ó
    °"³j�Ÿ  ã                  ó  • % S SK Jr  S SKrS SKrS SKrS SKrS SKrS SKrS SKrS SK	r	S SK
JrJrJrJrJrJr  S SKJr  S SKrSSKJrJr  SSKJrJrJrJrJrJr  SSKJrJ r J!r!J"r"J#r#J$r$J%r%J&r&J'r'J(r(J)r)J*r*J+r+J,r,J-r-J.r.J/r/J0r0J1r1J2r2J3r3J4r4  S	S
K5J6r6J7r7J8r8  \Rr                  " \:5      r;S\<S'   \(       a  SSK=J>r>  / SQr?SS jr@SrASrBSrCSrDSrES S jrF " S S5      rG " S S5      rH " S S5      rI " S S5      rJ " S S\I5      rKg)!é    )ÚannotationsN)ÚTYPE_CHECKINGÚAnyÚDictÚUnionÚOptionalÚcast)Úoverrideé   )ÚAccessTokenÚIdentityTokenProvider)Ú	SecretStrÚ_unwrap_secretÚ_strip_tracebackÚ_json_dumps_secretsÚ_wrap_secret_fieldsÚ_NonObjectPayloadError)Ú	ENV_SCOPEÚENV_PROFILEÚENV_BASE_URLÚENV_AUTH_TOKENÚENV_CONFIG_DIRÚTOKEN_ENDPOINTÚDEFAULT_BASE_URLÚENV_WORKSPACE_IDÚENV_ORGANIZATION_IDÚOAUTH_API_BETA_HEADERÚENV_FEDERATION_RULE_IDÚENV_SERVICE_ACCOUNT_IDÚTOKEN_EXCHANGE_TIMEOUTÚENV_IDENTITY_TOKEN_FILEÚGRANT_TYPE_REFRESH_TOKENÚMANDATORY_REFRESH_SECONDSÚ_user_agentÚ_require_httpsÚ_active_profileÚ_config_file_pathÚ_credentials_file_pathÚresolve_identity_token_pathé   )ÚAnthropicErrorÚCredentialsErrorÚIdentityTokenFileErrorzlogging.LoggerÚlog)ÚWorkloadIdentityCredentials)ÚStaticTokenÚEnvTokenÚCredentialsFileÚInMemoryConfigÚIdentityTokenFilec                óŒ   • U c  g [        U 5      $ ! [        [        4 a"  nUb  SU 3OSn[        U SU < S35      UeSnAff = f)z>Parse a credentials-file `expires_at` field into Unix seconds.Nzcredentials file at Úcredentialsz has invalid 'expires_at' u“   ; expected an integer Unix timestamp in seconds. The SDK does not parse ISO8601 â€” convert with int(datetime.timestamp()) before writing the file.)ÚintÚ	TypeErrorÚ
ValueErrorr,   )ÚvalueÚsourceÚerrÚwheres       Úa/home/mande/repo/quber/.venv/lib/python3.13/site-packages/anthropic/lib/credentials/_providers.pyÚ_coerce_expires_atr?   ;   sl   € à�}ØðÜ�5‹zÐøÜ”zÐ"ó Ø39Ñ3EÐ& v hÑ/È=ˆÜØˆgÐ/°©yð 9Fð Gó
ð ð		ûðús   †
 ‘A¡>¾AÚoauth_tokenz1.0Úoidc_federationÚ
user_oauthc                ó´  • SS jnU" U S[         5        U" U S[        5        U" U S[        5        UR                  S5      nU[        :X  au  U" US[
        5        U" US[        5        U" US[        5        UR                  S	5      (       d4  [        R                  R                  [        5      nU(       a	  S
US.US	'   gggU[        :X  a  U" US[        5        gg)uÄ   Fill empty profile fields from corresponding ANTHROPIC_* env vars.

The profile file is authoritative â€” this only fills fields the file left
unset. Empty-string env values are treated as unset.
c                óˆ   • U R                  U5      (       d,  [        R                  R                  U5      nU(       a  X0U'   g g g ©N)ÚgetÚosÚenviron)ÚtargetÚkeyÚenv_varÚvs       r>   ÚfillÚ$_fill_missing_from_env.<locals>.fill^   s5   € à�z‰z˜#�‰Ü—
‘
—‘˜wÓ'ˆAÞØ�s’ð ð ó    Úbase_urlÚorganization_idÚworkspace_idÚtypeÚfederation_rule_idÚservice_account_idÚscopeÚidentity_tokenÚfile)r;   ÚpathN)rI   úDict[str, Any]rJ   ÚstrrK   r[   ÚreturnÚNone)r   r   r   rF   ÚAUTH_TYPE_OIDC_FEDERATIONr   r   r   rG   rH   r!   ÚAUTH_TYPE_USER_OAUTH)ÚconfigÚauthrM   Ú	auth_typerL   s        r>   Ú_fill_missing_from_envrc   W   sË   € ô ñ 	ˆ�œ\Ô*ÙˆÐ"Ô$7Ô8Ùˆ�Ô!1Ô2à—‘˜Ó €IØÔ-Ó-ÙˆTÐ'Ô)?Ô@ÙˆTÐ'Ô)?Ô@ÙˆT�7œIÔ&Ø�x‰xÐ(×)Ñ)Ü—
‘
—‘Ô6Ó7ˆAÞØ4:ÀAÑ)F�Ð%Ò&ð ð *ð 
Ô*Ó	*ÙˆT�7œIÕ&ð 
+rO   c                  ó4   • \ rS rSrSrS	S jrSS.S
S jjrSrg)r0   év   zJAn `AccessTokenProvider` that always returns a fixed token with no expiry.c                ó   • Xl         g rE   ©Ú_token)ÚselfÚtokens     r>   Ú__init__ÚStaticToken.__init__y   s   € Ø�rO   F©Úforce_refreshc               ó,   • A[        U R                  S S9$ )N©rj   Ú
expires_at)r   rh   )ri   rn   s     r>   Ú__call__ÚStaticToken.__call__|   s   € ØÜ §¡¸Ñ>Ð>rO   rg   N)rj   r[   r\   r]   ©rn   Úboolr\   r   )Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__rk   rr   Ú__static_attributes__© rO   r>   r0   r0   v   s   † ÙTôð 16÷ ?ò ?rO   r0   c                  ó:   • \ rS rSrSr\4S	S jjrSS.S
S jjrSrg)r1   é�   zHAn `AccessTokenProvider` that reads `ANTHROPIC_AUTH_TOKEN` at call time.c                ó   • Xl         g rE   ©Ú_env_var)ri   rK   s     r>   rk   ÚEnvToken.__init__„   s   € Ø�rO   Frm   c               ó¢   • A[         R                  R                  U R                  5      nUc  [	        SU R                   S35      e[        US S9$ )NzEnvironment variable zN is not set. Set it or pass an explicit `credentials=` provider to the client.rp   )rG   rH   rF   r�   r,   r   )ri   rn   r:   s      r>   rr   ÚEnvToken.__call__‡   sS   € ØÜ—
‘
—‘˜tŸ}™}Ó-ˆØ‰=Ü"Ø'¨¯© ð 7Tð Uóð ô  °4Ñ8Ð8rO   r€   N)rK   r[   r\   r]   rt   )	rv   rw   rx   ry   rz   r   rk   rr   r{   r|   rO   r>   r1   r1   �   s   † ÙRà&4ö  ð 16÷ 9ò 9rO   r1   c                  ó.  • \ rS rSrSr SSS.     SS jjjr\SS j5       r\SS j5       r\S S j5       r	S!S	 jr
S"S
 jrS#S jrS$S jrS%S jrS%S jrS&S jrS'S jrS'S jrS(S jrS%S jrSS.S)S jjrSS.S*S jjrS+S jrSS.S*S jjrS,S jrSrg)-r2   é’   u'  An `AccessTokenProvider` backed by a named profile.

