ó
    °"³jë@  ã                  ó¤  • % S SK Jr  S SKrS SKrS SKrS SKJr  S SKJrJ	r	J
r
JrJrJr  S SKJr  S SKrSSKJrJr  SSKJrJrJrJrJrJr  SS	KJrJrJrJrJ r J!r!J"r"J#r#  S
SK$J%r%  \ S\  3r&Sr'Sr(Sr)SS jr*SS jr+SS.SS jjr,/ SQr-\R\                  " \/5      r0S\1S'    " S S\%5      r2 " S S5      r3SSSSS.               S S jjr4g)!é    )ÚannotationsN)ÚTracebackType)ÚAnyÚDictÚTypeÚUnionÚNoReturnÚOptional)Úoverrideé   )ÚAccessTokenÚIdentityTokenProvider)Ú	SecretStrÚ_unwrap_secretÚ_strip_tracebackÚ_json_dumps_secretsÚ_wrap_secret_fieldsÚ_NonObjectPayloadError)ÚTOKEN_ENDPOINTÚDEFAULT_BASE_URLÚGRANT_TYPE_JWT_BEARERÚOAUTH_API_BETA_HEADERÚFEDERATION_BETA_HEADERÚTOKEN_EXCHANGE_TIMEOUTÚ_user_agentÚ_require_httpsé   )ÚAnthropicErrorÚ,é   i @  i   c                ó€   • U R                   R                  S5      =(       d    U R                   R                  S5      nU$ )Nz
Request-Idz
request-id)ÚheadersÚget)ÚrespÚrids     Ú`/home/mande/repo/quber/.venv/lib/python3.13/site-packages/anthropic/lib/credentials/_workload.pyÚ_request_idr'   5   s/   € ØŸ™×)Ñ)¨,Ó7×Y¸4¿<¹<×;KÑ;KÈLÓ;Y€CØ€Jó    c                óþ   • U c  g[        U [        5      (       a5  [        U 5      [        ::  a  U $ U S[         S[        U 5      [        -
   S3-   $ [        U [        5      (       a  0 nS H  nX ;   d  M
  X   X'   M     U$ g)zHTruncate a token-endpoint error body for safe inclusion in an exception.Nz... <z more chars>)ÚerrorÚerror_descriptionÚ	error_uri)Ú
isinstanceÚstrÚlenÚ_MAX_ERROR_BODY_CHARSÚdict)ÚbodyÚkeptÚkeys      r&   Ú_redact_bodyr5   :   s†   € à�|ØÜ�$œ×ÑÜˆt‹9Ô-Ó-ØˆKØÐ*Ô*Ð+°´c¸$³iÔBWÑ6WÐ5XÐXdÐ.eÑeÐeä�$œ×ÑØ!ˆÛ>ˆCØ�{Ø ™I�“	ñ ?ð ˆØr(   )Úhintc               ó  •  [        U R                  5       5      nU SU R                   SU 3nU(       a  U SU 3n[        UU R                  U[        U 5      S9e! [         a    [        U R                  5      n Nbf = f)u€  Raise a redacted `WorkloadIdentityError` from a non-200 token-endpoint response.

Shared between the jwt-bearer exchange path in this module and the
refresh_token grant path in `_providers`.

The raw response body (which token endpoints can echo credential material
into) is never bound to a local in this frame â€” only the redaction is â€”
so this frame is safe under crash reporters that capture traceback locals.

