§
    }Štjº  ã                   ó*  — d Z ddlZddlmZ ddlmZ ddlmZ ddlm	Z	m
Z
 dZd	Z G d
„ dee¦  «        Zdedz  fd„Zdedefd„Zdddœdeez  dz  dedz  defd„Zddœdedededz  defd„Zdddddœdededz  deez  dz  dedz  dedz  defd„ZdS )u™  Keyless CI/CD authentication via OIDC token exchange ("Trusted Publishers").

A CI job proves its identity to the Hub with a short-lived OIDC id token minted by its CI
provider (e.g. GitHub Actions), then exchanges it at ``POST {ENDPOINT}/oauth/token`` (RFC 8693)
for a short-lived Hugging Face token â€” no long-lived ``HF_TOKEN`` secret to store.

This module is self-contained: it only handles minting the provider id token and the exchange.
It deliberately does not register a public API or a CLI verb; the integration point is the token
resolution in ``utils/_auth.py`` (see ``_get_token_from_oidc``).

Docs: https://huggingface.co/docs/hub/trusted-publishers
é    N)ÚEnumé   )Ú	constants)Ú	OIDCError)Úget_sessionÚhf_raise_for_statusz/urn:ietf:params:oauth:grant-type:token-exchangez)urn:ietf:params:oauth:token-type:id_tokenc                   ó   — e Zd ZdZdZdS )ÚProviderzRCI providers that can mint an OIDC id token natively. GitHub Actions only for now.ÚgithubN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚGITHUB© ó    úS/var/www/html/CA-Chatbot/venv/lib/python3.11/site-packages/huggingface_hub/_oidc.pyr
   r
   (   s   € € € € € Ø\Ð\à€F€F€Fr   r
   Úreturnc                  ód   — t           j                             d¦  «        dk    rt          j        S dS )zYDetect the CI provider able to mint an OIDC id token, or `None` if not in a supported CI.ÚGITHUB_ACTIONSÚtrueN)ÚosÚenvironÚgetr
   r   r   r   r   Údetect_providerr   .   s)   € å	„z‡~‚~Ð&Ñ'Ô'¨6Ò1Ð1ÝŒÐØˆ4r   Úaudiencec                 óL  — t           j                             d¦  «        }t           j                             d¦  «        }|r|st          d¦  «        ‚t	          ¦   «                              |d| idd|› �i¬¦  «        }t          |¦  «         |                     ¦   «         d         S )	zîMint an OIDC id token from the GitHub Actions runtime.

    Relies on the `ACTIONS_ID_TOKEN_REQUEST_URL` / `ACTIONS_ID_TOKEN_REQUEST_TOKEN` env vars,
    which GitHub only injects when the job declares `permissions: id-token: write`.
    ÚACTIONS_ID_TOKEN_REQUEST_URLÚACTIONS_ID_TOKEN_REQUEST_TOKENz÷Cannot request an OIDC id token from GitHub Actions. Make sure the workflow job sets `permissions: id-token: write`. See https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connectr   ÚAuthorizationzBearer )ÚparamsÚheadersÚvalue)r   r   r   r   r   r   Újson)r   Úrequest_urlÚrequest_tokenÚresponses       r   Ú_get_github_oidc_tokenr(   5   s²   € õ ”*—.’.Ð!?Ñ@Ô@€KÝ”J—N’NÐ#CÑDÔD€MØð 
˜mð 
ÝðMñ
ô 
ð 	
õ
 ‰}Œ}× Ò ØØ˜HÐ%Ø Ð";¨MÐ";Ð";Ð<ð !ñ ô €Hõ
 ˜Ñ!Ô!Ð!Ø�=Š=‰?Œ?˜7Ô#Ð#r   ©Úproviderr   r*   c                 ó  — |pt           j        }| pt          ¦   «         } d                     d„ t          D ¦   «         ¦  «        }| €t          d|› d�¦  «        ‚| t          j        k    rt          |¦  «        S t          d| › d|› d�¦  «        ‚)aå  Mint a raw OIDC id token (JWT) from the current CI provider.

    Args:
        provider (`str`, *optional*):
            CI provider to use. Auto-detected from the environment when omitted.
        audience (`str`, *optional*):
            The `aud` claim to request. Defaults to `constants.ENDPOINT` so it matches the endpoint
            that validates it (respects `HF_ENDPOINT`/staging).

