+
    Q?j=                      a  0 t $ ^ RIHt ^ RIt^ RIt^ RIHtHtHtH	t	H
t
Ht ^ RIHt ^ RIHtHtHtHt ^ RIt^RIHt ^RIHtHt ^RIHtHtHt ^R	IHt R
tRt Rt!RRRR/t" ! R R]
4      t# ! R R]
4      t$]$t%R]&R&    ! R R]
4      t']! R]$]'4      t(RR/R R llt)R/R R llt*R0RRR RR!RR"R#R$R%R&R/R' R( lllt+R1R$R%R&R/R) R* lllt, ! R+ R,]](,          4      t- ! R- R.]-]$,          4      t.R# )2    )annotationsN)AnyGenericTypeVarCallable	TypedDictcast)Path)Literal	TypeAliasNotRequiredoverride)is_dict)DefaultHttpx2Client_loaded_legacy_httpx)
OAuthErrorOpenAIErrorSubjectTokenProviderError)	to_threadz/urn:ietf:params:oauth:grant-type:token-exchangez#https://auth.openai.com/oauth/tokeni  jwtz$urn:ietf:params:oauth:token-type:jwtidz)urn:ietf:params:oauth:token-type:id_tokenc                  ,    ] tR t^t$ R]R&   R]R&   RtR# )SubjectTokenProviderzLiteral['jwt', 'id']
token_typezCallable[[], str]	get_token N)__name__
__module____qualname____firstlineno____annotations____static_attributes__r       ~/home/vela/workspace/domain/tn-silver/web/tn-site/.runtime/imagegen-venv/lib/python3.14/site-packages/openai/auth/_workload.pyr   r      s    $$  r#   r   c                  J    ] tR t^t$ RtR]R&    R]R&    R]R&    R]R&   R	tR
# )WorkloadIdentityz(Identity provider resource id in WIFAPI.stridentity_provider_idservice_account_idr   providerNotRequired[float]refresh_buffer_secondsr   Nr   r   r   r    __doc__r!   r"   r   r#   r$   r&   r&      s&    2GE""..r#   r&   r   SubjectTokenWorkloadIdentityc                  D    ] tR t^1t$ RtR]R&   R]R&   R]R&   R]R&   R	tR
# )X509WorkloadIdentityzJAuthenticate with the client certificate configured on the HTTP transport.zLiteral['x509']typer'   r(   r)   r+   r,   r   Nr-   r   r#   r$   r1   r1   1   s    T
..r#   r1   _WorkloadIdentityTr,   c               (    V ^8  d   QhRRRRRRRR/# )   r(   r'   r)   r,   zfloat | Nonereturnr1   r   )formats   "r$   __annotate__r8   =   s2        )	
 r#   c                &    RRRV RV/pVe   W#R&   V# )zHConfigure X.509 workload identity without handling certificate material.r2   x509r(   r)   r,   r   )r(   r)   r,   identitys   $$$ r$   x509_workload_identityr<   =   s2     	 40&H
 )-C)*Or#   c                    V ^8  d   QhRRRR/# )r5   token_file_pathz
str | Pathr6   r   r   )r7   s   "r$   r8   r8   N   s     9 999r#   c                "   a  R V 3R llpRRRV/# )a7  
Get a subject token provider for Kubernetes clusters with Workload Identity configured.

Cloud providers typically mount the subject token as a file in the container.

Args:
    token_file_path: path to the mounted service account token file. Defaults to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
c                   V ^8  d   QhRR/# r5   r6   r'   r   )r7   s   "r$   r8   8k8s_service_account_token_provider.<locals>.__annotate__Z   s     o os or#   c                 $  <  \        SR 4      ;_uu_ 4       p V P                  4       P                  4       pV'       g   \        RS R24      hVuuRRR4       #   + '       g   i     R# ; i  \         d   p\        RS RT 24      ThRp?ii ; i)rzThe token file at z
 is empty.Nz!Failed to read the token file at z: )openreadstripr   	Exception)ftokener>   s      r$   r   5k8s_service_account_token_provider.<locals>.get_tokenZ   s    	oos++q(36HHYYc4dee	 ,+++
  	o+.OP_O``bcdbe,fgmnn	os4   A- 7A
A- A*	$A- *A- -B8B

Br   r   r   r   )r>   r   s   f r$   "k8s_service_account_token_providerrM   N   s     o o %i88r#   	object_id	client_id
msi_res_idapi_versionz
2018-02-01timeout      $@http_clientc               8    V ^8  d   QhRRRRRRRRRRRR	R
RRR/# )r5   resourcer'   rN   
str | NonerO   rP   rQ   rR   floatrT   httpx2.Client | Noner6   r   r   )r7   s   "r$   r8   r8   g   sZ     99 9999 99 	99
 99 99 99 &99 99r#   c               :   a aaaaaa R VVVVVV V3R llpRRRV/# )ac  
Get a subject token provider for Azure Managed Identities.

