ó
    ýÞ j«�  ã                  ó2  • S SK Jr  S SKrS SKrS SKJrJr  S SKJrJ	r	  \R                  " S\	R                  S9r\R                  " S\	R                  S9r " S S	5      r\R                  " S
SS9r " S S\R"                  \   5      r\R                  " SSS9r " S S\R(                  \   5      r\R                  " SSS9r\R                  " SSS9r\R                  " SSS9r\R                  " SSS9r\R                  " SSS9r\R                  " S\S9r\R:                  S   r\\R:                  S   -  r " S S\R(                  \\\\\\4   5      r  " S S\ \	RB                  \	RD                  \	RF                  \	RH                  \	RJ                  \4   5      r& " S S \ \	RN                  \	RP                  \	RR                  \	RT                  \	RV                  \4   5      r, " S! S"\ \	RZ                  \	R\                  \	R^                  \	R`                  \	Rb                  \4   5      r2 " S# S$\R(                  \   5      r3 " S% S&5      r4\R                  " S'\\5\\Rl                  4      S9r7 " S( S)5      r8          S.S* jr9S/S+ jr:    S0S, jr;/ S-Qr<g)1é    )ÚannotationsN)ÚCallableÚSequence)Ú
exceptionsÚtypesÚTH)ÚboundÚAHc                  ó<   • \ rS rSrSrSr\r \r SS jrSS jr	Sr
g)	ÚAuthé   aÕ  Add custom authentication and authorization management to your LangGraph application.

The Auth class provides a unified system for handling authentication and
authorization in LangGraph applications. It supports custom user authentication
protocols and fine-grained authorization rules for different resources and
actions.

To use, create a separate python file and add the path to the file to your
LangGraph API configuration file (`langgraph.json`). Within that file, create
an instance of the Auth class and register authentication and authorization
handlers as needed.

Example `langgraph.json` file:

```json
{
  "dependencies": ["."],
  "graphs": {
    "agent": "./my_agent/agent.py:graph"
  },
  "env": ".env",
  "auth": {
    "path": "./auth.py:my_auth"
  }
```

Then the LangGraph server will load your auth file and run it server-side whenever a request comes in.

???+ example "Basic Usage"

    ```python
    from langgraph_sdk import Auth

    my_auth = Auth()

    @my_auth.authenticate
    async def authenticate(authorization: str) -> Auth.types.MinimalUserDict:
        user = await verify_token(authorization)  # Your token verification logic
        if not user:
            raise Auth.exceptions.HTTPException(
                status_code=401, detail="Unauthorized"
            )
        return {
            "identity": user["id"],
            "permissions": user.get("permissions", []),
        }

    # Default deny: reject all requests that don't have a specific handler
    @my_auth.on
    async def deny_all(ctx: Auth.types.AuthContext, value: Any) -> False:
        return False

    # Allow users to create threads with their own identity as owner
    @my_auth.on.threads.create
    async def allow_thread_create(
        ctx: Auth.types.AuthContext, value: Auth.types.on.threads.create.value
    ):
        metadata = value.setdefault("metadata", {})
        metadata["owner"] = ctx.user.identity

    # Allow users to read and search their own threads
    @my_auth.on.threads.read
    async def allow_thread_read(
        ctx: Auth.types.AuthContext, value: Auth.types.on.threads.read.value
    ) -> Auth.types.FilterType:
        return {"owner": ctx.user.identity}

    @my_auth.on.threads.search
    async def allow_thread_search(
        ctx: Auth.types.AuthContext, value: Auth.types.on.threads.search.value
    ) -> Auth.types.FilterType:
        return {"owner": ctx.user.identity}

    # Scope all store operations to the user's namespace
    @my_auth.on.store
    async def scope_store(ctx: Auth.types.AuthContext, value: Auth.types.on.store.value):
        namespace = tuple(value["namespace"]) if value.get("namespace") else ()
        if not namespace or namespace[0] != ctx.user.identity:
            namespace = (ctx.user.identity, *namespace)
        value["namespace"] = namespace
    ```

???+ note "Request Processing Flow"