`hint` is an optional caller-supplied diagnostic appended verbatim to the
error message (after the redacted body). Callers gate it on the response
status and their own state â€” this helper does not inspect `resp` for it.
z (HTTP ú): Ú ©Ústatus_coder2   Ú
request_id)r5   ÚjsonÚ
ValueErrorÚtextr;   ÚWorkloadIdentityErrorr'   )r$   Úmessage_prefixr6   ÚredactedÚmessages        r&   Ú_raise_token_endpoint_errorrD   L   s�   € ð+Ü §	¡	£Ó,ˆð  Ð  ¨×(8Ñ(8Ð'9¸¸X¸JÐG€GÞØ�I˜Q˜t˜fÐ%ˆÜ
ØØ×$Ñ$ØÜ˜tÓ$ñ	ð øô ó +Ü §	¡	Ó*Šð+ús   ‚A ÁA>Á=A>)ÚWorkloadIdentityCredentialsr@   Úexchange_federation_assertionzlogging.LoggerÚlogc                  óˆ   ^ • \ rS rSr% SrS\S'   S\S'   S\S'   S	S	S	S
.         SU 4S jjjr\SU 4S jj5       rSr	U =r
$ )r@   én   zCRaised when the OIDC token exchange (`POST /v1/oauth/token`) fails.úOptional[int]r;   r   r2   úOptional[str]r<   Nr:   c               óH   >• [         TU ]  U5        X l        X0l        X@l        g ©N)ÚsuperÚ__init__r;   r2   r<   )ÚselfrC   r;   r2   r<   Ú	__class__s        €r&   rO   ÚWorkloadIdentityError.__init__u   s"   ø€ ô 	‰Ñ˜Ô!Ø&ÔØŒ	Ø$�r(   c                ój   >• [         TU ]  5       nU R                  (       a  U SU R                   S3$ U$ )Nz [request_id=Ú])rN   Ú__str__r<   )rP   ÚbaserQ   s     €r&   rU   ÚWorkloadIdentityError.__str__‚   s3   ø€ ä‰w‰Ó ˆØ�?�?Ø�V˜=¨¯©Ð(9¸Ð;Ð;Øˆr(   )r2   r<   r;   )
rC   r.   r;   rJ   r2   r   r<   rK   ÚreturnÚNone©rX   r.   )Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__Ú__annotations__rO   r   rU   Ú__static_attributes__Ú__classcell__)rQ   s   @r&   r@   r@   n   sp   ø‡ ÙMàÓØ
ƒIØÓð &*ØØ$(ñ%àð%ð #ð	%ð
 ð%ð "ð%ð 
÷%ð %ð öó ör(   r@   c                  óÊ   • \ rS rSrSrSSSSS.               SS jjr\SS j5       r\SS j5       rSS jr	SS	 jr
SS
 jrSS jr        SS jrSS.SS jjrSrg)rE   éŠ   ub  Exchanges an external OIDC JWT for an Anthropic access token via the
RFC 7523 `jwt-bearer` grant.

This is an `AccessTokenProvider`: calling it performs a *fresh* token
exchange. Wrap in a `TokenCache` (done automatically when passed as
`credentials=` to `anthropic.Anthropic`) to avoid exchanging on every
request.

Args:
    organization_id: The organization's raw UUID string (organizations do
        not use tagged IDs).
    workspace_id: Optional `wrkspc_*` tagged ID, or the literal
        `"default"` to scope the token to the organization's default
        workspace. When omitted the server picks the rule's sole enabled
        workspace, else the org default if the rule covers it. Required
        when the rule enables more than one non-default workspace, or to
        target a specific workspace other than the one the server would
        pick. The minted token is workspace-scoped: per-request workspace
        selection (the `anthropic-workspace-id` header) is not supported
        for federation tokens â€” switching workspaces requires a new token
        exchange with a different `workspace_id`.
N)Úservice_account_idÚworkspace_idÚscopeÚhttp_clientc               óÄ   • Xl         X l        X0l        X@l        XPl        X`l        S U l        Uc%  [        R                  " [        S9U l
        SU l        g Xpl
        SU l        g )N)ÚtimeoutTF)Ú_identity_token_providerÚ_federation_rule_idÚ_organization_idÚ_service_account_idÚ_workspace_idÚ_scopeÚ_bound_base_urlÚhttpx2ÚClientr   Ú_http_clientÚ_owns_http_client)rP   Úidentity_token_providerÚfederation_rule_idÚorganization_idre   rf   rg   rh   s           r&   rO   Ú$WorkloadIdentityCredentials.__init__¢   sb   € ð )@Ô%Ø#5Ô Ø /ÔØ#5Ô Ø)Ôð
 Œð /3ˆÔØÑÜ &§¢Ô6LÑ MˆDÔØ%)ˆDÕ"à +ÔØ%*ˆDÕ"r(   c                ó   • U R                   $ rM   )rp   ©rP   s    r&   rg   Ú!WorkloadIdentityCredentials.scopeÅ   s   € à�{‰{Ðr(   c                ó4   • U R                   =(       d    [        $ rM   )rq   r   r{   s    r&   Ú	_base_urlÚ%WorkloadIdentityCredentials._base_urlÉ   s   € à×#Ñ#×7Ô'7Ð7r(   c                óF   • UR                  S5      n[        USS9  X l        g)zÑSet the API `base_url` the token exchange POSTs to.

