/objects/object for objects. A specific generation may be specified by appending #generationNumber to the end of the object name, e.g. projects/_/buckets/my-bucket/objects/data.txt#17. The current generation can be denoted with #0. This field is ignored on input.
    &quot;version&quot;: 42, # The IAM policy format version.
  }</pre>
</div>

<div class="method">
    <code class="details" id="get_media">get_media(bucket, object, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, projection=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Retrieves an object or its metadata.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration does not match the given value.
  projection: string, Set of properties to return. Defaults to noAcl.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  The media object as a string.

    </pre>
</div>

<div class="method">
    <code class="details" id="insert">insert(bucket, body=None, contentEncoding=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, kmsKeyName=None, name=None, predefinedAcl=None, projection=None, provisionalUserProject=None, userProject=None, media_body=None, media_mime_type=None)</code>
  <pre>Stores a new object and metadata.

Args:
  bucket: string, Name of the bucket in which to store the new object. Overrides the provided object metadata&#x27;s bucket value, if any. (required)
  body: object, The request body.
    The object takes the form of:

{ # An object.
  &quot;acl&quot;: [ # Access controls on the object.
    { # An access-control entry.
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
      &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
      &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
      &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
          # - user-userId
          # - user-email
          # - group-groupId
          # - group-email
          # - domain-domain
          # - project-team-projectId
          # - allUsers
          # - allAuthenticatedUsers Examples:
          # - The user liz@example.com would be user-liz@example.com.
          # - The group example@googlegroups.com would be group-example@googlegroups.com.
          # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
      &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
      &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
      &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
        &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
        &quot;team&quot;: &quot;A String&quot;, # The team.
      },
      &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
    },
  ],
  &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
  &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
  &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
  &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
  &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
  &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
  &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
  &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
  &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
  &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
    &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
    &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
  },
  &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
  &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
  &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
  &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
  &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
  &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
  &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
  &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
  &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
    &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
  },
  &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
  &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
  &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
    &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
    &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
  },
  &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
  &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
  &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
  &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
  &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
  &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
  &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
  &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
  &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
}

  contentEncoding: string, If set, sets the contentEncoding property of the final object to this value. Setting this parameter is equivalent to setting the contentEncoding metadata property. This can be useful when uploading an object with uploadType=media to indicate the encoding of the content being uploaded.
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration does not match the given value.
  kmsKeyName: string, Resource name of the Cloud KMS key, of the form projects/my-project/locations/global/keyRings/my-kr/cryptoKeys/my-key, that will be used to encrypt the object. Overrides the object metadata&#x27;s kms_key_name value, if any.
  name: string, Name of the object. Required when the object metadata is not otherwise provided. Overrides the object metadata&#x27;s name value, if any. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts.
  predefinedAcl: string, Apply a predefined set of access controls to this object.
    Allowed values
      authenticatedRead - Object owner gets OWNER access, and allAuthenticatedUsers get READER access.
      bucketOwnerFullControl - Object owner gets OWNER access, and project team owners get OWNER access.
      bucketOwnerRead - Object owner gets OWNER access, and project team owners get READER access.
      private - Object owner gets OWNER access.
      projectPrivate - Object owner gets OWNER access, and project team members get access according to their roles.
      publicRead - Object owner gets OWNER access, and allUsers get READER access.
  projection: string, Set of properties to return. Defaults to noAcl, unless the object resource specifies the acl property, when it defaults to full.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.
  media_body: string, The filename of the media request body, or an instance of a MediaUpload object.
  media_mime_type: string, The MIME type of the media request body, or an instance of a MediaUpload object.

Returns:
  An object of the form:

    { # An object.
    &quot;acl&quot;: [ # Access controls on the object.
      { # An access-control entry.
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
        &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
        &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
        &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
            # - user-userId
            # - user-email
            # - group-groupId
            # - group-email
            # - domain-domain
            # - project-team-projectId
            # - allUsers
            # - allAuthenticatedUsers Examples:
            # - The user liz@example.com would be user-liz@example.com.
            # - The group example@googlegroups.com would be group-example@googlegroups.com.
            # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
        &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
        &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
        &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
          &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
          &quot;team&quot;: &quot;A String&quot;, # The team.
        },
        &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
      },
    ],
    &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
    &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
    &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
    &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
    &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
    &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
    &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
    &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
    &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
    &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
      &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
      &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
    },
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
    &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
    &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
    &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
    &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
    &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
    &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
    &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
    &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
      &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
    },
    &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
    &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
    &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
      &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
    },
    &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
    &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
    &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
    &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
    &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
    &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
    &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
    &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
    &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
  }</pre>
</div>

<div class="method">
    <code class="details" id="list">list(bucket, delimiter=None, endOffset=None, includeTrailingDelimiter=None, maxResults=None, pageToken=None, prefix=None, projection=None, provisionalUserProject=None, startOffset=None, userProject=None, versions=None)</code>
  <pre>Retrieves a list of objects matching the criteria.