    1. Authentication (your `@auth.authenticate` handler) is performed first on **every request**
    2. For authorization, the most specific matching handler is called:
        * If a handler exists for the exact resource and action, it is used (e.g., `@auth.on.threads.create`)
        * Otherwise, if a handler exists for the resource with any action, it is used (e.g., `@auth.on.threads`)
        * Finally, if no specific handlers match, the global handler is used (e.g., `@auth.on`)
        * If no global handler is set, the request is accepted

    This allows you to set default behavior with a global handler while
    overriding specific routes as needed.
)Ú_authenticate_handlerÚ_global_handlersÚ_handler_cacheÚ	_handlersÚonc                ó^   • [        U 5      U l         0 U l        / U l        S U l        0 U l        g ©N)Ú_Onr   r   r   r   r   )Úselfs    ÚU/var/www/html/gaurav/venv/lib/python3.13/site-packages/langgraph_sdk/auth/__init__.pyÚ__init__ÚAuth.__init__�   s7   € Ü�d“)ˆŒðV	ðr FHˆŒØ57ˆÔØAEˆÔ"ØDFˆÕó    c                ó^   • U R                   b  [        SU R                    S35      eXl         U$ )a	  Register an authentication handler function.

The authentication handler is responsible for verifying credentials
and returning user scopes. It can accept any of the following parameters
by name:

    - request (Request): The raw ASGI request object
    - path (str): The request path, e.g., "/threads/abcd-1234-abcd-1234/runs/abcd-1234-abcd-1234/stream"
    - method (str): The HTTP method, e.g., "GET"
    - path_params (dict[str, str]): URL path parameters, e.g., {"thread_id": "abcd-1234-abcd-1234", "run_id": "abcd-1234-abcd-1234"}
    - query_params (dict[str, str]): URL query parameters, e.g., {"stream": "true"}
    - headers (dict[bytes, bytes]): Request headers
    - authorization (str | None): The Authorization header value (e.g., "Bearer <token>")

Args:
    fn: The authentication handler function to register.
        Must return a representation of the user. This could be a:
            - string (the user id)
            - dict containing {"identity": str, "permissions": list[str]}
            - or an object with identity and permissions properties
        Permissions can be optionally used by your handlers downstream.

Returns:
    The registered handler function.

Raises:
    ValueError: If an authentication handler is already registered.

???+ example "Examples"

    Basic token authentication:

    ```python
    @auth.authenticate
    async def authenticate(authorization: str) -> str:
        user_id = verify_token(authorization)
        return user_id
    ```

    Accept the full request context:

    ```python
    @auth.authenticate
    async def authenticate(
        method: str,
        path: str,
        headers: dict[str, bytes]
    ) -> str:
        user = await verify_request(method, path, headers)
        return user
    ```

    Return user name and permissions:

