mirror of
https://github.com/langchain-ai/langgraph.git
synced 2026-10-01 22:15:11 +02:00
Bumps the minor-and-patch group in /libs/sdk-py with 5 updates: | Package | From | To | | --- | --- | --- | | [langchain-core](https://github.com/langchain-ai/langchain) | `1.6.1` | `1.6.5` | | [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` | | [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` | | [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` | Updates `langchain-core` from 1.6.1 to 1.6.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchain/releases">langchain-core's releases</a>.</em></p> <blockquote> <h2>langchain-core==1.6.5</h2> <p>Changes since langchain-core==1.6.4</p> <p>release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>) fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p> <h2>langchain-core==1.6.4</h2> <p>Changes since langchain-core==1.6.3</p> <p>release(core): 1.6.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>) chore(core): deprecate chat message history (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p> <h2>langchain-core==1.6.3</h2> <p>Changes since langchain-core==1.6.2</p> <p>release(core): 1.6.3 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>) feat(core): Allow model name and provider tracing metadata override based on gateway response (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>) test(core): cover the deprecated <code>.text()</code> access path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p> <h2>langchain-core==1.6.2</h2> <p>Changes since langchain-core==1.6.1</p> <p>release(core): 1.6.2 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>) feat(openai): support async tools (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>) fix(core): avoid mutation in google-genai standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>) fix(core): avoid mutation in bedrock converse standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a> release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a> chore(model-profiles): refresh model profile data (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a> release(openai): 1.6.6 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a> docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a> fix(openai): raise on error events in stream path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a> fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a> chore(anthropic): fix integration test cassette (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a> release(openai): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a> release(anthropic): 1.7.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a> fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare view</a></li> </ul> </details> <br /> Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Updates `starlette` from 1.6.0 to 1.7.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kludex/starlette/releases">starlette's releases</a>.</em></p> <blockquote> <h2>Version 1.7.0</h2> <p>This release adds experimental OpenTelemetry tracing, HTTP <code>QUERY</code> support, and response trailers in <code>TestClient</code>. Starlette now requires AnyIO 4.</p> <blockquote> <p>[!WARNING] <code>OpenTelemetryMiddleware</code> is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.</p> </blockquote> <h2>Added</h2> <ul> <li>Add experimental <code>OpenTelemetryMiddleware</code> for HTTP server spans, with URL exclusions and custom tracer providers <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>, <a href="https://redirect.github.com/Kludex/starlette/pull/3463">#3463</a>, and <a href="https://redirect.github.com/Kludex/starlette/pull/3520">#3520</a>.</li> <li>Expose the matched route through <code>scope["route"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>.</li> <li>Support the <code>QUERY</code> HTTP method in <code>HTTPEndpoint</code>, CORS, and OpenAPI 3.2 schema generation <a href="https://redirect.github.com/Kludex/starlette/pull/3489">#3489</a>.</li> <li>Capture HTTP response trailers in <code>TestClient</code> and expose them through <code>response.extensions["http.response.trailers"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3563">#3563</a>.