Args:
  bucket: string, Name of the bucket in which to look for objects. (required)
  delimiter: string, Returns results in a directory-like mode. items will contain only objects whose names, aside from the prefix, do not contain delimiter. Objects whose names, aside from the prefix, contain delimiter will have their name, truncated after the delimiter, returned in prefixes. Duplicate prefixes are omitted.
  endOffset: string, Filter results to objects whose names are lexicographically before endOffset. If startOffset is also set, the objects listed will have names between startOffset (inclusive) and endOffset (exclusive).
  includeTrailingDelimiter: boolean, If true, objects that end in exactly one instance of delimiter will have their metadata included in items in addition to prefixes.
  maxResults: integer, Maximum number of items plus prefixes to return in a single page of responses. As duplicate prefixes are omitted, fewer total results may be returned than requested. The service will use this parameter or 1,000 items, whichever is smaller.
  pageToken: string, A previously-returned page token representing part of the larger set of results to view.
  prefix: string, Filter results to objects whose names begin with this prefix.
  projection: string, Set of properties to return. Defaults to noAcl.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  startOffset: string, Filter results to objects whose names are lexicographically equal to or after startOffset. If endOffset is also set, the objects listed will have names between startOffset (inclusive) and endOffset (exclusive).
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.
  versions: boolean, If true, lists all versions of an object as distinct results. The default is false. For more information, see Object Versioning.

Returns:
  An object of the form:

    { # A list of objects.
    &quot;items&quot;: [ # The list of items.
      { # An object.
        &quot;acl&quot;: [ # Access controls on the object.
          { # An access-control entry.
            &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
            &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
            &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
            &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
                # - user-userId
                # - user-email
                # - group-groupId
                # - group-email
                # - domain-domain
                # - project-team-projectId
                # - allUsers
                # - allAuthenticatedUsers Examples:
                # - The user liz@example.com would be user-liz@example.com.
                # - The group example@googlegroups.com would be group-example@googlegroups.com.
                # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
            &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
            &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
            &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
            &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
            &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
            &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
            &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
              &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
              &quot;team&quot;: &quot;A String&quot;, # The team.
            },
            &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
            &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
          },
        ],
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
        &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
        &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
        &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
        &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
        &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
        &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
        &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
        &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
        &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
          &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
          &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
        },
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
        &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
        &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
        &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
        &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
        &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
        &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
          &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
        },
        &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
        &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
        &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
          &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
          &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
        },
        &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
        &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
        &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
        &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
        &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
        &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
        &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
        &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
      },
    ],
    &quot;kind&quot;: &quot;storage#objects&quot;, # The kind of item this is. For lists of objects, this is always storage#objects.
    &quot;nextPageToken&quot;: &quot;A String&quot;, # The continuation token, used to page through large result sets. Provide this value in a subsequent request to return the next page of results.
    &quot;prefixes&quot;: [ # The list of prefixes of objects matching-but-not-listed up to and including the requested delimiter.
      &quot;A String&quot;,
    ],
  }</pre>
</div>

<div class="method">
    <code class="details" id="list_next">list_next(previous_request, previous_response)</code>
  <pre>Retrieves the next page of results.

Args:
  previous_request: The request for the previous page. (required)
  previous_response: The response from the request for the previous page. (required)

Returns:
  A request object that you can call &#x27;execute()&#x27; on to request the next
  page. Returns None if there are no more items in the collection.
    </pre>
</div>

<div class="method">
    <code class="details" id="patch">patch(bucket, object, body=None, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, predefinedAcl=None, projection=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Patches an object&#x27;s metadata.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  body: object, The request body.
    The object takes the form of:

{ # An object.
  &quot;acl&quot;: [ # Access controls on the object.
    { # An access-control entry.
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
      &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
      &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
      &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
          # - user-userId
          # - user-email
          # - group-groupId
          # - group-email
          # - domain-domain
          # - project-team-projectId
          # - allUsers
          # - allAuthenticatedUsers Examples:
          # - The user liz@example.com would be user-liz@example.com.
          # - The group example@googlegroups.com would be group-example@googlegroups.com.
          # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
      &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
      &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
      &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
        &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
        &quot;team&quot;: &quot;A String&quot;, # The team.
      },
      &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
    },
  ],
  &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
  &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
  &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
  &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
  &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
  &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
  &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
  &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
  &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
  &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
    &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
    &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
  },
  &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
  &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
  &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
  &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
  &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
  &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
  &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
  &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
  &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
    &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
  },
  &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
  &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
  &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
    &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
    &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
  },
  &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
  &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
  &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
  &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
  &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
  &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
  &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
  &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
  &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
}

  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration does not match the given value.
  predefinedAcl: string, Apply a predefined set of access controls to this object.
    Allowed values
      authenticatedRead - Object owner gets OWNER access, and allAuthenticatedUsers get READER access.
      bucketOwnerFullControl - Object owner gets OWNER access, and project team owners get OWNER access.
      bucketOwnerRead - Object owner gets OWNER access, and project team owners get READER access.
      private - Object owner gets OWNER access.
      projectPrivate - Object owner gets OWNER access, and project team members get access according to their roles.
      publicRead - Object owner gets OWNER access, and allUsers get READER access.
  projection: string, Set of properties to return. Defaults to full.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request, for Requester Pays buckets.