    ```python
    @auth.authenticate
    async def authenticate(
        method: str,
        path: str,
        headers: dict[str, bytes]
    ) -> Auth.types.MinimalUserDict:
        permissions, user = await verify_request(method, path, headers)
        # Permissions could be things like ["runs:read", "runs:write", "threads:read", "threads:write"]
        return {
            "identity": user["id"],
            "permissions": permissions,
            "display_name": user["name"],
        }
    ```
z&Authentication handler already set as Ú.)r   Ú
ValueError©r   Úfns     r   ÚauthenticateÚAuth.authenticateá   s?   € ðN ×%Ñ%Ñ1ÜØ8¸×9SÑ9SÐ8TÐTUÐVóð ð &(Ô"Øˆ	r   N)ÚreturnÚNone)r   r
   r"   r
   )Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__Ú	__slots__r   r   r   r    Ú__static_attributes__© r   r   r   r      s6   † ñ]ð~€Ið €Eð0ð
 €Jðô^G÷@Lr   r   ÚVT)Úcontravariantc                  ó*   • \ rS rSr      SS jrSrg)Ú_ActionHandleri5  c             ƒ  ó   #   • g 7fr   r+   )r   ÚctxÚvalues      r   Ú__call__Ú_ActionHandler.__call__6  s   é € à!ùs   ‚r+   N)r1   ztypes.AuthContextr2   r,   r"   ztypes.HandlerResult)r$   r%   r&   r'   r3   r*   r+   r   r   r/   r/   5  s   † ð"Ø'ð"Ø01ð"à	÷"r   r/   ÚT)Ú	covariantc                  ó<   • \ rS rSr          SS jrSS jrSrg)Ú_ResourceActionOni>  c                ó4   • Xl         X l        X0l        X@l        g r   )ÚauthÚresourceÚactionr2   )r   r:   r;   r<   r2   s        r   r   Ú_ResourceActionOn.__init__?  s   € ð Œ	Ø ŒØŒØ�
r   c                ót   • [        U5        [        U R                  U R                  U R                  U5        U$ r   )Ú_validate_handlerÚ_register_handlerr:   r;   r<   r   s     r   r3   Ú_ResourceActionOn.__call__M  s)   € Ü˜"ÔÜ˜$Ÿ)™) T§]¡]°D·K±KÀÔDØˆ	r   )r<   r:   r;   r2   N)
r:   r   r;   ú0typing.Literal['threads', 'crons', 'assistants']r<   zLtyping.Literal['create', 'read', 'update', 'delete', 'search', 'create_run']r2   útype[T]r"   r#   ©r   ú_ActionHandler[T]r"   rE   )r$   r%   r&   r'   r   r3   r*   r+   r   r   r8   r8   >  s=   † ðàðð Cðð
ð	ð ðð 
ô÷r   r8   ÚVCreateÚVUpdateÚVReadÚVDeleteÚVSearchÚResourceActionT)ÚcreateÚreadÚupdateÚdeleteÚsearchÚ
create_runc                  ó   • \ rS rSr% SrS\S'   S\S'   S\S'   S	\S
'   S\S'   S\S'         SS jr\R                      SS j5       r	\R                  SSS.     SS jj5       r	 SSSS.       SS jjjr	Sr
g)Ú_ResourceOni^  z4
Generic base class for resource-specific handlers.
z3type[VCreate | VUpdate | VRead | VDelete | VSearch]r2   ztype[VCreate]ÚCreateztype[VRead]ÚReadztype[VUpdate]ÚUpdateztype[VDelete]ÚDeleteztype[VSearch]ÚSearchc                ó4  • Xl         X l        [        XSU R                  5      U l        [        XSU R
                  5      U l        [        XSU R                  5      U l        [        XSU R                  5      U l
        [        XSU R                  5      U l        g )NrL   rM   rN   rO   rP   )r:   r;   r8   rT   rL   rU   rM   rV   rN   rW   rO   rX   rP   )r   r:   r;   s      r   r   Ú_ResourceOn.__init__m  s�   € ð
 Œ	Ø ŒÜ2CØ˜H d§k¡kó3
ˆŒô /@Ø˜F D§I¡Ió/
ˆŒ	ô 3DØ˜H d§k¡kó3
ˆŒô 3DØ˜H d§k¡kó3
ˆŒô 3DØ˜H d§k¡kó3
ˆ�r   c                ó   • g r   r+   r   s     r   r3   Ú_ResourceOn.__call__„  s	   € ð ILr   N©Ú	resourcesÚactionsc               ó   • g r   r+   ©r   r^   r_   s      r   r3   r\   �  s   € ð r   c               óh   ^ ^^•     SUUU 4S jjnUb  U" [         R                  " SU5      5      $ U$ )Nú=_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]c                ó   >• [        U 5        Tc  T	R                  /nOE[        T[        5      (       a  T/nO,[        T[        5      (       a  [        T5      nO[        S5      eUT	R                  /:w  a  [        ST	R                  < SU< S35      eTc  S/nOE[        T[        5      (       a  T/nO,[        T[        5      (       a  [        T5      nO[        S5      eU(       d  [        S5      e[        S U 5       5      (       d  [        S5      e[        T	5      R                  5        Vs1 sH&  n[        U[        5      (       d  M  UR                  iM(     nnTb  [        [        U5      U-
  5      O/ nU(       a*  [        S	T	R                   S
SR                  U5       35      e[!        U5      [!        [        U5      5      :w  a  [        S5      eU HE  nT	R                  U4T	R"                  R$                  ;   d  M+  [        ST	R                   SU S35      e   U H$  n['        T	R"                  T	R                  X`5        M&     U $ s  snf )Nz1resources must be a string or sequence of stringsz Resource-specific decorator for z cannot register handlers for z4. Use @auth.on(...) for other or multiple resources.Ú*z/actions must be a string or sequence of stringszactions must not be emptyc              3  ó@   #   • U H  n[        U[        5      v •  M     g 7fr   )Ú
isinstanceÚstr)Ú.0r<   s     r   Ú	<genexpr>Ú:_ResourceOn.__call__.<locals>.decorator.<locals>.<genexpr>Å  s   é € ÐI¹[°6”z &¬#×.Ð.º[ùs   ‚zInvalid action(s) for z: ú, z#actions must not contain duplicatesútypes.Handler already set for r   )r?   r;   rg   rh   r   ÚlistÚ	TypeErrorr   ÚallÚvarsÚvaluesr8   r<   ÚsortedÚsetÚjoinÚlenr:   r   r@   )
ÚhandlerÚresource_listÚaction_listr2   Úvalid_actionsÚinvalid_actionsr<   r_   r^   r   s
          €€€r   Ú	decoratorÚ'_ResourceOn.__call__.<locals>.decorator©  s+  ø€ ô ˜gÔ&ØÑ Ø!%§¡ ‘Ü˜I¤s×+Ñ+Ø!* ‘Ü˜I¤x×0Ñ0Ü $ Y£‘äÐ SÓTÐTØ §¡ Ó/Ü Ø6°t·}±}Ñ6Gð H-Ø-:Ñ,=ð >7ð7óð ð
 ‰Ø"˜e‘Ü˜G¤S×)Ñ)Ø&˜i‘Ü˜G¤X×.Ñ.Ü" 7›m‘äÐ QÓRÐRÞÜ Ð!<Ó=Ð=ÜÑI¹[ÓI×IÑIÜÐ QÓRÐRô " $›Z×.Ñ.Ô0óá0�EÜ˜eÔ%6×7ó �—”Ù0ð ð ð =DÑ<O””s˜;Ó'¨-Ñ7Ô8ÐUWð ö Ü Ø,¨T¯]©]¨O¸2¸d¿i¹iÈÓ>XÐ=YÐZóð ô �;Ó¤3¤s¨;Ó'7Ó#8Ó8Ü Ð!FÓGÐGÛ%�Ø—M‘M 6Ð*¨d¯i©i×.AÑ.AÕAÜ$Ø8¸¿¹¸ÀrÈ&ÈÐQRÐSóð ñ &ó
 &�Ü! $§)¡)¨T¯]©]¸FÖLñ &àˆNùò+s   Ä-IÅ	I)rw   rc   r"   rc   )ÚtypingÚcast©r   r   r^   r_   r|   s   ` `` r   r3   r\   ˜  sL   ú€ ð"3	ØRð3	àJ÷3	ñ 3	ðj ‰>ÙÜ—’ØSØóóð ð Ðr   )r:   rL   rO   rM   r;   rP   rN   ©r:   r   r;   rB   r"   r#   )r   ze_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch] | _ActionHandler[dict[str, typing.Any]]r"   rc   )r^   ústr | Sequence[str] | Noner_   ú2ResourceActionT | Sequence[ResourceActionT] | Noner"   zˆCallable[[_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]], _ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]]r   )r   zl_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch] | _ActionHandler[dict[str, typing.Any]] | Noner^   r‚   r_   rƒ   r"   zÈ_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch] | Callable[[_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]], _ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]])r$   r%   r&   r'   r(   Ú__annotations__r   r~   Úoverloadr3   r*   r+   r   r   rS   rS   ^  s  ‡ ñð ?Ó>àÓØ
ÓØÓØÓØÓð
àð
ð Cð
ð 
ô	
ð. ‡_�_ðLð4ðLð 
GóLó ðLð ‡_�_ð 15ØFJñ	ð .ðð Dð	ð

