Ë
    -Œ:jO  ã                   óô  — U d Z ddlZddlZddlZddlZddlZddlZddlmZ ddl	m
Z
 ddlmZ ddlmZ ddlmZmZmZ d	d
lmZ d	dlmZ d	dlmZmZ dZdZdededdfd„Zda e
«       Zda edz  e!d<    ejD                  e#«      Z$dedz  fd„Z%dedz  fd„Z&dedz  fd„Z'dedz  fd„Z( G d„ de«      Z) e
«       Z*da+e)dz  e!d<   dZ,dedz  fd„Z- G d„ de«      Z. e
«       Z/da0e.dz  e!d <   d!Z1dZ2da3dedz  fd"„Z4d#edefd$„Z5d%eddfd&„Z6d'e7eef   de8dz  fd(„Z9de7eef   fd)„Z:de7ee7eef   f   fd*„Z;d+e7ee7eef   f   ddfd,„Z<d-ededz  fd.„Z=ddd/œd#ed-ed0edz  d1e8dz  ddf
d2„Z>d#edz  dedz  fd3„Z?y)4zVContains a helper to get the token from machine (env variable, secret or config file).é    N)ÚPath)ÚLock)Ú	TypedDicté   )Ú	constants)ÚDeviceCodeErrorÚOAuthErrorCodeÚ	OIDCErroré   )ÚWeakFileLock)Úrefresh_access_token)Úis_colab_enterpriseÚis_google_colabi€  iÀ  ÚpathÚcontentÚreturnc                 óü  — | j                   j                  ddt        ¬«       t        j                  t        | «      t        j                  t        j                  z  t        j                  z  t        «      }t        j                  |d«      5 }|j                  |«       ddd«       	 | j                  t        «       | j                   j                  t        «       y# 1 sw Y   Œ?xY w# t        t        f$ r Y yw xY w)ziWrite content to file, restricting both the file and its parent directory to owner-only on POSIX systems.T)ÚparentsÚexist_okÚmodeÚwN)ÚparentÚmkdirÚ_SECRET_DIR_MODEÚosÚopenÚstrÚO_WRONLYÚO_CREATÚO_TRUNCÚ_SECRET_FILE_MODEÚfdopenÚwriteÚchmodÚOSErrorÚNotImplementedError)r   r   ÚfdÚfs       ú]/var/www/html/tokenscope/api/venv/lib/python3.12/site-packages/huggingface_hub/utils/_auth.pyÚ_write_secretr*   %   s¸   € à‡K�K×Ñ˜d¨TÔ8HÐÔIÜ	�‰”�T“œBŸK™K¬"¯*©*Ñ4´r·z±zÑAÔCTÓ	U€BÜ	�‰�2�sÓ	ð ˜qØ	�‰�Ô÷ðØ�
‰
Ô$Ô%Ø�‰×ÑÔ*Õ+÷	ð ûô
 Ô(Ð)ò áðús   ÂCÂ(4C) ÃC&Ã)C;Ã:C;FÚ_GOOGLE_COLAB_SECRETc                  ó^   — t        «       xs" t        «       xs t        «       xs
 t        «       S )a]  
    Get token if user is logged in.

    Note: in most cases, you should use [`huggingface_hub.utils.build_hf_headers`] instead. This method is only useful
          if you want to retrieve the token for other purposes than sending an HTTP request.

    If `HF_OIDC_RESOURCE` is set (Trusted Publishers, typically in CI), a short-lived token obtained via OIDC token
    exchange takes precedence. Otherwise the token is retrieved from the `HF_TOKEN` environment variable, then from the
    token file in the Hugging Face home folder. Returns None if user is not logged in. To log in, use [`login`] or
    `hf auth login`.

    OAuth tokens obtained with the browser-based login come with a refresh token: when such a token is close to
    expiry, it is transparently refreshed and persisted before being returned.

    Note: if `HF_OIDC_RESOURCE` is set but the OIDC token exchange fails, this raises instead of returning `None`,
    opting into OIDC is explicit, so a failure surfaces as a clear error rather than a silent fallback.

