Ë
    £…jCE  ã                   ó:  — d dl Z d dlZd dlmZmZmZmZ d dlmZm	Z	m
Z
 d dlmZmZ ddlmZ ddlmZ ddlmZmZmZmZ d	d
lmZ d	dlmZ d	dlmZ d	dlmZ d	dlm Z  d	dl!m"Z" d	dl#m$Z$ d	dl%m&Z& d	dl'm(Z(  e jR                  e*«      Z+ G d„ d«      Z, G d„ de«      Z-y)é    N)ÚListÚOptionalÚAnyÚcast)ÚAccessTokenÚAccessTokenInfoÚTokenRequestOptions)ÚAsyncTokenCredentialÚAsyncSupportsTokenInfoé   )ÚCredentialUnavailableError)ÚEnvironmentVariables)Úget_default_authorityÚnormalize_authorityÚ
within_dacÚprocess_credential_exclusionsé   )ÚAzureCliCredential)ÚAzureDeveloperCliCredential)ÚAzurePowerShellCredential)ÚChainedTokenCredential)ÚEnvironmentCredential)ÚManagedIdentityCredential)ÚSharedTokenCacheCredential)ÚVisualStudioCodeCredential)ÚWorkloadIdentityCredentialc                   ó|   — e Zd ZdZdededdfd„Zdededefd	„Zdd
œde	e
   dedefd„Zdededdfd„Zdd„Zdd„Zy)ÚAsyncFailedDACCredentialz´Async version of FailedDACCredential for use in async credential chains.

    This acts as a substitute for an async credential that has failed to initialize in the DAC chain.
    Úcredential_nameÚerrorÚreturnNc                 ó    — || _         || _        y ©N)Ú_errorÚ_credential_name)Úselfr   r    s      úh/root/aria/tools/markitdown-venv/lib/python3.12/site-packages/azure/identity/aio/_credentials/default.pyÚ__init__z!AsyncFailedDACCredential.__init__"   s   € ØˆŒØ /ˆÕó    ÚscopesÚkwargsc              �   ó4   K  — t        | j                  «      ‚­wr#   ©r   r$   )r&   r*   r+   s      r'   Ú	get_tokenz"AsyncFailedDACCredential.get_token&   s   è ø€ Ü(¨¯©Ó5Ð5ùó   ‚©Úoptionsr1   c             �   ó4   K  — t        | j                  «      ‚­wr#   r-   )r&   r1   r*   r+   s       r'   Úget_token_infoz'AsyncFailedDACCredential.get_token_info)   s   è ø€ ô )¨¯©Ó5Ð5ùr/   Úargsc              �   ó   K  — y ­wr#   © )r&   r4   r+   s      r'   Ú	__aexit__z"AsyncFailedDACCredential.__aexit__.   ó	   è ø€ Øùó   ‚c              ƒ   ó   K  — | S ­wr#   r6   ©r&   s    r'   Ú
__aenter__z#AsyncFailedDACCredential.__aenter__1   s   è ø€ Øˆùs   ‚c              ƒ   ó   K  — y ­wr#   r6   r;   s    r'   ÚclosezAsyncFailedDACCredential.close4   r8   r9   )r!   r   )r!   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ústrr(   r   r   r.   r   r	   r   r3   r7   r<   r>   r6   r)   r'   r   r      s‰   „ ñð
0¨ð 0°Cð 0¸Dó 0ð6 sð 6°cð 6¸kó 6ð AEò6Ø (Ð)<Ñ =ð6ØPSð6à	ó6ð
 Sð °Cð ¸Dó óôr)   r   c                   ó„   ‡ — e Zd ZdZdeddfˆ fd„Zdddœdedee   d	ee   dedef
ˆ fd
„Z	ddœdedee
   defˆ fd„Zˆ xZS )ÚDefaultAzureCredentialat  A credential capable of handling most Azure SDK authentication scenarios. See
    https://aka.ms/azsdk/python/identity/credential-chains#usage-guidance-for-defaultazurecredential.

