Ë
    -Œ:jº  ã                   ó"  — d Z ddlZddlmZ ddlmZ ddlmZ ddlm	Z	m
Z
 dZd	Z G d
„ dee«      Zdedz  fd„Zdedefd„Zdddœdeez  dz  dedz  defd„Zddœdedededz  defd„Zdddddœdededz  deez  dz  dedz  dedz  defd„Zy)u™  Keyless CI/CD authentication via OIDC token exchange ("Trusted Publishers").

A CI job proves its identity to the Hub with a short-lived OIDC id token minted by its CI
provider (e.g. GitHub Actions), then exchanges it at ``POST {ENDPOINT}/oauth/token`` (RFC 8693)
for a short-lived Hugging Face token â€” no long-lived ``HF_TOKEN`` secret to store.

This module is self-contained: it only handles minting the provider id token and the exchange.
It deliberately does not register a public API or a CLI verb; the integration point is the token
resolution in ``utils/_auth.py`` (see ``_get_token_from_oidc``).

Docs: https://huggingface.co/docs/hub/trusted-publishers
é    N)ÚEnumé   )Ú	constants)Ú	OIDCError)Úget_sessionÚhf_raise_for_statusz/urn:ietf:params:oauth:grant-type:token-exchangez)urn:ietf:params:oauth:token-type:id_tokenc                   ó   — e Zd ZdZdZy)ÚProviderzRCI providers that can mint an OIDC id token natively. GitHub Actions only for now.ÚgithubN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚGITHUB© ó    úW/var/www/html/tokenscope/api/venv/lib/python3.12/site-packages/huggingface_hub/_oidc.pyr
   r
   (   s
   „ Ù\à�Fr   r
   Úreturnc                  óh   — t         j                  j                  d«      dk(  rt        j                  S y)zYDetect the CI provider able to mint an OIDC id token, or `None` if not in a supported CI.ÚGITHUB_ACTIONSÚtrueN)ÚosÚenvironÚgetr
   r   r   r   r   Údetect_providerr   .   s%   € ä	‡z�z‡~�~Ð&Ó'¨6Ò1Ü�‰ÐØr   Úaudiencec                 ó  — t         j                  j                  d«      }t         j                  j                  d«      }|r|st        d«      ‚t	        «       j                  |d| idd|› �i¬«      }t        |«       |j                  «       d   S )	zîMint an OIDC id token from the GitHub Actions runtime.

    Relies on the `ACTIONS_ID_TOKEN_REQUEST_URL` / `ACTIONS_ID_TOKEN_REQUEST_TOKEN` env vars,
    which GitHub only injects when the job declares `permissions: id-token: write`.
    ÚACTIONS_ID_TOKEN_REQUEST_URLÚACTIONS_ID_TOKEN_REQUEST_TOKENz÷Cannot request an OIDC id token from GitHub Actions. Make sure the workflow job sets `permissions: id-token: write`. See https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connectr   ÚAuthorizationzBearer )ÚparamsÚheadersÚvalue)r   r   r   r   r   r   Újson)r   Úrequest_urlÚrequest_tokenÚresponses       r   Ú_get_github_oidc_tokenr(   5   s�   € ô —*‘*—.‘.Ð!?Ó@€KÜ—J‘J—N‘NÐ#CÓD€MÙ™mÜðMó
ð 	
ô
 ‹}× Ñ ØØ˜HÐ%Ø  G¨M¨?Ð";Ð<ð !ó €Hô
 ˜Ô!Ø�=‰=‹?˜7Ñ#Ð#r   ©Úproviderr   r*   c                 ó   — |xs t         j                  }| xs
 t        «       } dj                  d„ t        D «       «      }| €t        d|› d�«      ‚| t        j                  k(  rt        |«      S t        d| › d|› d�«      ‚)aå  Mint a raw OIDC id token (JWT) from the current CI provider.

    Args:
        provider (`str`, *optional*):
            CI provider to use. Auto-detected from the environment when omitted.
        audience (`str`, *optional*):
            The `aud` claim to request. Defaults to `constants.ENDPOINT` so it matches the endpoint
            that validates it (respects `HF_ENDPOINT`/staging).