Returns:
  An object of the form:

    { # An object.
    &quot;acl&quot;: [ # Access controls on the object.
      { # An access-control entry.
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
        &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
        &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
        &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
            # - user-userId
            # - user-email
            # - group-groupId
            # - group-email
            # - domain-domain
            # - project-team-projectId
            # - allUsers
            # - allAuthenticatedUsers Examples:
            # - The user liz@example.com would be user-liz@example.com.
            # - The group example@googlegroups.com would be group-example@googlegroups.com.
            # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
        &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
        &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
        &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
          &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
          &quot;team&quot;: &quot;A String&quot;, # The team.
        },
        &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
      },
    ],
    &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
    &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
    &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
    &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
    &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
    &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
    &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
    &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
    &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
    &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
      &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
      &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
    },
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
    &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
    &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
    &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
    &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
    &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
    &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
    &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
    &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
      &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
    },
    &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
    &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
    &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
      &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
    },
    &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
    &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
    &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
    &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
    &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
    &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
    &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
    &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
    &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
  }</pre>
</div>

<div class="method">
    <code class="details" id="rewrite">rewrite(sourceBucket, sourceObject, destinationBucket, destinationObject, body=None, destinationKmsKeyName=None, destinationPredefinedAcl=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, ifSourceGenerationMatch=None, ifSourceGenerationNotMatch=None, ifSourceMetagenerationMatch=None, ifSourceMetagenerationNotMatch=None, maxBytesRewrittenPerCall=None, projection=None, provisionalUserProject=None, rewriteToken=None, sourceGeneration=None, userProject=None)</code>
  <pre>Rewrites a source object to a destination object. Optionally overrides metadata.

Args:
  sourceBucket: string, Name of the bucket in which to find the source object. (required)
  sourceObject: string, Name of the source object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  destinationBucket: string, Name of the bucket in which to store the new object. Overrides the provided object metadata&#x27;s bucket value, if any. (required)
  destinationObject: string, Name of the new object. Required when the object metadata is not otherwise provided. Overrides the object metadata&#x27;s name value, if any. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  body: object, The request body.
    The object takes the form of:

{ # An object.
  &quot;acl&quot;: [ # Access controls on the object.
    { # An access-control entry.
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
      &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
      &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
      &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
          # - user-userId
          # - user-email
          # - group-groupId
          # - group-email
          # - domain-domain
          # - project-team-projectId
          # - allUsers
          # - allAuthenticatedUsers Examples:
          # - The user liz@example.com would be user-liz@example.com.
          # - The group example@googlegroups.com would be group-example@googlegroups.com.
          # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
      &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
      &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
      &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
        &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
        &quot;team&quot;: &quot;A String&quot;, # The team.
      },
      &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
    },
  ],
  &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
  &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
  &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
  &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
  &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
  &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
  &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
  &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
  &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
  &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
    &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
    &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
  },
  &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
  &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
  &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
  &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
  &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
  &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
  &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
  &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
  &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
    &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
  },
  &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
  &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
  &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
    &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
    &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
  },
  &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
  &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
  &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
  &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
  &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
  &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
  &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
  &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
  &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
}

  destinationKmsKeyName: string, Resource name of the Cloud KMS key, of the form projects/my-project/locations/global/keyRings/my-kr/cryptoKeys/my-key, that will be used to encrypt the object. Overrides the object metadata&#x27;s kms_key_name value, if any.
  destinationPredefinedAcl: string, Apply a predefined set of access controls to the destination object.
    Allowed values
      authenticatedRead - Object owner gets OWNER access, and allAuthenticatedUsers get READER access.
      bucketOwnerFullControl - Object owner gets OWNER access, and project team owners get OWNER access.
      bucketOwnerRead - Object owner gets OWNER access, and project team owners get READER access.
      private - Object owner gets OWNER access.
      projectPrivate - Object owner gets OWNER access, and project team members get access according to their roles.
      publicRead - Object owner gets OWNER access, and allUsers get READER access.
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the destination object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the destination object&#x27;s current metageneration does not match the given value.
  ifSourceGenerationMatch: string, Makes the operation conditional on whether the source object&#x27;s current generation matches the given value.
  ifSourceGenerationNotMatch: string, Makes the operation conditional on whether the source object&#x27;s current generation does not match the given value.
  ifSourceMetagenerationMatch: string, Makes the operation conditional on whether the source object&#x27;s current metageneration matches the given value.
  ifSourceMetagenerationNotMatch: string, Makes the operation conditional on whether the source object&#x27;s current metageneration does not match the given value.
  maxBytesRewrittenPerCall: string, The maximum number of bytes that will be rewritten per rewrite request. Most callers shouldn&#x27;t need to specify this parameter - it is primarily in place to support testing. If specified the value must be an integral multiple of 1 MiB (1048576). Also, this only applies to requests where the source and destination span locations and/or storage classes. Finally, this value must not change across rewrite calls else you&#x27;ll get an error that the rewriteToken is invalid.
  projection: string, Set of properties to return. Defaults to noAcl, unless the object resource specifies the acl property, when it defaults to full.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  rewriteToken: string, Include this field (from the previous rewrite response) on each rewrite request after the first one, until the rewrite response &#x27;done&#x27; flag is true. Calls that provide a rewriteToken can omit all other request fields, but if included those fields must match the values provided in the first rewrite request.
  sourceGeneration: string, If present, selects a specific revision of the source object (as opposed to the latest version, the default).
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # A rewrite response.
    &quot;done&quot;: True or False, # true if the copy is finished; otherwise, false if the copy is in progress. This property is always present in the response.
    &quot;kind&quot;: &quot;storage#rewriteResponse&quot;, # The kind of item this is.
    &quot;objectSize&quot;: &quot;A String&quot;, # The total size of the object being copied in bytes. This property is always present in the response.
    &quot;resource&quot;: { # An object. # A resource containing the metadata for the copied-to object. This property is present in the response only when copying completes.
      &quot;acl&quot;: [ # Access controls on the object.
        { # An access-control entry.
          &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
          &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
          &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
          &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
              # - user-userId
              # - user-email
              # - group-groupId
              # - group-email
              # - domain-domain
              # - project-team-projectId
              # - allUsers
              # - allAuthenticatedUsers Examples:
              # - The user liz@example.com would be user-liz@example.com.
              # - The group example@googlegroups.com would be group-example@googlegroups.com.
              # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
          &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
          &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
          &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
          &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
          &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
          &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
          &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
            &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
            &quot;team&quot;: &quot;A String&quot;, # The team.
          },
          &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
          &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
        },
      ],
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
      &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
      &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
      &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
      &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
      &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
      &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
      &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
      &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
      &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
        &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
        &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
      },
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
      &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
      &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
      &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
      &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
      &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
      &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
        &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
      },
      &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
      &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
      &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
        &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
      },
      &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
      &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
      &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
      &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
      &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
      &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
      &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
      &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
    },
    &quot;rewriteToken&quot;: &quot;A String&quot;, # A token to use in subsequent requests to continue copying data. This token is present in the response only when there is more data to copy.
    &quot;totalBytesRewritten&quot;: &quot;A String&quot;, # The total bytes written so far, which can be used to provide a waiting user with a progress indicator. This property is always present in the response.
  }</pre>
</div>