    Returns:
        `str` or `None`: The token, `None` if it doesn't exist.
    )Ú_get_token_from_oidcÚ_get_token_from_environmentÚ_get_token_from_file_refreshedÚ_get_token_from_google_colab© ó    r)   Ú	get_tokenr3   :   s2   € ô, 	Óò 	*Ü&Ó(ò	*ä)Ó+ò	*ô (Ó)ð	r2   c                  ó(  — t        «       r
t        «       ryt        5  t        rt        cddd«       S 	 ddlm}  ddlm} 	 | j                  d«      }t        |«      ad
at        cddd«       S # t        $ r Y ddd«       yw xY w# | j                  $ r t        j                  d«       daY ŒP| j                  $ r t         j#                  d«       daY Œw|$ r.}t        j                  dt%        |«      › d	�«       daY d}~Œ¤d}~ww xY w# 1 sw Y   yxY w)zãGet token from Google Colab secrets vault using `google.colab.userdata.get(...)`.

    Token is read from the vault only once per session and then stored in a global variable to avoid re-requesting
    access to the vault.
    Nr   )Úuserdata)ÚErrorÚHF_TOKENz¥
Access to the secret `HF_TOKEN` has not been granted on this notebook.
You will not be requested again.
Please restart the session if you want to be prompted again.z¯The secret `HF_TOKEN` does not exist in your Colab secrets. Run `huggingface_hub.login()` to authenticate (recommended but still optional to access public models or datasets).z@
Error while fetching `HF_TOKEN` secret value from your vault: 'zÍ'.
You are not authenticated with the Hugging Face Hub in this notebook.
If the error persists, please let us know by opening an issue on GitHub (https://github.com/huggingface/huggingface_hub/issues/new).T)r   r   Ú_GOOGLE_COLAB_SECRET_LOCKÚ_IS_GOOGLE_COLAB_CHECKEDr+   Úgoogle.colabr5   Úgoogle.colab.errorsr6   ÚImportErrorÚgetÚ_clean_tokenÚNotebookAccessErrorÚwarningsÚwarnÚSecretNotFoundErrorÚloggerÚinfor   )r5   Ú
ColabErrorÚtokenÚes       r)   r0   r0   W   s-  € ô ÔÔ 3Ô 5Øô 
#ñ -$õ $Ü'÷-$ñ -$ð	Ý-Ý?ð	(Ø—L‘L Ó,ˆEÜ#/°Ó#6Ð ð: $(Ð Ü#÷[-$ñ -$øô ò 	Ø÷-$ð -$ð	ûð ×+Ñ+ò 	(ô �M‰MðQôð
 $(Ò Ø×+Ñ+ò 	(ô �K‰Kðfôð $(Ò Øò 	(ä�M‰MØSÔTWÐXYÓTZÐS[ð \Oð Oôð $(Õ ûð	(ú÷E-$ð -$úsj   œD³A-Á BÁDÁ-	BÁ6DÂ BÂDÂ&DÂ*DÂ,%DÃDÃDÃ$D Ã;DÄ DÄDÄDc                  ó”   — t        t        j                  j                  d«      xs t        j                  j                  d«      «      S )Nr7   ÚHUGGING_FACE_HUB_TOKEN)r>   r   Úenvironr=   r1   r2   r)   r.   r.   –   s-   € äœŸ
™
Ÿ™ zÓ2Ò^´b·j±j·n±nÐE]Ó6^Ó_Ð_r2   c                  ó‚   — 	 t        t        t        j                  «      j	                  «       «      S # t
        $ r Y y w xY w)N)r>   r   r   ÚHF_TOKEN_PATHÚ	read_textÚFileNotFoundErrorr1   r2   r)   Ú_get_token_from_filerO   ›   s8   € ðÜœD¤×!8Ñ!8Ó9×CÑCÓEÓFÐFøÜò Ùðús   ‚/2 ²	>½>c                   ó,   — e Zd ZU eed<   eed<   eed<   y)Ú_OidcTokenCacheÚresourcerF   Ú
expires_atN©Ú__name__Ú
__module__Ú__qualname__r   Ú__annotations__Úfloatr1   r2   r)   rQ   rQ   ¢   s   … ØƒMØƒJØÔr2   rQ   Ú_OIDC_TOKEN_CACHEi,  c                  ó  — t         j                  j                  d«      } | syddlm}m} t        5  t        j                  «       }t        �*t        d   | k(  r|t        d   k  rt        d   cddd«       S t         j                  j                  d«      xs d}|€ |«       €t        d	«      ‚ || |¬
«      }|d   }t        |j                  dd«      «      }|�dnt        }| ||t        ||z
  d«      z   dœa	|cddd«       S # 1 sw Y   yxY w)aë  Get a short-lived OIDC token in CI (Trusted Publishers).