</li> <li>Support partitioned cookies in <code>SessionMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3510">#3510</a>.</li> <li>Add <code>partitioned</code> to <code>Response.delete_cookie()</code> on Python 3.14 and later <a href="https://redirect.github.com/Kludex/starlette/pull/3376">#3376</a>.</li> <li>Support IPv6 hosts in <code>TrustedHostMiddleware</code> and <code>TestClient</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3471">#3471</a>.</li> <li>Support Python 3.15 <a href="https://redirect.github.com/Kludex/starlette/pull/3508">#3508</a>.</li> </ul> <h2>Changed</h2> <ul> <li>Require <code>anyio>=4.0.0,<5</code>, dropping support for AnyIO 3 <a href="https://redirect.github.com/Kludex/starlette/pull/3512">#3512</a>.</li> <li>Raise <code>WebSocketDisconnected</code>, a <code>RuntimeError</code> subclass, for disconnected WebSocket operations <a href="https://redirect.github.com/Kludex/starlette/pull/2767">#2767</a>.</li> <li>Accept <code>Collection[str]</code> in <code>CORSMiddleware</code> configuration annotations, including sets and frozensets <a href="https://redirect.github.com/Kludex/starlette/pull/3518">#3518</a>.</li> </ul> <h2>Fixed</h2> <ul> <li>Run background tasks only after the response is sent when using <code>BaseHTTPMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3476">#3476</a>.</li> <li>Return <code>400</code> for invalid multipart parser input <a href="https://redirect.github.com/Kludex/starlette/pull/3492">#3492</a>.</li> <li>Include <code>Vary: Origin</code> on all normal CORS responses and vary preflight responses by all request headers that affect them <a href="https://redirect.github.com/Kludex/starlette/pull/3516">#3516</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3517">#3517</a>.</li> <li>Handle malformed <code>Host</code> headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware <a href="https://redirect.github.com/Kludex/starlette/pull/3472">#3472</a>.</li> <li>Ignore <code>Range</code> headers when <code>FileResponse</code> has a status other than <code>200</code>, preserving its status and full body <a href="https://redirect.github.com/Kludex/starlette/pull/3568">#3568</a>.</li> <li>Handle standalone <code>If-None-Match: *</code> in <code>StaticFiles</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3201">#3201</a>.</li> <li>Reject WebSocket requests to <code>StaticFiles</code> without raising an assertion error <a href="https://redirect.github.com/Kludex/starlette/pull/3532">#3532</a>.</li> <li>Persist session mutations made with <code>popitem()</code> and <code>|=</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3436">#3436</a>.</li> <li>Handle empty and absent payloads in <code>WebSocketEndpoint.decode()</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3372">#3372</a>.</li> <li>Implement <code>identity</code> on <code>SimpleUser</code> and <code>UnauthenticatedUser</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3271">#3271</a>.</li> <li>Allow <code>HTTPException</code> to use non-standard status codes without an explicit <code>detail</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3545">#3545</a>.</li> <li>Avoid deprecated AnyIO imports in <code>TestClient</code> and add explicit imports in <code>WSGIMiddleware</code> for AnyIO 4.15 compatibility <a href="https://redirect.github.com/Kludex/starlette/pull/3498">#3498</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3501">#3501</a>.</li> <li>Offload debug traceback rendering to a worker thread in <code>ServerErrorMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/2858">#2858</a>.</li> </ul> <p><strong>Full changelog:</strong> <a href="https://github.com/Kludex/starlette/compare/1.6.0...1.7.0">1.6.0...1.7.0</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kludex/starlette/blob/main/docs/release-notes.md">starlette's changelog</a>.</em></p> <blockquote> <h2>1.7.0 (September 23, 2026)</h2> <p>This release adds experimental OpenTelemetry tracing and requires AnyIO 4.</p> <p>!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period <a href="https://redirect.github.com/Kludex/starlette/pull/3574">#3574</a>.