A profile is a pair of files under the config directory
(`~/.config/anthropic/` by default; override with `ANTHROPIC_CONFIG_DIR`):

* `configs/<profile>.json` â€” non-secret. Holds the nested
  `"authentication"` object (discriminated by its `"type"` field), plus
  top-level `organization_id`, `workspace_id`, and `base_url`.
  The `authentication` object may contain a `credentials_path` field
  overriding the credentials file location.
* `credentials/<profile>.json` â€” secret (0600). Holds `access_token`,
  `expires_at`, and (for `user_oauth` with a `client_id`)
  `refresh_token`.

The split keeps secret material out of files that may need to be readable
by config-only consumers, and lets the SDK enforce 0600 on the credentials
file without locking out config readers.

Dispatches on the `authentication.type` discriminator:

`"oidc_federation"`
    OIDC workload identity federation. Lazily constructs a
    `WorkloadIdentityCredentials` delegate from the nested auth
    fields plus the top-level `organization_id` and calls it to perform
    the jwt-bearer exchange.

`"user_oauth"`
    Output of an interactive PKCE login. If the auth block has a
    `client_id`, performs `refresh_token` grants on expiry and
    writes the new tokens back to the credentials file (atomic replace,
    refresh-token rotation supported). Without a `client_id`, the
    credentials file is treated as externally rotated â€” the SDK re-reads
    it on every invocation and returns whatever `access_token` is
    there, no refresh grant attempted. This is the pattern for a
    sidecar/daemon that mints the access token out-of-band.

Args:
    profile: Profile name. `None` resolves via `ANTHROPIC_PROFILE` env
        â†’ `<config_dir>/active_config` pointer file â†’ `"default"`.
N)Úhttp_clientc               óÈ   • Ub  UO	[        5       U l        [        U R                  5      U l        S U l        X l        S U l        S U l        S U l        [        U l
        S U l        g rE   )r&   Ú_profiler'   Ú_config_pathÚ_bound_base_urlÚ_http_clientÚ_owned_http_clientÚ_configÚ_credentials_pathr   Ú	_base_urlÚ_workload_delegate)ri   Úprofiler‡   s      r>   rk   ÚCredentialsFile.__init__¼   s\   € ð $+Ñ#6™¼OÓ<MˆŒÜ-¨d¯m©mÓ<ˆÔØ.2ˆÔØ'ÔØ;?ˆÔð 26ˆŒØ9=ˆÔÜ.ˆŒØIMˆÕrO   c                ó   • U R                   $ rE   )r‰   ©ri   s    r>   r’   ÚCredentialsFile.profileÏ   s   € à�}‰}ÐrO   c                ó   • U R                   $ rE   )rŠ   r•   s    r>   Úconfig_pathÚCredentialsFile.config_pathÓ   s   € à× Ñ Ð rO   c                óŠ   • U R                  5       nUR                  S5      nU(       a  [        U5      R                  S5      $ S$ )uS  The `base_url` declared in the profile config file, if any.

Returns `None` when the config has no top-level `base_url` key â€”
callers should fall back to their own default rather than the
provider's bound/default value, so a profile that *doesn't* pin a
host never overrides an explicit client setting. Loads the config
on first access.
rP   Ú/N)Ú_load_configrF   r[   Úrstrip)ri   r`   Úraws      r>   Úresolved_base_urlÚ!CredentialsFile.resolved_base_url×   s:   € ð ×"Ñ"Ó$ˆØ�j‰j˜Ó$ˆÞ'*Œs�3‹x�‰˜sÓ#Ð4°Ð4rO   c                óü   • UR                  S5      n[        X R                   S3S9  X l        U R                  bB  U R                  U R                  5      U l        [        U R                  U R                   S3S9  gg)a,  Adopt the owning client's `base_url` as a fallback for the token
exchange. Slots between the config file's own `base_url` field and
the hard-coded default; a `base_url` in the config file still wins.

Rebinding affects every client holding this instance; clients bind
through `for_base_url` instead.
r›   ú
: base_url©ÚfieldN)r�   r%   rŠ   r‹   rŽ   Ú_resolve_base_urlr�   )ri   rP   Úbounds      r>   Úbind_base_urlÚCredentialsFile.bind_base_urlå   sq   € ð —‘ Ó$ˆô 	�u×'8Ñ'8Ð&9¸Ð$DÒEØ$ÔØ�<‰<Ñ#Ø!×3Ñ3°D·L±LÓAˆDŒNÜ˜4Ÿ>™>°D×4EÑ4EÐ3FÀjÐ1QÓRð $rO   c                óÈ  • UR                  S5      nU R                  b  U R                  U:X  a  U R                  U5        U $ U R                  5       nUR	                  S5      (       d'  U R                  5       R	                  S5      [        :w  a  U $ [        R                  " U 5      nU R                  5       Ul	        SUl
        SUl        SUl        UR                  U5        U$ )aŽ  Return the provider a client with `base_url` should exchange through.

