Ë
    A²Xj}�  ã                  óÊ  — U d dl mZ d dlZd dlZd dlZd dlZd dlZd dlZd dlZd dl	m
Z
mZmZmZmZmZ d dlmZ d dlZddlmZmZ ddlmZmZmZmZmZmZmZmZmZm Z m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z, dd	l-m.Z.  ej^                  e0«      Z1d
e2d<   e
rddl3m4Z4 g d¢Z5dd„Z6dZ7dZ8dZ9dZ:dZ;dd„Z< G d„ d«      Z= G d„ d«      Z> G d„ d«      Z? G d„ d«      Z@ G d„ de?«      ZAy) é    )ÚannotationsN)ÚTYPE_CHECKINGÚAnyÚDictÚUnionÚOptionalÚcast)Úoverrideé   )ÚAccessTokenÚIdentityTokenProvider)Ú	ENV_SCOPEÚENV_PROFILEÚENV_BASE_URLÚENV_AUTH_TOKENÚENV_CONFIG_DIRÚTOKEN_ENDPOINTÚDEFAULT_BASE_URLÚENV_WORKSPACE_IDÚENV_ORGANIZATION_IDÚOAUTH_API_BETA_HEADERÚENV_FEDERATION_RULE_IDÚENV_SERVICE_ACCOUNT_IDÚTOKEN_EXCHANGE_TIMEOUTÚENV_IDENTITY_TOKEN_FILEÚGRANT_TYPE_REFRESH_TOKENÚMANDATORY_REFRESH_SECONDSÚ_user_agentÚ_require_httpsÚ_active_profileÚ_config_file_pathÚ_credentials_file_pathÚresolve_identity_token_pathé   )ÚAnthropicErrorzlogging.LoggerÚlog)ÚWorkloadIdentityCredentials)ÚStaticTokenÚEnvTokenÚCredentialsFileÚInMemoryConfigÚIdentityTokenFilec                ó„   — | €y	 t        | «      S # t        t        f$ r }|�d|› �nd}t        |› d| ›d�«      |‚d}~ww xY w)z@Parse a credentials-file ``expires_at`` field into Unix seconds.Nzcredentials file at Úcredentialsz has invalid 'expires_at' u“   ; expected an integer Unix timestamp in seconds. The SDK does not parse ISO8601 â€” convert with int(datetime.timestamp()) before writing the file.)ÚintÚ	TypeErrorÚ
ValueErrorr%   )ÚvalueÚsourceÚerrÚwheres       új/var/www/html/content_generation/venv/lib/python3.12/site-packages/anthropic/lib/credentials/_providers.pyÚ_coerce_expires_atr7   2   sl   € à€}ØðÜ�5‹zÐøÜ”zÐ"ò Ø39Ð3EÐ& v hÑ/È=ˆÜØˆgÐ/°¨yð 9Fð Gó
ð ð		ûðús   …
 �?Ÿ:º?Úoauth_tokenz1.0Úoidc_federationÚ
user_oauthc                óš  — dd„} || dt         «        || dt        «        || dt        «       |j                  d«      }|t        k(  rk ||dt
        «        ||dt        «        ||dt        «       |j                  d	«      s/t        j                  j                  t        «      }|r	d
|dœ|d	<   yyy|t        k(  r ||dt        «       yy)uÐ   Fill empty profile fields from corresponding ANTHROPIC_* env vars.

    The profile file is authoritative â€” this only fills fields the file left
    unset. Empty-string env values are treated as unset.
    c                óv   — | j                  |«      s(t        j                  j                  |«      }|r|| |<   y y y ©N)ÚgetÚosÚenviron)ÚtargetÚkeyÚenv_varÚvs       r6   Úfillz$_fill_missing_from_env.<locals>.fillU   s5   € à�z‰z˜#ŒÜ—
‘
—‘˜wÓ'ˆAÙØ��s’ð ð ó    Úbase_urlÚorganization_idÚworkspace_idÚtypeÚfederation_rule_idÚservice_account_idÚscopeÚidentity_tokenÚfile)r3   ÚpathN)rA   úDict[str, Any]rB   ÚstrrC   rR   ÚreturnÚNone)r   r   r   r>   ÚAUTH_TYPE_OIDC_FEDERATIONr   r   r   r?   r@   r   ÚAUTH_TYPE_USER_OAUTH)ÚconfigÚauthrE   Ú	auth_typerD   s        r6   Ú_fill_missing_from_envrZ   N   sÈ   € ó ñ 	ˆ�œ\Ô*ÙˆÐ"Ô$7Ô8Ùˆ�Ô!1Ô2à—‘˜Ó €IØÔ-Ò-ÙˆTÐ'Ô)?Ô@ÙˆTÐ'Ô)?Ô@ÙˆT�7œIÔ&Ø�x‰xÐ(Ô)Ü—
‘
—‘Ô6Ó7ˆAÙØ4:ÀAÑ)F�Ð%Ò&ð ð *ð 
Ô*Ò	*ÙˆT�7œIÕ&ð 
+rF   c                  ó&   — e Zd ZdZdd„Zddœdd„Zy)	r(   zQAn :class:`AccessTokenProvider` that always returns a fixed token with no expiry.c                ó   — || _         y r=   )Ú_token)ÚselfÚtokens     r6   Ú__init__zStaticToken.__init__p   s	   € Øˆ�rF   F©Úforce_refreshc               ó2   — ~t        | j                  d ¬«      S )N©r_   Ú
expires_at)r   r]   )r^   rb   s     r6   Ú__call__zStaticToken.__call__s   s   € ØÜ §¡¸Ô>Ð>rF   N)r_   rR   rS   rT   ©rb   ÚboolrS   r   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r`   rf   © rF   r6   r(   r(   m   s   „ Ù[óð 16ö ?rF   r(   c                  ó*   — e Zd ZdZefdd„Zddœdd„Zy)	r)   zQAn :class:`AccessTokenProvider` that reads ``ANTHROPIC_AUTH_TOKEN`` at call time.c                ó   — || _         y r=   )Ú_env_var)r^   rC   s     r6   r`   zEnvToken.__init__{   s	   € Øˆ�rF   Fra   c               ó¦   — ~t         j                  j                  | j                  «      }|€t	        d| j                  › d�«      ‚t        |d ¬«      S )NzEnvironment variable zN is not set. Set it or pass an explicit `credentials=` provider to the client.rd   )r?   r@   r>   rp   r%   r   )r^   rb   r2   s      r6   rf   zEnvToken.__call__~   sS   € ØÜ—
‘
—‘˜tŸ}™}Ó-ˆØˆ=Ü Ø'¨¯© ð 7Tð Uóð ô  °4Ô8Ð8rF   N)rC   rR   rS   rT   rg   )ri   rj   rk   rl   r   r`   rf   rm   rF   r6   r)   r)   x   s   „ Ù[à&4ô  ð 16ö 9rF   r)   c                  óì   — e Zd ZdZ	 dddœ	 	 	 	 	 dd„Zedd„«       Zedd„«       Zedd„«       Zdd„Z	dd	„Z
d d
„Zd!d„Zd!d„Zd"d„Zd#d„Zd#d„Zd$d„Zd!d„Zddœd%d„Zddœd&d„Zd'd„Zddœd&d„Zd(d„Zy))r*   uí  An :class:`AccessTokenProvider` backed by a named profile.