</p> <h4>Added</h4> <ul> <li>Add experimental <code>OpenTelemetryMiddleware</code> for HTTP server spans, with URL exclusions and custom tracer providers <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>, <a href="https://redirect.github.com/Kludex/starlette/pull/3463">#3463</a>, and <a href="https://redirect.github.com/Kludex/starlette/pull/3520">#3520</a>.</li> <li>Expose the matched route through <code>scope["route"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>.</li> <li>Support the <code>QUERY</code> HTTP method in <code>HTTPEndpoint</code>, CORS, and OpenAPI 3.2 schema generation <a href="https://redirect.github.com/Kludex/starlette/pull/3489">#3489</a>.</li> <li>Capture HTTP response trailers in <code>TestClient</code> and expose them through <code>response.extensions["http.response.trailers"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3563">#3563</a>.</li> <li>Support partitioned cookies in <code>SessionMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3510">#3510</a>.</li> <li>Add <code>partitioned</code> to <code>Response.delete_cookie()</code> on Python 3.14 and later <a href="https://redirect.github.com/Kludex/starlette/pull/3376">#3376</a>.</li> <li>Support IPv6 hosts in <code>TrustedHostMiddleware</code> and <code>TestClient</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3471">#3471</a>.</li> <li>Support Python 3.15 <a href="https://redirect.github.com/Kludex/starlette/pull/3508">#3508</a>.</li> </ul> <h4>Changed</h4> <ul> <li>Require <code>anyio>=4.0.0,<5</code>, dropping support for AnyIO 3 <a href="https://redirect.github.com/Kludex/starlette/pull/3512">#3512</a>.</li> <li>Raise <code>WebSocketDisconnected</code>, a <code>RuntimeError</code> subclass, for disconnected WebSocket operations <a href="https://redirect.github.com/Kludex/starlette/pull/2767">#2767</a>.</li> <li>Accept <code>Collection[str]</code> in <code>CORSMiddleware</code> configuration annotations, including sets and frozensets <a href="https://redirect.github.com/Kludex/starlette/pull/3518">#3518</a>.</li> </ul> <h4>Fixed</h4> <ul> <li>Run background tasks only after the response is sent when using <code>BaseHTTPMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3476">#3476</a>.</li> <li>Return <code>400</code> for invalid multipart parser input <a href="https://redirect.github.com/Kludex/starlette/pull/3492">#3492</a>.</li> <li>Include <code>Vary: Origin</code> on all normal CORS responses and vary preflight responses by all request headers that affect them <a href="https://redirect.github.com/Kludex/starlette/pull/3516">#3516</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3517">#3517</a>.</li> <li>Handle malformed <code>Host</code> headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware <a href="https://redirect.github.com/Kludex/starlette/pull/3472">#3472</a>.</li> <li>Ignore <code>Range</code> headers when <code>FileResponse</code> has a status other than <code>200</code>, preserving its status and full body <a href="https://redirect.github.com/Kludex/starlette/pull/3568">#3568</a>.</li> <li>Handle standalone <code>If-None-Match: *</code> in <code>StaticFiles</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3201">#3201</a>.</li> <li>Reject WebSocket requests to <code>StaticFiles</code> without raising an assertion error <a href="https://redirect.github.com/Kludex/starlette/pull/3532">#3532</a>.</li> <li>Persist session mutations made with <code>popitem()</code> and <code>|=</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3436">#3436</a>.</li> <li>Handle empty and absent payloads in <code>WebSocketEndpoint.decode()</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3372">#3372</a>.</li> <li>Implement <code>identity</code> on <code>SimpleUser</code> and <code>UnauthenticatedUser</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3271">#3271</a>.</li> <li>Allow <code>HTTPException</code> to use non-standard status codes without an explicit <code>detail</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3545">#3545</a>.</li> <li>Avoid deprecated AnyIO imports in <code>TestClient</code> and add explicit imports in <code>WSGIMiddleware</code> for AnyIO 4.15 compatibility <a href="https://redirect.github.com/Kludex/starlette/pull/3498">#3498</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3501">#3501</a>.