ó
    °"³j‡(  ã                  ó*  • S SK Jr  S SKrS SKrS SKrS SKJr  SSKJrJ	r	  Sr
SrSrS	rS
rSrSrSrSrSrSrSrSrSrSrSrSrSrSrSrSrSrS+S jr S,S jr!S-S jr"S+S jr#S.S  jr$S!S".S/S# jjr%S0S$ jr&S1S% jr'S1S& jr(S2S' jr)S2S( jr*S3S4S) jjr+S2S* jr,g)5é    )ÚannotationsN)ÚOptionalé   )ÚAnthropicErrorÚCredentialsErrorz+urn:ietf:params:oauth:grant-type:jwt-bearerÚrefresh_tokenz/v1/oauth/tokeng      >@zoauth-2025-04-20zoidc-federation-2026-04-01éx   é   Údefaultzhttps://api.anthropic.comÚANTHROPIC_API_KEYÚANTHROPIC_AUTH_TOKENÚANTHROPIC_CONFIG_DIRÚANTHROPIC_PROFILEÚANTHROPIC_IDENTITY_TOKENÚANTHROPIC_IDENTITY_TOKEN_FILEÚANTHROPIC_FEDERATION_RULE_IDÚANTHROPIC_ORGANIZATION_IDÚANTHROPIC_SERVICE_ACCOUNT_IDÚANTHROPIC_WORKSPACE_IDÚANTHROPIC_SCOPEÚANTHROPIC_BASE_URLc                 ó   • SSK Jn   SU  3$ )z¼`User-Agent` value sent on token-endpoint POSTs.

Computed lazily so this module doesn't need to import `_version` at
module load time (the credentials package is otherwise import-light).
r   ©Ú__version__zanthropic-python/)Ú_versionr   r   s    Úa/home/mande/repo/quber/.venv/lib/python3.13/site-packages/anthropic/lib/credentials/_constants.pyÚ_user_agentr   8   s   € õ (à˜{˜mÐ,Ð,ó    c                 ó¼  • [         R                  R                  [        5      n U (       a  [        R
                  " U 5      $ [        R                  S:X  ae  [         R                  R                  S5      nU(       a  [        R
                  " U5      O#[        R
                  R                  5       S-  S-  nUS-  $ [        R
                  R                  5       S-  S-  $ )u5  Resolve the config directory.

`ANTHROPIC_CONFIG_DIR` env var â†’ platform default.

Platform defaults:
  * Linux & macOS: `~/.config/anthropic/` â€” XDG-style on both platforms
    for consistency across SDKs (macOS does **not** use
    `~/Library/Application Support/`).
  * Windows: `%APPDATA%\Anthropic\`
Úwin32ÚAPPDATAÚAppDataÚRoamingÚ	Anthropicz.configÚ	anthropic)	ÚosÚenvironÚgetÚENV_CONFIG_DIRÚpathlibÚPathÚsysÚplatformÚhome)ÚenvÚappdataÚbases      r   Ú_config_dirr2   C   s˜   € ô �*‰*�.‰.œÓ
(€CÞ
Ü�|Š|˜CÓ Ð Ü
‡|�|�wÓÜ—*‘*—.‘. Ó+ˆÞ(/Œw�|Š|˜GÔ$´W·\±\×5FÑ5FÓ5HÈ9Ñ5TÐW`Ñ5`ˆØ�kÑ!Ð!Ü�<‰<×ÑÓ Ñ*¨[Ñ8Ð8r   c                 óŠ   •  [        5       S-  R                  SS9R                  5       n U =(       d    S$ ! [         a     gf = f)zpReturn the stripped contents of `<config_dir>/active_config`, or `None`
if the pointer file is missing or empty.Úactive_configzutf-8)ÚencodingN)r2   Ú	read_textÚstripÚOSError)Únames    r   Ú_read_active_config_pointerr:   X   sJ   € ðÜ“ Ñ/×:Ñ:ÀGÐ:ÐL×RÑRÓTˆð �<�4Ðøô ó Ùðús   ‚(5 µ
AÁAc                 ó´   • [         R                  R                  [        5      n U (       a  [	        U [        S9  U $ [        5       nUc  [        $ [	        USS9  U$ )uÜ   Resolve the active profile name.

`ANTHROPIC_PROFILE` env var â†’ `<config_dir>/active_config` pointer file
â†’ `"default"` literal. The resolved name is validated against path-
traversal patterns before being returned.
©Úsourcezactive_config pointer file)r&   r'   r(   ÚENV_PROFILEÚ_validate_profile_namer:   ÚDEFAULT_PROFILE)r/   r9   s     r   Ú_active_profilerA   b   sK   € ô �*‰*�.‰.œÓ
%€CÞ
Ü˜s¬;Ò7Øˆ
Ü&Ó(€DØ�|ÜÐÜ˜4Ð(DÒEØ€Kr   c               óÀ   • U R                  5       R                  S5      nUR                  S5      (       a  gUR                  S5      (       a  g[        U SU < S35      e)a!  Reject non-`https://` token-endpoint URLs.