<div class="method">
    <code class="details" id="setIamPolicy">setIamPolicy(bucket, object, body=None, generation=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Updates an IAM policy for the specified object.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  body: object, The request body.
    The object takes the form of:

{ # A bucket/object IAM policy.
  &quot;bindings&quot;: [ # An association between a role, which comes with a set of permissions, and members who may assume that role.
    {
      &quot;condition&quot;: { # Represents an expression text. Example: title: &quot;User account presence&quot; description: &quot;Determines whether the request has a user account&quot; expression: &quot;size(request.user) &gt; 0&quot; # The condition that is associated with this binding. NOTE: an unsatisfied condition will not allow user access via current binding. Different bindings, including their conditions, are examined independently.
        &quot;description&quot;: &quot;A String&quot;, # An optional description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.
        &quot;expression&quot;: &quot;A String&quot;, # Textual representation of an expression in Common Expression Language syntax. The application context of the containing message determines which well-known feature set of CEL is supported.
        &quot;location&quot;: &quot;A String&quot;, # An optional string indicating the location of the expression for error reporting, e.g. a file name and a position in the file.
        &quot;title&quot;: &quot;A String&quot;, # An optional title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.
      },
      &quot;members&quot;: [ # A collection of identifiers for members who may assume the provided role. Recognized identifiers are as follows:
          # - allUsers — A special identifier that represents anyone on the internet; with or without a Google account.
          # - allAuthenticatedUsers — A special identifier that represents anyone who is authenticated with a Google account or a service account.
          # - user:emailid — An email address that represents a specific account. For example, user:alice@gmail.com or user:joe@example.com.
          # - serviceAccount:emailid — An email address that represents a service account. For example,  serviceAccount:my-other-app@appspot.gserviceaccount.com .
          # - group:emailid — An email address that represents a Google group. For example, group:admins@example.com.
          # - domain:domain — A Google Apps domain name that represents all the users of that domain. For example, domain:google.com or domain:example.com.
          # - projectOwner:projectid — Owners of the given project. For example, projectOwner:my-example-project
          # - projectEditor:projectid — Editors of the given project. For example, projectEditor:my-example-project
          # - projectViewer:projectid — Viewers of the given project. For example, projectViewer:my-example-project
        &quot;A String&quot;,
      ],
      &quot;role&quot;: &quot;A String&quot;, # The role to which members belong. Two types of roles are supported: new IAM roles, which grant permissions that do not map directly to those provided by ACLs, and legacy IAM roles, which do map directly to ACL permissions. All roles are of the format roles/storage.specificRole.
          # The new IAM roles are:
          # - roles/storage.admin — Full control of Google Cloud Storage resources.
          # - roles/storage.objectViewer — Read-Only access to Google Cloud Storage objects.
          # - roles/storage.objectCreator — Access to create objects in Google Cloud Storage.
          # - roles/storage.objectAdmin — Full control of Google Cloud Storage objects.   The legacy IAM roles are:
          # - roles/storage.legacyObjectReader — Read-only access to objects without listing. Equivalent to an ACL entry on an object with the READER role.
          # - roles/storage.legacyObjectOwner — Read/write access to existing objects without listing. Equivalent to an ACL entry on an object with the OWNER role.
          # - roles/storage.legacyBucketReader — Read access to buckets with object listing. Equivalent to an ACL entry on a bucket with the READER role.
          # - roles/storage.legacyBucketWriter — Read access to buckets with object listing/creation/deletion. Equivalent to an ACL entry on a bucket with the WRITER role.
          # - roles/storage.legacyBucketOwner — Read and write access to existing buckets with object listing/creation/deletion. Equivalent to an ACL entry on a bucket with the OWNER role.
    },
  ],
  &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1  Entity tag for the policy.
  &quot;kind&quot;: &quot;storage#policy&quot;, # The kind of item this is. For policies, this is always storage#policy. This field is ignored on input.
  &quot;resourceId&quot;: &quot;A String&quot;, # The ID of the resource to which this policy belongs. Will be of the form projects/_/buckets/bucket for buckets, and projects/_/buckets/bucket/objects/object for objects. A specific generation may be specified by appending #generationNumber to the end of the object name, e.g. projects/_/buckets/my-bucket/objects/data.txt#17. The current generation can be denoted with #0. This field is ignored on input.
  &quot;version&quot;: 42, # The IAM policy format version.
}

