o
    î6Wj´  ã                   @  sÈ   U d dl mZ d dlZd dlZd dlmZmZ d dlmZ d dl	Z	ddl
mZ ddlmZ dd	lmZ d
gZe e¡Zded< e ¡ Zeƒ Zded< ddd„Zd dd„Zd!dd„ZG dd
„ d
e	jƒZdS )"é    )ÚannotationsN)Ú	GeneratorÚAsyncGenerator)Úoverrideé   )Ú
TokenCacheé   )Úasyncify)ÚOAUTH_API_BETA_HEADERÚAccessTokenAuthzlogging.LoggerÚlogzset[str]Ú_warn_once_seenÚkeyÚstrÚmessageÚargsÚobjectÚreturnÚNonec                 G  s^   t � | tv r	 W d  ƒ dS t | ¡ W d  ƒ n1 sw   Y  tj|g|¢R Ž  dS )z8Emit a log warning at most once per ``key`` per process.N)Ú_warn_once_lockr   Úaddr   Úwarning)r   r   r   © r   ún/home/esfera/Documents/content_generation/venv/lib/python3.10/site-packages/anthropic/lib/credentials/_auth.pyÚ
_warn_once   s   þýr   Úparamc                 C  s   t d| › �d| ƒ dS )ag  Warn that an explicit ``api_key=`` / ``auth_token=`` argument shadows
    an explicit ``credentials=`` provider passed to the same constructor or
    ``copy()`` call. The static credential wins at the request-header level
    (``AccessTokenAuth.sync_auth_flow`` short-circuits on the pre-set header),
    which silently disables the credentials provider.
    zexplicit-shadow:z“`%s=` was passed alongside `credentials=`; the static credential takes precedence and the credentials provider is silently disabled. Pass only one.N©r   )r   r   r   r   Ú(warn_explicit_static_shadows_credentials   s
   ûr   Úenv_varc                 C  s   t d| › �d| | ƒ dS )a¥  Warn that an ``ANTHROPIC_API_KEY`` / ``ANTHROPIC_AUTH_TOKEN`` from the
    environment is shadowing the SDK's profile / federation auto-discovery.

    Per the credential-precedence spec, a static-credential env var silently
    disables the auto-discovered federation and profile paths. Surface a
    one-shot warning so migrating users can see why their ``ANTHROPIC_PROFILE``
    or WIF env vars are being ignored.
    zenv-shadow:z‚%s is set and takes precedence over the SDK's profile / federation auto-discovery; unset %s to use the auto-discovered credential.Nr   )r   r   r   r   Ú&warn_env_static_shadows_auto_discovery/   s   	ûr   c                   @  sR   e Zd ZdZdZddd„Zeddd„ƒZddd„Ze	ddd„ƒZ
e	ddd„ƒZdS )r   u’  Adapts a :class:`TokenCache` to httpx's :class:`~httpx.Auth` protocol.

    Used by :meth:`anthropic.Anthropic.custom_auth` to inject ``Authorization: Bearer``
    plus the OAuth beta header on every request, with proactive refresh handled by
    :class:`TokenCache`.

    Static credentials shadow federation: if the outgoing request already carries
    an ``X-Api-Key`` or ``Authorization`` header (set by the client's api_key /
    auth_token path), this auth flow is a no-op. That matches the Go SDK's
    ``authMiddleware`` and the documented precedence in the WIF user guide â€”
    a static ``ANTHROPIC_API_KEY`` shadows any credentials provider.
    FÚtoken_cacher   r   r   c                 C  s
   || _ d S ©N)Ú_token_cache)Úselfr    r   r   r   Ú__init__Q   s   
zAccessTokenAuth.__init__Úrequestúhttpx.RequestÚboolc                 C  s   t | j d¡p| j d¡ƒS )Nz	X-Api-KeyÚAuthorization)r'   ÚheadersÚget)r%   r   r   r   Ú_has_static_credentialT   s   z&AccessTokenAuth._has_static_credentialÚtokenr   c                 C  s\   d|› �|j d< |j  dd¡}dd„ | d¡D ƒ}t|vr,| t¡ d |¡|j d< d S d S )	NzBearer r(   zanthropic-betaÚ c                 S  s   g | ]
}|  ¡ r|  ¡ ‘qS r   )Ústrip)Ú.0Úflagr   r   r   Ú
<listcomp>c   s    z*AccessTokenAuth._apply.<locals>.<listcomp>ú,z, )r)   r*   Úsplitr
   ÚappendÚjoin)r#   r%   r,   Úexisting_betaÚexisting_flagsr   r   r   Ú_applyX   s   	
þzAccessTokenAuth._applyú.Generator[httpx.Request, httpx.Response, None]c                 c  s6   � |   |¡r|V  d S | j ¡ }|  ||¡ |V  d S r!   )r+   r"   Ú	get_tokenr8   ©r#   r%   r,   r   r   r   Úsync_auth_flowh   s   €


zAccessTokenAuth.sync_auth_flowú-AsyncGenerator[httpx.Request, httpx.Response]c                 C s@   �|   |¡r|V  d S t| jjƒƒ I d H }|  ||¡ |V  d S r!   )r+   r	   r"   r:   r8   r;   r   r   r   Úasync_auth_flowq   s   €

zAccessTokenAuth.async_auth_flowN)r    r   r   r   )r%   r&   r   r'   )r%   r&   r,   r   r   r   )r%   r&   r   r9   )r%   r&   r   r=   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__Úrequires_response_bodyr$   Ústaticmethodr+   r8   r   r<   r>   r   r   r   r   r   A   s    

)r   r   r   r   r   r   r   r   )r   r   r   r   )r   r   r   r   )Ú
__future__r   ÚloggingÚ	threadingÚtypingr   r   Útyping_extensionsr   ÚhttpxÚ_cacher   Ú_utilsr	   Ú
_constantsr
   Ú__all__Ú	getLoggerr?   r   Ú__annotations__ÚLockr   Úsetr   r   r   r   ÚAuthr   r   r   r   r   Ú<module>   s"    

	
