Ë
    A²Xjh  ã                  ór   — d Z ddlmZ ddlmZmZmZmZ ddlm	Z	m
Z
 erddlmZmZ dgZ ed	d
d«      Zdd„Zy)u€  Shared util for building a Bearer-only sub-client for a helper.

Several helpers (the environment poller, the environment worker, the session
tool runner) need to issue requests authenticated by a per-helper credential
(a self-hosted environment key, today) rather than the parent client's own
``X-Api-Key``. They each want to inherit the parent's full configuration â€”
``timeout``, ``max_retries``, ``http_client``, custom ``default_headers``,
``default_query`` â€” and override only the auth bits, plus tag every request
with their own ``x-stainless-helper`` value.

:func:`_copy_client_with_bearer_auth` is the one shared construction.
é    )Úannotations)ÚTYPE_CHECKINGÚDictÚTypeVarÚcasté   )ÚSTAINLESS_HELPER_HEADERÚStainlessHelperHeaderValueé   )Ú	AnthropicÚAsyncAnthropicÚ_copy_client_with_bearer_authÚClientTr   r   c               óü   — |st        d|›�«      ‚| j                  |dt        |i¬«      }d|_        t	        d|j
                  «      }t        |«      D ]&  }|j                  «       dv sŒ|j                  |«       Œ( |S )u*  Return a copy of ``client`` authenticated with ``auth_token`` as Bearer.

    The returned sub-client inherits the parent's full configuration via
    ``client.copy()`` (``base_url``, ``timeout``, ``max_retries``,
    ``http_client``, ``default_query``, and any custom ``default_headers``).
    Overrides applied:

    - ``auth_token=auth_token`` â€” the new credential.
    - ``credentials=None`` â€” any inherited credentials provider is cleared so
      the bearer is the unambiguous auth.
    - ``default_headers`` merges in ``x-stainless-helper: <helper>`` so every
      request the sub-client issues is tagged for SDK telemetry without
      per-call plumbing.
    - ``api_key=None`` â€” the parent's ``X-Api-Key`` is cleared via a post-hoc
      mutation; today's ``copy()`` treats ``api_key=None`` as "inherit" via
      truthy-or, so the assignment is the only way to drop the parent's API
      key from the sub-client.
    - Any inherited ``Authorization`` / ``X-Api-Key`` entries in the parent's
      custom default-headers are stripped from the sub-client. They would
      otherwise win over the bearer we just set, because
      :meth:`AsyncAnthropic.default_headers` merges ``_custom_headers`` after
      ``auth_headers`` (and so beats the ``Authorization`` value produced by
      ``auth_token``).
    z9Expected a non-empty value for `auth_token` but received N)Ú
auth_tokenÚcredentialsÚdefault_headerszDict[str, str])Úauthorizationz	x-api-key)	Ú
ValueErrorÚcopyr	   Úapi_keyr   Ú_custom_headersÚlistÚlowerÚpop)Úclientr   ÚhelperÚscopedÚcustomÚkeys         úb/var/www/html/content_generation/venv/lib/python3.12/site-packages/anthropic/lib/_scoped_client.pyr   r      sŠ   € ñ2 ÜÐTÐU_ÐTbÐcÓdÐdØ�[‰[ØØÜ0°&Ð9ð ó €Fð
 €F„Nô "Ð"2°F×4JÑ4JÓK€FÜ�FŽ|ˆØ�9‰9‹;Ð8Ò8Ø�J‰J�s�Oð ð €Mó    N)r   r   r   Ústrr   r
   Úreturnr   )Ú__doc__Ú
__future__r   Útypingr   r   r   r   Ú_stainless_helpersr	   r
   Ú_clientr   r   Ú__all__r   r   © r"   r!   Ú<module>r,      s>   ðñõ #ç 5Ó 5ç Sáß3ð +Ð
+€ñ �)˜[Ð*:Ó
;€ô(r"   