Binds in place, unless another client already bound this instance to a
different host (e.g. the parent of `copy(base_url=...)`). That binding
is left alone, and what happens depends on the profile:

* pins its own `base_url`: the bind is irrelevant, return `self`.
* `oidc_federation`: return a copy bound to `base_url`. It shares the
  identity token and http client, but not the on-disk token cache, whose
  tokens belong to the original deployment.
* `user_oauth`: return `self`. The refresh token is tied to the
  deployment that issued it, so there is nothing per-host to copy.
r›   NrP   rS   )r�   r‹   r§   rœ   rF   Ú_auth_blockr^   ÚcopyÚ_get_http_clientrŒ   r�   r‘   r�   )ri   rP   r¦   r`   Úproviders        r>   Úfor_base_urlÚCredentialsFile.for_base_urlö   sÅ   € ð —‘ Ó$ˆØ×ÑÑ'¨4×+?Ñ+?À5Ó+HØ×Ñ˜uÔ%ØˆKØ×"Ñ"Ó$ˆØ�:‰:�j×!Ñ! T×%5Ñ%5Ó%7×%;Ñ%;¸FÓ%CÔG`Ó%`ØˆKÜ—9’9˜T“?ˆØ $× 5Ñ 5Ó 7ˆÔØ&*ˆÔ#Ø&*ˆÔ#Ø%)ˆÔ"Ø×Ñ˜uÔ%ØˆrO   c                ó¦   • UR                  S5      (       a  [        US   5      R                  S5      $ U R                  b  U R                  $ [        $ )u  base_url precedence: top-level config field â†’ bound (the owning
client's base_url, via `bind_base_url`) â†’ default. Validated
against the scheme/TLS rules so a malicious config with
`base_url="http://evil/"` can't exfiltrate the assertion or refresh
token.rP   r›   )rF   r[   r�   r‹   r   ©ri   r`   s     r>   r¥   Ú!CredentialsFile._resolve_base_url  sL   € ð �:‰:�j×!Ñ!Ü�v˜jÑ)Ó*×1Ñ1°#Ó6Ð6Ø×ÑÑ+Ø×'Ñ'Ð'ÜÐrO   c                óÄ   • U R                  5       n0 nU R                  5       R                  S5      [        :w  a&  UR                  S5      nU(       a  [	        U5      US'   U$ )z½Return headers derived from the config file (e.g. `workspace_id`).

Eagerly reads the config if not yet loaded. The returned dict is
suitable for merging into the client's default headers.
rS   rR   zanthropic-workspace-id)rœ   rª   rF   r^   r[   )ri   r`   ÚheadersrR   s       r>   Úextra_headersÚCredentialsFile.extra_headers  s\   € ð ×"Ñ"Ó$ˆØ"$ˆð ×ÑÓ×!Ñ! &Ó)Ô-FÓFØ!Ÿ:™: nÓ5ˆLÞÜ47¸Ó4E�Ð0Ñ1ØˆrO   c                ó¤  • U R                   b  U R                   $  U R                  R                  SS9n [        R                  " U5      n[        U[        5      (       d/  [	        S	U R                   S[        U5      R                    S35      e[#        SU5      nUR%                  S5      n[        U[        5      (       d'  [	        S	U R                   S[&         S[(         S35      e[#        SU5      n[+        XF5        U R-                  U5      U l        [1        U R.                  U R                   S3S9  UR%                  S5      nU(       a3  [2        R4                  " [7        U5      5      R9                  5       U l        O[=        U R
                  5      U l        X@l         U$ ! [         a;  n[	        SU R                   SU R
                  < S[         S[         S3	5      UeSnAf[        [        4 a!  n[	        S	U R                   S
U 35      UeSnAff = f! [        R                   a!  n[	        S	U R                   SU 35      UeSnAff = f)zLRead and cache the config file, resolving `base_url` and `credentials_path`.Núutf-8©ÚencodingzConfig file not found at ú
 (profile z). Set z' to select a different profile, or set z" to relocate the config directory.zConfig file at ú could not be read: ú is not valid JSON: ú! must contain a JSON object, not Ú.rZ   ÚauthenticationzV is missing the 'authentication' object. Expected shape: {"authentication": {"type": "ú"|"ú", ...}, ...}r¢   r£   Úcredentials_path)rŽ   rŠ   Ú	read_textÚFileNotFoundErrorr,   r‰   r   r   ÚOSErrorÚUnicodeDecodeErrorÚjsonÚloadsÚJSONDecodeErrorÚ
isinstanceÚdictrS   rv   r	   rF   r^   r_   rc   r¥   r�   r%   ÚpathlibÚPathr[   Ú
expanduserr�   r(   )ri   rž   r<   Ú
raw_configr`   Úraw_authra   r
   s           r>   rœ   ÚCredentialsFile._load_config0  sR  € à�<‰<Ñ#Ø—<‘<Ðð		lØ×#Ñ#×-Ñ-°wÐ-Ð?ˆCð	lÜ"Ÿjšj¨›oˆJô ˜*¤d×+Ñ+Ü"Ø! $×"3Ñ"3Ð!4Ð4UÔVZÐ[eÓVf×VoÑVoÐUpÐpqÐróð ô Ð&¨
Ó3ˆà—:‘:Ð.Ó/ˆÜ˜(¤D×)Ñ)Ü"Ø! $×"3Ñ"3Ð!4ð 5ä-Ð.¨cÔ2FÐ1GÀðXóð ô
 Ð$ hÓ/ˆô 	˜vÔ,à×/Ñ/°Ó7ˆŒÜ�t—~‘~°×0AÑ0AÐ/BÀ*Ð-MÒNà—8‘8Ð.Ó/ˆÞÜ%,§\¢\´#°h³-Ó%@×%KÑ%KÓ%MˆDÕ"ä%;¸D¿M¹MÓ%JˆDÔ"àŒØˆøôU !ó 	Ü"Ø+¨D×,=Ñ,=Ð+>¸jÈÏÉÑHYð ZÜ"�mÐ#JÌ>ÐJZð [4ð5óð ð	ûô
 Ô+Ð,ó 	lÜ" _°T×5FÑ5FÐ4GÐG[Ð\_Ð[`Ð#aÓbÐhkÐkûð	lûô ×#Ñ#ó 	lÜ" _°T×5FÑ5FÐ4GÐG[Ð\_Ð[`Ð#aÓbÐhkÐkûð	lús:   ›F# µH Æ#
HÆ-6G#Ç#HÇ6HÈHÈIÈ.I
É
Ic           	     óž  • U R                   c   eU R                   n[        R                  S:X  aŠ   [        R                  " USS9n[        R                  " UR                  5      (       a  [        SU S
35      e[        R                  " UR                  5      nUS-  (       a  [        SU SUS SU S35      e [        [        R                  " UR                  SS95      5      nUR)                  S5      nUbR  U[*        :w  aH  U R,                  c   eU R,                  S   R)                  S5      n[        SU< S[*        < SU< 35      eU$ ! [         a#  n[        SU SU R                  < S35      UeSnAf[         a  n[        SU S	U 35      UeSnAff = f! [         a#  n[        SU SU R                  < S35      UeSnAf[        R                   a   n[        SU SU 35      [!        U5      eSnAf["         a"  n[        SU SUR$                   S35      SeSnAf[        [&        4 a  n[        SU SU 35      UeSnAff = f)uõ  Read the credentials file. Re-reads on every call â€” daemons rotate it.