For standalone use (no client) or tests. Clients bind through
`for_base_url`, which never rebinds an instance another client
is already exchanging through.
Ú/Úbase_url)ÚfieldN)Úrstripr   rq   )rP   r‚   Úbounds      r&   Úbind_base_urlÚ)WorkloadIdentityCredentials.bind_base_urlÍ   s"   € ð —‘ Ó$ˆÜ�u JÒ/Ø$Õr(   c                óÂ   • UR                  S5      nU nU R                  b-  U R                  U:w  a  [        R                  " U 5      nSUl        UR	                  U5        U$ )a‹  Return the provider a client with `base_url` should exchange through.

Binds in place, unless another client already bound this instance to a
different host (e.g. the parent of `copy(base_url=...)`). Rebinding
would move that client's token exchange too, so a copy bound to
`base_url` is returned instead; it shares the identity token and
borrows (never closes) this instance's `httpx2.Client`.
r�   F)r„   rq   Úcopyru   r†   )rP   r‚   r…   Úproviders       r&   Úfor_base_urlÚ(WorkloadIdentityCredentials.for_base_urlØ   sX   € ð —‘ Ó$ˆØˆØ×ÑÑ+°×0DÑ0DÈÓ0MÜ—y’y “ˆHØ).ˆHÔ&Ø×Ñ˜uÔ%Øˆr(   c                ó\   • U R                   (       a  U R                  R                  5         gg)z6Close the underlying `httpx2.Client` if we created it.N)ru   rt   Úcloser{   s    r&   rŽ   Ú!WorkloadIdentityCredentials.closeé   s"   € à×!×!Ø×Ñ×#Ñ#Õ%ð "r(   c                ó   • U $ rM   © r{   s    r&   Ú	__enter__Ú%WorkloadIdentityCredentials.__enter__î   s   € Øˆr(   c                ó$   • U R                  5         g rM   )rŽ   )rP   Úexc_typeÚexcÚtbs       r&   Ú__exit__Ú$WorkloadIdentityCredentials.__exit__ñ   s   € ð 	�
‰
�r(   F)Úforce_refreshc               óÎ  • A[        U R                  5       5      n[        UR                  5       R	                  S5      5      nU[
        :”  a  [        SU S[
         S35      e[        UU R                  U R                  S.nU R                  b  U R                  US'   U R                  b  U R                  US'   U R                   [         3n U R                  R                  U[!        U5      ["        S[%        5       S	.S
9n[-        U5      n[        UR.                  5      [0        :”  a3  [        S[0         S[        UR.                  5       S3UR2                  US9eUR2                  S:¼  a6  S n	UR2                  S:X  a  Sn	U R                  c  U	S-  n	U	S-  n	[5        USU	S9   [7        UR9                  5       5      n
U
RE                  S5      nUbA  [G        U5      RI                  5       S:w  a$  [        S U< S!3UR2                  [=        U
5      US9e U
S"   n[K        U
S#   5      n[S        [U        U5      [K        [V        RV                  " 5       5      U-   S%9$ ! [&        R(                   a   n[        SU SU 35      [+        U5      eS nAff = f! [:         aJ  n[=        UR>                  5      n[        SUR2                   SU 3UR2                  UUS9[+        U5      eS nAf[@         a6  n[        SURB                   SUR2                   S3UR2                  US9S eS nAff = f! [L        [N        [:        [P        4 a%  n[        S$UR2                  [=        U