    Returns:
        `str`: The raw id token (JWT) to pass to [`exchange_oidc_token`].
    z, c              3   ó4   K  — | ]  }|j                   –— Œ y ­w)N)r#   )Ú.0Úps     r   ú	<genexpr>z!get_oidc_token.<locals>.<genexpr>[   s   è ø€ Ò4 a˜!Ÿ'�'Ñ4ùs   ‚zONo supported CI OIDC provider detected. Trusted Publishers currently supports: ú.zOIDC provider 'z#' is not supported yet. Supported: )	r   ÚENDPOINTr   Újoinr
   r   r   r(   ÚNotImplementedError)r*   r   Ú	supporteds      r   Úget_oidc_tokenr5   L   sˆ   € ð Ò-œ9×-Ñ-€HØÒ,œ?Ó,€HØ—	‘	Ñ4¬8Ô4Ó4€IØÐÜÐiÐjsÐitÐtuÐvÓwÐwØ”8—?‘?Ò"Ü% hÓ/Ð/Ü
 °¨zÐ9\Ð]fÐ\gÐghÐiÓ
jÐjr   )ÚendpointÚsubject_tokenÚresourcer6   c                 ó²   — t        «       j                  |xs t        j                  › d�t        t
        | |dœ¬«      }t        |«       |j                  «       S )u  Exchange a CI OIDC id token for a short-lived Hugging Face token (RFC 8693).

    Args:
        subject_token (`str`):
            The raw OIDC id token (JWT) from the CI provider. Its `aud` claim must be the Hub URL.
        resource (`str`):
            What to scope the token to: a Hub repo (`namespace/name`, `datasets/namespace/name`,
            `spaces/namespace/name`, `kernels/namespace/name`) for a write token, or a bare Hub
            username for a read-only `gated-repos` token.
        endpoint (`str`, *optional*):
            Hub endpoint. Defaults to `constants.ENDPOINT` (respects `HF_ENDPOINT`/staging).

    Returns:
        `dict`: The token-exchange response, e.g.
        `{"access_token": "hf_jwt_â€¦", "token_type": "bearer", "expires_in": 3600, ...}`.
    z/oauth/token)Ú
grant_typeÚsubject_token_typer7   r8   )r$   )r   Úpostr   r1   Ú_TOKEN_EXCHANGE_GRANT_TYPEÚ_ID_TOKEN_TYPEr   r$   )r7   r8   r6   r'   s       r   Úexchange_oidc_tokenr?   c   sX   € ô" ‹}×!Ñ!ØÒ)”y×)Ñ)Ð
*¨,Ð7ä4Ü"0Ø*Ø ñ	
ð "ó €Hô ˜Ô!Ø�=‰=‹?Ðr   )r7   r*   r   r6   c                 ól   — |xs t         j                  }|€t        ||xs |¬«      }t        || |¬«      S )u¶  Mint a CI OIDC id token and exchange it for a Hugging Face token.

    Convenience wrapper around [`get_oidc_token`] + [`exchange_oidc_token`]. Returns the raw
    exchange response (it does not persist anything â€” the caller decides what to do with the token).

    Args:
        resource (`str`):
            Repo or username to scope the token to. See [`exchange_oidc_token`].
        subject_token (`str`, *optional*):
            A pre-minted OIDC id token to exchange directly. Use this for CI providers not yet
            supported natively (e.g. GitLab): mint the id token in your job and pass it here. When
            omitted, the token is minted from the detected `provider`.
        provider (`str`, *optional*):
            CI provider. Auto-detected when omitted. Ignored when `subject_token` is provided.
        audience (`str`, *optional*):
            The `aud` claim to request. Defaults to the resolved `endpoint`, so it matches the
            endpoint that validates it.
        endpoint (`str`, *optional*):
            Hub endpoint. Defaults to `constants.ENDPOINT`.

    Returns:
        `dict`: The token-exchange response (`access_token`, `token_type`, `expires_in`, ...).
    r)   )r7   r8   r6   )r   r1   r5   r?   )r8   r7   r*   r   r6   s        r   Ú
oidc_loginrA   �   s;   € ð> Ò-œ9×-Ñ-€HØÐÜ&°À8ÒCWÈxÔXˆÜ¨]ÀXÐX`ÔaÐar   )r   r   Úenumr   Ú r   Úerrorsr   Úutilsr   r   r=   r>   Ústrr
   r   r(   r5   Údictr?   rA   r   r   r   ú<module>rH      s%  ðñó 
Ý å Ý ß 3ð OÐ Ø<€ôˆs�Dô ð˜ D™ó ð$ Sð $¨Só $ð. 9=ÐUYò k ¨3¡°Ñ 5ð kÈÈdÉ
ð kÐ^aó kð. VZò ¨#ð ¸ð ÈÈdÉ
ð Ð^bó ðB !%Ø&*ØØò"bàð"bð ˜‘:ð"bð ˜‰n˜tÑ#ð	"bð
 �D‰jð"bð �D‰jð"bð 
ô"br   