</li> <li>Offload debug traceback rendering to a worker thread in <code>ServerErrorMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/2858">#2858</a>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kludex/starlette/commit/2269e9a08c1edd3dfdea865710f40f84c857b623"><code>2269e9a</code></a> Version 1.7.0 (<a href="https://redirect.github.com/Kludex/starlette/issues/3575">#3575</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/4fe55eb2649e74fb01472bad9a1bc54fc3495904"><code>4fe55eb</code></a> Preserve <code>FileResponse</code> status for range requests (<a href="https://redirect.github.com/Kludex/starlette/issues/3568">#3568</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/1f08daf1627c866a4244418ea6da673d272fc8bb"><code>1f08daf</code></a> Mark OpenTelemetryMiddleware as experimental (<a href="https://redirect.github.com/Kludex/starlette/issues/3574">#3574</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/57de5fa9c2a98089a78d32d560e9b23e62560d5f"><code>57de5fa</code></a> Support HTTP response trailers in TestClient (<a href="https://redirect.github.com/Kludex/starlette/issues/3563">#3563</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/03f12b7fcf0a3e21a8da648ca0900c79472e9efe"><code>03f12b7</code></a> Allow HTTPException to use non-standard status codes (<a href="https://redirect.github.com/Kludex/starlette/issues/3545">#3545</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/76fd00f1e293990ea41555946a6b0f58901eaca1"><code>76fd00f</code></a> Reject <code>WebSocket</code> requests to <code>StaticFiles</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3532">#3532</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/f03f65c2f98c592773d691b4d309c68b83e568ef"><code>f03f65c</code></a> docs: fix 'its not available' and 'This ensure' wording (<a href="https://redirect.github.com/Kludex/starlette/issues/3526">#3526</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/485aca4e797d41849743cf73d5adcfd699695467"><code>485aca4</code></a> docs: the test client is built on httpx2, not httpx (<a href="https://redirect.github.com/Kludex/starlette/issues/3525">#3525</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/fd662b17b9cc41dca32a03509305619643f2dd61"><code>fd662b1</code></a> Implement <code>identity</code> on <code>SimpleUser</code> and <code>UnauthenticatedUser</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3271">#3271</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/41db6a707f2636526847dbda0e5610e732e6b4fc"><code>41db6a7</code></a> Stabilize CodSpeed upload buffer allocations (<a href="https://redirect.github.com/Kludex/starlette/issues/3524">#3524</a>)</li> <li>Additional commits viewable in <a href="https://github.com/Kludex/starlette/compare/1.6.0...1.7.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
927 lines
32 KiB
Python
927 lines
32 KiB
Python
from __future__ import annotations
|
|
|
|
import inspect
|
|
import typing
|
|
from collections.abc import Callable, Sequence
|
|
|
|
from langgraph_sdk.auth import exceptions, types
|
|
|
|
TH = typing.TypeVar("TH", bound=types.Handler)
|
|
AH = typing.TypeVar("AH", bound=types.Authenticator)
|
|
|
|
|
|
class Auth:
|
|
"""Add custom authentication and authorization management to your LangGraph application.
|
|
|
|
The Auth class provides a unified system for handling authentication and
|
|
authorization in LangGraph applications. It supports custom user authentication
|
|
protocols and fine-grained authorization rules for different resources and
|
|
actions.
|
|
|
|
To use, create a separate python file and add the path to the file to your
|
|
LangGraph API configuration file (`langgraph.json`). Within that file, create
|
|
an instance of the Auth class and register authentication and authorization
|
|
handlers as needed.
|
|
|
|
Example `langgraph.json` file:
|
|
|
|
```json
|
|
{
|
|
"dependencies": ["."],
|
|
"graphs": {
|
|
"agent": "./my_agent/agent.py:graph"
|
|
},
|
|
"env": ".env",
|
|
"auth": {
|
|
"path": "./auth.py:my_auth"
|
|
}
|
|
```
|
|
|
|
Then the LangGraph server will load your auth file and run it server-side whenever a request comes in.