Localhost is allowed for testing so `base_url="http://localhost:8080"`
works against a local `oauth_server` instance; everything else must be
TLS-encrypted because the body of these POSTs carries the assertion JWT
or a long-lived refresh token.
Ú/zhttps://N)zhttp://localhostzhttp://127.0.0.1zhttp://[::1]z must use https (got z^); the token-exchange endpoint carries secret material and cannot be used over cleartext HTTP.)ÚlowerÚrstripÚ
startswithr   )ÚurlÚfieldÚlowereds      r   Ú_require_httpsrJ   t   sh   € ð �i‰i‹k× Ñ  Ó%€GØ×Ñ˜*×%Ñ%ØØ×ÑÐR×SÑSØÜ
Øˆ'Ð& s¡gð .Jð 	Kóð r   zprofile namer<   c          	     ót  • U (       d  [        U S35      eX R                  5       :w  a  [        U SU < S35      eU R                  S5      (       a  [        U SU < S35      eSS[        R                  4 H'  nU(       d  M  X ;   d  M  [        U SU < SU< S35      e   S	U ;   a  [        U SU < S
35      eg)aµ  Reject profile names that could escape the config directory.

Profile names come from user-controlled sources (`ANTHROPIC_PROFILE`,
the `active_config` pointer file, `CredentialsFile(profile=...)`) and
are interpolated into filesystem paths. A value like `"../../etc/shadow"`
would otherwise let a read of `configs/<profile>.json` escape the config
root entirely. Pass `source=` so the error message names where the bad
value came from.
z must not be empty.Ú z$ has leading or trailing whitespace.Ú.z must not start with a dot.rC   Ú\um    must not contain path separators â€” profiles are filenames under the config directory. Pick a name without Ú z must not contain null bytes.N)r   r7   rF   r&   Úsep)Úprofiler=   rP   s      r   r?   r?   ‡   sÜ   € ö Ü & Ð)<Ð=Ó>Ð>Ø—-‘-“/Ó!Ü & ¨¨7©+Ð5YÐZÓ[Ð[Ø×Ñ˜#×ÑÜ & ¨¨7©+Ð5PÐQÓRÐRØ�Tœ2Ÿ6™6Ó"ˆßˆ3�3•>Ü"Ø�(˜!˜G™;ð 'ZØZ]ÑY`Ð`aðcóð ñ #ð �ÓÜ & ¨¨7©+Ð5RÐSÓTÐTð r   c                ó°   • U R                  SS9nUR                  SS9n UR                  U5        U$ ! [         a  n[        SU SU S35      UeSnAff = f)uŒ  Assert `candidate` resolves to a descendant of `base`, return it verbatim.

The containment check uses `resolve(strict=False)` on both sides so
symlinks and `..` segments are normalized for the purposes of escape
detection. The returned path is the *original* (unresolved) candidate â€”
callers that care about symlink following must handle it themselves
(e.g. `os.stat(follow_symlinks=False)`).
F)ÚstrictzResolved path z escapes config directory rM   N)ÚresolveÚrelative_toÚ
ValueErrorr   )r1   Ú	candidateÚbase_resolvedÚcandidate_resolvedÚerrs        r   Ú_resolve_underr[   ¡   s{   € ð —L‘L¨�LÐ.€MØ"×*Ñ*°%Ð*Ð8ÐðyØ×&Ñ& }Ô5ð Ðøô ó yÜ Ð0BÐ/CÐC]Ð^kÐ]lÐlmÐnÓoÐuxÐxûðyús    3 ³
A½AÁAc                óT   • [        U 5        [        5       n[        XS-  U  S3-  5      $ )zAPath to `<config_dir>/configs/<profile>.json` (non-secret, 0644).Úconfigsú.json©r?   r2   r[   ©rQ   r1   s     r   Ú_config_file_pathra   ³   s-   € ä˜7Ô#Ü‹=€DÜ˜$ yÑ 0°g°Y¸eÐ3DÑ DÓEÐEr   c                óT   • [        U 5        [        5       n[        XS-  U  S3-  5      $ )zAPath to `<config_dir>/credentials/<profile>.json` (secret, 0600).Úcredentialsr^   r_   r`   s     r   Ú_credentials_file_pathrd   º   s-   € ä˜7Ô#Ü‹=€DÜ˜$ }Ñ 4¸'¸À%Ð7HÑ HÓIÐIr   c                 ór   •  [        [        5       5      R                  5       $ ! [        [        4 a     gf = f)ax  Tighter auto-discover check for the tier-1 credential chain.