Secret values in the returned dict (every string field not in
`_secrets._PLAIN_KEYS`) are `SecretStr`-wrapped â€” unwrap
with `_unwrap_secret` at the point of use. Writing the dict back
through `_atomic_write_credentials` unwraps automatically.

On Unix, refuses symlinks and any file readable or writable by group
or others (`mode & 0o077`). The check is skipped on Windows where
POSIX mode bits don't carry the same meaning.
NÚposixF)Úfollow_symlinkszCredentials file not found at r»   ú).úCredentials file at z could not be accessed: zu is a symlink; refusing to follow (move the real file into place to keep secret material on the expected filesystem).é?   z( is accessible by group or others (mode z#oz); run `chmod 600 z` before retrying.r¸   r¹   r½   r¾   r¿   r¼   rS   rÀ   zcredentials file has type z; expected z for authentication.type )r�   rG   ÚnameÚstatrÅ   r,   r‰   rÆ   ÚS_ISLNKÚst_modeÚS_IMODEr   rÈ   rÉ   rÄ   rÊ   r   r   Ú	type_namerÇ   rF   ÚCREDENTIALS_FILE_TYPErŽ   )ri   rY   Ú	file_statr<   ÚmodeÚcredsÚactualrb   s           r>   Ú_read_credentialsÚ!CredentialsFile._read_credentialsc  s¤  € ð ×%Ñ%Ñ1Ð1Ð1Ø×%Ñ%ˆÜ�7‰7�gÓðlÜŸGšG D¸%Ñ@�	ô
 �|Š|˜I×-Ñ-×.Ñ.Ü&Ø*¨4¨&ð 1jð kóð ô —<’< 	× 1Ñ 1Ó2ˆDØ�e�|Ü&Ø*¨4¨&Ð0XÐY]Ð^`ÐXað b&Ø&* VÐ+=ð?óð ð	dô
 %8¼¿
º
À4Ç>Á>Ð[bÀ>ÐCcÓ8dÓ$eˆEð" —‘˜6Ó"ˆØÑ &Ô,AÓ"AØ—<‘<Ñ+Ð+Ð+ØŸ™Ð%5Ñ6×:Ñ:¸6ÓBˆIÜ"Ø,¨V©J°kÔBWÑAZð [+Ø+4©-ð9óð ð ˆøô[ %ó vÜ&Ð)GÈÀvÈZÐX\×XeÑXeÑWhÐhjÐ'kÓlÐruÐuûÜó lÜ&Ð)=¸d¸VÐC[Ð\_Ð[`Ð'aÓbÐhkÐkûðlûô& !ó 	rÜ"Ð%CÀDÀ6ÈÐTX×TaÑTaÑSdÐdfÐ#gÓhÐnqÐqûÜ×#Ñ#ó 	vä"Ð%9¸$¸Ð?SÐTWÐSXÐ#YÓZÔ`pÐqtÓ`uÐuûÜ%ó 	ô #Ø& t fÐ,MÈcÏmÉmÈ_Ð\]Ð^óàðûô Ô+Ð,ó 	dÜ"Ð%9¸$¸Ð?SÐTWÐSXÐ#YÓZÐ`cÐcûð	dús_   ±E Â;,F Å
FÅE7Å7FÆFÆFÆ
IÆ(GÇIÇG8Ç8IÈH"È"IÈ5IÉIc                ó    • U R                   b  U R                   $ U R                  c  [        R                  " [        S9U l        U R                  $ )zEReturn an `httpx2.Client`, lazily creating (and tracking) one we own.)Útimeout)rŒ   r�   Úhttpx2ÚClientr    r•   s    r>   r¬   Ú CredentialsFile._get_http_client£  sD   € à×ÑÑ(Ø×$Ñ$Ð$Ø×"Ñ"Ñ*Ü&,§m¢mÔ<RÑ&SˆDÔ#Ø×&Ñ&Ð&rO   c                ó°   • U R                   b!  U R                   R                  5         SU l         U R                  b  U R                  R                  5         gg)z2Close the owned `httpx2.Client` if we created one.N)r�   Úcloser‘   r•   s    r>   rì   ÚCredentialsFile.close«  sK   € à×"Ñ"Ñ.Ø×#Ñ#×)Ñ)Ô+Ø&*ˆDÔ#Ø×"Ñ"Ñ.Ø×#Ñ#×)Ñ)Õ+ð /rO   c                ó    • SU l         SU l        g)a’  Drop the cached config so the next call re-reads it from disk.

`CredentialsFile` caches the parsed config across calls to keep the
hot path cheap; a daemon that rotates a profile in place (e.g. flips
`"type": "user_oauth"` to `"type": "oidc_federation"`) will not be
picked up automatically. Callers that need to react to such changes
can call `reload()` to force a fresh read on the next `__call__`.
N)rŽ   r‘   r•   s    r>   ÚreloadÚCredentialsFile.reload³  s   € ð ˆŒØ"&ˆÕrO   c                óv  • U R                   c   eU R                   R                  nUR                  SSSS9  [        R                  " USU R                   R
                   S3SS9u  p4  [        R                  " US5        [        R                  " U[        US	S
95        [        R                  " U5        [        R                  " U5        [        R                  " X@R                   5         [        R                   " U[        R"                  5      n [        R                  " U5        [        R                  " U5        g! [        R                  " U5        f = f! [         a)     [        R                  " U5        e ! [         a     e f = ff = f! [        R                  " U5        f = f! [         a     gf = f)a2  Atomic write to the credentials file (NOT the config file).

