Ë
    A²XjÁ(  ã                  ó  — d dl mZ d dlZd dlZd dlZd dlmZ ddlmZ dZ	dZ
dZd	Zd
ZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZd+d„Zd,d„Z d-d„Z!d+d„Z"d.d „Z#d!d"œd/d#„Z$d0d$„Z%d1d%„Z&d1d&„Z'd2d'„Z(d2d(„Z)d3d4d)„Z*d2d*„Z+y)5é    )ÚannotationsN)ÚOptionalé   )ÚAnthropicErrorz+urn:ietf:params:oauth:grant-type:jwt-bearerÚrefresh_tokenz/v1/oauth/tokeng      >@zoauth-2025-04-20zoidc-federation-2026-04-01éx   é   Údefaultzhttps://api.anthropic.comÚANTHROPIC_API_KEYÚANTHROPIC_AUTH_TOKENÚANTHROPIC_CONFIG_DIRÚANTHROPIC_PROFILEÚANTHROPIC_IDENTITY_TOKENÚANTHROPIC_IDENTITY_TOKEN_FILEÚANTHROPIC_FEDERATION_RULE_IDÚANTHROPIC_ORGANIZATION_IDÚANTHROPIC_SERVICE_ACCOUNT_IDÚANTHROPIC_WORKSPACE_IDÚANTHROPIC_SCOPEÚANTHROPIC_BASE_URLc                 ó   — ddl m}  d| › �S )zÌ``User-Agent`` value sent on token-endpoint POSTs.

    Computed lazily so this module doesn't need to import ``_version`` at
    module load time (the credentials package is otherwise import-light).
    r   ©Ú__version__zanthropic-python/)Ú_versionr   r   s    új/var/www/html/content_generation/venv/lib/python3.12/site-packages/anthropic/lib/credentials/_constants.pyÚ_user_agentr   8   s   € õ (à˜{˜mÐ,Ð,ó    c                 ó¢  — t         j                  j                  t        «      } | rt	        j
                  | «      S t        j                  dk(  r_t         j                  j                  d«      }|rt	        j
                  |«      n#t        j
                  j                  «       dz  dz  }|dz  S t        j
                  j                  «       dz  dz  S )uY  Resolve the config directory.

    ``ANTHROPIC_CONFIG_DIR`` env var â†’ platform default.

    Platform defaults:
      * Linux & macOS: ``~/.config/anthropic/`` â€” XDG-style on both platforms
        for consistency across SDKs (macOS does **not** use
        ``~/Library/Application Support/``).
      * Windows: ``%APPDATA%\Anthropic\``
    Úwin32ÚAPPDATAÚAppDataÚRoamingÚ	Anthropicz.configÚ	anthropic)	ÚosÚenvironÚgetÚENV_CONFIG_DIRÚpathlibÚPathÚsysÚplatformÚhome)ÚenvÚappdataÚbases      r   Ú_config_dirr1   C   s˜   € ô �*‰*�.‰.œÓ
(€CÙ
Ü�|‰|˜CÓ Ð Ü
‡|�|�wÒÜ—*‘*—.‘. Ó+ˆÙ(/Œw�|‰|˜GÔ$´W·\±\×5FÑ5FÓ5HÈ9Ñ5TÐW`Ñ5`ˆØ�kÑ!Ð!Ü�<‰<×ÑÓ Ñ*¨[Ñ8Ð8r   c                 ó„   — 	 t        «       dz  j                  d¬«      j                  «       } | xs dS # t        $ r Y yw xY w)zxReturn the stripped contents of ``<config_dir>/active_config``, or ``None``
    if the pointer file is missing or empty.Úactive_configzutf-8)ÚencodingN)r1   Ú	read_textÚstripÚOSError)Únames    r   Ú_read_active_config_pointerr9   X   sJ   € ðÜ“ Ñ/×:Ñ:ÀGÐ:ÓL×RÑRÓTˆð Š<�4Ðøô ò Ùðús   ‚+3 ³	?¾?c                 ó´   — t         j                  j                  t        «      } | rt	        | t        ¬«       | S t        «       }|€t        S t	        |d¬«       |S )uò   Resolve the active profile name.

    ``ANTHROPIC_PROFILE`` env var â†’ ``<config_dir>/active_config`` pointer file
    â†’ ``"default"`` literal. The resolved name is validated against path-
    traversal patterns before being returned.
    ©Úsourcezactive_config pointer file)r%   r&   r'   ÚENV_PROFILEÚ_validate_profile_namer9   ÚDEFAULT_PROFILE)r.   r8   s     r   Ú_active_profiler@   b   sK   € ô �*‰*�.‰.œÓ
%€CÙ
Ü˜s¬;Õ7Øˆ
Ü&Ó(€DØ€|ÜÐÜ˜4Ð(DÕEØ€Kr   c               óª   — | j                  «       j                  d«      }|j                  d«      ry|j                  d«      ryt        |› d| ›d�«      ‚)a;  Reject non-``https://`` token-endpoint URLs.