Returns `True` only if the *active* profile's config file exists. The
previous version returned `True` for any `.json` under `configs/`,
which meant a stray `configs/work.json` on disk was enough to steer
`default_credentials()` into reading `configs/default.json` and
failing because `default.json` wasn't there.
F)ra   rA   Úis_filer8   r   © r   r   Ú_has_active_profile_configrh   Á   s5   € ðÜ ¤Ó!2Ó3×;Ñ;Ó=Ð=øÜ”^Ð$ó Ùðús   ‚ # £6µ6c                 ó   • [        5       SL$ )us  True if the user wrote a non-empty `active_config` pointer file.

This is an explicit opt-in signal equivalent to setting `ANTHROPIC_PROFILE`:
the user has told us which profile to load. If the target config file is
missing or malformed, the chain should surface that error rather than
silently falling through â€” matching how `ANTHROPIC_PROFILE=missing`
behaves today.
N)r:   rg   r   r   Ú_has_explicit_active_configrj   Ð   s   € ô 'Ó(°Ð4Ð4r   c                ó¶   • U b  [         R                  " U 5      $ [        R                  R	                  [
        5      nU(       a  [         R                  " U5      $ g)u8   ctor arg â†’ `ANTHROPIC_IDENTITY_TOKEN_FILE` â†’ `None`.N)r*   r+   r&   r'   r(   ÚENV_IDENTITY_TOKEN_FILE)Úpathr/   s     r   Úresolve_identity_token_pathrn   Ü   s?   € àÑÜ�|Š|˜DÓ!Ð!Ü
�*‰*�.‰.Ô0Ó
1€CÞ
Ü�|Š|˜CÓ Ð Ør   c                 ó  • [         R                  R                  [        5      (       d(  [         R                  R                  [        5      (       a  g[        5       (       a  g[         R                  R                  [        5      (       ay  [         R                  R                  [        5      (       aQ  [         R                  R                  [        5      (       d(  [         R                  R                  [        5      (       a  gg)u¬  True if the environment / filesystem contains signals that would
normally drive the tier-1 (profile) or tier-2 (env federation) paths of
`default_credentials`.

Used by the shadow-warning detection in the client constructor: if a
static `ANTHROPIC_API_KEY` / `ANTHROPIC_AUTH_TOKEN` is set alongside
any of these signals, the auto-discovery would have yielded a credential
but got silently shadowed â€” and the user should know.
TF)
r&   r'   r(   r>   r)   rj   ÚENV_FEDERATION_RULE_IDÚENV_ORGANIZATION_IDrl   ÚENV_IDENTITY_TOKENrg   r   r   Ú"_has_auto_discoverable_credentialsrs   æ   sŒ   € ô 
‡z�z‡~�~”k×"Ñ"¤b§j¡j§n¡n´^×&DÑ&DØÜ"×$Ñ$ØÜ	‡z�z‡~�~Ô,×-Ñ-´"·*±*·.±.ÔAT×2UÑ2UÜ�:‰:�>‰>Ô1×2Ñ2´b·j±j·n±nÔEW×6XÑ6XØØr   )ÚreturnÚstr)rt   úpathlib.Path)rt   zOptional[str])rG   ru   rH   ru   rt   ÚNone)rQ   ru   r=   ru   rt   rw   )r1   rv   rW   rv   rt   rv   )rQ   ru   rt   rv   )rt   Úbool)N)rm   zstr | os.PathLike[str] | Nonert   zpathlib.Path | None)-Ú
__future__r   r&   r,   r*   Útypingr   Ú_exceptionsr   r   ÚGRANT_TYPE_JWT_BEARERÚGRANT_TYPE_REFRESH_TOKENÚTOKEN_ENDPOINTÚTOKEN_EXCHANGE_TIMEOUTÚOAUTH_API_BETA_HEADERÚFEDERATION_BETA_HEADERÚADVISORY_REFRESH_SECONDSÚMANDATORY_REFRESH_SECONDSr@   ÚDEFAULT_BASE_URLÚENV_API_KEYÚENV_AUTH_TOKENr)   r>   rr   rl   rp   rq   ÚENV_SERVICE_ACCOUNT_IDÚENV_WORKSPACE_IDÚ	ENV_SCOPEÚENV_BASE_URLr   r2   r:   rA   rJ   r?   r[   ra   rd   rh   rj   rn   rs   rg   r   r   Ú<module>r‹      së   ðÝ "ã 	Û 
Û Ý ç ;àEÐ Ø*Ð Ø"€ð Ð ð
 +Ð ð 6Ð ð Ð ØÐ à€Ø.Ð ð "€Ø'€ð (€Ø!€ð 0Ð Ø9Ð Ø7Ð Ø1Ð Ø7Ð Ø+Ð Ø€	Ø#€ô-ô9ô*ôô$ð& ;I÷ Uô4ô$FôJôô	5öõr   