ôó ðð  ðMð 15ØFJñMððMð .ðMð DðMð	
÷Mñ Mr   rS   c                  ó  • \ rS rSr\R
                  \R                  -  \R                  -  \R                  -  \R                  -  r
\R
                  r\R                  r\R                  r\R                  r\R                  rSrg)Ú_AssistantsOniè  r+   N)r$   r%   r&   r'   r   ÚAssistantsCreateÚAssistantsReadÚAssistantsUpdateÚAssistantsDeleteÚAssistantsSearchr2   rT   rU   rV   rW   rX   r*   r+   r   r   r‡   r‡   è  s‡   † ð 	×ÑØ
×
Ñ
ñ	à
×
 Ñ
 ñ	!ð ×
 Ñ
 ñ	!ð ×
 Ñ
 ñ		!ð 
ð ×#Ñ#€FØ×Ñ€DØ×#Ñ#€FØ×#Ñ#€FØ×#Ñ#ƒFr   r‡   c                  ób  ^ • \ rS rSr\R
                  \R                  -  \R                  -  \R                  -  \R                  -  \R                  -  r\R
                  r\R                  r\R                  r\R                  r\R                  r\R                  r      SU 4S jjrSrU =r$ )Ú
_ThreadsOni   c                ó\   >• [         TU ]  X5        [        XSU R                  5      U l        g )NrQ   )Úsuperr   r8   Ú	CreateRunrQ   )r   r:   r;   Ú	__class__s      €r   r   Ú_ThreadsOn.__init__  s*   ø€ ô
 	‰Ñ˜Ô(Ü?PØ˜L¨$¯.©.ó@
ˆ�r   )rQ   r�   )r$   r%   r&   r'   r   ÚThreadsCreateÚThreadsReadÚThreadsUpdateÚThreadsDeleteÚThreadsSearchÚ
RunsCreater2   rT   rU   rV   rW   rX   r‘   r   r*   Ú__classcell__)r’   s   @r   rŽ   rŽ      sÊ   ø† ð 	×ÑØ
×
Ñ
ñ	à
×
Ñ
ñ	ð ×
Ñ
ñ	ð ×
Ñ
ñ		ð
 ×
Ñ
ñ	ð 
ð × Ñ €FØ×Ñ€DØ× Ñ €FØ× Ñ €FØ× Ñ €FØ× Ñ €Ið
àð
ð Cð
ð 
÷	
õ 
r   rŽ   c                  ó  • \ rS rSr\\R                  \R                  -  \R                  -  \R                  -  \R                  -     r\R                  r\R                  r\R                  r\R                  r\R                  rSrg)Ú_CronsOni$  r+   N)r$   r%   r&   r'   Útyper   ÚCronsCreateÚ	CronsReadÚCronsUpdateÚCronsDeleteÚCronsSearchr2   rT   rU   rV   rW   rX   r*   r+   r   r   rœ   rœ   $  sˆ   † ð Ø×ÑØ
�/‰/ñ	à
×
Ñ
ñ	ð ×
Ñ
ñ	ð ×
Ñ
ñ		ñ€Eð ×Ñ€FØ�?‰?€DØ×Ñ€FØ×Ñ€FØ×ÑƒFr   rœ   c                  ó<   • \ rS rSrSr        SS jrSS jrSrg)	Ú_StoreActionOni=  z@Decorator for registering a handler for a specific store action.c                ó(   • Xl         X l        X0l        g r   )r:   r<   r2   )r   r:   r<   r2   s       r   r   Ú_StoreActionOn.__init__@  s   € ð Œ	ØŒØ�
r   c                ó`   • [        U5        [        U R                  SU R                  U5        U$ )NÚstore)r?   r@   r:   r<   r   s     r   r3   Ú_StoreActionOn.__call__J  s%   € Ü˜"ÔÜ˜$Ÿ)™) W¨d¯k©k¸2Ô>Øˆ	r   )r<   r:   r2   N)r:   r   r<   zCtyping.Literal['put', 'get', 'search', 'delete', 'list_namespaces']r2   rC   r"   r#   rD   )r$   r%   r&   r'   r(   r   r3   r*   r+   r   r   r¤   r¤   =  s6   † ÙJðàðð Tðð ð	ð
 