    Localhost is allowed for testing so ``base_url="http://localhost:8080"``
    works against a local ``oauth_server`` instance; everything else must be
    TLS-encrypted because the body of these POSTs carries the assertion JWT
    or a long-lived refresh token.
    Ú/zhttps://N)zhttp://localhostzhttp://127.0.0.1zhttp://[::1]z must use https (got z^); the token-exchange endpoint carries secret material and cannot be used over cleartext HTTP.)ÚlowerÚrstripÚ
startswithr   )ÚurlÚfieldÚlowereds      r   Ú_require_httpsrI   t   sb   € ð �i‰i‹k× Ñ  Ó%€GØ×Ñ˜*Ô%ØØ×ÑÐRÔSØÜ
Øˆ'Ð& s gð .Jð 	Kóð r   zprofile namer;   c          	     ó@  — | st        |› d�«      ‚| | j                  «       k7  rt        |› d| ›d�«      ‚| j                  d«      rt        |› d| ›d�«      ‚ddt        j                  fD ]  }|sŒ|| v sŒt        |› d| ›d|›d�«      ‚ d	| v rt        |› d| ›d
�«      ‚y)aÝ  Reject profile names that could escape the config directory.

    Profile names come from user-controlled sources (``ANTHROPIC_PROFILE``,
    the ``active_config`` pointer file, ``CredentialsFile(profile=...)``) and
    are interpolated into filesystem paths. A value like ``"../../etc/shadow"``
    would otherwise let a read of ``configs/<profile>.json`` escape the config
    root entirely. Pass ``source=`` so the error message names where the bad
    value came from.
    z must not be empty.Ú z$ has leading or trailing whitespace.Ú.z must not start with a dot.rB   Ú\um    must not contain path separators â€” profiles are filenames under the config directory. Pick a name without Ú z must not contain null bytes.N)r   r6   rE   r%   Úsep)Úprofiler<   rO   s      r   r>   r>   ‡   sÛ   € ñ Ü ˜xÐ':Ð;Ó<Ð<Ø�'—-‘-“/Ò!Ü ˜x q¨¨Ð3WÐXÓYÐYØ×Ñ˜#ÔÜ ˜x q¨¨Ð3NÐOÓPÐPØ�Tœ2Ÿ6™6Ó"ˆÚ�3˜'’>Ü Ø�(˜!˜G˜;ð 'ZØZ]ÐY`Ð`aðcóð ð #ð �ÑÜ ˜x q¨¨Ð3PÐQÓRÐRð r   c                óº   — | j                  d¬«      }|j                  d¬«      }	 |j                  |«       |S # t        $ r}t        d|› d|› d�«      |‚d}~ww xY w)u®  Assert ``candidate`` resolves to a descendant of ``base``, return it verbatim.

    The containment check uses ``resolve(strict=False)`` on both sides so
    symlinks and ``..`` segments are normalized for the purposes of escape
    detection. The returned path is the *original* (unresolved) candidate â€”
    callers that care about symlink following must handle it themselves
    (e.g. ``os.stat(follow_symlinks=False)``).
    F)ÚstrictzResolved path z escapes config directory rL   N)ÚresolveÚrelative_toÚ
ValueErrorr   )r0   Ú	candidateÚbase_resolvedÚcandidate_resolvedÚerrs        r   Ú_resolve_underrZ   ¡   s{   € ð —L‘L¨�LÓ.€MØ"×*Ñ*°%Ð*Ó8ÐðwØ×&Ñ& }Ô5ð Ðøô ò wÜ˜~Ð.@Ð-AÐA[Ð\iÐ[jÐjkÐlÓmÐsvÐvûðwús   ¦9 ¹	AÁAÁAc                óV   — t        | «       t        «       }t        ||dz  | › d�z  «      S )zCPath to ``<config_dir>/configs/<profile>.json`` (non-secret, 0644).Úconfigsú.json©r>   r1   rZ   ©rP   r0   s     r   Ú_config_file_pathr`   ³   s/   € ä˜7Ô#Ü‹=€DÜ˜$  yÑ 0°g°Y¸eÐ3DÑ DÓEÐEr   c                óV   — t        | «       t        «       }t        ||dz  | › d�z  «      S )zCPath to ``<config_dir>/credentials/<profile>.json`` (secret, 0600).Úcredentialsr]   r^   r_   s     r   Ú_credentials_file_pathrc   º   s/   € ä˜7Ô#Ü‹=€DÜ˜$  }Ñ 4¸'¸À%Ð7HÑ HÓIÐIr   c                 óp   — 	 t        t        «       «      j                  «       S # t        t        f$ r Y yw xY w)a   Tighter auto-discover check for the tier-1 credential chain.