See: https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/how-to-use-vm-token#get-a-token-using-http

Args:
    resource: the resource URI to request a token for. Defaults to `https://management.azure.com/` (Azure Resource Manager).
    object_id: the object ID of the managed identity to use, when multiple are assigned.
    client_id: the client ID of the managed identity to use, when multiple are assigned.
    msi_res_id: the ARM resource ID of the managed identity to use, when multiple are assigned.
    api_version: the Azure IMDS API version. Defaults to `2018-02-01`.
    timeout: the request timeout in seconds. Defaults to 10.0.
    http_client: optional httpx2.Client instance to use for requests. If not provided, a new client will be created for each request.
c                   V ^8  d   QhRR/# rA   r   )r7   s   "r$   r8   ;azure_managed_identity_token_provider.<locals>.__annotate__   s     j js jr#   c            	     H  <  R p RSRS/pSe   SVR&   Se   SVR&   S
e   S
VR&   S	e   S	P                  WRR/SR	7      pM<\        P                  ! 4       ;_uu_ 4       pVP                  WRR/SR	7      pRRR4       XP                  '       d   \	        R
VP
                   2VR7      hVP                  4       pVP                  R4      pV'       g   \	        RVR7      h\        \        V4      #   + '       g   i     L; i  \         d   p\	        RT 24      ThRp?ii ; i)z5http://169.254.169.254/metadata/identity/oauth2/tokenzapi-versionrV   NrN   rO   rP   MetadatatrueparamsheadersrR   z4Failed to fetch Azure subject token from IMDS: HTTP responseaccess_tokenz3Azure IMDS response did not include an access_tokenz/Failed to fetch Azure subject token from IMDS: )
gethttpx2Clientis_errorr   status_codejsonr	   r'   rH   )urlra   rd   clientdatarJ   rK   rQ   rO   rT   rP   rN   rV   rR   s          r$   r   8azure_managed_identity_token_provider.<locals>.get_token   s<   	jIC&3[*h%WF$&/{#$&/{#%'1|$&&??3
TZG[el?m]]__%zz#zSYFZdkzlH %    /J8K_K_J`a%  ==?DHH^,E/IT\  U## %_  	j+.]^_]`,abhii	js=   AD C/5D AD D /C?	:D D!DD!r   r   r   r   )rV   rN   rO   rP   rQ   rR   rT   r   s   fdddddd r$   %azure_managed_identity_token_providerrp   g   s!    2j j@ %i88r#   c               (    V ^8  d   QhRRRRRRRR/# )	r5   audiencer'   rR   rX   rT   rY   r6   r   r   )r7   s   "r$   r8   r8      s2     )8 )8)8 )8 &	)8
 )8r#   c               *   a aa R V VV3R llpRRRV/# )a  
Get a subject token provider for GCP VM instances using the instance metadata server.