ô÷r   r¤   c                  óž   • \ rS rSrS	S jr\R                  SS.   S
S jj5       r\R                  SS j5       r SSS.     SS jjjrSrg)Ú_StoreOniP  c                óX  • Xl         [        US[        R                  5      U l         [        US[        R
                  5      U l         [        US[        R                  5      U l         [        US[        R                  5      U l
         [        US[        R                  5      U l        g )NÚputÚgetrP   rO   Úlist_namespaces)Ú_authr¤   r   ÚStorePutr­   ÚStoreGetr®   ÚStoreSearchrP   ÚStoreDeleterO   ÚStoreListNamespacesr¯   ©r   r:   s     r   r   Ú_StoreOn.__init__Q  s—   € ØŒ
Ü! $¨¬u¯~©~Ó>ˆŒð	ô " $¨¬u¯~©~Ó>ˆŒð	ô % T¨8´U×5FÑ5FÓGˆŒð	ô % T¨8´U×5FÑ5FÓGˆŒð	ô  .ØÐ#¤U×%>Ñ%>ó 
ˆÔð	r   N©r_   c               ó   • g r   r+   )r   r_   s     r   r3   Ú_StoreOn.__call__œ  s   € ð  #r   c                ó   • g r   r+   r   s     r   r3   rº   ©  ó   € Ø(+r   c               ó^   ^ ^• Ub  [        T R                  SSU5        U$     SUU 4S jjnU$ )au  Register a handler for specific resources and actions.