5      US9UeS nAff = f)&Nzutf-8zIdentity token assertion is z bytes, which exceeds the uˆ   -byte limit. This is almost certainly not a JWT â€” check that the identity-token path points at the projected token, not a key or cert.)Ú
grant_typeÚ	assertionrw   rx   re   rf   zapplication/json)zanthropic-betazContent-Typez
User-Agent)Úcontentr"   zFailed to reach token endpoint z: z%Token endpoint response body exceeds z bytes (got z); refusing to parse.)r;   r<   i�  i‘  z9Ensure your federation rule matches your identity token. z­If your federation rule is scoped to multiple workspaces, set the ANTHROPIC_WORKSPACE_ID environment variable, the 'workspace_id' config key, or the workspace_id= argument. zaView your authentication events in the Workload identity page of Claude Console for more details.zToken exchange failed)rA   r6   z2Token endpoint returned non-JSON response (status r8   r:   zToken endpoint returned a JSON z	 (status z); expected an object.Ú
token_typeÚbearerz/Token endpoint returned unsupported token_type z (expected 'Bearer').Úaccess_tokenÚ
expires_inzLToken endpoint response missing required fields (access_token / expires_in).)ÚtokenÚ
expires_at),r   rk   r/   Úget_secret_valueÚencodeÚ_MAX_ASSERTION_BYTESr@   r   rl   rm   rn   ro   r~   r   rt   Úpostr   Ú_JWT_BEARER_BETA_HEADERr   rr   Ú	HTTPErrorr   r'   rž   Ú_MAX_TOKEN_RESPONSE_BYTESr;   rD   r   r=   r>   r5   r?   r   Ú	type_namer#   r.   ÚlowerÚintÚKeyErrorÚ	TypeErrorÚOverflowErrorr   r   Útime)rP   rš   ÚjwtÚassertion_bytesr2   Úurlr$   Úerrr<   r6   ÚdatarB   rŸ   r£   r¢   s                  r&   Ú__call__Ú$WorkloadIdentityCredentials.__call__ù   s¹  € ð Ü˜×5Ñ5Ó7Ó8ˆä˜c×2Ñ2Ó4×;Ñ;¸GÓDÓEˆØÔ1Ó1Ü'Ø.¨Ð.?Ð?YÜ'Ð(ð )aðbóð ô 0ØØ"&×":Ñ":Ø#×4Ñ4ñ	2
ˆð ×#Ñ#Ñ/Ø)-×)AÑ)AˆDÐ%Ñ&Ø×ÑÑ)Ø#'×#5Ñ#5ˆD�Ñ à—‘Ð ¤Ð 0Ð1ˆð	sØ×$Ñ$×)Ñ)Øô ,¨DÓ1ä&=Ø$6Ü"-£-ñð *ð 
ˆDô ! Ó&ˆ
äˆt�|‰|ÓÔ8Ó8Ü'Ø7Ô8QÐ7Rð SÜ˜DŸL™LÓ)Ð*Ð*?ðAà ×,Ñ,Ø%ñ	ð ð ×Ñ˜sÓ"ð
 #'ˆDØ×Ñ 3Ó&ØR�Ø×%Ñ%Ñ-ØðFñ�Dð
 Øwñ�ô (¨Ð=TÐ[_Ò`ð	ô ' t§y¡y£{Ó3ˆDð& —X‘X˜lÓ+ˆ
ØÑ!¤c¨*£o×&;Ñ&;Ó&=ÀÓ&IÜ'ØAÀ*ÁÐOdÐeØ ×,Ñ,Ü! $Ó'Ø%ñ	ð ð
	Ø˜Ñ(ˆEä˜T ,Ñ/Ó0ˆJô ¤°Ó!6Ä3ÄtÇyÂyÃ{ÓCSÐV`ÑC`ÑaÐaøôY ×Ñó 	sÜ'Ð*IÈ#ÈÈbÐQTÐPUÐ(VÓWÔ]mÐnqÓ]rÐrûð	sûôJ ó 	)Ü# D§I¡IÓ.ˆHÜ'ØDÀT×EUÑEUÐDVÐVYÐZbÐYcÐdØ ×,Ñ,ØØ%ñ	ô
 $ CÓ(ð)ûô &ó 	ô (Ø1°#·-±-°À	È$×JZÑJZÐI[Ð[qÐrØ ×,Ñ,Ø%ñð ð	ûð		ûô. œ)¤Z´Ð?ó 	Ü'Ø^Ø ×,Ñ,Ü! $Ó'Ø%ñ	ð
 ðûð	úsU   Ã4I Æ%J ÈL% ÉJÉ-JÊJÊ
L"ÊAKËL"Ë,1LÌL"Ì%M$Ì? MÍM$)	rq   rl   rt   rk   rm   ru   rp   rn   ro   )rv   r   rw   r.   rx   r.   re   rK   rf   rK   rg   rK   rh   úOptional[httpx2.Client]rX   rY   )rX   rK   rZ   )r‚   r.   rX   rY   )r‚   r.   rX   ú'WorkloadIdentityCredentials')rX   rY   )rX   r»   )r•   zOptional[Type[BaseException]]r–   zOptional[BaseException]r—   zOptional[TracebackType]rX   rY   )rš   ÚboolrX   r   )r[   r\   r]   r^   r_   rO   Úpropertyrg   r~   r†   r‹   rŽ   r’   r˜   r¸   ra   r‘   r(   r&   rE   rE   Š   så   † ñð: -1Ø&*Ø#Ø/3ñ!+ð "7ð!+ð  ð	!+ð
 ð!+ð *ð!+ð $ð!+ð ð!+ð -ð!+ð 
õ!+ðF óó ðð ó8ó ð8ô	%ôô"&ô
ðà/ðð %ðð $ð	ð
 
