o
    î6Wj  ã                   @  s¼   d dl mZ d dlZd dlmZ ddlmZmZ ddlm	Z	 ddl
mZmZmZmZmZmZmZmZmZmZmZmZmZ ddlmZmZmZ d	d
lmZ dgZddd„Zddœddd„Z dS )é    )ÚannotationsN)ÚOptionalé   )ÚCredentialResultÚIdentityTokenProvider)ÚWorkloadIdentityCredentials)Ú	ENV_SCOPEÚENV_API_KEYÚENV_PROFILEÚENV_AUTH_TOKENÚENV_CONFIG_DIRÚENV_WORKSPACE_IDÚENV_IDENTITY_TOKENÚENV_ORGANIZATION_IDÚENV_FEDERATION_RULE_IDÚENV_SERVICE_ACCOUNT_IDÚ_has_active_profile_configÚ_has_explicit_active_configÚresolve_identity_token_path)ÚStaticTokenÚCredentialsFileÚIdentityTokenFileé   )ÚAnthropicErrorÚdefault_credentialsÚbase_urlÚstrÚreturnúOptional[CredentialResult]c              	   C  s¨   t j t¡}t j t¡}tt jv }tƒ }|r|sdS |s"|du r"dS |dur+t|ƒ}nddd„}|}t|||t j t	¡t j t
¡pBdt j t¡d�}| | ¡ t|d�S )	z¡Build a :class:`CredentialResult` for the env-var federation path
    (step 4 in the precedence spec). Returns ``None`` if the required trio
    isn't fully set.Nr   r   c                  S  s&   t j t¡} | d u rtt› d�ƒ‚| S )Nzz is not set; the workload-identity chain selected this provider at construction time but the env var is no longer present.)ÚosÚenvironÚgetr   r   )Úvalue© r#   úo/home/esfera/Documents/content_generation/venv/lib/python3.10/site-packages/anthropic/lib/credentials/_chain.pyÚ_read_env_token1   s   ÿz1_build_federation_result.<locals>._read_env_token)Úidentity_token_providerÚfederation_rule_idÚorganization_idÚservice_account_idÚworkspace_idÚscope©Úprovider)r   r   )r   r    r!   r   r   r   r   r   r   r   r   r   Úbind_base_urlr   )r   r'   r(   Úhas_literal_tokenÚidentity_token_pathÚidentity_providerr%   r-   r#   r#   r$   Ú_build_federation_result   s,   





÷

r2   zhttps://api.anthropic.com©r   c                 C  sâ   t j t¡rdS t j t¡}|rtt|ƒd�S tt j t¡p#t j t	¡ƒ}t
ƒ }|s,|r@tƒ }| | ¡ | ¡ }t|||jd�S t| d�}|durK|S tƒ rotƒ }| | ¡ z| ¡ }W n
 tyf   Y dS w t|||jd�S dS )uÔ  Resolve a :class:`CredentialResult` from the environment per the
    credential-resolution spec. First match wins.

    Implements steps 2-5 of the spec precedence chain (step 1 is handled at
    the client constructor level, above this function):

    Step 2a: ``ANTHROPIC_API_KEY`` â†’ return ``None`` so the client uses its
             existing ``X-Api-Key`` header path. (API keys are not Bearer
             tokens, so they can't flow through this chain.)
    Step 2b: ``ANTHROPIC_AUTH_TOKEN`` â†’ :class:`StaticToken` (Bearer).
    Step 3:  ``ANTHROPIC_PROFILE`` / ``ANTHROPIC_CONFIG_DIR`` set, or the
             ``active_config`` pointer file exists â†’ load that profile.
             This is *explicit profile selection*; failures propagate.
    Step 4:  ``ANTHROPIC_FEDERATION_RULE_ID`` + ``ANTHROPIC_ORGANIZATION_ID``
             + ``ANTHROPIC_IDENTITY_TOKEN[_FILE]`` â†’ direct jwt-bearer
             exchange via :class:`WorkloadIdentityCredentials`. Critically,
             step 4 sits **between** explicit profile (step 3) and
             fallback profile (step 5): a machine with WIF env vars wired
             up must use WIF even if a leftover ``default`` profile exists
             on disk, but a user who explicitly ``ANTHROPIC_PROFILE=dev``
             still gets their profile.
    Step 5:  Fallback active profile from disk (``configs/default.json``
             or whatever ``active_config`` points at). Errors at this step
             are swallowed and the chain falls through â€” a corrupt
             unselected profile shouldn't break an otherwise-explicit
             api_key= path.

    Returns ``None`` when nothing matches â€” the client will fall back to
    its normal "no auth configured" error.
    Nr,   )r-   Úextra_headersr   r3   )r   r    r!   r	   r   r   r   Úboolr
   r   r   r   r.   r4   Úresolved_base_urlr2   r   r   )r   Ú
auth_tokenÚenv_explicitÚpointer_explicitÚ
creds_filer4   Úfederation_resultr#   r#   r$   r   L   sB    
ý
	
ÿý)r   r   r   r   )!Ú
__future__r   r   Útypingr   Ú_typesr   r   Ú	_workloadr   Ú
_constantsr   r	   r
   r   r   r   r   r   r   r   r   r   r   Ú
_providersr   r   r   Ú_exceptionsr   Ú__all__r2   r   r#   r#   r#   r$   Ú<module>   s    <
/