§
    ~Štjò  ã                  óÞ   — d Z ddlmZ ddlmZ ddlmZmZmZ  G d„ de¦  «        Z	e
eef         Ze
eef         Zd0d„Zd1d„Zd2d„Zd3d„Zd4d„Zd5d„Zddddœd6d"„Zd#d$d%œd7d*„Zdd+d$d,œd8d/„ZdS )9z2Helpers for building sandbox proxy configurations.é    )Úannotations)ÚSequence)ÚAnyÚLiteralÚ	TypedDictc                  ó(   — e Zd ZU dZded<   ded<   dS )ÚSandboxProxySecretz7A secret value that can be used by sandbox proxy rules.z%Literal['workspace_secret', 'opaque']ÚtypeÚstrÚvalueN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ú__annotations__© ó    ú]/var/www/html/CA-Chatbot/venv/lib/python3.11/site-packages/langsmith/sandbox/_proxy_config.pyr	   r	   	   s+   € € € € € € ØAÐAà/Ð/Ð/Ñ/Ø€J€J�J€J€Jr   r	   r   r   ÚfieldÚreturnc                ó    — t          | t          ¦  «        r|                      ¦   «         st          |› d�¦  «        ‚|                      ¦   «         S )Nz must be a non-empty string)Ú
isinstancer   ÚstripÚ
ValueError)r   r   s     r   Ú_require_non_empty_stringr      sJ   € Ý�e�SÑ!Ô!ð @¨¯ª©¬ð @Ý˜EÐ>Ð>Ð>Ñ?Ô?Ð?Ø�;Š;‰=Œ=Ðr   ÚvaluesúSequence[str]ú	list[str]c                óv   ‡— t          | t          ¦  «        s| st          ‰› d�¦  «        ‚ˆfd„| D ¦   «         }|S )Nz$ must be a non-empty list of stringsc                ó0   •— g | ]}t          |‰¦  «        ‘ŒS r   ©r   )Ú.0r   r   s     €r   ú
<listcomp>z2_require_non_empty_string_list.<locals>.<listcomp>   s$   ø€ ÐNÐNÐN¸eÕ+¨E°5Ñ9Ô9ÐNÐNÐNr   )r   r   r   )r   r   Ú
normalizeds    ` r   Ú_require_non_empty_string_listr%      sT   ø€ Ý�&�#ÑÔð I fð IÝ˜EÐGÐGÐGÑHÔHÐHØNÐNÐNÐNÀvÐNÑNÔN€JØÐr   Únamec                ó  — t          | d¦  «        }|                     d¦  «        }|                     d¦  «        }||k    rt          d¦  «        ‚|r+|dd…                              ¦   «         st          d¦  «        ‚|r|nd|› d�}d|d	œS )
a"  Create a LangSmith workspace secret reference for a proxy configuration.

    Args:
        name: Workspace secret name, with or without surrounding braces.

    Returns:
        A proxy secret reference such as
        ``{"type": "workspace_secret", "value": "{AWS_ACCESS_KEY_ID}"}``.
    r&   Ú{Ú}z5workspace secret must be a name or a {NAME} referenceé   éÿÿÿÿz.workspace secret reference must contain a nameÚworkspace_secret©r
   r   )r   Ú
startswithÚendswithr   r   )r&   r$   ÚstartsÚendsr   s        r   r,   r,   !   s®   € õ +¨4°Ñ8Ô8€JØ×"Ò" 3Ñ'Ô'€FØ×Ò˜sÑ#Ô#€DØ�‚~€~ÝÐPÑQÔQÐQØð K�j  2 Ô&×,Ò,Ñ.Ô.ð KÝÐIÑJÔJÐJØ Ð9ˆJˆJÐ&9¨:Ð&9Ð&9Ð&9€EØ&°Ð7Ð7Ð7r   c                ó(   — dt          | d¦  «        dœS )záProvide a write-only secret value for a proxy configuration.

