§
    ˜Štj×  ã                  ó”  — d dl mZ d dlmZ d dlmZ d dlmZmZm	Z	m
Z
mZmZ d dlmZ d dlmZ d dlmZmZ  ed¦  «        Z ed	¦  «        Z G d
„ de¦  «        Ze
eef         Z G d„ de¦  «        Ze G d„ d¦  «        ¦   «         Z G d„ de¦  «        Z G d„ dee¦  «        Ze G d„ d¦  «        ¦   «         Z G d„ de¦  «        ZdS )é    )Úannotations)Úabstractmethod)ÚEnum)ÚAnyÚListÚOptionalÚDictÚTupleÚTypeVar)Ú	dataclass)Ú	SecretStr)Ú	ComponentÚSystemÚTÚSc                  ó   — e Zd ZdS )Ú	AuthErrorN)Ú__name__Ú
__module__Ú__qualname__© ó    úT/var/www/html/CA-Chatbot/venv/lib/python3.11/site-packages/chromadb/auth/__init__.pyr   r      s   € € € € € Ø€Dr   r   c                  ó<   ‡ — e Zd ZdZd	ˆ fd„Zed
d„¦   «         Zˆ xZS )ÚClientAuthProviderzÚ
    ClientAuthProvider is responsible for providing authentication headers for
    client requests. Client implementations (in our case, just the FastAPI
    client) must inject these headers into their requests.
    Úsystemr   ÚreturnÚNonec                óJ   •— t          ¦   «                              |¦  «         d S ©N©ÚsuperÚ__init__©Úselfr   Ú	__class__s     €r   r#   zClientAuthProvider.__init__(   ó!   ø€ Ý‰Œ×Ò˜Ñ Ô Ð Ð Ð r   ÚClientAuthHeadersc                ó   — d S r    r   )r%   s    r   ÚauthenticatezClientAuthProvider.authenticate+   ó   € àˆr   ©r   r   r   r   )r   r(   )r   r   r   Ú__doc__r#   r   r*   Ú__classcell__©r&   s   @r   r   r   !   sg   ø€ € € € € ðð ð!ð !ð !ð !ð !ð !ð ðð ð ñ „^ðð ð ð ð r   r   c                  óH   — e Zd ZU dZded<   dZded<   dZded<   dZd	ed
<   dS )ÚUserIdentitya™  
    UserIdentity represents the identity of a user. In general, not all fields
    will be populated, and the fields that are populated will depend on the
    authentication provider.

    The idea is that the AuthenticationProvider is responsible for populating
    _all_ information known about the user, and the AuthorizationProvider is
    responsible for making decisions based on that information.
    ÚstrÚuser_idNúOptional[str]ÚtenantzOptional[List[str]]Ú	databaseszOptional[Dict[str, Any]]Ú
attributes)r   r   r   r-   Ú__annotations__r5   r6   r7   r   r   r   r1   r1   0   s\   € € € € € € ðð ð €L€L�LØ €FÐ Ð Ð Ñ Ø%)€IÐ)Ð)Ð)Ñ)ð ,0€JÐ/Ð/Ð/Ñ/Ð/Ð/r   r1   c                  óT   ‡ — e Zd ZdZdˆ fd„Zedd
„¦   «         Zdd„Zdd„Zdd„Z	ˆ xZ
S )ÚServerAuthenticationProvidera¹  
    ServerAuthenticationProvider is responsible for authenticating requests. If
    a ServerAuthenticationProvider is configured, it will be called by the
    server to authenticate requests. If no ServerAuthenticationProvider is
    configured, all requests will be authenticated.