ôð 16÷ sbò sbr(   rE   )re   rf   r‚   rh   c           	     óô   • [        U [        5      (       a  [        U 5      n [        U R                  UUUUUS9nUb  UR                  U5         U" 5       UR                  5         $ ! UR                  5         f = f)a�  Perform a single RFC 7523 `jwt-bearer` exchange and return the resulting
`AccessToken`.

This is a one-shot convenience wrapper around `WorkloadIdentityCredentials`
for callers that already have the assertion JWT in hand and just want the
Anthropic access token back (no caching, no provider plumbing).

`assertion` may be a `pydantic.SecretStr` to keep it redacted
end-to-end; a plain `str` is wrapped on entry.
)rv   rw   rx   re   rf   rh   )r-   r.   r   rE   r¥   r†   rŽ   )r�   rw   rx   re   rf   r‚   rh   Úcredss           r&   rF   rF   o  sr   € ô( �)œS×!Ñ!ô ˜iÓ(ˆ	Ü'Ø )× :Ñ :Ø-Ø'Ø-Ø!Øñ€Eð ÑØ×Ñ˜HÔ%ðÙ‹wà�‰�øˆ�‰�ús   ÁA% Á%A7)r$   úhttpx2.ResponserX   rK   )r2   r   rX   r   )r$   rÀ   rA   r.   r6   rK   rX   r	   )r�   zUnion[str, SecretStr]rw   r.   rx   r.   re   rK   rf   rK   r‚   rK   rh   rº   rX   r   )5Ú
__future__r   r‰   r²   ÚloggingÚtypesr   Útypingr   r   r   r   r	   r
   Útyping_extensionsr   rr   Ú_typesr   r   Ú_secretsr   r   r   r   r   r   Ú
_constantsr   r   r   r   r   r   r   r   Ú_exceptionsr   r©   r0   r§   r«   r'   r5   rD   Ú__all__Ú	getLoggerr[   rG   r`   r@   rE   rF   r‘   r(   r&   Ú<module>rÌ      s  ðÞ "ã Û Û Ý ß =× =Ý &ã ç 6÷÷ ÷	÷ 	ó 	õ *ð
 3Ð3°1Ð5KÐ4LÐMÐ ð Ð ð !Ð Ø#Ð ôô
ð$ fj÷ ò: d€à×'Ò'¨Ó1€€^Ó 1ô˜Nô ÷8bbñ bbðT )-Ø"&Ø"Ø+/ñ%à$ð%ð ð%ð ð	%ð
 &ð%ð  ð%ð ð%ð )ð%ð ö%r(   