    A profile is a pair of files under the config directory
    (``~/.config/anthropic/`` by default; override with ``ANTHROPIC_CONFIG_DIR``):

    * ``configs/<profile>.json`` â€” non-secret. Holds the nested
      ``"authentication"`` object (discriminated by its ``"type"`` field), plus
      top-level ``organization_id``, ``workspace_id``, and ``base_url``.
      The ``authentication`` object may contain a ``credentials_path`` field
      overriding the credentials file location.
    * ``credentials/<profile>.json`` â€” secret (0600). Holds ``access_token``,
      ``expires_at``, and (for ``user_oauth`` with a ``client_id``)
      ``refresh_token``.

    The split keeps secret material out of files that may need to be readable
    by config-only consumers, and lets the SDK enforce 0600 on the credentials
    file without locking out config readers.

    Dispatches on the ``authentication.type`` discriminator:

    ``"oidc_federation"``
        OIDC workload identity federation. Lazily constructs a
        :class:`WorkloadIdentityCredentials` delegate from the nested auth
        fields plus the top-level ``organization_id`` and calls it to perform
        the jwt-bearer exchange.

    ``"user_oauth"``
        Output of an interactive PKCE login. If the auth block has a
        ``client_id``, performs ``refresh_token`` grants on expiry and
        writes the new tokens back to the credentials file (atomic replace,
        refresh-token rotation supported). Without a ``client_id``, the
        credentials file is treated as externally rotated â€” the SDK re-reads
        it on every invocation and returns whatever ``access_token`` is
        there, no refresh grant attempted. This is the pattern for a
        sidecar/daemon that mints the access token out-of-band.

    Args:
        profile: Profile name. ``None`` resolves via ``ANTHROPIC_PROFILE`` env
            â†’ ``<config_dir>/active_config`` pointer file â†’ ``"default"``.
    N)Úhttp_clientc               óÈ   — |�|n	t        «       | _        t        | j                  «      | _        d | _        || _        d | _        d | _        d | _        t        | _
        d | _        y r=   )r    Ú_profiler!   Ú_config_pathÚ_bound_base_urlÚ_http_clientÚ_owned_http_clientÚ_configÚ_credentials_pathr   Ú	_base_urlÚ_workload_delegate)r^   Úprofilers   s      r6   r`   zCredentialsFile.__init__³   s^   € ð $+Ð#6™¼OÓ<MˆŒÜ-¨d¯m©mÓ<ˆÔØ.2ˆÔØ'ˆÔØ:>ˆÔð 26ˆŒØ9=ˆÔÜ.ˆŒØIMˆÕrF   c                ó   — | j                   S r=   )ru   ©r^   s    r6   r~   zCredentialsFile.profileÆ   s   € à�}‰}ÐrF   c                ó   — | j                   S r=   )rv   r€   s    r6   Úconfig_pathzCredentialsFile.config_pathÊ   s   € à× Ñ Ð rF   c                ó€   — | j                  «       }|j                  d«      }|rt        |«      j                  d«      S dS )u‰  The ``base_url`` declared in the profile config file, if any.

        Returns ``None`` when the config has no top-level ``base_url`` key â€”
        callers should fall back to their own default rather than the
        provider's bound/default value, so a profile that *doesn't* pin a
        host never overrides an explicit client setting. Loads the config
        on first access.
        rG   Ú/N)Ú_load_configr>   rR   Úrstrip)r^   rW   Úraws      r6   Úresolved_base_urlz!CredentialsFile.resolved_base_urlÎ   s:   € ð ×"Ñ"Ó$ˆØ�j‰j˜Ó$ˆÙ'*Œs�3‹x�‰˜sÓ#Ð4°Ð4rF   c                ó
  — |j                  d«      }t        || j                  › d�¬«       || _        | j                  �E| j                  | j                  «      | _        t        | j                  | j                  › d�¬«       yy)aÝ  Adopt the owning client's ``base_url`` as a fallback for the token
        exchange. Slots between the config file's own ``base_url`` field and
        the hard-coded default; a ``base_url`` in the config file still wins.