    Enabled by setting `HF_OIDC_RESOURCE`, which scopes the token to a repo or user.
    The ID token is read from `HF_OIDC_ID_TOKEN` if available, or minted from a supported CI provider (e.g. GitHub Actions).

    Returns `None` when OIDC is not enabled.
    If enabled, any failure is raised explicitly rather than falling back silently.

    See `huggingface_hub._oidc` and https://huggingface.co/docs/hub/trusted-publishers.
    ÚHF_OIDC_RESOURCENr   )Údetect_providerÚ
oidc_loginrR   rS   rF   ÚHF_OIDC_ID_TOKENzçHF_OIDC_RESOURCE is set but no OIDC id token is available: not running in a supported CI provider (github) and HF_OIDC_ID_TOKEN is not set. Set HF_OIDC_ID_TOKEN to the id token minted by your CI provider, or unset HF_OIDC_RESOURCE.)rR   Úsubject_tokenÚaccess_tokenÚ
expires_ini  r   )rR   rF   rS   )r   rJ   r=   Ú_oidcr]   r^   Ú_OIDC_TOKEN_LOCKÚtimeÚ	monotonicrZ   r
   ÚintÚ_OIDC_REFRESH_MARGINÚmax)	rR   r]   r^   Únowr`   ÚresultrF   rb   Úmargins	            r)   r-   r-   ¯   s  € ô �z‰z�~‰~Ð0Ó1€HÙØç3ô 
ñ Ü�n‰nÓˆäÐ)Ü! *Ñ-°Ò9ØÔ'¨Ñ5Ò5ä$ WÑ-÷ñ ô Ÿ
™
Ÿ™Ð'9Ó:ÒB¸dˆØÐ ¡_Ó%6Ð%>ÜðOóð ñ  X¸]ÔKˆØ�~Ñ&ˆÜ˜Ÿ™ L°$Ó7Ó8ˆ
ð $Ð/‘Ô5Iˆà ØØ¤ J°Ñ$7¸Ó ;Ñ;ñ
Ðð
 ÷=÷ ò ús   ±;DÁ6BDÄDc                   ó,   — e Zd ZU eed<   eed<   eed<   y)Ú_OAuthRefreshCacheÚ
file_tokenÚresolved_tokenÚ
recheck_atNrT   r1   r2   r)   rn   rn   â   s   … ØƒOØÓØÔr2   rn   Ú_OAUTH_REFRESH_CACHEi€Q c                  ó2   — t        «       } | €yt        | «      S )zSGet the token from `HF_TOKEN_PATH`, transparently refreshing it if close to expiry.N)rO   Ú_refresh_oauth_token_if_needed©rF   s    r)   r/   r/   ñ   s   € ä Ó"€EØ€}ØÜ)¨%Ó0Ð0r2   rF   c           	      óª  ‡ — t         5  t        j                  «       }t        }|�|d   ‰ k(  r||d   k  r|d   cddd«       S t        ˆ fd„t	        «       j                  «       D «       di f«      \  }}|j                  d«      }t        |«      }|�|�|€4t        «       }|�|‰ k7  r|cddd«       S ‰ ‰ |t        z   dœa‰ cddd«       S |t        z
  |kD  r‰ ‰ |t        z
  dœa‰ cddd«       S 	 t        t        j                  dz   d	¬
«      5  t	        «       j                  |i «      }|j                  d«      ‰ k7  r!|j                  d«      xs ‰ }t        |«      }	n›t        |«      }
|
d   }d|
v rt        |«      t        |
d   «      z   nd}	t!        |||
j                  d«      xs ||	¬«       t        «       ‰ k(  r#t#        t%        t        j&                  «      |«       t(        j+                  d|› d�«       ddd«       |t?        |t        z   	r	|	t        z
  nd«      dœa|cddd«       S # 1 sw Y   Œ6xY w# t,        $ r…}t/        |t0        «      rB|j2                  t4        j6                  k(  r%t(        j9                  d|› d�«       t;        d«      }nt=        d|› d�«       |t        z   }‰ ‰ |dœa‰ cY d}~cddd«       S d}~ww xY w# 1 sw Y   yxY w)a“  Refresh an OAuth access token if it is close to expiry. Best-effort: never raises.