|
|
|
|
???+ example "Basic Usage"
|
|
|
|
```python
|
|
from langgraph_sdk import Auth
|
|
|
|
my_auth = Auth()
|
|
|
|
@my_auth.authenticate
|
|
async def authenticate(authorization: str) -> Auth.types.MinimalUserDict:
|
|
user = await verify_token(authorization) # Your token verification logic
|
|
if not user:
|
|
raise Auth.exceptions.HTTPException(
|
|
status_code=401, detail="Unauthorized"
|
|
)
|
|
return {
|
|
"identity": user["id"],
|
|
"permissions": user.get("permissions", []),
|
|
}
|
|
|
|
# Default deny: reject all requests that don't have a specific handler
|
|
@my_auth.on
|
|
async def deny_all(ctx: Auth.types.AuthContext, value: Any) -> False:
|
|
return False
|
|
|
|
# Allow users to create threads with their own identity as owner
|
|
@my_auth.on.threads.create
|
|
async def allow_thread_create(
|
|
ctx: Auth.types.AuthContext, value: Auth.types.on.threads.create.value
|
|
):
|
|
metadata = value.setdefault("metadata", {})
|
|
metadata["owner"] = ctx.user.identity
|
|
|
|
# Allow users to read and search their own threads
|
|
@my_auth.on.threads.read
|
|
async def allow_thread_read(
|
|
ctx: Auth.types.AuthContext, value: Auth.types.on.threads.read.value
|
|
) -> Auth.types.FilterType:
|
|
return {"owner": ctx.user.identity}
|
|
|
|
@my_auth.on.threads.search
|
|
async def allow_thread_search(
|
|
ctx: Auth.types.AuthContext, value: Auth.types.on.threads.search.value
|
|
) -> Auth.types.FilterType:
|
|
return {"owner": ctx.user.identity}
|
|
|
|
# Scope all store operations to the user's namespace
|
|
@my_auth.on.store
|
|
async def scope_store(ctx: Auth.types.AuthContext, value: Auth.types.on.store.value):
|
|
namespace = tuple(value["namespace"]) if value.get("namespace") else ()
|
|
if not namespace or namespace[0] != ctx.user.identity:
|
|
namespace = (ctx.user.identity, *namespace)
|
|
value["namespace"] = namespace
|
|
```
|
|
|
|
???+ note "Request Processing Flow"
|
|
|
|
1. Authentication (your `@auth.authenticate` handler) is performed first on **every request**
|
|
2. For authorization, the most specific matching handler is called:
|
|
* If a handler exists for the exact resource and action, it is used (e.g., `@auth.on.threads.create`)
|
|
* Otherwise, if a handler exists for the resource with any action, it is used (e.g., `@auth.on.threads`)
|
|
* Finally, if no specific handlers match, the global handler is used (e.g., `@auth.on`)
|
|
* If no global handler is set, the request is accepted
|
|
|
|
This allows you to set default behavior with a global handler while
|
|
overriding specific routes as needed.
|
|
"""
|
|
|
|
__slots__ = (
|
|
"_authenticate_handler",
|
|
"_global_handlers",
|
|
"_handler_cache",
|
|
"_handlers",
|
|
"on",
|
|
)
|
|
types = types
|
|
"""Reference to auth type definitions.
|
|
|
|
Provides access to all type definitions used in the auth system,
|
|
like ThreadsCreate, AssistantsRead, etc."""
|
|
|
|
exceptions = exceptions
|
|
"""Reference to auth exception definitions.
|
|
|
|
Provides access to all exception definitions used in the auth system,
|
|
like HTTPException, etc.
|
|
"""
|
|
|
|
def __init__(self) -> None:
|
|
self.on = _On(self)
|
|
"""Entry point for authorization handlers that control access to specific resources.
|
|
|
|
The on class provides a flexible way to define authorization rules for different
|
|
resources and actions in your application. It supports three main usage patterns:
|
|
|
|
1. Global handlers that run for all resources and actions
|
|
2. Resource-specific handlers that run for all actions on a resource
|
|
3. Resource and action specific handlers for fine-grained control
|
|
|
|
Each handler must be an async function that accepts two parameters:
|
|
- ctx (AuthContext): Contains request context and authenticated user info
|
|
- value: The data being authorized (type varies by endpoint)
|
|
|
|
The handler should return one of:
|
|
|
|
- None or True: Accept the request
|
|
- False: Reject with 403 error
|
|
- FilterType: Apply filtering rules to the response
|
|
|
|
???+ example "Examples"
|
|
|
|
Start by denying all requests by default, then add specific handlers
|
|
to allow access:
|
|
|
|
```python
|
|
# Default deny: reject all unhandled requests
|
|
@auth.on
|
|
async def deny_all(ctx: AuthContext, value: Any) -> False:
|
|
return False
|
|
```
|
|
|
|
Resource-specific handler. This takes precedence over the global handler
|
|
for all actions on the `threads` resource:
|
|
|
|
```python
|
|
@auth.on.threads
|
|
async def allow_thread_access(ctx: AuthContext, value: Any) -> Auth.types.FilterType:
|
|
# Only allow access to threads owned by the user
|
|
return {"owner": ctx.user.identity}
|
|
```
|
|
|
|
Resource and action specific handler:
|
|
|
|
```python
|
|
@auth.on.threads.delete
|
|
async def allow_admin_thread_deletion(ctx: AuthContext, value: Any) -> bool:
|
|
# Only admins can delete threads
|
|
return "admin" in ctx.user.permissions
|
|
```
|
|
|
|
Multiple resources or actions:
|
|
|
|
```python
|
|
@auth.on(resources=["threads", "assistants"], actions=["read", "search"])
|
|
async def allow_reads(ctx: AuthContext, value: Any) -> Auth.types.FilterType:
|
|
# Allow read/search access to resources owned by the user
|
|
return {"owner": ctx.user.identity}
|
|
```
|
|
|
|
Auth for the `store` resource is a bit different since its structure is developer defined.