`data` may hold `SecretStr` token values (see
`_read_credentials`); they are unwrapped at dump time, so the
on-disk format is unchanged and this frame's locals stay redacted if
the write fails (e.g. ENOSPC) with a crash reporter capturing them.
NTiÀ  )ÚparentsÚexist_okrá   r¿   z.tmp)ÚdirÚprefixÚsuffixi€  é   )Úindent)r�   ÚparentÚmkdirÚtempfileÚmkstemprÙ   rG   ÚfchmodÚwriter   Úfsyncrì   ÚreplaceÚBaseExceptionÚunlinkrÆ   ÚopenÚO_RDONLY)ri   Údatarù   ÚfdÚtmpÚdir_fds         r>   Ú_atomic_write_credentialsÚ)CredentialsFile._atomic_write_credentials¿  s^  € ð ×%Ñ%Ñ1Ð1Ð1Ø×'Ñ'×.Ñ.ˆØ�‰˜T¨D°uˆÑ=ô
 ×"Ò" v¸¸$×:PÑ:P×:UÑ:UÐ9VÐVWÐ6XÐagÑh‰ˆð	ðÜ—	’	˜"˜eÔ$Ü—’˜Ô0°¸aÑ@ÔAÜ—’˜”ä—’˜”Ü�JŠJ�s×2Ñ2Ô3ð	Ü—W’W˜V¤R§[¡[Ó1ˆFð!Ü—’˜Ô ä—’˜Õ øô! —’˜•ûäó 	ðÜ—	’	˜#”ð øô ó ØØðúð	ûô —’˜Õ ûÜó 	Ùð	úsm   Á)AD? Â56E Ã,%F+ ÄF Ä(F+ Ä?EÅE Å
FÅ%E<Å;FÅ<
F	ÆFÆF	Æ	FÆF(Æ(F+ Æ+
F8Æ7F8c                ó@   • U R                  5       n[        SUS   5      $ )zCReturn the cached `authentication` sub-object from the config file.rZ   rÀ   )rœ   r	   r±   s     r>   rª   ÚCredentialsFile._auth_blocké  s$   € à×"Ñ"Ó$ˆÜÐ$ fÐ-=Ñ&>Ó?Ð?rO   Frm   c               ó  • U R                  5       nUR                  S5      nU[        :X  a  U R                  X!S9$ U[        :X  a  U R                  X!S9$ [        SU< SU R                   S[        < S[        < S3	5      e)NrS   rm   úUnknown authentication.type ú at ú. Expected ú or r¿   )rª   rF   r^   Ú_call_oidc_federationr_   Ú_call_user_oauthr,   rŠ   )ri   rn   ra   rb   s       r>   rr   ÚCredentialsFile.__call__î  s–   € Ø×ÑÓ!ˆØ—H‘H˜VÓ$ˆ	àÔ1Ó1Ø×-Ñ-¨dÐ-ÐPÐPàÔ,Ó,Ø×(Ñ(¨Ð(ÐKÐKäØ*¨9©-°t¸D×<MÑ<MÐ;Nð OÜ1Ñ4°DÔ9MÑ8PÐPQðSó
ð 	
rO   c               ó¸  • SSK JnJnJn  U R	                  5       nUR                  S5      nU(       d  [        SU R                   S35      eUR                  S5      nU(       d8  [        UR                  S5      U R                  5      n	[        [        U5      U	S9$ UR                  S	5      n
U
(       d+  U" S
U R                  < S[        < SU R                   35      e[        UR                  S5      U R                  5      n	U(       d/  U	b,  [        R                  " 5       U	:  a  [        [        U5      U	S9$ [        U
US.n U R                  5       R!                  U R"                   [$         3['        U5      S[(        [+        5       S.S9nUR2                  S:w  a  U" USS9   [5        UR7                  5       5      nUR                  S5      nU(       d  U" S5      eUR                  SS5      n [?        U5      n[?        [        R                  " 5       5      U-   nUR                  S	5      =(       d    U
n[D        US!'   [F        US"'   XöS'   UUS'   UUS	'   U RI                  U5        [        [        U5      US9$ ! [,        R.                   a  nU" SU 35      [1        U5      eSnAff = f! [8         a5  nU" SUR2                   S3UR2                  U" U5      S9[1        U5      eSnAf[:         a9  nU" SUR<                   SUR2                   S3UR2                  U" U5      S9SeSnAff = f! [@        [8        [B        4 a  nU" SU< S 35      UeSnAff = f)#zÄInteractive-login profile. With a `client_id` in the auth block,
we run the refresh_token grant on expiry; without one, we treat the
credentials file as externally rotated and just read it fresh.
r   )ÚWorkloadIdentityErrorÚ_request_idÚ_raise_token_endpoint_errorÚaccess_tokenr×   z is missing 'access_token'.Ú	client_idrq   rp   Úrefresh_tokenzcredentials file for profile z (authentication.type z/ with client_id) must include 'refresh_token': N)Ú
grant_typer  r  zapplication/json)zContent-Typezanthropic-betaz
User-Agent)Úcontentr´   z3user_oauth refresh failed to reach token endpoint: éÈ   zuser_oauth refresh failed)Úmessage_prefixz8user_oauth refresh returned a non-JSON response (status rÖ   )Ústatus_codeÚ
request_idz#user_oauth refresh returned a JSON z	 (status z); expected an object.z2user_oauth refresh response missing 'access_token'Ú
expires_ini  z5user_oauth refresh response has invalid 'expires_in' z(; expected an integer number of seconds.ÚversionrS   )%Ú	_workloadr  r  r  rä   rF   r,   r�   r?   r   r   r‰   r_   Útimer"   r¬   Úpostr�   r   r   r   r$   rè   Ú	HTTPErrorr   r   r   rÈ   r9   r   rÞ   r7   r8   ÚOverflowErrorÚCREDENTIALS_FILE_VERSIONrß   r	  )ri   ra   rn   r  r  r  râ   r  r  rq   r  ÚbodyÚrespr<   ÚpayloadÚ
new_accessÚraw_expires_inr"  Únew_expires_atÚnew_refreshs                       r>   r  Ú CredentialsFile._call_user_oauthý  sp  € ÷
 	_Ñ^à×&Ñ&Ó(ˆØ—y‘y Ó0ˆÞÜ"Ð%9¸$×:PÑ:PÐ9QÐQlÐ#mÓnÐnà—H‘H˜[Ó)ˆ	Þô ,¨E¯I©I°lÓ,CÀT×E[ÑE[Ó\ˆJÜ¤^°LÓ%AÈjÑYÐYàŸ	™	 /Ó2ˆÞÙ'Ø/°·±Ñ/@Ð@VÜ'Ñ*Ð*YØ×)Ñ)Ð*ð,óð ô (¨¯	©	°,Ó(?À×AWÑAWÓXˆ