    OAuth tokens obtained with the browser-based login are stored with a `refresh_token` and an
    `expires_at` timestamp (see `_save_token`). When the active token is one of them and about to
    expire, exchange the refresh token for a new access token and persist it. Any other token is
    returned unchanged.
    Nro   rq   rp   c              3   óV   •K  — | ]   \  }}|j                  d «      ‰k(  sŒ||f–— Œ" y­w)Úhf_tokenN)r=   )Ú.0ÚnameÚfieldsrF   s      €r)   ú	<genexpr>z1_refresh_oauth_token_if_needed.<locals>.<genexpr>	  s.   øè ø€ Òv¡  fÐV\×V`ÑV`ÐakÓVlÐpuÓVuˆd�FŒ^Ñvùs   ƒ) 	)Úrefresh_token)ro   rp   rq   z.locké   )Útimeoutrx   ra   rb   )rF   Ú
token_namer}   rS   zAccess token `z` has been refreshed.z�Your Hugging Face access token has expired and could not be refreshed (session expired or revoked). Run `hf auth login` to re-authenticate. (ú)Úinfz2Could not refresh your Hugging Face access token: z. Will retry later.r   ) Ú_OAUTH_REFRESH_LOCKre   rr   ÚnextÚ_read_stored_tokens_fullÚitemsr=   Ú_parse_expires_atrO   Ú_OAUTH_RECHECK_INTERVALÚ_OAUTH_REFRESH_MARGINr   r   ÚHF_STORED_TOKENS_PATHr   rg   Ú_save_tokenr*   r   rL   rC   rD   Ú	ExceptionÚ
isinstancer   Ú
error_coder	   ÚINVALID_GRANTÚwarningrY   Ú_warn_refresh_failure_onceri   )rF   rj   Úcacher€   r{   r}   rS   Úcurrent_file_tokenÚ	new_tokenÚnew_expires_atÚresponserG   rq   s   `            r)   rt   rt   ù   s-  ø€ ô 
ñ WÜ�i‰i‹kˆÜ$ˆØÐ  |Ñ!4¸Ò!=À#ÈÈlÑH[ÒB[ØÐ)Ñ*÷	Wñ Wô "ÛvÔ0HÓ0J×0PÑ0PÓ0RÔvØ�2ˆJó
Ñˆ
�Fð Ÿ
™
 ?Ó3ˆÜ& vÓ.ˆ
ØÐ Ð!6¸*Ð:Lô "6Ó!7ÐØ!Ð-Ð2DÈÒ2MØ)÷#Wñ Wð( $Ø"'Ø!Ô$;Ñ;ñ$Ð ð
 ÷1Wñ Wð4 Ô-Ñ-°Ò3à#Ø"'Ø(Ô+@Ñ@ñ$Ð ð
 ÷AWñ WðD)	ô œi×=Ñ=ÀÑGÐQSÔTñ Tä1Ó3×7Ñ7¸
ÀBÓG�Ø—:‘:˜jÓ)¨UÒ2à &§
¡
¨:Ó 6Ò ?¸%�IÜ%6°vÓ%>‘Nä3°MÓB�HØ (¨Ñ 8�IØO[Ð_gÑOg¤S¨£X´°H¸\Ñ4JÓ0KÒ%KÐmq�NÜØ'Ø#-à&.§l¡l°?Ó&CÒ&TÀ}Ø#1õô ,Ó-°Ò6Ü%¤d¬9×+BÑ+BÓ&CÀYÔOÜ—K‘K .°°Ð<QÐ RÔS÷+TðR $Ø'ô ØÔ-Ñ-Ù:H�Ô!6Ò6Èaóñ	 
Ðð ÷oWñ W÷JTð Tûô, ò 	Ü˜!œ_Ô-°!·,±,Ä.×B^ÑB^Ò2^ô —‘ð^Ø^_Ð]`Ð`aðcôô # 5›\‘
ô +Ð-_Ð`aÐ_bÐbuÐ+vÔwØ Ô#:Ñ:�
à27È5Ð`jÑ#kÐ ØŒL÷WWñ Wûðv	ú÷wWð Wúsh   ˆ1K	ÁA$K	Â1K	Ã	K	Ã.H8ÄC+H,Ç7H8Ç?#K	È,H5	È1H8È8	KÉA1KÊ2KÊ3K	ËKËK	Ë	KÚmessagec                 ó@   — t         st        j                  | «       da y y )NT)Ú_OAUTH_REFRESH_WARNEDrC   r�   )r—   s    r)   r‘   r‘   \  s   € å Ü�‰�wÔØ $Ñð !r2   r{   c                 óJ   — 	 t        | d   «      S # t        t        f$ r Y yw xY w)zVParse the `expires_at` field of a stored-tokens section, `None` if missing or corrupt.rS   N)rg   ÚKeyErrorÚ
ValueError)r{   s    r)   r‡   r‡   c  s.   € ðÜ�6˜,Ñ'Ó(Ð(øÜ”jÐ!ò Ùðús   ‚ �"¡"c            	      ó†   — t        «       j                  «       D � �ci c]  \  } }| |j                  dd«      “Œ c}} S c c}} w )aA  
    Returns the parsed INI file containing the access tokens.
    The file is located at `HF_STORED_TOKENS_PATH`, defaulting to `~/.cache/huggingface/stored_tokens`.
    If the file does not exist, an empty dictionary is returned.