|
|
You typically want to scope store operations by rewriting the namespace to include the user's identity.
|
|
The `value` dict is mutable — changes to `value["namespace"]` are used by the server for the actual operation.
|
|
|
|
```python
|
|
@auth.on.store
|
|
async def scope_store(ctx: AuthContext, value: Auth.types.on.store.value):
|
|
# Allow store access but scope to user's namespace
|
|
namespace = tuple(value["namespace"]) if value.get("namespace") else ()
|
|
if not namespace or namespace[0] != ctx.user.identity:
|
|
namespace = (ctx.user.identity, *namespace)
|
|
value["namespace"] = namespace
|
|
```
|
|
|
|
You can also register handlers for specific store actions:
|
|
|
|
```python
|
|
@auth.on.store.put
|
|
async def allow_put(ctx: AuthContext, value: Auth.types.on.store.put.value):
|
|
# Allow puts, scoped to user's namespace
|
|
value["namespace"] = (ctx.user.identity, *value["namespace"])
|
|
|
|
@auth.on.store.get
|
|
async def allow_get(ctx: AuthContext, value: Auth.types.on.store.get.value):
|
|
# Allow gets, scoped to user's namespace
|
|
value["namespace"] = (ctx.user.identity, *value["namespace"])
|
|
```
|
|
"""
|
|
# These are accessed by the API. Changes to their names or types is
|
|
# will be considered a breaking change.
|
|
self._handlers: dict[tuple[str, str], list[types.Handler]] = {}
|
|
self._global_handlers: list[types.Handler] = []
|
|
self._authenticate_handler: types.Authenticator | None = None
|
|
self._handler_cache: dict[tuple[str, str], types.Handler] = {}
|
|
|
|
def authenticate(self, fn: AH) -> AH:
|
|
"""Register an authentication handler function.
|
|
|
|
The authentication handler is responsible for verifying credentials
|
|
and returning user scopes. It can accept any of the following parameters
|
|
by name:
|
|
|
|
- request (Request): The raw ASGI request object
|
|
- path (str): The request path, e.g., "/threads/abcd-1234-abcd-1234/runs/abcd-1234-abcd-1234/stream"
|
|
- method (str): The HTTP method, e.g., "GET"
|
|
- path_params (dict[str, str]): URL path parameters, e.g., {"thread_id": "abcd-1234-abcd-1234", "run_id": "abcd-1234-abcd-1234"}
|
|
- query_params (dict[str, str]): URL query parameters, e.g., {"stream": "true"}
|
|
- headers (dict[bytes, bytes]): Request headers
|
|
- authorization (str | None): The Authorization header value (e.g., "Bearer <token>")
|
|
|
|
Args:
|
|
fn: The authentication handler function to register.
|
|
Must return a representation of the user. This could be a:
|
|
- string (the user id)
|
|
- dict containing {"identity": str, "permissions": list[str]}
|
|
- or an object with identity and permissions properties
|
|
Permissions can be optionally used by your handlers downstream.
|
|
|
|
Returns:
|
|
The registered handler function.
|
|
|
|
Raises:
|
|
ValueError: If an authentication handler is already registered.