  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # A bucket/object IAM policy.
    &quot;bindings&quot;: [ # An association between a role, which comes with a set of permissions, and members who may assume that role.
      {
        &quot;condition&quot;: { # Represents an expression text. Example: title: &quot;User account presence&quot; description: &quot;Determines whether the request has a user account&quot; expression: &quot;size(request.user) &gt; 0&quot; # The condition that is associated with this binding. NOTE: an unsatisfied condition will not allow user access via current binding. Different bindings, including their conditions, are examined independently.
          &quot;description&quot;: &quot;A String&quot;, # An optional description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.
          &quot;expression&quot;: &quot;A String&quot;, # Textual representation of an expression in Common Expression Language syntax. The application context of the containing message determines which well-known feature set of CEL is supported.
          &quot;location&quot;: &quot;A String&quot;, # An optional string indicating the location of the expression for error reporting, e.g. a file name and a position in the file.
          &quot;title&quot;: &quot;A String&quot;, # An optional title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.
        },
        &quot;members&quot;: [ # A collection of identifiers for members who may assume the provided role. Recognized identifiers are as follows:
            # - allUsers — A special identifier that represents anyone on the internet; with or without a Google account.
            # - allAuthenticatedUsers — A special identifier that represents anyone who is authenticated with a Google account or a service account.
            # - user:emailid — An email address that represents a specific account. For example, user:alice@gmail.com or user:joe@example.com.
            # - serviceAccount:emailid — An email address that represents a service account. For example,  serviceAccount:my-other-app@appspot.gserviceaccount.com .
            # - group:emailid — An email address that represents a Google group. For example, group:admins@example.com.
            # - domain:domain — A Google Apps domain name that represents all the users of that domain. For example, domain:google.com or domain:example.com.
            # - projectOwner:projectid — Owners of the given project. For example, projectOwner:my-example-project
            # - projectEditor:projectid — Editors of the given project. For example, projectEditor:my-example-project
            # - projectViewer:projectid — Viewers of the given project. For example, projectViewer:my-example-project
          &quot;A String&quot;,
        ],
        &quot;role&quot;: &quot;A String&quot;, # The role to which members belong. Two types of roles are supported: new IAM roles, which grant permissions that do not map directly to those provided by ACLs, and legacy IAM roles, which do map directly to ACL permissions. All roles are of the format roles/storage.specificRole.
            # The new IAM roles are:
            # - roles/storage.admin — Full control of Google Cloud Storage resources.
            # - roles/storage.objectViewer — Read-Only access to Google Cloud Storage objects.
            # - roles/storage.objectCreator — Access to create objects in Google Cloud Storage.
            # - roles/storage.objectAdmin — Full control of Google Cloud Storage objects.   The legacy IAM roles are:
            # - roles/storage.legacyObjectReader — Read-only access to objects without listing. Equivalent to an ACL entry on an object with the READER role.
            # - roles/storage.legacyObjectOwner — Read/write access to existing objects without listing. Equivalent to an ACL entry on an object with the OWNER role.
            # - roles/storage.legacyBucketReader — Read access to buckets with object listing. Equivalent to an ACL entry on a bucket with the READER role.
            # - roles/storage.legacyBucketWriter — Read access to buckets with object listing/creation/deletion. Equivalent to an ACL entry on a bucket with the WRITER role.
            # - roles/storage.legacyBucketOwner — Read and write access to existing buckets with object listing/creation/deletion. Equivalent to an ACL entry on a bucket with the OWNER role.
      },
    ],
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1  Entity tag for the policy.
    &quot;kind&quot;: &quot;storage#policy&quot;, # The kind of item this is. For policies, this is always storage#policy. This field is ignored on input.
    &quot;resourceId&quot;: &quot;A String&quot;, # The ID of the resource to which this policy belongs. Will be of the form projects/_/buckets/bucket for buckets, and projects/_/buckets/bucket/objects/object for objects. A specific generation may be specified by appending #generationNumber to the end of the object name, e.g. projects/_/buckets/my-bucket/objects/data.txt#17. The current generation can be denoted with #0. This field is ignored on input.
    &quot;version&quot;: 42, # The IAM policy format version.
  }</pre>
</div>