    Returns ``True`` only if the *active* profile's config file exists. The
    previous version returned ``True`` for any ``.json`` under ``configs/``,
    which meant a stray ``configs/work.json`` on disk was enough to steer
    ``default_credentials()`` into reading ``configs/default.json`` and
    failing because ``default.json`` wasn't there.
    F)r`   r@   Úis_filer7   r   © r   r   Ú_has_active_profile_configrg   Á   s5   € ðÜ ¤Ó!2Ó3×;Ñ;Ó=Ð=øÜ”^Ð$ò Ùðús   ‚ # £5´5c                 ó   — t        «       duS )u‘  True if the user wrote a non-empty ``active_config`` pointer file.

    This is an explicit opt-in signal equivalent to setting ``ANTHROPIC_PROFILE``:
    the user has told us which profile to load. If the target config file is
    missing or malformed, the chain should surface that error rather than
    silently falling through â€” matching how ``ANTHROPIC_PROFILE=missing``
    behaves today.
    N)r9   rf   r   r   Ú_has_explicit_active_configri   Ð   s   € ô 'Ó(°Ð4Ð4r   c                ó¦   — | �t        j                  | «      S t        j                  j	                  t
        «      }|rt        j                  |«      S y)u<   ctor arg â†’ ``ANTHROPIC_IDENTITY_TOKEN_FILE`` â†’ ``None``.N)r)   r*   r%   r&   r'   ÚENV_IDENTITY_TOKEN_FILE)Úpathr.   s     r   Úresolve_identity_token_pathrm   Ü   s?   € àÐÜ�|‰|˜DÓ!Ð!Ü
�*‰*�.‰.Ô0Ó
1€CÙ
Ü�|‰|˜CÓ Ð Ør   c                 óÂ  — t         j                  j                  t        «      s#t         j                  j                  t        «      ryt        «       ryt         j                  j                  t        «      rjt         j                  j                  t        «      rGt         j                  j                  t        «      s#t         j                  j                  t        «      ryy)uÒ  True if the environment / filesystem contains signals that would
    normally drive the tier-1 (profile) or tier-2 (env federation) paths of
    :func:`default_credentials`.

    Used by the shadow-warning detection in the client constructor: if a
    static ``ANTHROPIC_API_KEY`` / ``ANTHROPIC_AUTH_TOKEN`` is set alongside
    any of these signals, the auto-discovery would have yielded a credential
    but got silently shadowed â€” and the user should know.
    TF)
r%   r&   r'   r=   r(   ri   ÚENV_FEDERATION_RULE_IDÚENV_ORGANIZATION_IDrk   ÚENV_IDENTITY_TOKENrf   r   r   Ú"_has_auto_discoverable_credentialsrr   æ   sw   € ô 
‡z�z‡~�~”kÔ"¤b§j¡j§n¡n´^Ô&DØÜ"Ô$ØÜ	‡z�z‡~�~Ô,Ô-´"·*±*·.±.ÔATÔ2UÜ�:‰:�>‰>Ô1Ô2´b·j±j·n±nÔEWÔ6XØØr   )ÚreturnÚstr)rs   úpathlib.Path)rs   zOptional[str])rF   rt   rG   rt   rs   ÚNone)rP   rt   r<   rt   rs   rv   )r0   ru   rV   ru   rs   ru   )rP   rt   rs   ru   )rs   Úbool)N)rl   zstr | os.PathLike[str] | Noners   zpathlib.Path | None),Ú
__future__r   r%   r+   r)   Útypingr   Ú_exceptionsr   ÚGRANT_TYPE_JWT_BEARERÚGRANT_TYPE_REFRESH_TOKENÚTOKEN_ENDPOINTÚTOKEN_EXCHANGE_TIMEOUTÚOAUTH_API_BETA_HEADERÚFEDERATION_BETA_HEADERÚADVISORY_REFRESH_SECONDSÚMANDATORY_REFRESH_SECONDSr?   ÚDEFAULT_BASE_URLÚENV_API_KEYÚENV_AUTH_TOKENr(   r=   rq   rk   ro   rp   ÚENV_SERVICE_ACCOUNT_IDÚENV_WORKSPACE_IDÚ	ENV_SCOPEÚENV_BASE_URLr   r1   r9   r@   rI   r>   rZ   r`   rc   rg   ri   rm   rr   rf   r   r   Ú<module>rŠ      së   ðÝ "ã 	Û 
Û Ý å )àEÐ Ø*Ð Ø"€ð Ð ð
 +Ð ð 6Ð ð Ð ØÐ à€Ø.Ð ð "€Ø'€ð (€Ø!€ð 0Ð Ø9Ð Ø7Ð Ø1Ð Ø7Ð Ø+Ð Ø€	Ø#€ó-ó9ó*óó$ð& ;Iõ Só4ó$FóJóó	5ôôr   