Ë
    A²XjŒ   ã                  óÆ   — U d dl mZ d dlZd dlZd dlZd dlmZmZ d dlZddl	m
Z
mZ ddlmZ ddlmZmZ dd	lmZ d
gZ ej(                  e«      Zded<   dZ G d„ d
«      Zy)é    )ÚannotationsN)ÚCallableÚOptionalé   )ÚAccessTokenÚAccessTokenProvider)ÚWorkloadIdentityError)ÚADVISORY_REFRESH_SECONDSÚMANDATORY_REFRESH_SECONDSé   )ÚAnthropicErrorÚ
TokenCachezlogging.LoggerÚlogé   c                  óh   — e Zd ZdZeeej                  dœ	 	 	 	 	 	 	 	 	 d	d„Zd
d„Zdd„Z	dd„Z
dd„Zy)r   u2  Thread-safe cache wrapping an :class:`AccessTokenProvider` with two-tier
    proactive refresh and single-flight semantics.

    Refresh policy on each :meth:`get_token` call:

    * No cached token â†’ call provider (blocking), cache, return.
    * Cached with ``expires_at=None`` â†’ return cached forever (never refresh).
    * More than ``advisory_refresh_seconds`` remaining â†’ return cached.
    * Between ``mandatory_refresh_seconds`` and ``advisory_refresh_seconds``
      remaining (advisory window) â†’ try provider; on success swap cache; on
      failure log a warning and return the stale cached token. If another
      caller is already refreshing, the advisory caller just returns the
      cached token â€” no second refresh, no waiting.
    * Less than ``mandatory_refresh_seconds`` remaining or already expired
      (mandatory window) â†’ call provider; on failure RAISE. Concurrent
      mandatory callers wait on a shared ``Event`` so exactly one provider
      call is in flight.