        The owning client binds exactly once at construction; sharing one
        instance across clients with different ``base_url`` values is
        unsupported and silently picks the last bind when the config file
        doesn't pin a host.
        r„   ú
: base_url©ÚfieldN)r†   r   rv   rw   rz   Ú_resolve_base_urlr|   )r^   rG   Úbounds      r6   Úbind_base_urlzCredentialsFile.bind_base_urlÜ   su   € ð —‘ Ó$ˆô 	�u t×'8Ñ'8Ð&9¸Ð$DÕEØ$ˆÔØ�<‰<Ð#Ø!×3Ñ3°D·L±LÓAˆDŒNÜ˜4Ÿ>™>°D×4EÑ4EÐ3FÀjÐ1QÖRð $rF   c                óš   — |j                  d«      rt        |d   «      j                  d«      S | j                  �| j                  S t        S )u+  base_url precedence: top-level config field â†’ bound (the owning
        client's base_url, via :meth:`bind_base_url`) â†’ default. Validated
        against the scheme/TLS rules so a malicious config with
        ``base_url="http://evil/"`` can't exfiltrate the assertion or refresh
        token.rG   r„   )r>   rR   r†   rw   r   ©r^   rW   s     r6   r�   z!CredentialsFile._resolve_base_urlï   sI   € ð �:‰:�jÔ!Ü�v˜jÑ)Ó*×1Ñ1°#Ó6Ð6Ø×ÑÐ+Ø×'Ñ'Ð'ÜÐrF   c                ó¸   — | j                  «       }i }| j                  «       j                  d«      t        k7  r!|j                  d«      }|rt	        |«      |d<   |S )z×Return headers derived from the config file (e.g. ``workspace_id``).

        Eagerly reads the config if not yet loaded. The returned dict is
        suitable for merging into the client's default headers.
        rJ   rI   zanthropic-workspace-id)r…   Ú_auth_blockr>   rU   rR   )r^   rW   ÚheadersrI   s       r6   Úextra_headerszCredentialsFile.extra_headersû   s\   € ð ×"Ñ"Ó$ˆØ"$ˆð ×ÑÓ×!Ñ! &Ó)Ô-FÒFØ!Ÿ:™: nÓ5ˆLÙÜ47¸Ó4E�Ð0Ñ1ØˆrF   c                óˆ  — | j                   �| j                   S 	 | j                  j                  d¬«      }	 t        j                  |«      }t        |t        «      s/t	        d	| j                  › dt        |«      j                   › d�«      ‚t#        d|«      }|j%                  d«      }t        |t        «      s't	        d	| j                  › dt&        › dt(        › d�«      ‚t#        d|«      }t+        ||«       | j-                  |«      | _        t1        | j.                  | j                  › d�¬«       |j%                  d«      }|r2t3        j4                  t7        |«      «      j9                  «       | _        nt=        | j
                  «      | _        || _         |S # t        $ r:}t	        d| j                  › d| j
                  ›dt        › dt        › d�	«      |‚d}~wt        t        f$ r!}t	        d	| j                  › d
|› �«      |‚d}~ww xY w# t        j                  $ r!}t	        d	| j                  › d|› �«      |‚d}~ww xY w)zPRead and cache the config file, resolving ``base_url`` and ``credentials_path``.Núutf-8©ÚencodingzConfig file not found at ú
 (profile z). Set z' to select a different profile, or set z" to relocate the config directory.zConfig file at ú could not be read: ú is not valid JSON: z! must contain a JSON object, not Ú.rQ   ÚauthenticationzV is missing the 'authentication' object. Expected shape: {"authentication": {"type": "ú"|"ú", ...}, ...}rŠ   r‹   Úcredentials_path)rz   rv   Ú	read_textÚFileNotFoundErrorr%   ru   r   r   ÚOSErrorÚUnicodeDecodeErrorÚjsonÚloadsÚJSONDecodeErrorÚ
isinstanceÚdictrJ   ri   r	   r>   rU   rV   rZ   r�   r|   r   ÚpathlibÚPathrR   Ú
expanduserr{   r"   )r^   r‡   r4   Ú
raw_configrW   Úraw_authrX   r
   s           r6   r…   zCredentialsFile._load_config  sP  € à�<‰<Ð#Ø—<‘<Ðð		jØ×#Ñ#×-Ñ-°wÐ-Ó?ˆCð	jÜ"Ÿj™j¨›oˆJô ˜*¤dÔ+Ü Ø! $×"3Ñ"3Ð!4Ð4UÔVZÐ[eÓVf×VoÑVoÐUpÐpqÐróð ô Ð&¨
Ó3ˆà—:‘:Ð.Ó/ˆÜ˜(¤DÔ)Ü Ø! $×"3Ñ"3Ð!4ð 5ä-Ð.¨cÔ2FÐ1GÀðXóð ô
 Ð$ hÓ/ˆô 	˜v tÔ,à×/Ñ/°Ó7ˆŒÜ�t—~‘~°×0AÑ0AÐ/BÀ*Ð-MÕNà—8‘8Ð.Ó/ˆÙÜ%,§\¡\´#°h³-Ó%@×%KÑ%KÓ%MˆDÕ"ä%;¸D¿M¹MÓ%JˆDÔ"àˆŒØˆøôU !ò 	Ü Ø+¨D×,=Ñ,=Ð+>¸jÈÏÉÐHYð ZÜ"�mÐ#JÌ>ÐJZð [4ð5óð ð	ûô
 Ô+Ð,ò 	jÜ  ?°4×3DÑ3DÐ2EÐEYÐZ]ÐY^Ð!_Ó`ÐfiÐiûð	jûô ×#Ñ#ò 	jÜ  ?°4×3DÑ3DÐ2EÐEYÐZ]ÐY^Ð!_Ó`ÐfiÐiûð	jús:   šF ·H Æ	H
Æ"5GÇH
Ç)HÈH
ÈIÈ H<È<Ic           	     óB  — | j                   €J ‚| j                   }t        j                  dk(  r�	 t        j                  |d¬«      }t        j                  |j                  «      rt        d|› d
�«      ‚t        j                  |j                  «      }|dz  rt        d|› d|d›d|› d�«      ‚|dz  rt        j                  d|||«       	 |j                  d¬«      }	 t        j                   |«      }|j%                  d«      }|�M|t&        k7  rD| j(                  €J ‚| j(                  d   j%                  d«      }t        d|›dt&        ›d|›�«      ‚|S # t        $ r"}t        d|› d| j                  ›d�«      |‚d}~wt        $ r}t        d|› d	|› �«      |‚d}~ww xY w# t        $ r"}t        d|› d| j                  ›d�«      |‚d}~wt        t        f$ r}t        d|› d|› �«      |‚d}~ww xY w# t        j"                  $ r}t        d|› d|› �«      |‚d}~ww xY w)uj  Read the credentials file. Re-reads on every call â€” daemons rotate it.