    The identity it uses depends on the environment. When an access token is needed, it requests one using these
    identities in turn, stopping when one provides a token:

    1. A service principal configured by environment variables. See :class:`~azure.identity.aio.EnvironmentCredential`
       for more details.
    2. WorkloadIdentityCredential if environment variable configuration is set by the Azure workload
       identity webhook.
    3. An Azure managed identity. See :class:`~azure.identity.aio.ManagedIdentityCredential` for more details.
    4. On Windows only: a user who has signed in with a Microsoft application, such as Visual Studio. If multiple
       identities are in the cache, then the value of  the environment variable ``AZURE_USERNAME`` is used to select
       which identity to use. See :class:`~azure.identity.aio.SharedTokenCacheCredential` for more details.
    5. The identity logged in to Visual Studio Code with the Azure Resources extension.
    6. The identity currently logged in to the Azure CLI.
    7. The identity currently logged in to Azure PowerShell.
    8. The identity currently logged in to the Azure Developer CLI.
    9. Brokered authentication. On Windows and WSL only, this uses the default account logged in via
       Web Account Manager (WAM) if the `azure-identity-broker` package is installed.

    This default behavior is configurable with keyword arguments.

    :keyword str authority: Authority of a Microsoft Entra endpoint, for example 'login.microsoftonline.com',
        the authority for Azure Public Cloud (which is the default). :class:`~azure.identity.AzureAuthorityHosts`
        defines authorities for other clouds. Managed identities ignore this because they reside in a single cloud.
    :keyword bool exclude_workload_identity_credential: Whether to exclude the workload identity from the credential.
        Defaults to **False**.
    :keyword bool exclude_developer_cli_credential: Whether to exclude the Azure Developer CLI
        from the credential. Defaults to **False**.
    :keyword bool exclude_cli_credential: Whether to exclude the Azure CLI from the credential. Defaults to **False**.
    :keyword bool exclude_environment_credential: Whether to exclude a service principal configured by environment
        variables from the credential. Defaults to **False**.
    :keyword bool exclude_powershell_credential: Whether to exclude Azure PowerShell. Defaults to **False**.
    :keyword bool exclude_visual_studio_code_credential: Whether to exclude stored credential from VS Code.
        Defaults to **False**.
    :keyword bool exclude_managed_identity_credential: Whether to exclude managed identity from the credential.
        Defaults to **False**.
    :keyword bool exclude_shared_token_cache_credential: Whether to exclude the shared token cache. Defaults to
        **False**.
    :keyword str managed_identity_client_id: The client ID of a user-assigned managed identity. Defaults to the value
        of the environment variable AZURE_CLIENT_ID, if any. If not specified, a system-assigned identity will be used.
    :keyword str workload_identity_client_id: The client ID of an identity assigned to the pod. Defaults to the value
        of the environment variable AZURE_CLIENT_ID, if any. If not specified, the pod's default identity will be used.
    :keyword str workload_identity_tenant_id: Preferred tenant for :class:`~azure.identity.WorkloadIdentityCredential`.
        Defaults to the value of environment variable AZURE_TENANT_ID, if any.
    :keyword str shared_cache_username: Preferred username for :class:`~azure.identity.aio.SharedTokenCacheCredential`.
        Defaults to the value of environment variable AZURE_USERNAME, if any.
    :keyword str shared_cache_tenant_id: Preferred tenant for :class:`~azure.identity.aio.SharedTokenCacheCredential`.
        Defaults to the value of environment variable AZURE_TENANT_ID, if any.
    :keyword str visual_studio_code_tenant_id: Tenant ID to use when authenticating with
        :class:`~azure.identity.VisualStudioCodeCredential`. Defaults to the tenant specified in the authentication
        record file used by the Azure Resources extension.
    :keyword int process_timeout: The timeout in seconds to use for developer credentials that run
        subprocesses (e.g. AzureCliCredential, AzurePowerShellCredential). Defaults to **10** seconds.
    :keyword bool require_envvar: If **True**, require that the AZURE_TOKEN_CREDENTIALS environment variable be set
        to a value denoting the credential type or credential group to use. If unset or empty, DefaultAzureCredential
        will raise a `ValueError`. Defaults to **False**.