Þ Ñ!7¼D¿IºI»KÈ*Ó<TÜ¤^°LÓ%AÈjÑYÐYô 3Ø*Ø"ñ2
ˆð	)Ø×(Ñ(Ó*×/Ñ/Ø—>‘>Ð"¤>Ð"2Ð3ô ,¨DÓ1à$6ô
 '<Ü"-£-ñð 0ð ˆDð( ×Ñ˜sÓ"Ù'¨Ð=XÒYð	Ü&9¸$¿)¹)»+Ó&FˆGð$ —[‘[ Ó0ˆ
ÞÙ'Ð(\Ó]Ð]Ø Ÿ™ \°4Ó8ˆð	Ü˜^Ó,ˆJô œTŸYšY›[Ó)¨JÑ6ˆØ—k‘k /Ó2×C°mˆä3ˆˆiÑÜ-ˆˆf‰Ø *ˆnÑØ,ˆˆlÑØ!,ˆˆoÑð 	×&Ñ& uÔ-ä¤°
Ó!;ÈÑWÐWøôe ×Ñó 	)Ù'ØEÀcÀUÐKóä# CÓ(ð)ûð	)ûô ó 	)ñ (ØJÈ4×K[ÑK[ÐJ\Ð\^Ð_Ø ×,Ñ,Ù& tÓ,ñô $ CÓ(ð	)ûô
 &ó 	ñ (Ø5°c·m±m°_ÀIÈd×N^ÑN^ÐM_Ð_uÐvØ ×,Ñ,Ù& tÓ,ñð ð	ûð	ûô œ:¤}Ð5ó 	Ù'ØGÈÑGYð Z9ð :óð ðûð	úsU   ÅA
I= Æ'J. Ç3L1 É=J+ÊJ&Ê&J+Ê.
L.Ê80K(Ë(L.Ë54L)Ì)L.Ì1MÍMÍMc                óð   • U R                   c   eU R                   R                  5       (       d  g U R                  5       $ ! [         a*  n[	        UR
                  [        5      (       a   SnAge SnAff = f)uµ   `_read_credentials` variant that returns `None` on absence
instead of raising â€” used by the federation disk-cache path where a
missing credentials file just means "exchange now".
N)r�   Úexistsrä   r+   rË   Ú	__cause__rÅ   )ri   r<   s     r>   Ú_read_credentials_if_existsÚ+CredentialsFile._read_credentials_if_existsk  sj   € ð
 ×%Ñ%Ñ1Ð1Ð1Ø×%Ñ%×,Ñ,×.Ñ.Øð	Ø×)Ñ)Ó+Ð+øÜó 	Ü˜#Ÿ-™-Ô):×;Ñ;ÜØûð	ús   ±A Á
A5ÁA0Á/A0Á0A5c               óê  • U R                   c  U R                  U5      U l         U R                  c  U R                  5       $ U R                  5       nU(       d~  Ub{  UR	                  S5      nUR	                  S5      n U(       aQ  UbN  [
        R
                  " 5       [        U5      [        -
  :  a%  [        [        [        U5      5      [        U5      S9$ U R                  5       n U R                  0 U=(       d    0 E[        [         [#        UR$                  5      UR&                  S.E5        U$ ! [        [        4 a     Nmf = f! [(         a!  n[*        R-                  SU5         S nAU$ S nAff = f)Nr  rq   rp   )r#  rS   r  rq   z?federation token disk-cache write-back failed (best-effort): %s)r‘   Ú_build_workload_delegater�   r5  rF   r%  Úfloatr#   r   r[   r   r7   r8   r9   r	  r)  rß   r   rj   rq   rÆ   r.   Údebug)ri   ra   rn   Úcachedr  rq   rj   r<   s           r>   r  Ú%CredentialsFile._call_oidc_federationz  sY  € Ø×"Ñ"Ñ*Ø&*×&CÑ&CÀDÓ&IˆDÔ#ð ×!Ñ!Ñ)Ø×*Ñ*Ó,Ð,ð ×1Ñ1Ó3ˆÞ Ñ!3Ø!Ÿ:™: nÓ5ˆLØŸ™ LÓ1ˆJð	æ Ø"Ñ.ÜŸ	š	›¤e¨JÓ&7Ô:SÑ&SÓSä&¬S´ÀÓ1MÓ-NÔ[^Ð_iÓ[jÑkÐkð
 ×'Ñ'Ó)ˆð	^Ø×*Ñ*ðØ—| ðä7Ü1ô %.¨e¯k©kÓ$:Ø"'×"2Ñ"2òô
ð ˆøô' œzÐ*ó áðûô" ó 	^Ü�I‰IÐWÐY\×]Ð]Øˆûð	^ús,   Á>AD1 Ã'AE Ä1EÅEÅ
E2ÅE-Å-E2c           
     óô  • SSK JnJn  UR                  S5      nU R                  c   eU R                  R                  S5      nU(       a  U(       d  U" S[
        < SU R                   35      eUR                  S5      nUbk  UR                  S5      nUS	:w  a  [        S
U< S35      eUR                  S5      nU(       d+  [        SU R                  < SU R                   SU< S35      eOS nU(       a  [        U5      O	[        5       n	U" U	UUUR                  S5      U R                  R                  S5      UR                  S5      U R                  5       S9n
U
R                  U R                  5        U
$ )Nr   ©r  r/   rT   rQ   z%config file with authentication.type zS must include 'authentication.federation_rule_id' and top-level 'organization_id': rW   r;   rX   zidentity_token source z- is not supported; only 'file' is implementedrY   z@identity_token source 'file' requires a non-empty path; profile r  z has identity_token=r¿   rU   rR   rV   ©Úidentity_token_providerrT   rQ   rU   rR   rV   r‡   )r$  r  r/   rF   rŽ   r^   rŠ   r,   r‰   r4   r¬   r§   r�   )ri   ra   r  r/   rT   rQ   Úidentity_token_cfgr;   Úidentity_token_pathr­   Údelegates              r>   r8  Ú(CredentialsFile._build_workload_delegateª  s�  € ÷ 	Rà!ŸX™XÐ&:Ó;ÐØ�|‰|Ñ'Ð'Ð'ØŸ,™,×*Ñ*Ð+<Ó=ˆÞ!®Ù'Ø7Ô8QÑ7Tð UXà×$Ñ$Ð%ð'óð ð "ŸX™XÐ&6Ó7ÐØÑ)Ø'×+Ñ+¨HÓ5ˆFØ˜ÓÜ&Ð)?À¹zÐIvÐ'wÓxÐxØ"4×"8Ñ"8¸Ó"@ÐÞ&ô 'ðØ#Ÿ}™}Ñ/¨t°D×4EÑ4EÐ3FÐFZÐ[mÑZpÐpqðsóð ð 'ð #'ÐÞ=PÔ$Ð%8Ô9ÔVgÓViˆñ
 /Ø$,Ø1Ø+Ø#Ÿx™xÐ(<Ó=ØŸ™×)Ñ)¨.Ó9Ø—(‘(˜7Ó#Ø×-Ñ-Ó/ñ
ˆð 	×Ñ˜tŸ~™~Ô.ØˆrO   )	r�   r‹   rŽ   rŠ   r�   rŒ   r�   r‰   r‘   rE   )r’   úOptional[str]r‡   úOptional[httpx2.Client]r\   r]   ©r\   r[   ©r\   zpathlib.Path)r\   rE  )rP   r[   r\   r]   )rP   r[   r\   z'CredentialsFile')r`   rZ   r\   r[   )r\   zDict[str, str]©r\   rZ   )r\   zhttpx2.Client©r\   r]   )r  rZ   r\   r]   rt   )ra   rZ   rn   ru   r\   r   )r\   zOptional[Dict[str, Any]]©ra   rZ   r\   r/   )rv   rw   rx   ry   rz   rk   Úpropertyr’   r˜   rŸ   r§   r®   r¥   rµ   rœ   rä   r¬   rì   rï   r	  rª   rr   r  r5  r  r8  r{   r|   rO   r>   r2   r2   ’   så   † ñ'ðV "&ðNð 04ñ	NàðNð -ð	Nð
 