|
|
|
|
???+ example "Examples"
|
|
|
|
Basic token authentication:
|
|
|
|
```python
|
|
@auth.authenticate
|
|
async def authenticate(authorization: str) -> str:
|
|
user_id = verify_token(authorization)
|
|
return user_id
|
|
```
|
|
|
|
Accept the full request context:
|
|
|
|
```python
|
|
@auth.authenticate
|
|
async def authenticate(
|
|
method: str,
|
|
path: str,
|
|
headers: dict[str, bytes]
|
|
) -> str:
|
|
user = await verify_request(method, path, headers)
|
|
return user
|
|
```
|
|
|
|
Return user name and permissions:
|
|
|
|
```python
|
|
@auth.authenticate
|
|
async def authenticate(
|
|
method: str,
|
|
path: str,
|
|
headers: dict[str, bytes]
|
|
) -> Auth.types.MinimalUserDict:
|
|
permissions, user = await verify_request(method, path, headers)
|
|
# Permissions could be things like ["runs:read", "runs:write", "threads:read", "threads:write"]
|
|
return {
|
|
"identity": user["id"],
|
|
"permissions": permissions,
|
|
"display_name": user["name"],
|
|
}
|
|
```
|
|
"""
|
|
if self._authenticate_handler is not None:
|
|
raise ValueError(
|
|
f"Authentication handler already set as {self._authenticate_handler}."
|
|
)
|
|
self._authenticate_handler = fn
|
|
return fn
|
|
|
|
|
|
## Helper types & utilities
|
|
|
|
V = typing.TypeVar("V", contravariant=True)
|
|
|
|
|
|
class _ActionHandler(typing.Protocol[V]):
|
|
async def __call__(
|
|
self, *, ctx: types.AuthContext, value: V
|
|
) -> types.HandlerResult: ...
|
|
|
|
|
|
T = typing.TypeVar("T")
|
|
|
|
|
|
class _ResourceActionOn(typing.Generic[T]):
|
|
def __init__(
|
|
self,
|
|
auth: Auth,
|
|
resource: typing.Literal["threads", "crons", "assistants"],
|
|
action: typing.Literal[
|
|
"create", "read", "update", "delete", "search", "create_run"
|
|
],
|
|
value: type[T],
|
|
) -> None:
|
|
self.auth = auth
|
|
self.resource = resource
|
|
self.action = action
|
|
self.value = value
|
|
|
|
def __call__(self, fn: _ActionHandler[T]) -> _ActionHandler[T]:
|
|
_validate_handler(fn)
|
|
_register_handler(self.auth, self.resource, self.action, fn)
|
|
return fn
|
|
|
|
|
|
VCreate = typing.TypeVar("VCreate", covariant=True)
|
|
VUpdate = typing.TypeVar("VUpdate", covariant=True)
|
|
VRead = typing.TypeVar("VRead", covariant=True)
|
|
VDelete = typing.TypeVar("VDelete", covariant=True)
|
|
VSearch = typing.TypeVar("VSearch", covariant=True)
|
|
ResourceActionT = typing.TypeVar("ResourceActionT", bound=str)
|
|
|
|
_ResourceAction = typing.Literal["create", "read", "update", "delete", "search"]
|
|
_ThreadAction = _ResourceAction | typing.Literal["create_run"]
|
|
|
|
|
|
class _ResourceOn(
|
|
typing.Generic[VCreate, VRead, VUpdate, VDelete, VSearch, ResourceActionT]
|
|
):
|
|
"""
|
|
Generic base class for resource-specific handlers.