See: https://cloud.google.com/compute/docs/instances/verifying-instance-identity

Args:
    audience: the unique URI agreed upon by both the instance and the system verifying
        the instance's identity. Defaults to `https://api.openai.com/v1`.
    timeout: the request timeout in seconds. Defaults to 10.0.
    http_client: optional httpx2.Client instance to use for requests. If not provided, a new client will be created for each request.
c                   V ^8  d   QhRR/# rA   r   )r7   s   "r$   r8   +gcp_id_token_provider.<locals>.__annotate__   s     s ss sr#   c            	       <  R p RS/pSe   SP                  WRR/SR7      pM<\        P                  ! 4       ;_uu_ 4       pVP                  WRR/SR7      pRRR4       XP                  '       d   \	        RVP
                   2VR7      hVP                  P                  4       pV'       g   \	        RVR7      hV#   + '       g   i     Lm; i  \         d   p\	        R	T 24      ThRp?ii ; i)
z]http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/identityrr   NzMetadata-FlavorGoogler`   z=Failed to fetch GCP subject token from metadata server: HTTP rc   z+GCP metadata server returned an empty tokenz8Failed to fetch GCP subject token from metadata server: )	rf   rg   rh   ri   r   rj   textrG   rH   )	rl   ra   rd   rm   rJ   rK   rr   rT   rR   s	         r$   r   (gcp_id_token_provider.<locals>.get_token   s    	sqC (+F&&??3HY[cGdnu?v]]__%zz#GXZbFcmtzuH %    /ST\ThThSij%  MM'')E/0]hpqqL %_  	s+.fghfi,jkqrr	ss;   >C B=C 2;C .C =C	C C/C**C/r   r   r   r   )rr   rR   rT   r   s   fdd r$   gcp_id_token_providerrz      s     $s s. $Y77r#   c                      ] tR t^tR]RR/R R lltR R ltR R	 ltR$R R lltR R lt	R R lt
R R ltR R ltR R ltR R ltR R ltR R ltR R ltR R  ltR! R" ltR#tR
# )%_WorkloadIdentityAuthtoken_exchange_url_use_httpx2Tc               (    V ^8  d   QhRRRRRRRR/# )	r5   workload_identityr3   r}   r'   r~   boolr6   Noner   )r7   s   "r$   r8   "_WorkloadIdentityAuth.__annotate__   s4     : : .:  	:
 : 
:r#   c               	    Wn         W n        W0n        R V n        R V n        R V n        R V n        RV n        \        P                  ! 4       V n
        \        P                  ! V P                  4      V n        R # NF)r   r}   r~   _follow_redirects_cached_token"_cached_token_expires_at_monotonic"_cached_token_refresh_at_monotonic_refreshing	threadingLock_lock	Condition
_condition)selfr   r}   r~   s   &$$$r$   __init___WorkloadIdentityAuth.__init__   sc     6G"4&.2)-@D/@D/!&^^%
#--djj9r#   c                   V ^8  d   QhRR/# rA   r   )r7   s   "r$   r8   r      s     - -3 -r#   c           	     	   V P                   ;_uu_ 4        V P                  '       d3   V P                  4       '       d   V P                  P	                  4        KD  V P                  4       '       g;   V P                  4       '       g%   \        \        V P                  4      uuR R R 4       # V P                  '       dv   V P                  '       d   V P                  P	                  4        K.  V P                  pV P                  4       '       d   \        R4      h\        \        V4      uuR R R 4       # RV n        R R R 4        V P                  4        V P                   ;_uu_ 4        V P                  4       '       d   \        R4      h\        \        V P                  4      uuR R R 4       V P                   ;_uu_ 4        RV n        V P                  P                  4        R R R 4       #   + '       g   i     L; i  + '       g   i     # ; i  + '       g   i     M; i T P                   ;_uu_ 4        RT n        T P                  P                  4        R R R 4       R #   + '       g   i     R # ; i  T P                   ;_uu_ 4        RT n        T P                  P                  4        R R R 4       i   + '       g   i     i ; i; i)Nz)Token is unusable after refresh completedTF)r   r   _token_unusabler   wait_needs_refreshr	   r'   r   RuntimeError_perform_refresh
notify_allr   rJ   s   & r$   r   _WorkloadIdentityAuth.get_token   s   ZZZ"""t';';'='=$$&''))$2E2E2G2GC!3!34 Z &&&OO((***''))&'RSSC' Z  $D "		-!!#''))&'RSSC!3!34 
 #( **, 1 Z0  
 #( **, #( **, s   G)G)1G)0G)G)*G)<G)=G)G)1G)$I7 %;H 
I7 >"G<)G9	<HH	I7 7"I##I4	7K
"J7	.	K
7KK
c                   V ^8  d   QhRR/# rA   r   )r7   s   "r$   r8   r      s     / /s /r#   c                	H   "   \        V P                  4      G R j  xL
 #  L5iN)r   r   r   s   &r$   get_token_async%_WorkloadIdentityAuth.get_token_async   s     t~~....s   " "Nc                    V ^8  d   QhRRRR/# )r5   rJ   rW   r6   r   r   )r7   s   "r$   r8   r     s     ; ;j ;D ;r#   c                	    V P                   ;_uu_ 4        Ve   V P                  V8w  d    R R R 4       R # R V n        R V n        R V n        R R R 4       R #   + '       g   i     R # ; ir   )r   r   r   r   r   s   &&r$   invalidate_token&_WorkloadIdentityAuth.invalidate_token  sN    ZZZ T%7%75%@ Z "&D6:D36:D3 ZZZs   AAA&	c                   V ^8  d   QhRR/# )r5   r6   r   r   )r7   s   "r$   r8   r     s     & &$ &r#   c                	H    V P                  4       pV P                  V4       R # r   )_fetch_token_from_exchange_store_token)r   
token_datas   & r$   r   &_WorkloadIdentityAuth._perform_refresh  s    446
*%r#   c                    V ^8  d   QhRRRR/# )r5   r   dict[str, Any]r6   r   r   )r7   s   "r$   r8   r     s     d d~ d$ dr#   c                	   \         P                  ! 4       pVR ,          pV P                  ;_uu_ 4        VR,          V n        W#,           V n        W P                  V4      ,           V n        RRR4       R#   + '       g   i     R# ; i)
expires_inre   N)time	monotonicr   r   r   _refresh_delay_secondsr   )r   r   nowr   s   &&  r$   r   "_WorkloadIdentityAuth._store_token  s\    nn-
ZZZ!+N!;D696FD369<W<WXb<c6cD3 ZZZs   8A55B	c                   V ^8  d   QhRR/# r5   r6   r   r   )r7   s   "r$   r8   r     s     d dN dr#   c                	    \        R 4      h)z>Workload identity authentication must implement token exchange)NotImplementedErrorr   s   &r$   r   0_WorkloadIdentityAuth._fetch_token_from_exchange  s    !"bccr#   c                    V ^8  d   QhRRRR/# )r5   rd   zhttpx2.Responser6   r   r   )r7   s   "r$   r8   r     s     
 