    Returns: `dict[str, str]`
        Key is the token name and value is the token.
    rx   Ú )r…   r†   r=   )r€   r{   s     r)   Úget_stored_tokensrŸ   k  s;   € ô NfÓMg×MmÑMmÓMo×pÑ7I°zÀ6ˆJ˜Ÿ
™
 :¨rÓ2Ñ2ÓpÐpùÓps   œ=c            	      ó”  — t        t        j                  «      } | j                  «       si S t	        j
                  d¬«      }	 |j                  | «       |j                  «       D �ci c]  }|t        |j                  |«      «      “Œ c}S c c}w # t        j                  $ r$}t        j                  d|› �«       i cY d}~S d}~ww xY w)zõRead all sections of the stored tokens INI file, with all their fields.

    Beside `hf_token`, sections for OAuth tokens also carry `refresh_token` and `expires_at`
    (unix timestamp), used by [`get_token`] to transparently refresh them.
    N©Úinterpolationz"Error parsing stored tokens file: )r   r   rŠ   ÚexistsÚconfigparserÚConfigParserÚreadÚsectionsÚdictr†   r6   rC   Úerror)Útokens_pathÚconfigr€   rG   s       r)   r…   r…   w  s£   € ô ”y×6Ñ6Ó7€KØ×ÑÔØˆ	ä×&Ñ&°TÔ:€FðØ�‰�KÔ ØMSÏ_É_ÓM^Ö_¸z�
œD §¡¨jÓ!9Ó:Ñ:Ò_Ð_ùÒ_øÜ×Ñò Ü�‰Ð9¸!¸Ð=Ô>Ø�	ûðús0   Á#B Á&"BÂB ÂB ÂCÂ#CÂ<CÃCÚstored_tokensc                 ó–  — t        j                  d¬«      }t        | j                  «       «      D ]A  }|j	                  |«       | |   j                  «       D ]  \  }}|j                  |||«       Œ ŒC t        j                  «       }|j                  |«       t        t        t        j                  «      |j                  «       «       y)zBWrite all sections and their fields to the stored tokens INI file.Nr¡   )r¤   r¥   ÚsortedÚkeysÚadd_sectionr†   ÚsetÚioÚStringIOr#   r*   r   r   rŠ   Úgetvalue)r¬   r«   r€   ÚkeyÚvalueÚbufs         r)   Ú_save_stored_tokens_fullr¸   Š  s¢   € ä×&Ñ&°TÔ:€FÜ˜]×/Ñ/Ó1Ó2ò /ˆ
Ø×Ñ˜:Ô&Ø'¨
Ñ3×9Ñ9Ó;ò 	/‰JˆC�Ø�J‰J�z 3¨Õ.ñ	/ð/ô
 �+‰+‹-€CØ
‡L�L�ÔÜ”$”y×6Ñ6Ó7¸¿¹»ÕHr2   r€   c                 ó<   — t        «       }| |vryt        ||    «      S )zÀ
    Get the token by name.