        On Unix, verifies the file is not group/world-readable. World-readable
        credentials files are refused outright; group-readable files log a
        warning but are accepted. The check is skipped on Windows where POSIX
        mode bits don't carry the same meaning.
        NÚposixF)Úfollow_symlinkszCredentials file not found at rš   z).úCredentials file at z could not be accessed: zu is a symlink; refusing to follow (move the real file into place to keep secret material on the expected filesystem).é   z is world-readable (mode z#oz); run `chmod 600 z` before retrying.é8   zMCredentials file at %s is group-readable (mode %#o); consider `chmod 600 %s`.r—   r˜   r›   rœ   rJ   rž   zcredentials file has type z; expected z for authentication.type )r{   r?   ÚnameÚstatr£   r%   ru   r¤   ÚS_ISLNKÚst_modeÚS_IMODEr&   Úwarningr¢   r¥   r¦   r§   r¨   r>   ÚCREDENTIALS_FILE_TYPErz   )	r^   rP   Ú	file_statr4   Úmoder‡   ÚcredsÚactualrY   s	            r6   Ú_read_credentialsz!CredentialsFile._read_credentialsA  s�  € ð ×%Ñ%Ð1Ð1Ð1Ø×%Ñ%ˆÜ�7‰7�gÒðjÜŸG™G D¸%Ô@�	ô
 �|‰|˜I×-Ñ-Ô.Ü$Ø*¨4¨&ð 1jð kóð ô —<‘< 	× 1Ñ 1Ó2ˆDØ�eŠ|Ü$Ø*¨4¨&Ð0IÈ$ÈrÈð S&Ø&* VÐ+=ð?óð ð �eŠ|Ü—‘ØcØØØô	ð	bØ—.‘.¨'�.Ó2ˆCð
	bÜ$(§J¡J¨s£OˆEð —‘˜6Ó"ˆØÐ &Ô,AÒ"AØ—<‘<Ð+Ð+Ð+ØŸ™Ð%5Ñ6×:Ñ:¸6ÓBˆIÜ Ø,¨V¨J°kÔBWÐAZð [+Ø+4¨-ð9óð ð ˆøôW %ò tÜ$Ð'EÀdÀVÈ:ÐVZ×VcÑVcÐUfÐfhÐ%iÓjÐpsÐsûÜò jÜ$Ð';¸D¸6ÐAYÐZ]ÐY^Ð%_Ó`ÐfiÐiûðjûô, !ò 	pÜ Ð#AÀ$ÀÀzÐRV×R_ÑR_ÐQbÐbdÐ!eÓfÐloÐoûÜÔ+Ð,ò 	bÜ Ð#7¸°vÐ=QÐRUÐQVÐ!WÓXÐ^aÐaûð	bûô ×#Ñ#ò 	bÜ Ð#7¸°vÐ=QÐRUÐQVÐ!WÓXÐ^aÐaûð	bús_   ¯E ÃF" ÃG4 Å	FÅE<Å<FÆFÆFÆ"	G1Æ+GÇG1ÇG,Ç,G1Ç4HÈHÈHc                ó    — | j                   �| j                   S | j                  €t        j                  t        ¬«      | _        | j                  S )zFReturn an ``httpx.Client``, lazily creating (and tracking) one we own.)Útimeout)rx   ry   ÚhttpxÚClientr   r€   s    r6   Ú_get_http_clientz CredentialsFile._get_http_client{  sD   € à×ÑÐ(Ø×$Ñ$Ð$Ø×"Ñ"Ð*Ü&+§l¡lÔ;QÔ&RˆDÔ#Ø×&Ñ&Ð&rF   c                ó¬   — | j                   �!| j                   j                  «        d| _         | j                  �| j                  j                  «        yy)z3Close the owned ``httpx.Client`` if we created one.N)ry   Úcloser}   r€   s    r6   rÈ   zCredentialsFile.closeƒ  sK   € à×"Ñ"Ð.Ø×#Ñ#×)Ñ)Ô+Ø&*ˆDÔ#Ø×"Ñ"Ð.Ø×#Ñ#×)Ñ)Õ+ð /rF   c                ó    — d| _         d| _        y)aÌ  Drop the cached config so the next call re-reads it from disk.