 
> 
r#   c                	    VP                   '       d   VP                  4       MR pVP                  R9   d   \	        WR7      hVP
                  '       d   Vf   \        R4      h\        V4      '       g   \        R4      hVP                  R4      pVP                  R4      p\        V\        4      '       d	   V'       g   \        R4      hRVRV P                  V4      /# \        RVP                   24      h  \         d    R p Li ; i)	N)rd   bodyz4Token exchange succeeded but response body was emptyz@Token exchange succeeded but response body was not a JSON objectre   r   z<Token exchange response did not include a valid access_tokenz"Token exchange failed with status )i  i  i  )contentrk   
ValueErrorrj   r   
is_successr   r   rf   
isinstancer'   _validate_expires_in)r   rd   r   re   r   s   &&   r$   _handle_token_response,_WorkloadIdentityAuth._handle_token_response  s    	&.&6&6&68==?DD ?2h::|!"XYY4==!"dee88N3L,/JlC00!"`aa"L,@Y@YZd@eff01E1E0FG
 	
#  	D	s   C8 C8 8DDc                    V ^8  d   QhRRRR/# )r5   r   objectr6   rX   r   )r7   s   "r$   r8   r   3  s     ! !v !% !r#   c                	f    \        V\        \        34      '       g   \        R 4      h\        V4      # )z:Token exchange response did not include a valid expires_in)r   intrX   r   )r   r   s   &&r$   r   *_WorkloadIdentityAuth._validate_expires_in3  s*    *sEl33Z[[Z  r#   c                   V ^8  d   QhRR/# r5   r6   r   r   )r7   s   "r$   r8   r   8  s     C C Cr#   c                	N    V P                   R J ;'       g    V P                  4       # r   )r   _token_expiredr   s   &r$   r   %_WorkloadIdentityAuth._token_unusable8  s$    !!T)BBT-@-@-BBr#   c                   V ^8  d   QhRR/# r   r   )r7   s   "r$   r8   r   ;       K K Kr#   c                	f    V P                   f   R# \        P                  ! 4       V P                   8  # )NT)r   r   r   r   s   &r$   r   $_WorkloadIdentityAuth._token_expired;  s)    22:~~4#J#JJJr#   c                   V ^8  d   QhRR/# r   r   )r7   s   "r$   r8   r   @  r   r#   c                	f    V P                   f   R# \        P                  ! 4       V P                   8  # r   )r   r   r   r   s   &r$   r   $_WorkloadIdentityAuth._needs_refresh@  s)    22:~~4#J#JJJr#   c                    V ^8  d   QhRRRR/# )r5   r   rX   r6   r   )r7   s   "r$   r8   r   E  s     7 7 75 7r#   c                	    V P                   P                  R \        4      p\        W!^,          4      p\	        W,
          R4      # )r,   g        )r   rf   DEFAULT_REFRESH_BUFFER_SECONDSminmax)r   r   configured_buffereffective_buffers   &&  r$   r   ,_WorkloadIdentityAuth._refresh_delay_secondsE  s=     22667OQop0q.A:0#66r#   c                    V ^8  d   QhRRRR/# )r5   requesthttpx2.Requestr6   r   r   )r7   s   "r$   r8   r   J  s      . T r#   c                    ?R# )>Preserve the established subject-token request retry behavior.Tr   r   r   s   &&r$   _can_retry_request(_WorkloadIdentityAuth._can_retry_requestJ  s    r#   c                    V ^8  d   QhRRRR/# )r5   r   r   r6   r   r   )r7   s   "r$   r8   r   O  s      n  r#   c                    ?R# )r   Nr   r   s   &&r$   _prepare_retry_request,_WorkloadIdentityAuth._prepare_retry_requestO  s    r#   )
r   r   r   r   r   r   r   r~   r}   r   r   )r   r   r   r    DEFAULT_TOKEN_EXCHANGE_URLr   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r"   r   r#   r$   r|   r|      sk    : #=	:
 !:&-:/;&dd
0!
CK
K
7