öNð& óó ðð ó!ó ð!ð ó5ó ð5ôSô"ô:
 ôô"1ôf>ô@'ô,ô
'ô(ôT@ð
 16÷ 
ð OT÷ lXô\ð TY÷ .÷`3rO   r2   c                  óD   • \ rS rSrSrSS	S jjr\S
S j5       rSS jrSr	g)r4   ià  zÜAn `IdentityTokenProvider` that reads a JWT from a file on every call.

Kubernetes projected service-account tokens (and similar) are rotated in place,
so the file MUST be re-read on every invocation rather than cached.
Nc                óR   • [        U5      nUc  [        S[         S35      eX l        g )Nz;No identity token file path given. Pass `path=` or set the z environment variable.)r)   r,   r!   Ú_path)ri   rY   Úresolveds      r>   rk   ÚIdentityTokenFile.__init__ç  s:   € Ü.¨tÓ4ˆØÑÜ"ØMÔNeÐMfð g(ð )óð ð �
rO   c                ó   • U R                   $ rE   ©rO  r•   s    r>   rY   ÚIdentityTokenFile.pathð  s   € à�z‰zÐrO   c                óH  •  U R                   R                  SS9R                  5       nU(       d"  [	        SU R                    S3U R                   S9eU$ ! [         a(  n[	        SU R                    S3U R                   S9UeS nAf[
         a+  n[	        SU R                    SU S3U R                   S9UeS nAf[         a(  n[	        S	U R                    S
3U R                   S9UeS nAf[        [        4 a*  n[	        SU R                    SU 3U R                   S9UeS nAff = f)Nr¸   r¹   z!Identity token file not found at r¿   )rY   zIdentity token file at z" is not readable by this process: z;. Check the file mode and the effective uid of the process.zIdentity token path zF is a directory, not a file. Point at the projected token file itself.r¼   z‹ is empty. If this is a Kubernetes projected service-account token, check the volume mount and the serviceAccountToken projection audience.)	rO  rÄ   ÚstriprÅ   r-   ÚPermissionErrorÚIsADirectoryErrorrÆ   rÇ   )ri   r  r<   s      r>   rr   ÚIdentityTokenFile.__call__ô  sT  € ð	Ø—j‘j×*Ñ*°GÐ*Ð<×BÑBÓDˆGö& Ü(Ø)¨$¯*©*¨ð 6Pð Qð —Z‘Zñ	ð ð ˆøô3 !ó 	vÜ(Ð+LÈTÏZÉZÈLÐXYÐ)ZÐae×akÑakÑlÐruÐuûÜó 	Ü(Ø)¨$¯*©*¨Ð5WÐX[ÐW\ð ]Lð Mà—Z‘Zñð ð	ûô
 !ó 	Ü(Ø& t§z¡z lð 3<ð =à—Z‘Zñð ð	ûô
 Ô+Ð,ó 	Ü(Ø)¨$¯*©*¨Ð5IÈ#ÈÐOÐVZ×V`ÑV`ñàðûð	ús;   ‚'A Á
D!Á#BÂD!Â&B4Â4D!Ã#C$Ã$D!Ã7%DÄD!rS  rE   )rY   z$Union[str, 'os.PathLike[str]', None]r\   r]   rH  rG  )
rv   rw   rx   ry   rz   rk   rL  rY   rr   r{   r|   rO   r>   r4   r4   à  s%   † ñöð óó ð÷rO   r4   c                  ó¨   ^ • \ rS rSrSr\R                  " S5      rSSS.       SS jjr\	SS j5       r
\	SS j5       r\	SU 4S	 jj5       rS
rU =r$ )r3   i  uK  An `AccessTokenProvider` driven by an in-memory config dict
(same shape as `configs/<profile>.json`) rather than files on disk.

Intended for callers that want to construct an `anthropic.Anthropic`
client with a fully programmatic credentials setup â€” equivalent to the Go
SDK's `option.WithConfig` / TypeScript SDK's `ClientOptions.config`.

Both `authentication.type` discriminator values are supported:

`"oidc_federation"`
    `authentication.credentials_path` is **optional**. If set, exchanged
    tokens are cached to / read from that file (same atomic 0600 write as
    `CredentialsFile`). If omitted, every call performs a fresh
    jwt-bearer exchange with no on-disk cache.