        ``CredentialsFile`` caches the parsed config across calls to keep the
        hot path cheap; a daemon that rotates a profile in place (e.g. flips
        ``"type": "user_oauth"`` to ``"type": "oidc_federation"``) will not be
        picked up automatically. Callers that need to react to such changes
        can call ``reload()`` to force a fresh read on the next ``__call__``.
        N)rz   r}   r€   s    r6   ÚreloadzCredentialsFile.reload‹  s   € ð ˆŒØ"&ˆÕrF   c                óž  — | j                   €J ‚| j                   j                  }|j                  ddd¬«       t        j                  |d| j                   j
                  › d�d¬«      \  }}	 	 t        j                  |d«       t        j                  |t        j                  |d	¬
«      j                  d«      «       t        j                  |«       t        j                  |«       t        j                  || j                   «       	 t        j$                  |t        j&                  «      }	 t        j                  |«       t        j                  |«       y# t        j                  |«       w xY w# t        $ r' 	 t        j                   |«       ‚ # t"        $ r Y ‚ w xY ww xY w# t        j                  |«       w xY w# t"        $ r Y yw xY w)z;Atomic write to the credentials file (NOT the config file).NTiÀ  )ÚparentsÚexist_okr¾   r�   z.tmp)ÚdirÚprefixÚsuffixi€  é   )Úindentr—   )r{   ÚparentÚmkdirÚtempfileÚmkstempr¶   r?   ÚfchmodÚwriter¦   ÚdumpsÚencodeÚfsyncrÈ   ÚreplaceÚBaseExceptionÚunlinkr¤   ÚopenÚO_RDONLY)r^   ÚdatarÓ   ÚfdÚtmpÚdir_fds         r6   Ú_atomic_write_credentialsz)CredentialsFile._atomic_write_credentials—  sn  € à×%Ñ%Ð1Ð1Ð1Ø×'Ñ'×.Ñ.ˆØ�‰˜T¨D°uˆÔ=ô
 ×"Ñ" v¸¸$×:PÑ:P×:UÑ:UÐ9VÐVWÐ6XÐagÔh‰ˆˆCð	ðÜ—	‘	˜"˜eÔ$Ü—‘˜œTŸZ™Z¨°QÔ7×>Ñ>¸wÓGÔHÜ—‘˜”ä—‘˜”Ü�J‰J�s˜D×2Ñ2Ô3ð	Ü—W‘W˜V¤R§[¡[Ó1ˆFð!Ü—‘˜Ô ä—‘˜Õ øô! —‘˜•ûäò 	ðÜ—	‘	˜#”ð øô ò ØØðúð	ûô —‘˜Õ ûÜò 	Ùð	úsm   Á.A%E Ã5E3 Ä	$G  Ä.F& ÅG  ÅE0Å0E3 Å3	F#Å=FÆF#Æ	FÆF#ÆFÆF#Æ&F=Æ=G  Ç 	GÇGc                ó@   — | j                  «       }t        d|d   «      S )zEReturn the cached ``authentication`` sub-object from the config file.rQ   rž   )r…   r	   r‘   s     r6   r“   zCredentialsFile._auth_block½  s$   € à×"Ñ"Ó$ˆÜÐ$ fÐ-=Ñ&>Ó?Ð?rF   Fra   c               ó  — | j                  «       }|j                  d«      }|t        k(  r| j                  ||¬«      S |t        k(  r| j                  ||¬«      S t        d|›d| j                  › dt        ›dt        ›d�	«      ‚)NrJ   ra   úUnknown authentication.type ú at ú. Expected ú or r�   )r“   r>   rU   Ú_call_oidc_federationrV   Ú_call_user_oauthr%   rv   )r^   rb   rX   rY   s       r6   rf   zCredentialsFile.__call__Â  sš   € Ø×ÑÓ!ˆØ—H‘H˜VÓ$ˆ	àÔ1Ò1Ø×-Ñ-¨dÀ-Ð-ÓPÐPàÔ,Ò,Ø×(Ñ(¨¸]Ð(ÓKÐKäØ*¨9¨-°t¸D×<MÑ<MÐ;Nð OÜ1Ð4°DÔ9MÐ8PÐPQðSó
ð 	
rF   c               ó  — ddl m}m} | j                  «       }|j	                  d«      }|st        d| j                  › d�«      ‚|j	                  d«      }|s2t        |j	                  d«      | j                  «      }t        ||¬«      S |j	                  d	«      }	|	s) |d
| j                  ›dt        ›d| j                  › �«      ‚t        |j	                  d«      | j                  «      }|s&|�$t        j                  «       |k  rt        ||¬«      S t        |	|dœ}
	 | j                  «       j                  | j                  › t         › �|
dt"        t%        «       dœ¬«      }|j*                  dk7  r
 ||d¬«       |j-                  «       }|j	                  d«      }|s |d«      ‚|j	                  dd«      }	 t/        |«      }t/        t        j                  «       «      |z   }|j	                  d	«      xs |	}t4        |d<   t6        |d<   ||d<   ||d<   ||d	<   | j9                  |«       t        ||¬«      S # t&        j(                  $ r} |d|› �«      |‚d}~ww xY w# t0        t2        f$ r} |d|›d�«      |‚d}~ww xY w)zÞInteractive-login profile. With a ``client_id`` in the auth block,
        we run the refresh_token grant on expiry; without one, we treat the
        credentials file as externally rotated and just read it fresh.
        r   )ÚWorkloadIdentityErrorÚ_raise_token_endpoint_errorÚaccess_tokenr³   z is missing 'access_token'.Ú	client_idre   rd   Úrefresh_tokenzcredentials file for profile z (authentication.type z/ with client_id) must include 'refresh_token': N)Ú
grant_typeró   rò   zapplication/json)zContent-Typezanthropic-betaz
User-Agent)r¦   r”   z3user_oauth refresh failed to reach token endpoint: éÈ   zuser_oauth refresh failed)Úmessage_prefixz2user_oauth refresh response missing 'access_token'Ú