    .. admonition:: Example:

        .. literalinclude:: ../samples/credential_creation_code_snippets.py
            :start-after: [START create_default_credential_async]
            :end-before: [END create_default_credential_async]
            :language: python
            :dedent: 4
            :caption: Create a DefaultAzureCredential.
    r+   r!   Nc                 ój  •— d|v rt        d«      ‚|j                  dd «      }|rt        |«      n	t        «       }|j                  dd «      }|j                  dt        j
                  j                  t        j                  «      «      }|j                  dt        j
                  j                  t        j                  «      «      }|j                  dt        j
                  j                  t        j                  «      «      }|j                  d|«      }|j                  d	t        j
                  j                  t        j                  «      «      }|j                  d
d«      }	|j                  dd«      }
t        j
                  j                  t        j                  d«      j                  «       j                  «       }|
r|st        d«      ‚ddddœddddœddddœdddœddddœddddœddddœdd ddœd!œ}i }i }|j                  «       D ]5  \  }}t!        t"        |d"   «      }|j                  |d «      ||<   |d#   ||<   Œ7 t%        |||«      }|d$   }|d%   }|d&   }|d'   }|d(   }|d)   }|d*   }|d+   }g }t'        j(                  d,«       |s|j+                  t-        d5|d,d-œ|¤Ž«       |sX	 |j+                  t/        d5t!        t"        |«      |t        j
                  j                  t        j0                  «      d.œ|¤Ž«       |s!|j+                  t5        d5|||dk7  d1œ|¤Ž«       |s4t7        j8                  «       r t7        d5|||d2œ|¤Ž}|j+                  |«       |s|j+                  t;        |¬3«      «       |s|j+                  t=        |	¬4«      «       |s|j+                  t?        |	¬4«      «       |s|j+                  tA        |	¬4«      «       t'        j(                  d«       tC        ‰| �ˆ  |Ž  y # t        $ r0}|j+                  t3        d/t#        |«      ¬0«      «       Y d }~�Œ#d }~ww xY w)6NÚ	tenant_idz7'tenant_id' is not supported in DefaultAzureCredential.Ú	authorityÚvisual_studio_code_tenant_idÚshared_cache_usernameÚshared_cache_tenant_idÚmanaged_identity_client_idÚworkload_identity_client_idÚworkload_identity_tenant_idÚprocess_timeouté