    The ServerAuthenticationProvider should return a UserIdentity object if the
    request is authenticated for use by the ServerAuthorizationProvider.
    r   r   r   r   c                óŽ   •— t          ¦   «                              |¦  «         |j        j        | _        |j        j        | _        d S r    )r"   r#   ÚsettingsÚchroma_server_auth_ignore_pathsÚ_ignore_auth_pathsÚ;chroma_overwrite_singleton_tenant_database_access_from_authÚ4overwrite_singleton_tenant_database_access_from_authr$   s     €r   r#   z%ServerAuthenticationProvider.__init__P   sE   ø€ Ý‰Œ×Ò˜Ñ Ô Ð ð ŒOÔ;ð 	Ôð ŒOÔWð 	ÔAÐAÐAr   ÚheadersúDict[str, str]r1   c                ó   — d S r    r   )r%   rA   s     r   Úauthenticate_or_raisez2ServerAuthenticationProvider.authenticate_or_raiseY   r+   r   Úverbr2   ÚpathÚboolc                ó‚   — || j                              ¦   «         v r#|                     ¦   «         | j         |         v rdS dS )NTF)r>   ÚkeysÚupper)r%   rE   rF   s      r   Úignore_operationz-ServerAuthenticationProvider.ignore_operation]   sA   € à�DÔ+×0Ò0Ñ2Ô2Ð2Ð2Ø—
’
‘” Ô 7¸Ô =Ð=Ð=à�4Øˆur   ú	List[str]c                óò  — d }d }| j         j        j        rt          | j         j        d         ¦  «        }| j         j        j        rt          | j         j        d         ¦  «        }|s|st          d¦  «        ‚|r|rt          d¦  «        ‚|rd„ |                     d¦  «        D ¦   «         S |r<t          |d¦  «        5 }|                     ¦   «         cd d d ¦  «         S # 1 swxY w Y   t          d¦  «        ‚)	NÚ$chroma_server_authn_credentials_fileÚchroma_server_authn_credentialszNNo credentials file or credentials found in [chroma_server_authn_credentials].zDBoth credentials file and credentials found.Please provide only one.c                ó   — g | ]}|¯|‘ŒS r   r   ©Ú.0Úcs     r   ú
<listcomp>zIServerAuthenticationProvider.read_creds_or_creds_file.<locals>.<listcomp>z   s   € Ð7Ð7Ð7˜!°QÐ7�AÐ7Ð7Ð7r   ú
ÚrúShould never happen)	Ú_systemr<   rN   r2   rO   Ú
ValueErrorÚsplitÚopenÚ	readlines)r%   Ú_creds_fileÚ_credsÚfs       r   Úread_creds_or_creds_filez5ServerAuthenticationProvider.read_creds_or_creds_filee   se  € ØˆØˆàŒ<Ô ÔEð 	ÝØ”Ô%Ð&LÔMñô ˆKð Œ<Ô Ô@ð 	SÝ˜œÔ.Ð/PÔQÑRÔRˆFØð 	 6ð 	Ýð5ñô ð ð ð 	˜6ð 	Ýð+ñô ð ð ð 	%Ø7Ð7˜vŸ|š|¨DÑ1Ô1Ð7Ñ7Ô7Ð7Øð 	%Ý�k 3Ñ'Ô'ð %¨1Ø—{’{‘}”}ð%ð %ð %ð %ñ %ô %ð %ð %ð %ð %ð %ð %øøøð %ð %ð %ð %åÐ.Ñ/Ô/Ð/s   Â>CÃC#Ã&C#ÚuserúOptional[UserIdentity]ú#Tuple[Optional[str], Optional[str]]c                óÔ   — | j         r|sdS d}d}|j        r|j        dk    r|j        }|j        r6t          |j        ¦  «        dk    r|j        d         dk    r|j        d         }||fS )aR  
        If settings.chroma_overwrite_singleton_tenant_database_access_from_auth
        is False, this function always returns (None, None).

        If settings.chroma_overwrite_singleton_tenant_database_access_from_auth
        is True, follows the following logic:
        - If the user only has access to a single tenant, this function will
          return that tenant as its first return value.