expires_ini  z5user_oauth refresh response has invalid 'expires_in' z(; expected an integer number of seconds.ÚversionrJ   )Ú	_workloadrï   rð   rÁ   r>   r%   r{   r7   r   ru   rV   Útimer   rÆ   Úpostr|   r   r   r   rÄ   Ú	HTTPErrorÚstatus_coder¦   r/   r0   r1   ÚCREDENTIALS_FILE_VERSIONr¼   rå   )r^   rX   rb   rï   rð   r¿   rñ   rò   re   ró   ÚbodyÚrespr4   ÚpayloadÚ
new_accessÚraw_expires_inr÷   Únew_expires_atÚnew_refreshs                      r6   rí   z CredentialsFile._call_user_oauthÓ  s¥  € ÷
 	Rà×&Ñ&Ó(ˆØ—y‘y Ó0ˆÙÜ Ð#7¸×8NÑ8NÐ7OÐOjÐ!kÓlÐlà—H‘H˜[Ó)ˆ	Ùô ,¨E¯I©I°lÓ,CÀT×E[ÑE[Ó\ˆJÜ \¸jÔIÐIàŸ	™	 /Ó2ˆÙÙ'Ø/°·±Ð/@Ð@VÜ'Ð*Ð*YØ×)Ñ)Ð*ð,óð ô (¨¯	©	°,Ó(?À×AWÑAWÓXˆ
Ù Ð!7¼D¿I¹I»KÈ*Ò<TÜ \¸jÔIÐIô 3Ø*Ø"ñ 
ˆð	nØ×(Ñ(Ó*×/Ñ/Ø—>‘>Ð"¤>Ð"2Ð3Øà$6ô
 '<Ü"-£-ñð 0ó ˆDð  ×Ñ˜sÒ"Ù'¨Ð=XÕYà"&§)¡)£+ˆØ—[‘[ Ó0ˆ
ÙÙ'Ð(\Ó]Ð]Ø Ÿ™ \°4Ó8ˆð	Ü˜^Ó,ˆJô œTŸY™Y›[Ó)¨JÑ6ˆØ—k‘k /Ó2ÒC°mˆä3ˆˆiÑÜ-ˆˆf‰Ø *ˆˆnÑØ,ˆˆlÑØ!,ˆˆoÑØ×&Ñ& uÔ-ä ¸ÔGÐGøô9 �‰ò 	nÙ'Ð*]Ð^aÐ]bÐ(cÓdÐjmÐmûð	nûô œ:Ð&ò 	Ù'ØGÈÐGYð Z9ð :óð ðûð	ús1   ÄAH8 Æ9I È8IÉIÉIÉJ É.I;É;J c                óØ   — | j                   €J ‚| j                   j                  «       sy	 | j                  «       S # t        $ r%}t	        |j
                  t        «      rY d}~y‚ d}~ww xY w)uÑ   ``_read_credentials`` variant that returns ``None`` on absence
        instead of raising â€” used by the federation disk-cache path where a
        missing credentials file just means "exchange now".
        N)r{   ÚexistsrÁ   r%   r©   Ú	__cause__r£   )r^   r4   s     r6   Ú_read_credentials_if_existsz+CredentialsFile._read_credentials_if_exists+  sd   € ð
 ×%Ñ%Ð1Ð1Ð1Ø×%Ñ%×,Ñ,Ô.Øð	Ø×)Ñ)Ó+Ð+øÜò 	Ü˜#Ÿ-™-Ô):Ô;ÜØûð	ús   «; »	A)ÁA$Á#A$Á$A)c               óž  — | j                   €| j                  |«      | _         | j                  €| j                  «       S | j                  «       }|so|�m|j	                  d«      }|j	                  d«      }	 |rH|�Ft        j
                  «       t        |«      t        z
  k  rt        t        |«      t        |«      ¬«      S | j                  «       }	 | j                  i |xs i ¥t        t        |j                   |j"                  dœ¥«       |S # t        t        f$ r Y Œ^w xY w# t$        $ r!}t&        j)                  d|«       Y d }~|S d }~ww xY w)Nrñ   re   rd   )rø   rJ   rñ   re   z?federation token disk-cache write-back failed (best-effort): %s)r}   Ú_build_workload_delegater{   r	  r>   rú   Úfloatr   r   rR   r/   r0   r1   rå   rþ   r¼   r_   re   r¤   r&   Údebug)r^   rX   rb   Úcachedrñ   re   r_   r4   s           r6   rì   z%CredentialsFile._call_oidc_federation:  sJ  € Ø×"Ñ"Ð*Ø&*×&CÑ&CÀDÓ&IˆDÔ#ð ×!Ñ!Ð)Ø×*Ñ*Ó,Ð,ð ×1Ñ1Ó3ˆÙ Ð!3Ø!Ÿ:™: nÓ5ˆLØŸ™ LÓ1ˆJð	á Ø"Ð.ÜŸ	™	›¤e¨JÓ&7Ô:SÑ&SÒSä&¬S°Ó->Ì3ÈzË?Ô[Ð[ð
 ×'Ñ'Ó)ˆð	^Ø×*Ñ*ðØ’| ðä7Ü1Ø$)§K¡KØ"'×"2Ñ"2òôð ˆøô# œzÐ*ò áðûô ò 	^Ü�I‰IÐWÐY\×]Ð]Øˆûð	^ús+   Á6A	D Ã:D" ÄDÄDÄ"	EÄ+EÅEc           
     óÂ  — ddl m}m} |j                  d«      }| j                  €J ‚| j                  j                  d«      }|r|s |dt
        ›d| j                  › �«      ‚|j                  d«      }|�a|j                  d«      }|d	k7  rt        d
|›d�«      ‚|j                  d«      }|s+t        d| j                  ›d| j                  › d|›d�«      ‚d }|rt        |«      n	t        «       }	 ||	|||j                  d«      | j                  j                  d«      |j                  d«      | j                  «       ¬«      }
|
j                  | j                  «       |
S )Nr   ©rï   r'   rK   rH   z%config file with authentication.type zS must include 'authentication.federation_rule_id' and top-level 'organization_id': rN   r3   rO   zidentity_token source z- is not supported; only 'file' is implementedrP   z@identity_token source 'file' requires a non-empty path; profile ré   z has identity_token=r�   rL   rI   rM   ©Úidentity_token_providerrK   rH   rL   rI   rM   rs   )rù   rï   r'   r>   rz   rU   rv   r%   ru   r,   rÆ   r�   r|   )r^   rX   rï   r'   rK   rH   Úidentity_token_cfgr3   Úidentity_token_pathÚproviderÚdelegates              r6   r  z(CredentialsFile._build_workload_delegateh  sˆ  € ÷ 	Rà!ŸX™XÐ&:Ó;ÐØ�|‰|Ð'Ð'Ð'ØŸ,™,×*Ñ*Ð+<Ó=ˆÙ!©Ù'Ø7Ô8QÐ7Tð UXà×$Ñ$Ð%ð'óð ð "ŸX™XÐ&6Ó7ÐØÐ)Ø'×+Ñ+¨HÓ5ˆFØ˜ÒÜ$Ð'=¸f¸ZÐGtÐ%uÓvÐvØ"4×"8Ñ"8¸Ó"@ÐÙ&ô %ðØ#Ÿ}™}Ð/¨t°D×4EÑ4EÐ3FÐFZÐ[mÐZpÐpqðsóð ð
 #'ÐÙ=PÔ$Ð%8Ô9ÔVgÓViˆñ
 /Ø$,Ø1Ø+Ø#Ÿx™xÐ(<Ó=ØŸ™×)Ñ)¨.Ó9Ø—(‘(˜7Ó#Ø×-Ñ-Ó/ô
ˆð 	×Ñ˜tŸ~™~Ô.ØˆrF   r=   )r~   úOptional[str]rs   úOptional[httpx.Client]rS   rT   ©rS   rR   ©rS   zpathlib.Path)rS   r  )rG   rR   rS   rT   )rW   rQ   rS   rR   )rS   zDict[str, str]©rS   rQ   )rS   zhttpx.Client©rS   rT   )rá   rQ   rS   rT   rg   )rX   rQ   rb   rh   rS   r   )rS   zOptional[Dict[str, Any]]©rX   rQ   rS   r'   )ri   rj   rk   rl   r`   Úpropertyr~   r‚   rˆ   r�   r�   r•   r…   rÁ   rÆ   rÈ   rÊ   rå   r“   rf   rí   r	  rì   r  rm   rF   r6   r*   r*   ‰   sà   „ ñ'ðV "&ðNð /3ñ	NàðNð ,ð	Nð
 
