Ë
    £…jà  ã                   óÎ   — d dl Z d dlZd dlmZmZmZmZ d dlmZm	Z	m
Z
 d dlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ ddlmZ ddlmZ  e j2                  e«      Z G d„ de«      Zy)é    N)ÚOptionalÚUnionÚAnyÚcast)ÚAccessTokenÚAccessTokenInfoÚTokenRequestOptions)ÚAsyncSupportsTokenInfoé   )Úlog_get_token_asyncé   )ÚCredentialUnavailableError)ÚEnvironmentVariables)ÚAsyncContextManageré   )ÚCertificateCredential)ÚClientSecretCredentialc                   ó”   — e Zd ZdZdeddfd„Zdd„Zdd„Zedddœd	e	d
e
e	   de
e	   dedef
d„«       Zeddœd	e	de
e   defd„«       Zy)ÚEnvironmentCredentiala¹  A credential configured by environment variables.

    This credential is capable of authenticating as a service principal using a client secret or a certificate.
    Configuration is attempted in this order, using these environment variables:

    Service principal with secret:
      - **AZURE_TENANT_ID**: ID of the service principal's tenant. Also called its 'directory' ID.
      - **AZURE_CLIENT_ID**: the service principal's client ID
      - **AZURE_CLIENT_SECRET**: one of the service principal's client secrets
      - **AZURE_AUTHORITY_HOST**: authority of a Microsoft Entra endpoint, for example
        "login.microsoftonline.com", the authority for Azure Public Cloud, which is the default
        when no value is given.

    Service principal with certificate:
      - **AZURE_TENANT_ID**: ID of the service principal's tenant. Also called its 'directory' ID.
      - **AZURE_CLIENT_ID**: the service principal's client ID
      - **AZURE_CLIENT_CERTIFICATE_PATH**: path to a PEM or PKCS12 certificate file including the private key.
      - **AZURE_CLIENT_CERTIFICATE_PASSWORD**: (optional) password of the certificate file, if any.
      - **AZURE_AUTHORITY_HOST**: authority of a Microsoft Entra endpoint, for example
        "login.microsoftonline.com", the authority for Azure Public Cloud, which is the default
        when no value is given.

    .. admonition:: Example:

        .. literalinclude:: ../samples/credential_creation_code_snippets.py
            :start-after: [START create_environment_credential_async]
            :end-before: [END create_environment_credential_async]
            :language: python
            :dedent: 4
            :caption: Create an EnvironmentCredential.
    ÚkwargsÚreturnNc                 ó  — d | _         t        d„ t        j                  D «       «      rrt	        dt
        j                  t        j                     t
        j                  t        j                     t
        j                  t        j                     dœ|¤Ž| _         nót        d„ t        j                  D «       «      rÓt        dt
        j                  t        j                     t
        j                  t        j                     t
        j                  t        j                     t
        j                  j                  t        j                  «      t        t
        j                  j                  t        j                   d«      «      dœ|¤Ž| _         | j                   r5t"        j%                  d| j                   j&                  j(                  «       y t+        t        j                  t        j                  z   «      }|D �cg c]  }|t
        j                  v sŒ|‘Œ }}|rVt"        j-                  |j                  d«      rt.        j0                  nt.        j2                  dd	j5                  |«      «       y t"        j%                  d
«       y c c}w )Nc              3   ó^   K  — | ]%  }t         j                  j                  |«      d u–— Œ' y ­w©N©ÚosÚenvironÚget©Ú.0Úvs     úl/root/aria/tools/markitdown-venv/lib/python3.12/site-packages/azure/identity/aio/_credentials/environment.pyú	<genexpr>z1EnvironmentCredential.__init__.<locals>.<genexpr>9   s"   è ø€ Ò^°Œr�z‰z�~‰~˜aÓ ¨Ô,Ñ^ùó   ‚+-)Ú	client_idÚclient_secretÚ	tenant_idc              3   ó^   K  — | ]%  }t         j                  j                  |«      d u–— Œ' y ­wr   r   r   s     r"   r#   z1EnvironmentCredential.__init__.<locals>.<genexpr>@   s"   è ø€ ÒW°1”—‘—‘ Ó"¨$Ô.ÑWùr$   F)r%   r'   Úcertificate_pathÚpasswordÚsend_certificate_chainz Environment is configured for %sÚ_within_dacz[Incomplete environment configuration for EnvironmentCredential. These variables are set: %sz, z#No environment configuration found.© )Ú_credentialÚallr   ÚCLIENT_SECRET_VARSr   r   r   ÚAZURE_CLIENT_IDÚAZURE_CLIENT_SECRETÚAZURE_TENANT_IDÚ	CERT_VARSr   ÚAZURE_CLIENT_CERTIFICATE_PATHr   Ú!AZURE_CLIENT_CERTIFICATE_PASSWORDÚboolÚ#AZURE_CLIENT_SEND_CERTIFICATE_CHAINÚ_LOGGERÚinfoÚ	__class__Ú__name__ÚsetÚlogÚloggingÚINFOÚWARNINGÚjoin)Úselfr   Úexpected_variablesr!   Úset_variabless        r"   Ú__init__zEnvironmentCredential.__init__6   sË  € Ø[_ˆÔäÑ^Ô6J×6]Ñ6]Ô^Ô^Ü5ð  ÜŸ*™*Ô%9×%IÑ%IÑJÜ Ÿj™jÔ)=×)QÑ)QÑRÜŸ*™*Ô%9×%IÑ%IÑJñ ð ñ	 ˆDÕô ÑWÔ8L×8VÑ8VÔWÔWÜ4ð 	 ÜŸ*™*Ô%9×%IÑ%IÑJÜŸ*™*Ô%9×%IÑ%IÑJÜ!#§¡Ô,@×,^Ñ,^Ñ!_ÜŸ™Ÿ™Ô(<×(^Ñ(^Ó_Ü'+Ü—J‘J—N‘NÔ#7×#[Ñ#[Ð]bÓcó(ñ	 ð ñ	 ˆDÔð ×ÒÜ�L‰LÐ;¸T×=MÑ=M×=WÑ=W×=`Ñ=`Õaä!$Ô%9×%CÑ%CÔFZ×FmÑFmÑ%mÓ!nÐØ(:ÖN 1¸aÄ2Ç:Á:ºošQÐNˆMÐNÙÜ—‘Ø$*§J¡J¨}Ô$=”G—L’LÄ7Ç?Á?ØqØ—I‘I˜mÓ,õô —‘ÐBÕCùò Os   Ç<JÈJc              ƒ   ón   K  — | j                   r"| j                   j                  «       ƒ d {  –—†  | S 7 Œ­wr   )r.   Ú
__aenter__©rC   s    r"   rH   z EnvironmentCredential.__aenter__Z   s1   è ø€ Ø×ÒØ×"Ñ"×-Ñ-Ó/×/Ð/Øˆð 0úó   ‚*5¬3­5c              ƒ   ón   K  — | j                   r#| j                   j                  «       ƒ d{  –—†  yy7 Œ­w)z)Close the credential's transport session.N)r.   Ú	__aexit__rI   s    r"   ÚclosezEnvironmentCredential.close_   s1   è ø€ ð ×ÒØ×"Ñ"×,Ñ,Ó.×.Ñ.ð Ø.úrJ   ©Úclaimsr'   ÚscopesrO   r'   c             �   ó�   K  — | j                   sd}t        |¬«      ‚ | j                   j                  |||dœ|¤Žƒ d{  –—† S 7 Œ­w)aN  Asynchronously request an access token for `scopes`.