        - If the user only has access to a single database, this function will
          return that database as its second return value. If the user has
          access to multiple tenants and/or databases, including "*", this
          function will return None for the corresponding value(s).
        - If the user has access to multiple tenants and/or databases this
          function will return None for the corresponding value(s).
        )NNNÚ*é   r   )r@   r5   r6   Úlen)r%   ra   r5   Údatabases       r   Ú'singleton_tenant_database_if_applicablezDServerAuthenticationProvider.singleton_tenant_database_if_applicable€   sŠ   € ð$ ÔHð 	ÐPTð 	Ø�:ØˆØˆØŒ;ð 	!˜4œ;¨#Ò-Ð-Ø”[ˆFØŒ>ð 	)�c $¤.Ñ1Ô1°QÒ6Ð6¸4¼>È!Ô;LÐPSÒ;SÐ;SØ”~ aÔ(ˆHØ�xÐÐr   r,   )rA   rB   r   r1   )rE   r2   rF   r2   r   rG   ©r   rL   )ra   rb   r   rc   )r   r   r   r-   r#   r   rD   rK   r`   ri   r.   r/   s   @r   r:   r:   E   s£   ø€ € € € € ðð ð
ð 
ð 
ð 
ð 
ð 
ð ðð ð ñ „^ððð ð ð ð0ð 0ð 0ð 0ð6 ð  ð  ð  ð  ð  ð  ð  r   r:   c                  óf   — e Zd ZdZdZdZdZdZdZdZ	dZ
d	Zd
ZdZdZdZdZdZdZdZdZdZdZdZdZdS )ÚAuthzActionzR
    The set of actions that can be authorized by the authorization provider.
    zsystem:resetztenant:create_tenantztenant:get_tenantzdb:create_databasezdb:get_databasezdb:delete_databasezdb:list_databaseszdb:list_collectionszdb:count_collectionszdb:create_collectionzdb:get_or_create_collectionzcollection:get_collectionzcollection:delete_collectionzcollection:update_collectionzcollection:addzcollection:deletezcollection:getzcollection:queryzcollection:countzcollection:updatezcollection:upsertN)r   r   r   r-   ÚRESETÚCREATE_TENANTÚ
GET_TENANTÚCREATE_DATABASEÚGET_DATABASEÚDELETE_DATABASEÚLIST_DATABASESÚLIST_COLLECTIONSÚCOUNT_COLLECTIONSÚCREATE_COLLECTIONÚGET_OR_CREATE_COLLECTIONÚGET_COLLECTIONÚDELETE_COLLECTIONÚUPDATE_COLLECTIONÚADDÚDELETEÚGETÚQUERYÚCOUNTÚUPDATEÚUPSERTr   r   r   rl   rl   �   s‰   € € € € € ðð ð €EØ*€MØ$€JØ*€OØ$€LØ*€OØ(€NØ,ÐØ.ÐØ.ÐØ<ÐØ0€NØ6ÐØ6ÐØ
€CØ €FØ
€CØ€EØ€EØ €FØ €F€F€Fr   rl   c                  ó2   — e Zd ZU dZded<   ded<   ded<   dS )ÚAuthzResourcezB
    The resource being accessed in an authorization request.
    r4   r5   rh   Ú
collectionN)r   r   r   r-   r8   r   r   r   rƒ   rƒ   ¹   sB   € € € € € € ðð ð ÐÐÑØÐÐÑØÐÐÑÐÐr   rƒ   c                  óD   ‡ — e Zd ZdZdˆ fd„Zedd„¦   «         Zdd„Zˆ xZS )ÚServerAuthorizationProviderat  
    ServerAuthorizationProvider is responsible for authorizing requests. If a
    ServerAuthorizationProvider is configured, it will be called by the server
    to authorize requests. If no ServerAuthorizationProvider is configured, all
    requests will be authorized.