óNð& òó ðð ò!ó ð!ð ò5ó ð5óSó&
 óó&1óf8ót'ó,ó
'ó"óL@ð
 16õ 
ð" OTõ THópð TYõ ,ô\3rF   r*   c                  ó4   — e Zd ZdZddd„Zedd„«       Zd	d„Zy)
r,   zïAn :class:`IdentityTokenProvider` that reads a JWT from a file on every call.

    Kubernetes projected service-account tokens (and similar) are rotated in place,
    so the file MUST be re-read on every invocation rather than cached.
    Nc                óR   — t        |«      }|€t        dt        › d�«      ‚|| _        y )Nz;No identity token file path given. Pass `path=` or set the z environment variable.)r#   r%   r   Ú_path)r^   rP   Úresolveds      r6   r`   zIdentityTokenFile.__init__¥  s<   € Ü.¨tÓ4ˆØÐÜ ØMÔNeÐMfð g(ð )óð ð ˆ�
rF   c                ó   — | j                   S r=   )r!  r€   s    r6   rP   zIdentityTokenFile.path®  s   € à�z‰zÐrF   c                óâ  — 	 | j                   j                  d¬«      j                  «       }|st	        d| j                   › d�«      ‚|S # t        $ r}t	        d| j                   › d�«      |‚d }~wt
        $ r"}t	        d| j                   › d|› d�«      |‚d }~wt        $ r}t	        d| j                   › d	�«      |‚d }~wt        t        f$ r!}t	        d| j                   › d
|› �«      |‚d }~ww xY w)Nr—   r˜   z!Identity token file not found at r�   zIdentity token file at z" is not readable by this process: z;. Check the file mode and the effective uid of the process.zIdentity token path zF is a directory, not a file. Point at the projected token file itself.r›   z‹ is empty. If this is a Kubernetes projected service-account token, check the volume mount and the serviceAccountToken projection audience.)	r!  r¢   Ústripr£   r%   ÚPermissionErrorÚIsADirectoryErrorr¤   r¥   )r^   Úcontentr4   s      r6   rf   zIdentityTokenFile.__call__²  s,  € ð	kØ—j‘j×*Ñ*°GÐ*Ó<×BÑBÓDˆGñ Ü Ø)¨$¯*©*¨ð 6Pð Qóð ð
 ˆøô) !ò 	]Ü Ð#DÀTÇZÁZÀLÐPQÐ!RÓSÐY\Ð\ûÜò 	Ü Ø)¨$¯*©*¨Ð5WÐX[ÐW\ð ]Lð Móð ðûô !ò 	Ü Ø& t§z¡z lð 3<ð =óð ðûô Ô+Ð,ò 	kÜ Ð#:¸4¿:¹:¸,ÐFZÐ[^ÐZ_Ð!`ÓaÐgjÐjûð	kús;   ‚*A	 Á		C.ÁA,Á,C.Á8BÂC.Â!B;Â;C.ÃC)Ã)C.r=   )rP   z$Union[str, 'os.PathLike[str]', None]rS   rT   r  r  )ri   rj   rk   rl   r`   r  rP   rf   rm   rF   r6   r,   r,   ž  s%   „ ñôð òó ðôrF   r,   c                  ó”   ‡ — e Zd ZdZ ej
                  d«      Zdddœ	 	 	 	 	 	 	 d	d„Zed
d„«       Z	edd„«       Z
edˆ fd„«       Zˆ xZS )r+   uÆ  An :class:`AccessTokenProvider` driven by an in-memory config dict
    (same shape as ``configs/<profile>.json``) rather than files on disk.

    Intended for callers that want to construct an :class:`anthropic.Anthropic`
    client with a fully programmatic credentials setup â€” equivalent to the Go
    SDK's ``option.WithConfig`` / TypeScript SDK's ``ClientOptions.config``.

    Both ``authentication.type`` discriminator values are supported:

    ``"oidc_federation"``
        ``authentication.credentials_path`` is **optional**. If set, exchanged
        tokens are cached to / read from that file (same atomic 0600 write as
        :class:`CredentialsFile`). If omitted, every call performs a fresh
        jwt-bearer exchange with no on-disk cache.

    ``"user_oauth"``
        ``authentication.credentials_path`` is **required** â€” it is where the
        access/refresh tokens live. Behaviour is identical to a file-backed
        :class:`CredentialsFile` profile of the same shape.