        This method is called automatically by Azure SDK clients.

        :param str scopes: desired scopes for the access token. This method requires at least one scope.
            For more information about scopes, see
            https://learn.microsoft.com/entra/identity-platform/scopes-oidc.
        :keyword str claims: additional claims required in the token, such as those returned in a resource provider's
            claims challenge following an authorization failure.
        :keyword str tenant_id: optional tenant to include in the token request.

        :return: An access token with the desired scopes.
        :rtype: ~azure.core.credentials.AccessToken
        :raises ~azure.identity.CredentialUnavailableError: environment variable configuration is incomplete
        úËEnvironmentCredential authentication unavailable. Environment variables are not fully configured.
Visit https://aka.ms/azsdk/python/identity/environmentcredential/troubleshoot to troubleshoot this issue.©ÚmessagerN   N)r.   r   Ú	get_token)rC   rO   r'   rP   r   rT   s         r"   rU   zEnvironmentCredential.get_tokene   sR   è ø€ ð& ×Òðð ô
 -°WÔ=Ð=Ø/�T×%Ñ%×/Ñ/°ÀÐR[ÑfÐ_eÑf×fÐfÐfús   ‚=A¿AÁ A)ÚoptionsrV   c             ‡   ó¦   K  — | j                   sd}t        |¬«      ‚ t        t        | j                   «      j                  |d|iŽƒ d{  –—† S 7 Œ­w)a‚  Request an access token for `scopes`.

        This is an alternative to `get_token` to enable certain scenarios that require additional properties
        on the token. This method is called automatically by Azure SDK clients.

        :param str scopes: desired scope for the access token. This method requires at least one scope.
            For more information about scopes, see https://learn.microsoft.com/entra/identity-platform/scopes-oidc.
        :keyword options: A dictionary of options for the token request. Unknown options will be ignored. Optional.
        :paramtype options: ~azure.core.credentials.TokenRequestOptions

        :rtype: ~azure.core.credentials.AccessTokenInfo
        :return: An AccessTokenInfo instance containing information about the token.

        :raises ~azure.identity.CredentialUnavailableError: environment variable configuration is incomplete.
        rR   rS   rV   N)r.   r   r   r
   Úget_token_info)rC   rV   rP   rT   s       r"   rX   z$EnvironmentCredential.get_token_info�   sV   è ø€ ð" ×Òðð ô
 -°WÔ=Ð=ØR”TÔ0°$×2BÑ2BÓC×RÑRÐTZÐlÐdkÑl×lÐlÐlús   ‚AAÁ
AÁA)r   r   )r   N)r<   Ú
__module__Ú__qualname__Ú__doc__r   rF   rH   rM   r   Ústrr   r   rU   r	   r   rX   r-   ó    r"   r   r      s²   „ ñð@"D ð "D¨ó "DóHó
/ð à48ÐUYògØðgØ$,¨S¡MðgØEMÈcÁ]ðgØehðgà	ògó ðgð6 ØZ^ò m¨Cð m¸(ÐCVÑ:Wð mÐcrò mó ñmr]   r   )r?   r   Útypingr   r   r   r   Úazure.core.credentialsr   r   r	   Úazure.core.credentials_asyncr
   Ú_internal.decoratorsr   Ú r   Ú
_constantsr   Ú	_internalr   Úcertificater   r&   r   Ú	getLoggerr<   r9   r   r-   r]   r"   ú<module>rg      sQ   ðó
 Û 	ß -Ó -ç TÑ TÝ ?Ý 6Ý *Ý .Ý +Ý .Ý 1à
ˆ'×
Ñ
˜HÓ
%€ôDmÐ/õ Dmr]   