    The lock is released before the provider call so a 30-second HTTP POST
    doesn't serialize unrelated callers through a single thread. This matters
    under async: ``asyncify(get_token)`` runs on the thread pool, and holding
    the lock across the network call would pin an async worker for the whole
    exchange.
    )Úadvisory_refresh_secondsÚmandatory_refresh_secondsÚtime_sourcec               ó¦   — || _         || _        || _        || _        t	        j
                  «       | _        d | _        d | _        d| _	        d| _
        y )NFg        )Ú	_providerÚ	_advisoryÚ
_mandatoryÚ_time_sourceÚ	threadingÚLockÚ_lockÚ_cachedÚ_refresh_eventÚ_next_forceÚ_last_advisory_failure_time)ÚselfÚproviderr   r   r   s        úf/var/www/html/content_generation/venv/lib/python3.12/site-packages/anthropic/lib/credentials/_cache.pyÚ__init__zTokenCache.__init__3   sT   € ð "ˆŒØ1ˆŒØ3ˆŒØ'ˆÔÜ—^‘^Ó%ˆŒ
Ø.2ˆŒð :>ˆÔð !ˆÔð 36ˆÕ(ó    c               ó�   — 	 | j                  |¬«      S # t        $ r(}dt        |«      vr‚ | j                  «       cY d}~S d}~ww xY w)z@Invoke ``self._provider``, tolerating legacy zero-arg callables.)Úforce_refreshr'   N)r   Ú	TypeErrorÚstr)r!   ÚforceÚerrs      r#   Ú_invoke_providerzTokenCache._invoke_providerL   sF   € ð	$Ø—>‘>°�>Ó6Ð6øÜò 	$ð ¤c¨#£hÑ.ØØ—>‘>Ó#Õ#ûð	$ús   ‚ ”	A�A ºAÁ Ac                ór  — | j                   5  | j                  }ddd«       	 | j                  ¬«      }| j                   5  d| _        ddd«       |S # 1 sw Y   Œ:xY w# t        $ rA}|j                  dk7  r‚ t
        j                  d«       | j                  d¬«      }Y d}~Œod}~ww xY w# 1 sw Y   |S xY w)zBCall the provider, retrying once on a 401 from the token endpoint.N)r*   i‘  z*Token provider returned 401; retrying onceTF)r   r   r,   r	   Ústatus_coder   Údebug)r!   r*   Úresultr+   s       r#   Ú_call_providerzTokenCache._call_providerX   s¡   € ð �Z‹ZØ×$Ñ$ˆE÷ ð	7Ø×*Ñ*°Ð*Ó7ˆFð �Z‹ZØ$ˆDÔ÷ àˆ÷ ˆZûô %ò 	7Ø�‰ #Ò%ØÜ�I‰IÐBÔCØ×*Ñ*°Ð*Ó6�Fûð		7ú÷
 àˆús.   �A£A ÁB,ÁAÁ	B)Á(7B$Â$B)Â,B6c                ó<  — 	 d}d}| j                   5  | j                  }|�Ø|j                  €|j                  cddd«       S |j                  | j	                  «       z
  }|| j
                  kD  r|j                  cddd«       S || j                  kD  rg| j                  �|j                  cddd«       S | j	                  «       | j                  z
  t        k  r|j                  cddd«       S |}t        |«      }| j                  �| j                  }nt        j                  «       | _        d}ddd«       �|j                  «        �ŒH	 | j                  «       }| j                   5  || _        | j                  }d| _        ddd«       €J ‚|j!                  «        |j                  S # 1 sw Y   Œ}xY w# t        $ rÐ}| j                   5  | j                  }d| _        ddd«       n# 1 sw Y   nxY w€J ‚|j!                  «        |�t#        |t$        t&        j(                  f«      r_t*        j-                  d||«       | j                   5  | j	                  «       | _        ddd«       n# 1 sw Y   nxY w|j                  cY d}~S ‚ d}~ww xY w# 1 sw Y   �ŒxY w)z5Return a valid bearer token, refreshing if necessary.Nr   zGAdvisory token refresh failed (%ds remaining); serving cached token: %s)r   r   Ú
expires_atÚtokenr   r   r   r   r    Ú ADVISORY_REFRESH_BACKOFF_SECONDSÚintr   ÚEventÚwaitr1   ÚBaseExceptionÚsetÚ
isinstancer   ÚhttpxÚ	HTTPErrorr   Úwarning)	r!   Úadvisory_fallbackÚremaining_secondsÚcachedÚ	remainingÚwaiter_eventÚfreshr+   Úreleaseds	            r#   Ú	get_tokenzTokenCache.get_tokeni   sG  € àØ7;ÐØ !ÐØ—“ØŸ™�ØÐ%Ø×(Ñ(Ð0Ø%Ÿ|™|÷	 ‘ð
 !'× 1Ñ 1°D×4EÑ4EÓ4GÑ G�IØ  4§>¡>Ò1Ø%Ÿ|™|÷ ‘ð ! 4§?¡?Ò2ð  ×.Ñ.Ð:Ø#)§<¡<÷ ‘ð   ×,Ñ,Ó.°×1QÑ1QÑQÔTtÒtØ#)§<¡<÷# ‘ð$ -3Ð)Ü,/°	«NÐ)à×&Ñ&Ð2à>B×>QÑ>Q‘Lô +4¯/©/Ó*;�DÔ'Ø#'�L÷7 ð: Ð'Ø×!Ñ!Ô#ñ ðØ×+Ñ+Ó-�ð$ —“Ø$�”Ø×.Ñ.�Ø&*�Ô#÷ ð Ð'Ð'Ð'Ø�L‰LŒNØ—;‘;Ð÷C �ûôT !ò Ø—Z“ZØ#×2Ñ2�HØ*.�DÔ'÷  —Z‘Zúð  Ð+Ð+Ð+Ø—‘”Ø$Ð0´ZÀÄnÔV[×VeÑVeÐEfÔ5gÜ—K‘KØaØ)Øôð
 Ÿ›Ø;?×;LÑ;LÓ;N˜Ô8÷ $Ÿ™úà,×2Ñ2Õ2Øûðú÷" ‘ús…   ’&F)Á7F)Â&F)Â3/F)Ã,AF)Å
F5 Å&JÆ)F2Æ5	JÆ>J	Ç
G'Ç	J	Ç'G0	Ç,A J	ÉI+É"	J	É+I4	É0J	ÊJÊJ	Ê	JÊJc                ób   — | j                   5  d| _        d| _        ddd«       y# 1 sw Y   yxY w)zôClear the cached token so the next :meth:`get_token` re-invokes the provider.

        Also sets a one-shot ``force_refresh`` flag so on-disk providers skip
        their freshness short-circuit instead of re-serving the revoked token.
        NT)r   r   r   )r!   s    r#   Ú
invalidatezTokenCache.invalidate±   s$   € ð �Z‹ZØˆDŒLØ#ˆDÔ÷ �Z‰Zús   �%¥.N)
r"   r   r   r6   r   r6   r   zCallable[[], float]ÚreturnÚNone)r*   ÚboolrI   r   )rI   r   )rI   r)   )rI   rJ   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r
   r   Útimer$   r,   r1   rF   rH   © r%   r#   r   r      sb   „ ñð: )AØ)BØ+/¯9©9ñ6à%ð6ð #&ð	6ð
 $'ð6ð )ð6ð 
ó6ó2
$óó"FôP$r%   )Ú
__future__r   rP   Úloggingr   Útypingr   r   r<   Ú_typesr   r   Ú	_workloadr	   Ú
_constantsr
   r   Ú_exceptionsr   Ú__all__Ú	getLoggerrL   r   Ú__annotations__r5   r   rQ   r%   r#   Ú<module>r\      sU   ðÞ "ã Û Û ß %ã ç 4Ý ,ß KÝ )àˆ.€à'�g×'Ñ'¨Ó1€€^Ó 1ð
 $%Ð  ÷`$ò `$r%   