Can be used as a decorator or with explicit resource/action parameters:

@auth.on.store
async def handler(): ... # Handle all store ops

@auth.on.store(actions=("put", "get", "search", "delete"))
async def handler(): ... # Handle specific store ops

@auth.on.store.put
async def handler(): ... # Handle store.put ops
Nr¨   c                óœ   >• [        T[        5      (       a  T/nOTb  [        T5      OS/nU H  n[        TR                  SX 5        M     U $ )Nre   r¨   ©rg   rh   rn   r@   r°   )rw   ry   r<   r_   r   s      €€r   r|   Ú$_StoreOn.__call__.<locals>.decoratorË  sJ   ø€ ô ˜'¤3×'Ñ'Ø&˜i‘à/6Ñ/Bœd 7œmÈÈ�Û%�Ü! $§*¡*¨g°vÖGñ &àˆNr   ©rw   ÚAHOr"   rÂ   ©r@   r°   )r   r   r_   r|   s   ` ` r   r3   rº   ¬  sC   ù€ ð2 ‰>ä˜dŸj™j¨'°4¸Ô<ØˆIð		Øð		à÷		ð 		ð Ðr   )r°   rO   r®   r¯   r­   rP   ©r:   r   r"   r#   )r_   úštyping.Literal['put', 'get', 'search', 'list_namespaces', 'delete'] | Sequence[typing.Literal['put', 'get', 'search', 'list_namespaces', 'delete']] | Noner"   úCallable[[AHO], AHO]©r   rÂ   r"   rÂ   r   )r   ú
AHO | Noner_   rÅ   r"   úAHO | Callable[[AHO], AHO])	r$   r%   r&   r'   r   r~   r…   r3   r*   r+   r   r   r«   r«   P  sƒ   † ôIðV ‡_�_ð ñ
#ðð	
#ð 
ô
#ó ð
#ð ‡_�_Û+ó Ø+ð ð*ð ñ*àð*ð
ð*ð 
$÷*ñ *r   r«   rÂ   c                  ó°   • \ rS rSrSrSrSS jr\R                  SS.     SS jj5       r	\R                  SS j5       r	 SSSS	.       SS
 jjjr	Sr
g)r   iÜ  a"  Entry point for authorization handlers that control access to specific resources.

The _On class provides a flexible way to define authorization rules for different resources
and actions in your application. It supports three main usage patterns:

1. Global handlers that run for all resources and actions
2. Resource-specific handlers that run for all actions on a resource
3. Resource and action specific handlers for fine-grained control

Each handler must be an async function that accepts two parameters:
- ctx (AuthContext): Contains request context and authenticated user info
- value: The data being authorized (type varies by endpoint)

The handler should return one of:
    - None or True: Accept the request
    - False: Reject with 403 error
    - FilterType: Apply filtering rules to the response

???+ example "Examples"

    Start by denying all requests by default with a global handler,
    then add specific handlers to allow access:

    ```python
    # Default deny: reject all requests without a specific handler
    @auth.on
    async def deny_all(ctx: AuthContext, value: Any) -> False:
        return False
    ```

    Resource-specific handler to allow access (takes precedence
    over the global deny handler):

    ```python
    @auth.on.threads
    async def allow_thread_access(ctx: AuthContext, value: Any) -> Auth.types.FilterType:
        # Allow access only to threads owned by the user
        return {"owner": ctx.user.identity}
    ```

    Resource and action specific handler:

    ```python
    @auth.on.threads.create
    async def allow_thread_create(ctx: AuthContext, value: Any) -> None:
        # Allow thread creation, stamping the owner
        value.setdefault("metadata", {})["owner"] = ctx.user.identity
    ```

    Multiple resources or actions:

    ```python
    @auth.on(resources=["threads", "assistants"], actions=["read", "search"])
    async def allow_reads(ctx: AuthContext, value: Any) -> Auth.types.FilterType:
        # Allow read/search, scoped to user's resources
        return {"owner": ctx.user.identity}
    ```
)r°   Ú
assistantsÚcronsÚrunsr¨   Úthreadsr2   c                óÚ   • Xl         [        US5      U l        [        US5      U l        [        US5      U l        [        U5      U l        [        [        [        R                  4   U l        g )NrË   rÎ   rÌ   )r°   r‡   rË   rŽ   rÎ   rœ   rÌ   r«   r¨   Údictrh   r~   ÚAnyr2   r¶   s     r   r   Ú_On.__init__"  sP   € ØŒ
Ü'¨¨lÓ;ˆŒÜ! $¨	Ó2ˆŒÜ˜d GÓ,ˆŒ
Ü˜d“^ˆŒ
Üœ#œvŸz™z˜/Ñ*ˆ�
r   Nr¸   c               ó   • g r   r+   ra   s      r   r3   Ú_On.__call__*  s   € ð  #r   c                ó   • g r   r+   r   s     r   r3   rÔ   2  r¼   r   r]   c               ób   ^ ^^• Ub  [        T R                  SSU5        U$     SUUU 4S jjnU$ )a„  Register a handler for specific resources and actions.

Can be used as a decorator or with explicit resource/action parameters:

@auth.on
async def handler(): ...  # Global handler

@auth.on(resources="threads")
async def handler(): ...  # types.Handler for all thread actions

@auth.on(resources="threads", actions="create")
async def handler(): ...  # types.Handler for thread creation
Nc                ó  >• [        T[        5      (       a  T/nOTb  [        T5      OS/n[        T[        5      (       a  T/nOTb  [        T5      OS/nU H#  nU H  n[        TR                  X4U 5        M     M%     U $ )Nre   r¿   )rw   rx   ry   r;   r<   r_   r^   r   s        €€€r   r|   Ú_On.__call__.<locals>.decoratorO  s|   ø€ ô ˜)¤S×)Ñ)Ø!* ‘à3<Ñ3H¤ Y¤ÈsÈe�ä˜'¤3×'Ñ'Ø&˜i‘à/6Ñ/Bœd 7œmÈÈ�Û)�Û)�FÜ% d§j¡j°(ÀGÖLó *ñ *ð ˆNr   rÁ   rÃ   r€   s   ` `` r   r3   rÔ   5  sC   ú€ ð( ‰>ä˜dŸj™j¨$°°bÔ9ØˆIð	Øð	à÷	ñ 	ð" Ðr   )r°   rË   rÌ   r¨   rÎ   r2   rÄ   )r^   zstr | Sequence[str]r_   r‚   r"   rÆ   rÇ   r   )r   rÈ   r^   r‚   r_   r‚   r"   rÉ   )r$   r%   r&   r'   r(   r)   r   r~   r…   r3   r*   r+   r   r   r   r   Ü  s¥   † ñ9ðv€Iô+ð ‡_�_ð
 /3ñ	#ð 'ð#ð ,ð	#ð
 
ô#ó ð#ð ‡_�_Û+ó Ø+ð ð+ð 15Ø.2ñ+àð+ð .ð	+ð
 ,ð+ð 
$÷+ñ +r   r   c                óV  • [        U5        U=(       d    SnU=(       d    SnUS:X  a?  US:X  a9  U R                  (       a  [        S5      eU R                  R                  U5        U$ Ub  UOSnUb  UOSnXE4U R                  ;   a  [        SU SU S35      eU/U R                  XE4'   U$ )Nre   zGlobal handler already set.rm   rl   r   )r?   r   r   Úappendr   )r:   r;   r<   r   ÚrÚas         r   r@   r@   c  sµ   € ô �bÔØ�˜3€HØ�]�s€FØ�3ƒ˜6 S›=Ø× × ÜÐ:Ó;Ð;Ø×Ñ×$Ñ$ RÔ(ð €Ið !Ñ,‰H°#ˆØÑ(‰F¨cˆØˆ6�T—^‘^Ó#ÜÐ=¸a¸SÀÀ1À#ÀQÐGÓHÐHØ"$ ˆ�‰˜�vÑØ€Ir   c                óB  • [         R                  " U 5      (       d  [        S[        U SU 5       S35      e[         R                  " U 5      nSUR
                  ;  a  [        S[        U SU 5       S35      eSUR
                  ;  a  [        S[        U SU 5       S35      eg)	zÙValidates that an auth handler function meets the required signature.