    The implementation subclasses :class:`CredentialsFile` so the dispatch,
    refresh-grant, disk-cache and atomic-write logic are shared verbatim;
    only config loading and identity-token resolution are overridden.
    z<in-memory config>N)r  rs   c          	     ó°  — |j                  d«      }t        |t        «      st        dt        › dt
        › d�«      ‚t        d|«      }|j                  d«      }|t        t
        fvrt        d|›dt        ›d	t
        ›d
�«      ‚|j                  d«      }|t
        k(  r|st        dt
        ›d�«      ‚d| _        | j                  | _	        d | _
        || _        d | _        d | _        || _        || _        |r,t!        j"                  t%        |«      «      j'                  «       nd | _        | j+                  |«      | _        t/        | j,                  d¬«       y )Nrž   zaconfig dict is missing the 'authentication' object. Expected shape: {"authentication": {"type": "rŸ   r    rQ   rJ   rè   rê   rë   r�   r¡   zauthentication.type zŽ requires 'authentication.credentials_path' (where the access/refresh tokens live). For profile-based resolution, use CredentialsFile instead.z<in-memory>zconfig: base_urlr‹   )r>   r©   rª   r%   rU   rV   r	   ru   Ú_IN_MEMORY_PATHrv   rw   rx   ry   r}   Ú!_identity_token_provider_overriderz   r«   r¬   rR   r­   r{   r�   r|   r   )r^   rW   r  rs   r¯   rX   rY   r¡   s           r6   r`   zInMemoryConfig.__init__è  sq  € ð —:‘:Ð.Ó/ˆÜ˜(¤DÔ)Ü ðBÜB[ÐA\ð ]Ü)Ð*¨/ð;óð ô
 Ð$ hÓ/ˆØ—H‘H˜VÓ$ˆ	ØÔ6Ô8LÐMÑMÜ Ø.¨y¨mð <Ü5Ð8¸Ô=QÐ<TÐTUðWóð ð
  Ÿ8™8Ð$6Ó7ÐØÔ,Ò,Ñ5EÜ Ø&Ô';Ð&>ð ?Mð Nóð ð &ˆŒØ ×0Ñ0ˆÔØ.2ˆÔØ'ˆÔØ:>ˆÔØIMˆÔØ1HˆÔ.àˆŒÙUe¤§¡¬cÐ2BÓ.CÓ!D×!OÑ!OÔ!QÐkoˆÔØ×/Ñ/°Ó7ˆŒÜ�t—~‘~Ð-?Ö@rF   c                ó6   — | j                   €J ‚| j                   S r=   )rz   r€   s    r6   r…   zInMemoryConfig._load_config  s   € à�|‰|Ð'Ð'Ð'Ø�|‰|ÐrF   c                ó   — d | _         y r=   )r}   r€   s    r6   rÊ   zInMemoryConfig.reload  s   € ð #'ˆÕrF   c           
     óÜ  •— | j                   €t        ‰| �	  |«      S ddlm}m} |j                  d«      }| j                  €J ‚| j                  j                  d«      }|r|s |dt        ›d�«      ‚ || j                   |||j                  d«      | j                  j                  d«      |j                  d	«      | j                  «       ¬
«      }|j                  | j                  «       |S )Nr   r  rK   rH   z%config dict with authentication.type zQ must include 'authentication.federation_rule_id' and top-level 'organization_id'rL   rI   rM   r  )r,  Úsuperr  rù   rï   r'   r>   rz   rU   rÆ   r�   r|   )r^   rX   rï   r'   rK   rH   r  Ú	__class__s          €r6   r  z'InMemoryConfig._build_workload_delegate   sê   ø€ à×1Ñ1Ð9Ü‘7Ñ3°DÓ9Ð9çQà!ŸX™XÐ&:Ó;ÐØ�|‰|Ð'Ð'Ð'ØŸ,™,×*Ñ*Ð+<Ó=ˆÙ!©Ù'Ø7Ô8QÐ7Tð UVð Wóð ñ /Ø$(×$JÑ$JØ1Ø+Ø#Ÿx™xÐ(<Ó=ØŸ™×)Ñ)¨.Ó9Ø—(‘(˜7Ó#Ø×-Ñ-Ó/ô
ˆð 	×Ñ˜tŸ~™~Ô.ØˆrF   )rW   rQ   r  zOptional[IdentityTokenProvider]rs   r  rS   rT   r  r  r  )ri   rj   rk   rl   r«   r¬   r+  r`   r
   r…   rÊ   r  Ú__classcell__)r1  s   @r6   r+   r+   Ì  s“   ø„ ñð2 #�g—l‘lÐ#7Ó8€Oð DHØ.2ñ+Aàð+Að "Að	+Að
 ,ð+Að 
ó+AðZ òó ðð ò'ó ð'ð
 ôó ôrF   r+   )r2   r   r3   zOptional[pathlib.Path]rS   zOptional[int])rW   rQ   rX   rQ   rS   rT   )BÚ
__future__r   r?   r¦   r·   rú   Úloggingr«   rÕ   Útypingr   r   r   r   r   r	   Útyping_extensionsr
   rÄ   Ú_typesr   r   Ú
_constantsr   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r    r!   r"   r#   Ú_exceptionsr%   Ú	getLoggerri   r&   Ú__annotations__rù   r'   Ú__all__r7   r¼   ÚCONFIG_FILE_VERSIONrþ   rU   rV   rZ   r(   r)   r*   r,   r+   rm   rF   r6   Ú<module>r>     sÙ   ðÞ "ã 	Û Û Û Û Û Û ß B× BÝ &ã ç 6÷÷ ÷ ÷ ÷ ÷ õ0 *à'�g×'Ñ'¨Ó1€€^Ó 1áÝ6â
_€óð" &Ð ð Ð Ø Ð ð .Ð Ø#Ð ó'÷>?ñ ?÷9ñ 9÷"Rñ R÷j+ñ +ô\m�_õ mrF   