    ServerAuthorizationProvider should raise an exception if the request is not
    authorized.
    r   r   r   r   c                óJ   •— t          ¦   «                              |¦  «         d S r    r!   r$   s     €r   r#   z$ServerAuthorizationProvider.__init__Ï   r'   r   ra   r1   Úactionrl   Úresourcerƒ   c                ó   — d S r    r   )r%   ra   rˆ   r‰   s       r   Úauthorize_or_raisez.ServerAuthorizationProvider.authorize_or_raiseÒ   s	   € ð 	ˆr   rL   c                óØ  — d }d }| j         j        j        r| j         j        d         }| j         j        j        rt	          | j         j        d         ¦  «        }|s|st          d¦  «        ‚|r|rt          d¦  «        ‚|rd„ |                     d¦  «        D ¦   «         S |r<t          |d¦  «        5 }|                     ¦   «         cd d d ¦  «         S # 1 swxY w Y   t          d¦  «        ‚)	NÚchroma_server_authz_config_fileÚchroma_server_authz_configz9No authz configuration file or authz configuration found.zTBoth authz configuration file and authz configuration found.Please provide only one.c                ó   — g | ]}|¯|‘ŒS r   r   rQ   s     r   rT   zJServerAuthorizationProvider.read_config_or_config_file.<locals>.<listcomp>é   s   € Ð8Ð8Ð8˜!°aÐ8�AÐ8Ð8Ð8r   rU   rV   rW   )	rX   r<   r�   rŽ   r2   rY   rZ   r[   r\   )r%   Ú_config_fileÚ_configr_   s       r   Úread_config_or_config_filez6ServerAuthorizationProvider.read_config_or_config_fileØ   sU  € ØˆØˆØŒ<Ô Ô@ð 	TØœ<Ô0Ð1RÔSˆLØŒ<Ô Ô;ð 	OÝ˜$œ,Ô/Ð0LÔMÑNÔNˆGØð 	 Gð 	ÝØKñô ð ð ð 	˜Gð 	Ýð+ñô ð ð ð 	%Ø8Ð8˜wŸ}š}¨TÑ2Ô2Ð8Ñ8Ô8Ð8Øð 	%Ý�l CÑ(Ô(ð %¨AØ—{’{‘}”}ð%ð %ð %ð %ñ %ô %ð %ð %ð %ð %ð %ð %øøøð %ð %ð %ð %åÐ.Ñ/Ô/Ð/s   Â1CÃCÃCr,   )ra   r1   rˆ   rl   r‰   rƒ   r   r   rj   )	r   r   r   r-   r#   r   r‹   r’   r.   r/   s   @r   r†   r†   Ä   s{   ø€ € € € € ðð ð!ð !ð !ð !ð !ð !ð ðð ð ñ „^ðð
0ð 0ð 0ð 0ð 0ð 0ð 0ð 0r   r†   N) Ú
__future__r   Úabcr   Úenumr   Útypingr   r   r   r	   r
   r   Údataclassesr   Úpydanticr   Úchromadb.configr   r   r   r   Ú	Exceptionr   r2   r(   r   r1   r:   rl   rƒ   r†   r   r   r   ú<module>r›      sU  ðØ "Ð "Ð "Ð "Ð "Ð "à Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð ðð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ð "Ð !Ð !Ð !Ð !Ð !à Ð Ð Ð Ð Ð ðð ð ð ð ð ð ð ð
 €GˆC�L„L€Ø€GˆC�L„L€ð	ð 	ð 	ð 	ð 	�	ñ 	ô 	ð 	ð ˜˜i˜Ô(Ð ðð ð ð ð ˜ñ ô ð ð ð0ð 0ð 0ð 0ð 0ñ 0ô 0ñ „ð0ð(U ð U ð U ð U ð U  9ñ U ô U ð U ðp!ð !ð !ð !ð !�#�tñ !ô !ð !ð8 ðð ð ð ð ñ ô ñ „ðð)0ð )0ð )0ð )0ð )0 )ñ )0ô )0ð )0ð )0ð )0r   