<div class="method">
    <code class="details" id="testIamPermissions">testIamPermissions(bucket, object, permissions, generation=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Tests a set of permissions on the given object to see which, if any, are held by the caller.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  permissions: string, Permissions to test. (required) (repeated)
  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # A storage.(buckets|objects).testIamPermissions response.
    &quot;kind&quot;: &quot;storage#testIamPermissionsResponse&quot;, # The kind of item this is.
    &quot;permissions&quot;: [ # The permissions held by the caller. Permissions are always of the format storage.resource.capability, where resource is one of buckets or objects. The supported permissions are as follows:
        # - storage.buckets.delete — Delete bucket.
        # - storage.buckets.get — Read bucket metadata.
        # - storage.buckets.getIamPolicy — Read bucket IAM policy.
        # - storage.buckets.create — Create bucket.
        # - storage.buckets.list — List buckets.
        # - storage.buckets.setIamPolicy — Update bucket IAM policy.
        # - storage.buckets.update — Update bucket metadata.
        # - storage.objects.delete — Delete object.
        # - storage.objects.get — Read object data and metadata.
        # - storage.objects.getIamPolicy — Read object IAM policy.
        # - storage.objects.create — Create object.
        # - storage.objects.list — List objects.
        # - storage.objects.setIamPolicy — Update object IAM policy.
        # - storage.objects.update — Update object metadata.
      &quot;A String&quot;,
    ],
  }</pre>
</div>

<div class="method">
    <code class="details" id="update">update(bucket, object, body=None, generation=None, ifGenerationMatch=None, ifGenerationNotMatch=None, ifMetagenerationMatch=None, ifMetagenerationNotMatch=None, predefinedAcl=None, projection=None, provisionalUserProject=None, userProject=None)</code>
  <pre>Updates an object&#x27;s metadata.

Args:
  bucket: string, Name of the bucket in which the object resides. (required)
  object: string, Name of the object. For information about how to URL encode object names to be path safe, see Encoding URI Path Parts. (required)
  body: object, The request body.
    The object takes the form of:

{ # An object.
  &quot;acl&quot;: [ # Access controls on the object.
    { # An access-control entry.
      &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
      &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
      &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
      &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
          # - user-userId
          # - user-email
          # - group-groupId
          # - group-email
          # - domain-domain
          # - project-team-projectId
          # - allUsers
          # - allAuthenticatedUsers Examples:
          # - The user liz@example.com would be user-liz@example.com.
          # - The group example@googlegroups.com would be group-example@googlegroups.com.
          # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
      &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
      &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
      &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
      &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
      &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
      &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
        &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
        &quot;team&quot;: &quot;A String&quot;, # The team.
      },
      &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
      &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
    },
  ],
  &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
  &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
  &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
  &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
  &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
  &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
  &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
  &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
  &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
  &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
    &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
    &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
  },
  &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
  &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
  &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
  &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
  &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
  &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
  &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
  &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
  &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
    &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
  },
  &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
  &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
  &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
    &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
    &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
  },
  &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
  &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
  &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
  &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
  &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
  &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
  &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
  &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
  &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
}

  generation: string, If present, selects a specific revision of this object (as opposed to the latest version, the default).
  ifGenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current generation matches the given value. Setting to 0 makes the operation succeed only if there are no live versions of the object.
  ifGenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current generation does not match the given value. If no live object exists, the precondition fails. Setting to 0 makes the operation succeed only if there is a live version of the object.
  ifMetagenerationMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration matches the given value.
  ifMetagenerationNotMatch: string, Makes the operation conditional on whether the object&#x27;s current metageneration does not match the given value.
  predefinedAcl: string, Apply a predefined set of access controls to this object.
    Allowed values
      authenticatedRead - Object owner gets OWNER access, and allAuthenticatedUsers get READER access.
      bucketOwnerFullControl - Object owner gets OWNER access, and project team owners get OWNER access.
      bucketOwnerRead - Object owner gets OWNER access, and project team owners get READER access.
      private - Object owner gets OWNER access.
      projectPrivate - Object owner gets OWNER access, and project team members get access according to their roles.
      publicRead - Object owner gets OWNER access, and allUsers get READER access.
  projection: string, Set of properties to return. Defaults to full.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.

Returns:
  An object of the form:

    { # An object.
    &quot;acl&quot;: [ # Access controls on the object.
      { # An access-control entry.
        &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket.
        &quot;domain&quot;: &quot;A String&quot;, # The domain associated with the entity, if any.
        &quot;email&quot;: &quot;A String&quot;, # The email address associated with the entity, if any.
        &quot;entity&quot;: &quot;A String&quot;, # The entity holding the permission, in one of the following forms:
            # - user-userId
            # - user-email
            # - group-groupId
            # - group-email
            # - domain-domain
            # - project-team-projectId
            # - allUsers
            # - allAuthenticatedUsers Examples:
            # - The user liz@example.com would be user-liz@example.com.
            # - The group example@googlegroups.com would be group-example@googlegroups.com.
            # - To refer to all members of the Google Apps for Business domain example.com, the entity would be domain-example.com.
        &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity, if any.
        &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the access-control entry.
        &quot;generation&quot;: &quot;A String&quot;, # The content generation of the object, if applied to an object.
        &quot;id&quot;: &quot;A String&quot;, # The ID of the access-control entry.
        &quot;kind&quot;: &quot;storage#objectAccessControl&quot;, # The kind of item this is. For object access control entries, this is always storage#objectAccessControl.
        &quot;object&quot;: &quot;A String&quot;, # The name of the object, if applied to an object.
        &quot;projectTeam&quot;: { # The project team associated with the entity, if any.
          &quot;projectNumber&quot;: &quot;A String&quot;, # The project number.
          &quot;team&quot;: &quot;A String&quot;, # The team.
        },
        &quot;role&quot;: &quot;A String&quot;, # The access permission for the entity.
        &quot;selfLink&quot;: &quot;A String&quot;, # The link to this access-control entry.
      },
    ],
    &quot;bucket&quot;: &quot;A String&quot;, # The name of the bucket containing this object.
    &quot;cacheControl&quot;: &quot;A String&quot;, # Cache-Control directive for the object data. If omitted, and the object is accessible to all anonymous users, the default will be public, max-age=3600.
    &quot;componentCount&quot;: 42, # Number of underlying components that make up this object. Components are accumulated by compose operations.
    &quot;contentDisposition&quot;: &quot;A String&quot;, # Content-Disposition of the object data.
    &quot;contentEncoding&quot;: &quot;A String&quot;, # Content-Encoding of the object data.
    &quot;contentLanguage&quot;: &quot;A String&quot;, # Content-Language of the object data.
    &quot;contentType&quot;: &quot;A String&quot;, # Content-Type of the object data. If an object is stored without a Content-Type, it is served as application/octet-stream.
    &quot;crc32c&quot;: &quot;A String&quot;, # CRC32c checksum, as described in RFC 4960, Appendix B; encoded using base64 in big-endian byte order. For more information about using the CRC32c checksum, see Hashes and ETags: Best Practices.
    &quot;customTime&quot;: &quot;A String&quot;, # A timestamp in RFC 3339 format specified by the user for an object.
    &quot;customerEncryption&quot;: { # Metadata of customer-supplied encryption key, if the object is encrypted by such a key.
      &quot;encryptionAlgorithm&quot;: &quot;A String&quot;, # The encryption algorithm.
      &quot;keySha256&quot;: &quot;A String&quot;, # SHA256 hash value of the encryption key.
    },
    &quot;etag&quot;: &quot;A String&quot;, # HTTP 1.1 Entity tag for the object.
    &quot;eventBasedHold&quot;: True or False, # Whether an object is under event-based hold. Event-based hold is a way to retain objects until an event occurs, which is signified by the hold&#x27;s release (i.e. this value is set to false). After being released (set to false), such objects will be subject to bucket-level retention (if any). One sample use case of this flag is for banks to hold loan documents for at least 3 years after loan is paid in full. Here, bucket-level retention is 3 years and the event is the loan being paid in full. In this example, these objects will be held intact for any number of years until the event has occurred (event-based hold on the object is released) and then 3 more years after that. That means retention duration of the objects begins from the moment event-based hold transitioned from true to false.
    &quot;generation&quot;: &quot;A String&quot;, # The content generation of this object. Used for object versioning.
    &quot;id&quot;: &quot;A String&quot;, # The ID of the object, including the bucket name, object name, and generation number.
    &quot;kind&quot;: &quot;storage#object&quot;, # The kind of item this is. For objects, this is always storage#object.
    &quot;kmsKeyName&quot;: &quot;A String&quot;, # Cloud KMS Key used to encrypt this object, if the object is encrypted by such a key.
    &quot;md5Hash&quot;: &quot;A String&quot;, # MD5 hash of the data; encoded using base64. For more information about using the MD5 hash, see Hashes and ETags: Best Practices.
    &quot;mediaLink&quot;: &quot;A String&quot;, # Media download link.
    &quot;metadata&quot;: { # User-provided metadata, in key/value pairs.
      &quot;a_key&quot;: &quot;A String&quot;, # An individual metadata entry.
    },
    &quot;metageneration&quot;: &quot;A String&quot;, # The version of the metadata for this object at this generation. Used for preconditions and for detecting changes in metadata. A metageneration number is only meaningful in the context of a particular generation of a particular object.
    &quot;name&quot;: &quot;A String&quot;, # The name of the object. Required if not specified by URL parameter.
    &quot;owner&quot;: { # The owner of the object. This will always be the uploader of the object.
      &quot;entity&quot;: &quot;A String&quot;, # The entity, in the form user-userId.
      &quot;entityId&quot;: &quot;A String&quot;, # The ID for the entity.
    },
    &quot;retentionExpirationTime&quot;: &quot;A String&quot;, # A server-determined value that specifies the earliest time that the object&#x27;s retention period expires. This value is in RFC 3339 format. Note 1: This field is not provided for objects with an active event-based hold, since retention expiration is unknown until the hold is removed. Note 2: This value can be provided even when temporary hold is set (so that the user can reason about policy without having to first unset the temporary hold).
    &quot;selfLink&quot;: &quot;A String&quot;, # The link to this object.
    &quot;size&quot;: &quot;A String&quot;, # Content-Length of the data in bytes.
    &quot;storageClass&quot;: &quot;A String&quot;, # Storage class of the object.
    &quot;temporaryHold&quot;: True or False, # Whether an object is under temporary hold. While this flag is set to true, the object is protected against deletion and overwrites. A common use case of this flag is regulatory investigations where objects need to be retained while the investigation is ongoing. Note that unlike event-based hold, temporary hold does not impact retention expiration time of an object.
    &quot;timeCreated&quot;: &quot;A String&quot;, # The creation time of the object in RFC 3339 format.
    &quot;timeDeleted&quot;: &quot;A String&quot;, # The deletion time of the object in RFC 3339 format. Will be returned if and only if this version of the object has been deleted.
    &quot;timeStorageClassUpdated&quot;: &quot;A String&quot;, # The time at which the object&#x27;s storage class was last changed. When the object is initially created, it will be set to timeCreated.
    &quot;updated&quot;: &quot;A String&quot;, # The modification time of the object metadata in RFC 3339 format.
  }</pre>
</div>