    The value is sent when creating or updating the sandbox proxy config, but
    LangSmith stores it as an opaque secret and does not return it from the API.
    Úopaquer   r-   r!   )r   s    r   Úopaque_secretr4   6   s   € ð Õ'@ÀÈÑ'PÔ'PÐQÐQÐQr   Úrulesú!Sequence[SandboxProxyRule] | Noneúlist[SandboxProxyRule]c                ó"  — | €g S t          | t          ¦  «        st          | t          ¦  «        rt          d¦  «        ‚g }| D ]L}t          |t          ¦  «        r|st          d¦  «        ‚t	          |¦  «         |                     |¦  «         ŒM|S )Nz/rules must be a list of proxy rule dictionaries)r   Údictr   r   Ú_validate_proxy_provider_ruleÚappend)r5   r$   Úrules      r   Ú_normalize_proxy_rulesr=   ?   s«   € ð €}Øˆ	Ý�%�ÑÔð L¥*¨UµCÑ"8Ô"8ð LÝÐJÑKÔKÐKØ)+€JØð  ð  ˆÝ˜$¥Ñ%Ô%ð 	P¨Tð 	PÝÐNÑOÔOÐOÝ% dÑ+Ô+Ð+Ø×Ò˜$ÑÔÐÐØÐr   r<   ÚSandboxProxyRuleÚNonec                óâ   — |                       d¦  «        dk    rd S |                       d¦  «        }t          |t          ¦  «        rd|vrt          d¦  «        ‚t	          |d         d¦  «         d S )Nr
   ÚgcpÚscopesz#gcp proxy auth rules require scopes)Úgetr   r9   r   r%   )r<   rA   s     r   r:   r:   O   ss   € Ø‡x‚x�ÑÔ˜5Ò Ð ØˆØ
�(Š(�5‰/Œ/€CÝ�c�4Ñ Ô ð @ H°CÐ$7Ð$7ÝÐ>Ñ?Ô?Ð?Ý" 3 x¤=°(Ñ;Ô;Ð;Ð;Ð;r   N)r5   Úno_proxyÚaccess_controlrD   úSequence[str] | NonerE   údict[str, Any] | NoneÚSandboxProxyConfigc                óÂ   — dt          | ¦  «        i}|�t          |d¦  «        |d<   |�6t          |t          ¦  «        st	          d¦  «        ‚t          |¦  «        |d<   |S )z»Build a sandbox proxy config from one or more proxy rules.

    Use provider-specific rule helpers such as ``aws_auth`` and ``gcp_auth``
    when a sandbox needs multiple auth flows.
    r5   NrD   z#access_control must be a dictionaryrE   )r=   r%   r   r9   r   )r5   rD   rE   Úconfigs       r   Úproxy_configrK   X   sq   € ð #*Õ+AÀ%Ñ+HÔ+HÐ!I€FØÐÝ;¸HÀjÑQÔQˆˆzÑØÐ!Ý˜.­$Ñ/Ô/ð 	DÝÐBÑCÔCÐCÝ#'¨Ñ#7Ô#7ˆÐÑ Ø€Mr   ÚawsT)r&   ÚenabledÚaccess_key_idÚsecret_access_keyrM   Úboolc                ó6   — t          |d¦  «        }|d|| |dœdœS )ac  Build a sandbox proxy rule that signs AWS HTTPS requests.

    The sandbox proxy keeps the real AWS credentials outside the sandbox and
    signs supported AWS requests with SigV4 on the sandbox's behalf. AWS
    credentials must be supplied as ``workspace_secret`` or ``opaque`` values;
    plaintext AWS credentials are intentionally not supported.
    r&   rL   )rN   rO   )r&   r
   rM   rL   r!   )rN   rO   r&   rM   Ú	rule_names        r   Úaws_authrS   m   s;   € õ *¨$°Ñ7Ô7€IàØØà*Ø!2ð
ð 
ð	ð ð r   rA   )rB   r&   rM   Úservice_account_jsonrB   c                ób   — t          |d¦  «        }d| i}|�t          |d¦  «        |d<   |d||dœS )a|  Build a sandbox proxy rule that injects GCP OAuth bearer auth.

    The sandbox proxy keeps the service account JSON outside the sandbox and
    injects OAuth bearer tokens for built-in Google API host matching.
    ``service_account_json`` must be supplied as a ``workspace_secret`` or
    ``opaque`` value; plaintext service account JSON is intentionally not
    supported.
    r&   rT   NrB   rA   )r&   r
   rM   rA   )r   r%   )rT   rB   r&   rM   rR   Ú
gcp_configs         r   Úgcp_authrW   ‡   sW   € õ *¨$°Ñ7Ô7€IàÐ 4ð"€Jð ÐÝ=¸fÀhÑOÔOˆ
�8ÑàØØØð	ð ð r   )r   r   r   r   r   r   )r   r   r   r   r   r   )r&   r   r   r	   )r   r   r   r	   )r5   r6   r   r7   )r<   r>   r   r?   )r5   r6   rD   rF   rE   rG   r   rH   )
rN   r	   rO   r	   r&   r   rM   rP   r   r>   )
rT   r	   rB   rF   r&   r   rM   rP   r   r>   )r   Ú
__future__r   Úcollections.abcr   Útypingr   r   r   r	   r9   r   r>   rH   r   r%   r,   r4   r=   r:   rK   rS   rW   r   r   r   ú<module>r[      s“  ðØ 8Ð 8à "Ð "Ð "Ð "Ð "Ð "à $Ð $Ð $Ð $Ð $Ð $Ø *Ð *Ð *Ð *Ð *Ð *Ð *Ð *Ð *Ð *ðð ð ð ð ˜ñ ô ð ð ˜˜S˜”>Ð Ø˜#˜s˜(”^Ð ðð ð ð ðð ð ð ð8ð 8ð 8ð 8ð*Rð Rð Rð Rðð ð ð ð <ð <ð <ð <ð 04Ø%)Ø,0ð	ð ð ð ð ð ð2 Øðð ð ð ð ð ð: $(ØØðð ð ð ð ð ð ð r   