`"user_oauth"`
    `authentication.credentials_path` is **required** â€” it is where the
    access/refresh tokens live. Behaviour is identical to a file-backed
    `CredentialsFile` profile of the same shape.

The implementation subclasses `CredentialsFile` so the dispatch,
refresh-grant, disk-cache and atomic-write logic are shared verbatim;
only config loading and identity-token resolution are overridden.
z<in-memory config>N)r@  r‡   c          	     óÒ  • UR                  S5      n[        U[        5      (       d  [        S[         S[
         S35      e[        SU5      nUR                  S5      nU[        [
        4;  a   [        SU< S[        < S	[
        < S
35      eUR                  S5      nU[
        :X  a  U(       d  [        S[
        < S35      eSU l        U R                  U l	        S U l
        X0l        S U l        S U l        X l        Xl        U(       a-  [         R"                  " [%        U5      5      R'                  5       OS U l        U R+                  U5      U l        [/        U R,                  SS9  g )NrÀ   zaconfig dict is missing the 'authentication' object. Expected shape: {"authentication": {"type": "rÁ   rÂ   rZ   rS   r  r  r  r¿   rÃ   zauthentication.type zŽ requires 'authentication.credentials_path' (where the access/refresh tokens live). For profile-based resolution, use CredentialsFile instead.z<in-memory>zconfig: base_urlr£   )rF   rË   rÌ   r,   r^   r_   r	   r‰   Ú_IN_MEMORY_PATHrŠ   r‹   rŒ   r�   r‘   Ú!_identity_token_provider_overriderŽ   rÍ   rÎ   r[   rÏ   r�   r¥   r�   r%   )ri   r`   r@  r‡   rÑ   ra   rb   rÃ   s           r>   rk   ÚInMemoryConfig.__init__/  sn  € ð —:‘:Ð.Ó/ˆÜ˜(¤D×)Ñ)Ü"ðBÜB[ÐA\ð ]Ü)Ð*¨/ð;óð ô
 Ð$ hÓ/ˆØ—H‘H˜VÓ$ˆ	ØÔ6Ô8LÐMÓMÜ"Ø.¨y©mð <Ü5Ñ8¸Ô=QÑ<TÐTUðWóð ð
  Ÿ8™8Ð$6Ó7ÐØÔ,Ó,Ö5EÜ"Ø&Ô';Ñ&>ð ?Mð Nóð ð &ˆŒØ ×0Ñ0ˆÔØ.2ˆÔØ'ÔØ;?ˆÔØIMˆÔØ1HÔ.àŒÞUe¤§¢¬cÐ2BÓ.CÓ!D×!OÑ!OÔ!QÐkoˆÔØ×/Ñ/°Ó7ˆŒÜ�t—~‘~Ð-?Ó@rO   c                ó8   • U R                   c   eU R                   $ rE   )rŽ   r•   s    r>   rœ   ÚInMemoryConfig._load_config\  s   € à�|‰|Ñ'Ð'Ð'Ø�|‰|ÐrO   c                ó   • S U l         g rE   )r‘   r•   s    r>   rï   ÚInMemoryConfig.reloada  s   € ð #'ˆÕrO   c           
     óð  >• U R                   c  [        TU ]	  U5      $ SSKJnJn  UR                  S5      nU R                  c   eU R                  R                  S5      nU(       a  U(       d  U" S[        < S35      eU" U R                   UUUR                  S5      U R                  R                  S5      UR                  S	5      U R                  5       S
9nUR                  U R                  5        U$ )Nr   r>  rT   rQ   z%config dict with authentication.type zQ must include 'authentication.federation_rule_id' and top-level 'organization_id'rU   rR   rV   r?  )r]  Úsuperr8  r$  r  r/   rF   rŽ   r^   r¬   r§   r�   )ri   ra   r  r/   rT   rQ   rC  Ú	__class__s          €r>   r8  Ú'InMemoryConfig._build_workload_delegateg  sê   ø€ à×1Ñ1Ñ9Ü‘7Ñ3°DÓ9Ð9çQà!ŸX™XÐ&:Ó;ÐØ�|‰|Ñ'Ð'Ð'ØŸ,™,×*Ñ*Ð+<Ó=ˆÞ!®Ù'Ø7Ô8QÑ7Tð UVð Wóð ñ /Ø$(×$JÑ$JØ1Ø+Ø#Ÿx™xÐ(<Ó=ØŸ™×)Ñ)¨.Ó9Ø—(‘(˜7Ó#Ø×-Ñ-Ó/ñ
ˆð 	×Ñ˜tŸ~™~Ô.ØˆrO   )
r�   r‹   rŽ   rŠ   r�   rŒ   r]  r�   r‰   r‘   )r`   rZ   r@  zOptional[IdentityTokenProvider]r‡   rF  r\   r]   rI  rJ  rK  )rv   rw   rx   ry   rz   rÍ   rÎ   r\  rk   r
   rœ   rï   r8  r{   Ú__classcell__)re  s   @r>   r3   r3     s‘   ø† ñð2 —l’lÐ#7Ó8€Oð DHØ/3ñ+Aàð+Að "Að	+Að
 -ð+Að 
õ+AðZ óó ðð ó'ó ð'ð
 öó örO   r3   )r:   r   r;   zOptional[pathlib.Path]r\   zOptional[int])r`   rZ   ra   rZ   r\   r]   )LÚ
__future__r   rG   r«   rÈ   rÚ   r%  ÚloggingrÍ   rû   Útypingr   r   r   r   r   r	   Útyping_extensionsr
   rè   Ú_typesr   r   Ú_secretsr   r   r   r   r   r   Ú
_constantsr   r   r   r   r   r   r   r   r   r   r   r   r    r!   r"   r#   r$   r%   r&   r'   r(   r)   Ú_exceptionsr+   r,   r-   Ú	getLoggerrv   r.   Ú__annotations__r$  r/   Ú__all__r?   rß   ÚCONFIG_FILE_VERSIONr)  r^   r_   rc   r0   r1   r2   r4   r3   r|   rO   r>   Ú<module>rt     sè   ðÞ "ã 	Û Û Û Û Û Û Û ß B× BÝ &ã ç 6÷÷ ÷÷ ÷ ÷ ÷ ÷ ÷0 TÑ Sà×'Ò'¨Ó1€€^Ó 1æÝ6â
_€ôð" &Ð ð Ð Ø Ð ð .Ð Ø#Ð ô'÷>?ñ ?÷9ñ 9÷"K	ñ K	÷\0ñ 0ôfm�_õ mrO   