    Args:
        token_name (`str`):
            The name of the token to get.

    Returns:
        `str` or `None`: The token, `None` if it doesn't exist.

    N)rŸ   r>   )r€   r¬   s     r)   Ú_get_token_by_namerº   —  s'   € ô &Ó'€MØ˜Ñ&ØÜ˜ jÑ1Ó2Ð2r2   )r}   rS   r}   rS   c                óÀ   — t        «       }d| i}|�||d<   |�t        |«      |d<   |||<   t        |«       t        j	                  d|› dt
        j                  › �«       y)aÂ  
    Save the given token.

    If the stored tokens file does not exist, it will be created.
    Args:
        token (`str`):
            The token to save.
        token_name (`str`):
            The name of the token.
        refresh_token (`str`, *optional*):
            OAuth refresh token used to renew the access token when it expires.
        expires_at (`int`, *optional*):
            Unix timestamp at which the access token expires.
    rx   Nr}   rS   zThe token `z` has been saved to )r…   r   r¸   rC   rD   r   rŠ   )rF   r€   r}   rS   r¬   r{   s         r)   r‹   r‹   ©  sm   € ô" -Ó.€MØ˜%Ð €FØÐ Ø"/ˆˆÑØÐÜ" :›ˆˆ|Ñà &€M�*ÑÜ˜]Ô+Ü
‡K�K�+˜j˜\Ð)=¼i×>]Ñ>]Ð=^Ð_Õ`r2   c                 óp   — | €y| j                  dd«      j                  dd«      j                  «       xs dS )zuClean token by removing trailing and leading spaces and newlines.

    If token is an empty string, return None.
    Núrž   ú
)ÚreplaceÚstripru   s    r)   r>   r>   Æ  s8   € ð
 €}ØØ�=‰=˜˜rÓ"×*Ñ*¨4°Ó4×:Ñ:Ó<ÒDÀÐDr2   )@Ú__doc__r¤   r²   Úloggingr   re   r@   Úpathlibr   Ú	threadingr   Útypingr   rž   r   Úerrorsr   r	   r
   Ú_fixesr   Ú_oauth_devicer   Ú_runtimer   r   r!   r   r   r*   r9   r8   r+   rX   Ú	getLoggerrU   rC   r3   r0   r.   rO   rQ   rd   rZ   rh   r-   rn   rƒ   rr   r‰   rˆ   r™   r/   rt   r‘   r¨   rg   r‡   rŸ   r…   r¸   rº   r‹   r>   r1   r2   r)   ú<module>rË      s{  ðò ]ã Û 	Û Û 	Û Û Ý Ý Ý å ß ?Ñ ?Ý  Ý /ß :ð Ð ØÐ ð˜ð  sð ¨tó ð !Ð Ù ›FÐ Ø#'Ð �c˜D‘jÓ 'à	ˆ×	Ñ	˜8Ó	$€ð�3˜‘:ó ð:<$ c¨D¡jó <$ð~` S¨4¡Zó `ð
˜c D™jó ô�iô ñ “6Ð Ø,0Ð �? TÑ)Ó 0ØÐ ð0˜c D™jó 0ôf˜ô ñ “fÐ Ø26Ð Ð(¨4Ñ/Ó 6Ø!Ð ØÐ ØÐ ð1¨¨d©
ó 1ð`¨#ð `°#ó `ðF%¨ð %°ó %ð˜d 3¨ 8™nð °°t±ó ð	q˜4  S ™>ó 	qð $ s¨D°°c°©NÐ':Ñ";ó ð&
I¨D°°d¸3À¸8±nÐ1DÑ,Eð 
IÈ$ó 
Ið3 3ð 3¨3°©:ó 3ð& AEÐ_còaØðaØðaØ36¸±:ðaØRUÐX\ÑR\ðaà	óað:E˜˜d™
ð E s¨T¡zô Er2   