Auth handlers must:
1. Be async functions
2. Accept a ctx parameter of type AuthContext
3. Accept a value parameter for the data being authorized
zAuth handler 'r$   z|' must be an async function. Add 'async' before 'def' to make it asynchronous and ensure any IO operations are non-blocking.r1   zm' must have a 'ctx: AuthContext' parameter. Update the function signature to include this required parameter.r2   z¢' must have a 'value' parameter.  The value contains the mutable data being sent to the endpoint.Update the function signature to include this required parameter.N)ÚinspectÚiscoroutinefunctionr   ÚgetattrÚ	signatureÚ
parameters)r   Úsigs     r   r?   r?   y  sÂ   € ô ×&Ò& r×*Ñ*ÜØœW R¨°RÓ8Ð9ð :3ð 3ó
ð 	
ô ×
Ò
˜BÓ
€CØ�C—N‘NÓ"ÜØœW R¨°RÓ8Ð9ð :Pð Pó
ð 	
ð �c—n‘nÓ$ÜØœW R¨°RÓ8Ð9ð :Pð Pó
ð 	
ð %r   c                óš   • [        U [        R                  5      =(       d+    [        U [        5      =(       a    U R	                  S5      S:H  $ )NÚkindÚ
StudioUser)rg   r   ræ   rÐ   r®   )Úusers    r   Úis_studio_userrè   –  s;   € ô �dœE×,Ñ,Ó-÷ Ü�4œÓ×C 4§8¡8¨FÓ#3°|Ñ#Cðr   )r   r   r   )
r:   r   r;   ú
str | Noner<   ré   r   útypes.Handlerr"   rê   )r   zCallable[..., typing.Any]r"   r#   )rç   z:types.MinimalUser | types.BaseUser | types.MinimalUserDictr"   Úbool)=Ú
__future__r   rÞ   r~   Úcollections.abcr   r   Úlanggraph_sdk.authr   r   ÚTypeVarÚHandlerr   ÚAuthenticatorr
   r   r,   ÚProtocolr/   r5   ÚGenericr8   rF   rG   rH   rI   rJ   rh   rK   ÚLiteralÚ_ResourceActionÚ_ThreadActionrS   rˆ   r‰   rŠ   r‹   rŒ   r‡   r”   r•   r–   r—   r˜   rŽ   rž   rŸ   r    r¡   r¢   rœ   r¤   r«   rÐ   rÑ   rÂ   r   r@   r?   rè   Ú__all__r+   r   r   Ú<module>rø      s¿  ðÝ "ã Û ß .ç 0à‡^‚^�D §¡Ñ.€Ø‡^‚^�D × 3Ñ 3Ñ4€÷`ñ `ðJ	 ‡N‚N�3 dÑ+€ô"�V—_‘_ QÑ'ô "ð ‡N‚N�3 $Ñ'€ô˜Ÿ™ qÑ)ô ð* �.Š.˜¨dÑ
3€Ø
�.Š.˜¨dÑ
3€Ø�Š�w¨$Ñ/€Ø
�.Š.˜¨dÑ
3€Ø
�.Š.˜¨dÑ
3€Ø—.’.Ð!2¸#Ñ>€à—.‘.Ð!OÑP€Ø &§.¡.°Ñ">Ñ>€ôGØ
‡N�N�7˜E 7¨G°W¸oÐMÑNôGôT$ØØ×ÑØ×ÑØ×ÑØ×ÑØ×ÑØð	ñô$ô0!
ØØ×ÑØ×ÑØ×ÑØ×ÑØ×ÑØð	ñô!
ôHØØ×ÑØ�‰Ø×ÑØ×ÑØ×ÑØð	ñôô2�V—^‘^ AÑ&ô ÷&Fñ FðR ‡n‚n�U .°°c¸6¿:¹:°oÑ1FÑ"GÑH€÷Dñ DðNØ
ðàðð ðð 	ð	ð
 ôô,
ð:Ø
Dðà	ôò *�r   