<div class="method">
    <code class="details" id="watchAll">watchAll(bucket, body=None, delimiter=None, endOffset=None, includeTrailingDelimiter=None, maxResults=None, pageToken=None, prefix=None, projection=None, provisionalUserProject=None, startOffset=None, userProject=None, versions=None)</code>
  <pre>Watch for changes on all objects in a bucket.

Args:
  bucket: string, Name of the bucket in which to look for objects. (required)
  body: object, The request body.
    The object takes the form of:

{ # An notification channel used to watch for resource changes.
    &quot;address&quot;: &quot;A String&quot;, # The address where notifications are delivered for this channel.
    &quot;expiration&quot;: &quot;A String&quot;, # Date and time of notification channel expiration, expressed as a Unix timestamp, in milliseconds. Optional.
    &quot;id&quot;: &quot;A String&quot;, # A UUID or similar unique string that identifies this channel.
    &quot;kind&quot;: &quot;api#channel&quot;, # Identifies this as a notification channel used to watch for changes to a resource, which is &quot;api#channel&quot;.
    &quot;params&quot;: { # Additional parameters controlling delivery channel behavior. Optional.
      &quot;a_key&quot;: &quot;A String&quot;, # Declares a new parameter by name.
    },
    &quot;payload&quot;: True or False, # A Boolean value to indicate whether payload is wanted. Optional.
    &quot;resourceId&quot;: &quot;A String&quot;, # An opaque ID that identifies the resource being watched on this channel. Stable across different API versions.
    &quot;resourceUri&quot;: &quot;A String&quot;, # A version-specific identifier for the watched resource.
    &quot;token&quot;: &quot;A String&quot;, # An arbitrary string delivered to the target address with each notification delivered over this channel. Optional.
    &quot;type&quot;: &quot;A String&quot;, # The type of delivery mechanism used for this channel.
  }

  delimiter: string, Returns results in a directory-like mode. items will contain only objects whose names, aside from the prefix, do not contain delimiter. Objects whose names, aside from the prefix, contain delimiter will have their name, truncated after the delimiter, returned in prefixes. Duplicate prefixes are omitted.
  endOffset: string, Filter results to objects whose names are lexicographically before endOffset. If startOffset is also set, the objects listed will have names between startOffset (inclusive) and endOffset (exclusive).
  includeTrailingDelimiter: boolean, If true, objects that end in exactly one instance of delimiter will have their metadata included in items in addition to prefixes.
  maxResults: integer, Maximum number of items plus prefixes to return in a single page of responses. As duplicate prefixes are omitted, fewer total results may be returned than requested. The service will use this parameter or 1,000 items, whichever is smaller.
  pageToken: string, A previously-returned page token representing part of the larger set of results to view.
  prefix: string, Filter results to objects whose names begin with this prefix.
  projection: string, Set of properties to return. Defaults to noAcl.
    Allowed values
      full - Include all properties.
      noAcl - Omit the owner, acl property.
  provisionalUserProject: string, The project to be billed for this request if the target bucket is requester-pays bucket.
  startOffset: string, Filter results to objects whose names are lexicographically equal to or after startOffset. If endOffset is also set, the objects listed will have names between startOffset (inclusive) and endOffset (exclusive).
  userProject: string, The project to be billed for this request. Required for Requester Pays buckets.
  versions: boolean, If true, lists all versions of an object as distinct results. The default is false. For more information, see Object Versioning.

Returns:
  An object of the form:

    { # An notification channel used to watch for resource changes.
      &quot;address&quot;: &quot;A String&quot;, # The address where notifications are delivered for this channel.
      &quot;expiration&quot;: &quot;A String&quot;, # Date and time of notification channel expiration, expressed as a Unix timestamp, in milliseconds. Optional.
      &quot;id&quot;: &quot;A String&quot;, # A UUID or similar unique string that identifies this channel.
      &quot;kind&quot;: &quot;api#channel&quot;, # Identifies this as a notification channel used to watch for changes to a resource, which is &quot;api#channel&quot;.
      &quot;params&quot;: { # Additional parameters controlling delivery channel behavior. Optional.
        &quot;a_key&quot;: &quot;A String&quot;, # Declares a new parameter by name.
      },
      &quot;payload&quot;: True or False, # A Boolean value to indicate whether payload is wanted. Optional.
      &quot;resourceId&quot;: &quot;A String&quot;, # An opaque ID that identifies the resource being watched on this channel. Stable across different API versions.
      &quot;resourceUri&quot;: &quot;A String&quot;, # A version-specific identifier for the watched resource.
      &quot;token&quot;: &quot;A String&quot;, # An arbitrary string delivered to the target address with each notification delivered over this channel. Optional.
      &quot;type&quot;: &quot;A String&quot;, # The type of delivery mechanism used for this channel.
    }</pre>
</div>

</body></html>