    Returns:
        `str`: The raw id token (JWT) to pass to [`exchange_oidc_token`].
    z, c              3   ó$   K  — | ]}|j         V — Œd S )N)r#   )Ú.0Úps     r   ú	<genexpr>z!get_oidc_token.<locals>.<genexpr>[   s$   è è € Ð4Ð4 a˜!œ'Ð4Ð4Ð4Ð4Ð4Ð4r   NzONo supported CI OIDC provider detected. Trusted Publishers currently supports: ú.zOIDC provider 'z#' is not supported yet. Supported: )	r   ÚENDPOINTr   Újoinr
   r   r   r(   ÚNotImplementedError)r*   r   Ú	supporteds      r   Úget_oidc_tokenr5   L   s    € ð Ð-�9Ô-€HØÐ,�?Ñ,Ô,€HØ—	’	Ð4Ð4­8Ð4Ñ4Ô4Ñ4Ô4€IØÐÝÐvÐjsÐvÐvÐvÑwÔwÐwØ•8”?Ò"Ð"Ý% hÑ/Ô/Ð/Ý
Ði°ÐiÐiÐ]fÐiÐiÐiÑ
jÔ
jÐjr   )ÚendpointÚsubject_tokenÚresourcer6   c                 óÊ   — t          ¦   «                              |pt          j        › d�t          t
          | |dœ¬¦  «        }t          |¦  «         |                     ¦   «         S )u  Exchange a CI OIDC id token for a short-lived Hugging Face token (RFC 8693).

    Args:
        subject_token (`str`):
            The raw OIDC id token (JWT) from the CI provider. Its `aud` claim must be the Hub URL.
        resource (`str`):
            What to scope the token to: a Hub repo (`namespace/name`, `datasets/namespace/name`,
            `spaces/namespace/name`, `kernels/namespace/name`) for a write token, or a bare Hub
            username for a read-only `gated-repos` token.
        endpoint (`str`, *optional*):
            Hub endpoint. Defaults to `constants.ENDPOINT` (respects `HF_ENDPOINT`/staging).

    Returns:
        `dict`: The token-exchange response, e.g.
        `{"access_token": "hf_jwt_â€¦", "token_type": "bearer", "expires_in": 3600, ...}`.
    z/oauth/token)Ú
grant_typeÚsubject_token_typer7   r8   )r$   )r   Úpostr   r1   Ú_TOKEN_EXCHANGE_GRANT_TYPEÚ_ID_TOKEN_TYPEr   r$   )r7   r8   r6   r'   s       r   Úexchange_oidc_tokenr?   c   sj   € õ" ‰}Œ}×!Ò!ØÐ)•yÔ)Ð7Ð7Ð7å4Ý"0Ø*Ø ð	
ð 
ð "ñ ô €Hõ ˜Ñ!Ô!Ð!Ø�=Š=‰?Œ?Ðr   )r7   r*   r   r6   c                 ól   — |pt           j        }|€t          ||p|¬¦  «        }t          || |¬¦  «        S )u¶  Mint a CI OIDC id token and exchange it for a Hugging Face token.

    Convenience wrapper around [`get_oidc_token`] + [`exchange_oidc_token`]. Returns the raw
    exchange response (it does not persist anything â€” the caller decides what to do with the token).

    Args:
        resource (`str`):
            Repo or username to scope the token to. See [`exchange_oidc_token`].
        subject_token (`str`, *optional*):
            A pre-minted OIDC id token to exchange directly. Use this for CI providers not yet
            supported natively (e.g. GitLab): mint the id token in your job and pass it here. When
            omitted, the token is minted from the detected `provider`.
        provider (`str`, *optional*):
            CI provider. Auto-detected when omitted. Ignored when `subject_token` is provided.
        audience (`str`, *optional*):
            The `aud` claim to request. Defaults to the resolved `endpoint`, so it matches the
            endpoint that validates it.
        endpoint (`str`, *optional*):
            Hub endpoint. Defaults to `constants.ENDPOINT`.

    Returns:
        `dict`: The token-exchange response (`access_token`, `token_type`, `expires_in`, ...).
    Nr)   )r7   r8   r6   )r   r1   r5   r?   )r8   r7   r*   r   r6   s        r   Ú
oidc_loginrA   �   sD   € ð> Ð-�9Ô-€HØÐÝ&°À8ÐCWÈxÐXÑXÔXˆÝ¨]ÀXÐX`ÐaÑaÔaÐar   )r   r   Úenumr   Ú r   Úerrorsr   Úutilsr   r   r=   r>   Ústrr
   r   r(   r5   Údictr?   rA   r   r   r   ú<module>rH      s  ððð ð 
€	€	€	Ø Ð Ð Ð Ð Ð à Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø 3Ð 3Ð 3Ð 3Ð 3Ð 3Ð 3Ð 3ð OÐ Ø<€ðð ð ð ð ˆs�Dñ ô ð ð˜ D™ð ð ð ð ð$ Sð $¨Sð $ð $ð $ð $ð. 9=ÐUYð kð kð k ¨3¡°Ñ 5ð kÈÈdÉ
ð kÐ^að kð kð kð kð. VZð ð ð ¨#ð ¸ð ÈÈdÉ
ð Ð^bð ð ð ð ðB !%Ø&*ØØð"bð "bð "bàð"bð ˜‘:ð"bð ˜‰n˜tÑ#ð	"bð
 �D‰jð"bð �D‰jð"bð 
ð"bð "bð "bð "bð "bð "br   