ó
    üÞ j¨  ã                  ó6  • S r SSKJr  SSKJrJr  SSKJrJrJ	r	   " S S\	5      r
\\\4   r\\\4   rSS jrSS jrSS	 jrSS
 jrSS jr    SS jrSS jrSSSS.       SS jjrSSSS.           S S jjrSSSSS.           S!S jjrg)"z2Helpers for building sandbox proxy configurations.é    )Úannotations)ÚMappingÚSequence)ÚAnyÚLiteralÚ	TypedDictc                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚSandboxProxySecreté	   z7A secret value that can be used by sandbox proxy rules.z%Literal['workspace_secret', 'opaque']ÚtypeÚstrÚvalue© N)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__Ú__annotations__Ú__static_attributes__r   ó    ÚY/var/www/html/gaurav/venv/lib/python3.13/site-packages/langsmith/sandbox/_proxy_config.pyr
   r
   	   s   ‡ ÙAà
/Ó/Ø†Jr   r
   c                ó’   • [        U [        5      (       a  U R                  5       (       d  [        U S35      eU R                  5       $ )Nz must be a non-empty string)Ú
isinstancer   ÚstripÚ
ValueError)r   Úfields     r   Ú_require_non_empty_stringr      s8   € Ü�eœS×!Ñ!¨¯©¯©Ü˜E˜7Ð"=Ð>Ó?Ð?Ø�;‰;‹=Ðr   c                ó˜   • [        U [        5      (       d  U (       d  [        U S35      eU  Vs/ sH  n[        X!5      PM     nnU$ s  snf )Nz$ must be a non-empty list of strings)r   r   r   r   )Úvaluesr   r   Ú
normalizeds       r   Ú_require_non_empty_string_listr"      sJ   € Ü�&œ#×Ñ¦fÜ˜E˜7Ð"FÐGÓHÐHÙGMÓNÁv¸eÔ+¨EÖ9Áv€JÐNØÐùò Os   ¯Ac                óÆ   • [        U [        5      (       a  U (       d  [        S5      e0 nU R                  5        H#  u  p#[	        USU S35        X1[	        US5      '   M%     U$ )Nz7env_vars must be a non-empty mapping of names to valuesz	env_vars[Ú]zenv_vars name)r   r   r   Úitemsr   )Úenv_varsÚresolvedÚnamer   s       r   Ú_require_env_varsr)   !   s_   € Ü�h¤×(Ñ(¶ÜÐRÓSÐSØ!€HØ—~‘~Ö'‰ˆä! %¨9°T°F¸!Ð)<Ô=ØEJÔ*¨4°ÓAÓBñ (ð €Or   c                óú   • [        U S5      nUR                  S5      nUR                  S5      nX#:w  a  [        S5      eU(       a#  USS R	                  5       (       d  [        S5      eU(       a  UOSU S3nSUS	.$ )
a
  Create a LangSmith workspace secret reference for a proxy configuration.

Args:
    name: Workspace secret name, with or without surrounding braces.

Returns:
    A proxy secret reference such as
    ``{"type": "workspace_secret", "value": "{AWS_ACCESS_KEY_ID}"}``.
r(   Ú{Ú}z5workspace secret must be a name or a {NAME} referenceé   éÿÿÿÿz.workspace secret reference must contain a nameÚworkspace_secret©r   r   )r   Ú
startswithÚendswithr   r   )r(   r!   ÚstartsÚendsr   s        r   r/   r/   ,   s‚   € ô +¨4°Ó8€JØ×"Ñ" 3Ó'€FØ×Ñ˜sÓ#€DØƒ~ÜÐPÓQÐQÞ�j  2Ð&×,Ñ,×.Ñ.ÜÐIÓJÐJÞ ‰J¨¨:¨,°bÐ&9€EØ&°Ñ7Ð7r   c                ó    • S[        U S5      S.$ )zÕProvide a write-only secret value for a proxy configuration.

The value is sent when creating or updating the sandbox proxy config, but
LangSmith stores it as an opaque secret and does not return it from the API.
Úopaquer   r0   )r   )r   s    r   Úopaque_secretr7   A   s   € ð Ô'@ÀÈÓ'PÑQÐQr   c                ó  • U c  / $ [        U [        5      (       d  [        U [        5      (       a  [        S5      e/ nU  HF  n[        U[        5      (       a  U(       d  [        S5      e[	        U5        UR                  U5        MH     U$ )Nz/rules must be a list of proxy rule dictionaries)r   Údictr   r   Ú_validate_proxy_provider_ruleÚappend)Úrulesr!   Úrules      r   Ú_normalize_proxy_rulesr>   J   s{   € ð �}Øˆ	Ü�%œ×Ñ¤*¨U´C×"8Ñ"8ÜÐJÓKÐKØ)+€JÛˆÜ˜$¤×%Ñ%®TÜÐNÓOÐOÜ% dÔ+Ø×Ñ˜$Öñ	 ð
 Ðr   c                ó¼   • U R                  S5      S:w  a  g U R                  S5      n[        U[        5      (       a  SU;  a  [        S5      e[	        US   S5        g )Nr   ÚgcpÚscopesz#gcp proxy auth rules require scopes)Úgetr   r9   r   r"   )r=   r@   s     r   r:   r:   Z   sQ   € Ø‡x�x�Ó˜5Ó ØØ
�(‰(�5‹/€CÜ�cœ4× Ñ  H°CÓ$7ÜÐ>Ó?Ð?Ü" 3 x¡=°(Õ;r   N)r<   Úno_proxyÚaccess_controlc                ó¦   • S[        U 5      0nUb  [        US5      US'   Ub.  [        U[        5      (       d  [	        S5      e[        U5      US'   U$ )z¯Build a sandbox proxy config from one or more proxy rules.