 r#   r|   c                  \   a  ] tR tRtR]RR/R V 3R lllt]R R l4       tR	 R
 ltRt	V ;t
# )WorkloadIdentityAuthiT  r}   r~   Tc               (    V ^8  d   QhRRRRRRRR/# )	r5   r   r&   r}   r'   r~   r   r6   r   r   )r7   s   "r$   r8   !WorkloadIdentityAuth.__annotate__U  s4     
 
 ,
  	

 
 

r#   c               	,   < \         SV `  VVVR 7       R# ))r   r}   r~   N)superr   )r   r   r}   r~   	__class__s   &$$$r$   r   WorkloadIdentityAuth.__init__U  s      	/1# 	 	
r#   c                   V ^8  d   QhRR/# r   r   )r7   s   "r$   r8   r   c  s     9 9N 9r#   c                	z   V P                  4       pV P                  R ,          R,          p\        P                  V4      pVf4   \	        RV: RRP                  \        P                  4       4       24      hV P                  '       g   \        4       MRpVe   VP                  4       M\        RR7      pV;_uu_ 4       pVP                  V P                  R\        R	VR
VRV P                  R,          RV P                  R,          /RR7      pV P                  V4      uuRRR4       #   + '       g   i     R# ; i)r*   r   NzUnsupported token type: z. Supported types: z, F)follow_redirects
grant_typesubject_tokensubject_token_typer(   r)   rS   )rk   rR   )_get_subject_tokenr   SUBJECT_TOKEN_TYPESrf   r   joinkeysr~   r   rh   r   postr}   TOKEN_EXCHANGE_GRANT_TYPEr   )r   r   r   r   legacy_httpxexchange_clientrm   rd   s   &       r$   r   /WorkloadIdentityAuth._fetch_token_from_exchangeb  s#   //1++J7E
044Z@%*:.8KDIIViVnVnVpLqKrs  6:5E5E5E+-4%1%=L!CVhmCn 	 _{{'' ";#](*<*D,B,BCY,Z($*@*@AU*V  # 
H ..x8 ___s   ?AD))D:	c                   V ^8  d   QhRR/# rA   r   )r7   s   "r$   r8   r   ~  s      C r#   c                	n    V P                   R ,          pVR,          ! 4       pV'       g   \        R4      hV# )r*   r   z>The workload identity provider returned an empty subject token)r   r   )r   r*   r   s   &  r$   r   'WorkloadIdentityAuth._get_subject_token~  s4    ))*5 -/^__r#   r   )r   r   r   r    r   r   r   r   r   r"   __classcell__)r   s   @r$   r   r   T  s?    
 #=	

 !
 
 9 96 r#   r   )z3/var/run/secrets/kubernetes.io/serviceaccount/token)zhttps://management.azure.com/)zhttps://api.openai.com/v1)/__conditional_annotations__
__future__r   r   r   typingr   r   r   r   r   r	   pathlibr
   typing_extensionsr   r   r   r   rg   _utilsr   _httpx2r   r   _exceptionsr   r   r   _utils._syncr   r   r   r   r   r   r&   r/   r!   r1   r3   r<   rM   rp   rz   r|   r   )r  s   @r$   <module>r     sB   " "   C C  G G   ? L L $M B !%  
1
5 !9 !
/y / +; i :/9 / 13CEYZ  ,0	"9299 !99 !	99
 "99 $99 99 )-99 99x)8 )8 )-	)8 )8XBG$67 BJ/01AB /r#   