Ë
    A²Xj  ã                  ó¸   — d dl mZ d dlZd dlmZ ddlmZmZ ddlm	Z	 ddl
mZmZmZmZmZmZmZmZmZmZmZmZmZ ddlmZmZmZ d	d
lmZ dgZdd„Zddœdd„Z y)é    )ÚannotationsN)ÚOptionalé   )ÚCredentialResultÚIdentityTokenProvider)ÚWorkloadIdentityCredentials)Ú	ENV_SCOPEÚENV_API_KEYÚENV_PROFILEÚENV_AUTH_TOKENÚENV_CONFIG_DIRÚENV_WORKSPACE_IDÚENV_IDENTITY_TOKENÚENV_ORGANIZATION_IDÚENV_FEDERATION_RULE_IDÚENV_SERVICE_ACCOUNT_IDÚ_has_active_profile_configÚ_has_explicit_active_configÚresolve_identity_token_path)ÚStaticTokenÚCredentialsFileÚIdentityTokenFileé   )ÚAnthropicErrorÚdefault_credentialsc           
     ó4  — t         j                  j                  t        «      }t         j                  j                  t        «      }t
        t         j                  v }t        «       }|r|sy|s|€y|�t        |«      }ndd„}|}t        |||t         j                  j                  t        «      t         j                  j                  t        «      xs dt         j                  j                  t        «      ¬«      }|j                  | «       t        |¬«      S )z¡Build a :class:`CredentialResult` for the env-var federation path
    (step 4 in the precedence spec). Returns ``None`` if the required trio
    isn't fully set.Nc                 ót   — t         j                  j                  t        «      } | €t	        t        › d�«      ‚| S )Nzz is not set; the workload-identity chain selected this provider at construction time but the env var is no longer present.)ÚosÚenvironÚgetr   r   )Úvalues    úf/var/www/html/content_generation/venv/lib/python3.12/site-packages/anthropic/lib/credentials/_chain.pyÚ_read_env_tokenz1_build_federation_result.<locals>._read_env_token1   s>   € Ü—J‘J—N‘NÔ#5Ó6ˆEØˆ}Ü$Ü)Ð*ð +,ð -óð ð
 ˆLó    )Úidentity_token_providerÚfederation_rule_idÚorganization_idÚservice_account_idÚworkspace_idÚscope©Úprovider)ÚreturnÚstr)r   r   r    r   r   r   r   r   r   r   r   r	   Úbind_base_urlr   )Úbase_urlr&   r'   Úhas_literal_tokenÚidentity_token_pathÚidentity_providerr#   r,   s           r"   Ú_build_federation_resultr4      sß   € ô Ÿ™Ÿ™Ô(>Ó?ÐÜ—j‘j—n‘nÔ%8Ó9€OÜ*¬b¯j©jÐ8ÐÜ5Ó7Ðá¡_ØÙÐ!4Ð!<Øð Ð&Ü-Ð.AÓBÑó	ð ,Ðä*Ø 1Ø-Ø'ÜŸ:™:Ÿ>™>Ô*@ÓAô —Z‘Z—^‘^Ô$4Ó5Ò=¸Ü�j‰j�n‰nœYÓ'ô
€Hð ×Ñ˜8Ô$Ü XÔ.Ð.r$   zhttps://api.anthropic.com©r0   c                óÞ  — t         j                  j                  t        «      ryt         j                  j                  t        «      }|rt        t        |«      ¬«      S t        t         j                  j                  t        «      xs# t         j                  j                  t        «      «      }t        «       }|s|rCt        «       }|j                  | «       |j                  «       }t        |||j                  ¬«      S t        | ¬«      }|�|S t!        «       rDt        «       }|j                  | «       	 |j                  «       }t        |||j                  ¬«      S y# t"        $ r Y yw xY w)uÔ  Resolve a :class:`CredentialResult` from the environment per the
    credential-resolution spec. First match wins.

    Implements steps 2-5 of the spec precedence chain (step 1 is handled at
    the client constructor level, above this function):

    Step 2a: ``ANTHROPIC_API_KEY`` â†’ return ``None`` so the client uses its
             existing ``X-Api-Key`` header path. (API keys are not Bearer
             tokens, so they can't flow through this chain.)
    Step 2b: ``ANTHROPIC_AUTH_TOKEN`` â†’ :class:`StaticToken` (Bearer).
    Step 3:  ``ANTHROPIC_PROFILE`` / ``ANTHROPIC_CONFIG_DIR`` set, or the
             ``active_config`` pointer file exists â†’ load that profile.
             This is *explicit profile selection*; failures propagate.
    Step 4:  ``ANTHROPIC_FEDERATION_RULE_ID`` + ``ANTHROPIC_ORGANIZATION_ID``
             + ``ANTHROPIC_IDENTITY_TOKEN[_FILE]`` â†’ direct jwt-bearer
             exchange via :class:`WorkloadIdentityCredentials`. Critically,
             step 4 sits **between** explicit profile (step 3) and
             fallback profile (step 5): a machine with WIF env vars wired
             up must use WIF even if a leftover ``default`` profile exists
             on disk, but a user who explicitly ``ANTHROPIC_PROFILE=dev``
             still gets their profile.
    Step 5:  Fallback active profile from disk (``configs/default.json``
             or whatever ``active_config`` points at). Errors at this step
             are swallowed and the chain falls through â€” a corrupt
             unselected profile shouldn't break an otherwise-explicit
             api_key= path.

    Returns ``None`` when nothing matches â€” the client will fall back to
    its normal "no auth configured" error.
    Nr+   )r,   Úextra_headersr0   r5   )r   r   r    r
   r   r   r   Úboolr   r   r   r   r/   r7   Úresolved_base_urlr4   r   r   )r0   Ú
auth_tokenÚenv_explicitÚpointer_explicitÚ
creds_filer7   Úfederation_results          r"   r   r   L   s:  € ô@ 
‡z�z‡~�~”kÔ"Øô —‘—‘¤Ó/€JÙÜ¬°ZÓ)@ÔAÐAô
 œŸ
™
Ÿ™¤{Ó3ÒU´r·z±z·~±~ÄnÓ7UÓV€LÜ2Ó4ÐÙÑ'Ü$Ó&ˆ
Ø× Ñ  Ô*Ø"×0Ñ0Ó2ˆÜØØ'Ø×1Ñ1ô
ð 	
ô 1¸(ÔCÐØÐ$Ø Ð ô "Ô#Ü$Ó&ˆ
Ø× Ñ  Ô*ð	Ø&×4Ñ4Ó6ˆMô  ØØ'Ø×1Ñ1ô
ð 	
ð øô ò 	Ùð	ús   Ä7E  Å 	E,Å+E,)r0   r.   r-   zOptional[CredentialResult])!Ú
__future__r   r   Útypingr   Ú_typesr   r   Ú	_workloadr   Ú
_constantsr	   r
   r   r   r   r   r   r   r   r   r   r   r   Ú
_providersr   r   r   Ú_exceptionsr   Ú__all__r4   r   © r$   r"   Ú<module>rH      sN   ðÝ "ã 	Ý ç ;Ý 2÷÷ ÷ õ ÷ HÑ GÝ )à Ð
!€ó,/ð^ ,Gö Or$   