   Úrequire_envvarFÚ zŒAZURE_TOKEN_CREDENTIALS environment variable is required but is not set or is empty. Set it to 'dev', 'prod', or a specific credential name.Úexclude_environment_credentialÚenvironmentcredential)Úexclude_paramÚenv_nameÚdefault_excludeÚ$exclude_workload_identity_credentialÚworkloadidentitycredentialÚ#exclude_managed_identity_credentialÚmanagedidentitycredentialÚ%exclude_shared_token_cache_credential)rU   rW   Ú%exclude_visual_studio_code_credentialÚvisualstudiocodecredentialÚexclude_cli_credentialÚazureclicredentialÚ exclude_developer_cli_credentialÚazuredeveloperclicredentialÚexclude_powershell_credentialÚazurepowershellcredential)ÚenvironmentÚworkload_identityÚmanaged_identityÚshared_token_cacheÚvisual_studio_codeÚcliÚdeveloper_cliÚ
powershellrU   rW   re   rf   rg   rh   ri   rj   rk   rl   T)rH   Ú_within_dac)Ú	client_idrG   Útoken_file_pathr   )r    )rn   Ú%_exclude_workload_identity_credentialÚ_enable_imds_probe)ÚusernamerG   rH   )rG   )rO   r6   )#Ú	TypeErrorÚpopr   r   ÚosÚenvironÚgetr   ÚAZURE_USERNAMEÚAZURE_TENANT_IDÚAZURE_CLIENT_IDÚAZURE_TOKEN_CREDENTIALSÚstripÚlowerÚ
ValueErrorÚitemsr   rC   r   r   ÚsetÚappendr   r   ÚAZURE_FEDERATED_TOKEN_FILEr   r   r   Ú	supportedr   r   r   r   Úsuperr(   )r&   r+   rH   Úvscode_tenant_idrJ   rK   rL   rM   rN   rO   rQ   Útoken_credentials_envÚcredential_configÚexclude_flagsÚuser_excludesÚcred_keyÚconfigÚ
param_namerS   rX   rZ   r\   r]   r_   ra   rc   ÚcredentialsÚexÚshared_cacheÚ	__class__s                                €r'   r(   zDefaultAzureCredential.__init__~   sx  ø€ Ø˜&Ñ ÜÐUÓVÐVà—J‘J˜{¨DÓ1ˆ	Ù6?Ô'¨	Ô2ÔEZÓE\ˆ	à!Ÿ:™:Ð&DÀdÓKÐà &§
¡
Ð+BÄBÇJÁJÇNÁNÔSg×SvÑSvÓDwÓ xÐØ!'§¡Ø$¤b§j¡j§n¡nÔ5I×5YÑ5YÓ&Zó"
Ðð &,§Z¡ZØ(¬"¯*©*¯.©.Ô9M×9]Ñ9]Ó*^ó&
Ð"ð '-§j¡jÐ1NÐPjÓ&kÐ#Ø&,§j¡jØ)¬2¯:©:¯>©>Ô:N×:^Ñ:^Ó+_ó'
Ð#ð !Ÿ*™*Ð%6¸Ó;ˆØŸ™Ð$4°eÓ<ˆÜ "§
¡
§¡Ô/C×/[Ñ/[Ð]_Ó `× fÑ fÓ h× nÑ nÓ pÐÙÑ"7ÜðJóð ð "BØ3Ø#(ñð "HØ8Ø#(ñ"ð "GØ7Ø#(ñ!ð "IØ#(ñ#ð
 "IØ8Ø#(ñ#ð ":Ø0Ø#(ñð "DØ9Ø#(ñð "AØ7Ø#(ññG(
ÐðV ˆØˆØ 1× 7Ñ 7Ó 9ò 	@ÑˆH�fÜœc 6¨/Ñ#:Ó;ˆJØ&,§j¡j°¸TÓ&BˆM˜(Ñ#Ø&,Ð->Ñ&?ˆM˜(Ò#ð	@ô 6Ð6GÈÐXeÓfˆð *7°}Ñ)EÐ&Ø/<Ð=PÑ/QÐ,Ø.;Ð<NÑ.OÐ+Ø0=Ð>RÑ0SÐ-Ø0=Ð>RÑ0SÐ-Ø!.¨uÑ!5ÐØ+8¸Ñ+IÐ(Ø(5°lÑ(CÐ%à46ˆÜ�‰�tÔÙ-Ø×ÑÔ4Ðe¸yÐVZÑeÐ^dÑeÔfÙ3ð
jØ×"Ñ"Ü.ð Ü"&¤sÐ,GÓ"HØ"=Ü(*¯
©
¯©Ô7K×7fÑ7fÓ(gñð !ñ	ôñ 3Ø×ÑÜ)ð Ø8Ø:^Ø'<Ð@[Ñ'[ñð ñ	ôñ 5Ô9S×9]Ñ9]Ô9_ä5ð Ø.Ð:PÐ\eñØioñˆLð ×Ñ˜|Ô,Ù4Ø×ÑÔ9ÐDTÔUÔVÙ%Ø×ÑÔ1À/ÔRÔSÙ,Ø×ÑÔ8ÈÔYÔZÙ/Ø×ÑÔ:È?Ô[Ô\Ü�‰�uÔÜ‰Ñ˜+Ò&øô5 ò jØ×"Ñ"Ô#;Ð<XÔ`cÐdfÓ`gÔ#h×iÒiûðjús   Ê3AO9 Ï9	P2Ð%P-Ð-P2©ÚclaimsrG   r*   r’   rG   c             �   óî  •K  — | j                   r€ t        t        | j                   «      j                  |||dœ|¤Žƒ d{  –—† }t        j                  d| j                  j                  | j                   j                  j                  «       |S t        j                  d«       	 t        ‰| �  |||dœ|¤Žƒ d{  –—† }t        j                  d«       |S 7 Œ–7 Œ# t        j                  d«       w xY w­w)a§  Asynchronously request an access token for `scopes`.