Use provider-specific rule helpers such as ``aws_auth`` and ``gcp_auth``
when a sandbox needs multiple auth flows.
r<   rC   z#access_control must be a dictionaryrD   )r>   r"   r   r9   r   )r<   rC   rD   Úconfigs       r   Úproxy_configrG   c   s_   € ð #*Ô+AÀ%Ó+HÐ!I€FØÑÜ;¸HÀjÓQˆˆzÑØÑ!Ü˜.¬$×/Ñ/ÜÐBÓCÐCÜ#'¨Ó#7ˆÐÑ Ø€Mr   ÚawsT)r(   Úenabledr&   c                óT   • [        US5      nUSUU US.S.nUb  [        U5      US'   U$ )aa  Build a sandbox proxy rule that signs AWS HTTPS requests.

The sandbox proxy keeps the real AWS credentials outside the sandbox and
signs supported AWS requests with SigV4 on the sandbox's behalf. AWS
credentials must be supplied as ``workspace_secret`` or ``opaque`` values;
plaintext AWS credentials are intentionally not supported.

Args:
    env_vars: Plaintext environment variables set for every command in the
        sandbox while this rule is enabled, for tools that refuse to run
        unless a credential variable is present even though the proxy
        injects the real credential on the wire.
r(   rH   )Úaccess_key_idÚsecret_access_key)r(   r   rI   rH   r&   )r   r)   )rK   rL   r(   rI   r&   Ú	rule_namer=   s          r   Úaws_authrN   x   sG   € ô* *¨$°Ó7€IàØØà*Ø!2ñ
ñ	€Dð ÑÜ,¨XÓ6ˆˆZÑØ€Kr   r@   )rA   r(   rI   r&   c                óz   • [        US5      nSU 0nUb  [        US5      US'   USUUS.nUb  [        U5      US'   U$ )av  Build a sandbox proxy rule that injects GCP OAuth bearer auth.

The sandbox proxy keeps the service account JSON outside the sandbox and
injects OAuth bearer tokens for built-in Google API host matching.
``service_account_json`` must be supplied as a ``workspace_secret`` or
``opaque`` value; plaintext service account JSON is intentionally not
supported.

Args:
    env_vars: Plaintext environment variables set for every command in the
        sandbox while this rule is enabled, for tools that refuse to run
        unless a credential variable is present even though the proxy
        injects the real credential on the wire.
r(   Úservice_account_jsonrA   r@   )r(   r   rI   r@   r&   )r   r"   r)   )rP   rA   r(   rI   r&   rM   Ú
gcp_configr=   s           r   Úgcp_authrR   œ   se   € ô, *¨$°Ó7€IàÐ 4ð"€Jð ÑÜ=¸fÀhÓOˆ
�8ÑàØØØñ	€Dð ÑÜ,¨XÓ6ˆˆZÑØ€Kr   )r   r   r   r   Úreturnr   )r    zSequence[str]r   r   rS   z	list[str])r&   zMapping[str, str]rS   zdict[str, str])r(   r   rS   r
   )r   r   rS   r
   )r<   ú!Sequence[SandboxProxyRule] | NonerS   zlist[SandboxProxyRule])r=   ÚSandboxProxyRulerS   ÚNone)r<   rT   rC   úSequence[str] | NonerD   zdict[str, Any] | NonerS   ÚSandboxProxyConfig)rK   r
   rL   r
   r(   r   rI   Úboolr&   úMapping[str, str] | NonerS   rU   )rP   r
   rA   rW   r(   r   rI   rY   r&   rZ   rS   rU   )r   Ú
__future__r   Úcollections.abcr   r   Útypingr   r   r   r
   r9   r   rU   rX   r   r"   r)   r/   r7   r>   r:   rG   rN   rR   r   r   r   Ú<module>r^      s@  ðÙ 8å "ç -ß *Ñ *ô˜ô ð ˜˜S˜‘>Ð Ø˜#˜s˜(‘^Ð ôôôô8ô*RðØ,ðàôô <ð 04Ø%)Ø,0ñ	à,ðð #ðð *ð	ð
 õð2 ØØ)-ñ!à%ð!ð *ð!ð ð	!ð
 ð!ð 'ð!ð õ!ðN $(ØØØ)-ñ$à,ð$ð !ð$ð ð	$ð
 ð$ð 'ð$ð ö$r   