        This method is called automatically by Azure SDK clients.

        :param str scopes: desired scopes for the access token. This method requires at least one scope.
            For more information about scopes, see
            https://learn.microsoft.com/entra/identity-platform/scopes-oidc.
        :keyword str claims: additional claims required in the token, such as those returned in a resource provider's
            claims challenge following an authorization failure.
        :keyword str tenant_id: optional tenant to include in the token request.

        :return: An access token with the desired scopes.
        :rtype: ~azure.core.credentials.AccessToken
        :raises ~azure.core.exceptions.ClientAuthenticationError: authentication failed. The exception has a
          `message` attribute listing each authentication attempt and its error message.
        r‘   Nú%s acquired a token from %sTF)Ú_successful_credentialr   r
   r.   Ú_LOGGERÚinfor�   r?   r   r€   r„   )r&   r’   rG   r*   r+   Útokenr�   s         €r'   r.   z DefaultAzureCredential.get_token  sÕ   øè ø€ ð& ×&Ò&Ø[œ$Ô3°T×5PÑ5PÓQ×[Ñ[Ø °)ñØ?Eñ÷ ˆEô �L‰LØ-¨t¯~©~×/FÑ/FÈ×HcÑHc×HmÑHm×HvÑHvôð ˆLä�‰�tÔð	"Ü™'Ñ+¨V¸FÈiÑbÐ[aÑb×bˆEä�N‰N˜5Ô!Øˆðøð cùä�N‰N˜5Õ!üs<   ƒ=C5Á CÁA$C5Â&C Â;CÂ<C Ã C5ÃC ÃC2Ã2C5r0   r1   c             ‡   ó  •K  — | j                   r} t        t        | j                   «      j                  |d|iŽƒ d{  –—† }t        j                  d| j                  j                  | j                   j                  j                  «       |S t        j                  d«       	  t        t        t        «       «      j                  |d|iŽƒ d{  –—† }t        j                  d«       |S 7 Œ¬7 Œ# t        j                  d«       w xY w­w)aë  Asynchronously request an access token for `scopes`.

        This is an alternative to `get_token` to enable certain scenarios that require additional properties
        on the token. This method is called automatically by Azure SDK clients.

        :param str scopes: desired scopes for the access token. This method requires at least one scope.
            For more information about scopes, see https://learn.microsoft.com/entra/identity-platform/scopes-oidc.
        :keyword options: A dictionary of options for the token request. Unknown options will be ignored. Optional.
        :paramtype options: ~azure.core.credentials.TokenRequestOptions

        :rtype: ~azure.core.credentials.AccessTokenInfo
        :return: An AccessTokenInfo instance containing information about the token.

        :raises ~azure.core.exceptions.ClientAuthenticationError: authentication failed. The exception has a
           `message` attribute listing each authentication attempt and its error message.
        r1   Nr”   TF)r•   r   r   r3   r–   r—   r�   r?   r   r€   r„   )r&   r1   r*   Ú
token_infor�   s       €r'   r3   z%DefaultAzureCredential.get_token_info*  sÝ   øè ø€ ð" ×&Ò&ØgœtÔ$:¸D×<WÑ<WÓX×gÑgØð Ø!(ñ ÷ ˆJô �L‰LØ-¨t¯~©~×/FÑ/FÈ×HcÑHc×HmÑHm×HvÑHvôð Ðä�‰�tÔð	"ØSœtÔ$:¼E»GÓD×SÑSÐU[ÐmÐelÑm×mˆJä�N‰N˜5Ô!ØÐðøð nùä�N‰N˜5Õ!üs:   ƒ:D½C*¾A$DÂ#+C. ÃC,ÃC. ÃDÃ,C. Ã.DÄD)r?   r@   rA   rB   r   r(   rC   r   r   r.   r	   r   r3   Ú__classcell__)r�   s   @r'   rE   rE   8   sŒ   ø„ ñCðJG' ð G'¨õ G'ðT 59ÐUYò!Øð!Ø$,¨S¡Mð!ØEMÈcÁ]ð!Øehð!à	õ!ðF [_ò ¨Cð ¸(ÐCVÑ:Wð Ðcr÷ ñ r)   rE   ).Úloggingru   Útypingr   r   r   r   Úazure.core.credentialsr   r   r	   Úazure.core.credentials_asyncr
   r   rR   r   Ú
_constantsr   Ú	_internalr   r   r   r   Ú	azure_clir   Úazd_clir   Úazure_powershellr   Úchainedr   re   r   rg   r   r�   r   Úvscoder   rf   r   Ú	getLoggerr?   r–   r   rE   r6   r)   r'   ú<module>r¨      sp   ðó
 Û 	ß ,Ó ,ç TÑ Tß UÝ *Ý .ß nÓ nÝ )Ý 0Ý 7Ý +Ý .Ý 7Ý 4Ý .Ý 9ð ˆ'×
Ñ
˜HÓ
%€÷ñ ô8QÐ3õ Qr)   