|
|
"""
|
|
|
|
value: type[VCreate | VUpdate | VRead | VDelete | VSearch]
|
|
|
|
Create: type[VCreate]
|
|
Read: type[VRead]
|
|
Update: type[VUpdate]
|
|
Delete: type[VDelete]
|
|
Search: type[VSearch]
|
|
|
|
def __init__(
|
|
self,
|
|
auth: Auth,
|
|
resource: typing.Literal["threads", "crons", "assistants"],
|
|
) -> None:
|
|
self.auth = auth
|
|
self.resource = resource
|
|
self.create: _ResourceActionOn[VCreate] = _ResourceActionOn(
|
|
auth, resource, "create", self.Create
|
|
)
|
|
self.read: _ResourceActionOn[VRead] = _ResourceActionOn(
|
|
auth, resource, "read", self.Read
|
|
)
|
|
self.update: _ResourceActionOn[VUpdate] = _ResourceActionOn(
|
|
auth, resource, "update", self.Update
|
|
)
|
|
self.delete: _ResourceActionOn[VDelete] = _ResourceActionOn(
|
|
auth, resource, "delete", self.Delete
|
|
)
|
|
self.search: _ResourceActionOn[VSearch] = _ResourceActionOn(
|
|
auth, resource, "search", self.Search
|
|
)
|
|
|
|
@typing.overload
|
|
def __call__(
|
|
self,
|
|
fn: (
|
|
_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]
|
|
| _ActionHandler[dict[str, typing.Any]]
|
|
),
|
|
) -> _ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]: ...
|
|
|
|
@typing.overload
|
|
def __call__(
|
|
self,
|
|
*,
|
|
resources: str | Sequence[str] | None = None,
|
|
actions: ResourceActionT | Sequence[ResourceActionT] | None = None,
|
|
) -> Callable[
|
|
[_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]],
|
|
_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch],
|
|
]: ...
|
|
|
|
def __call__(
|
|
self,
|
|
fn: (
|
|
_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]
|
|
| _ActionHandler[dict[str, typing.Any]]
|
|
| None
|
|
) = None,
|
|
*,
|
|
resources: str | Sequence[str] | None = None,
|
|
actions: ResourceActionT | Sequence[ResourceActionT] | None = None,
|
|
) -> (
|
|
_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]
|
|
| Callable[
|
|
[_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]],
|
|
_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch],
|
|
]
|
|
):
|
|
def decorator(
|
|
handler: _ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch],
|
|
) -> _ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]:
|
|
_validate_handler(handler)
|
|
if resources is None:
|
|
resource_list = [self.resource]
|
|
elif isinstance(resources, str):
|
|
resource_list = [resources]
|
|
elif isinstance(resources, Sequence):
|
|
resource_list = list(resources)
|
|
else:
|
|
raise TypeError("resources must be a string or sequence of strings")
|
|
if resource_list != [self.resource]:
|
|
raise ValueError(
|
|
f"Resource-specific decorator for {self.resource!r} cannot "
|
|
f"register handlers for {resource_list!r}. Use @auth.on(...) "
|
|
"for other or multiple resources."
|
|
)
|
|
if actions is None:
|
|
action_list = ["*"]
|
|
elif isinstance(actions, str):
|
|
action_list = [actions]
|
|
elif isinstance(actions, Sequence):
|
|
action_list = list(actions)
|
|
else:
|
|
raise TypeError("actions must be a string or sequence of strings")
|
|
if not action_list:
|
|
raise ValueError("actions must not be empty")
|
|
if not all(isinstance(action, str) for action in action_list):
|
|
raise TypeError("actions must be a string or sequence of strings")
|
|
valid_actions = {
|
|
value.action
|
|
for value in vars(self).values()
|
|
if isinstance(value, _ResourceActionOn)
|
|
}
|
|
invalid_actions = (
|
|
sorted(set(action_list) - valid_actions) if actions is not None else []
|
|
)
|
|
if invalid_actions:
|
|
raise ValueError(
|
|
f"Invalid action(s) for {self.resource}: {', '.join(invalid_actions)}"
|
|
)
|
|
if len(action_list) != len(set(action_list)):
|
|
raise ValueError("actions must not contain duplicates")
|
|
for action in action_list:
|
|
if (self.resource, action) in self.auth._handlers:
|
|
raise ValueError(
|
|
f"types.Handler already set for {self.resource}, {action}."
|
|
)
|
|
for action in action_list:
|
|
_register_handler(self.auth, self.resource, action, handler)
|
|
return handler
|
|
|
|
if fn is not None:
|
|
return decorator(
|
|
typing.cast(
|
|
"_ActionHandler[VCreate | VUpdate | VRead | VDelete | VSearch]",
|
|
fn,
|
|
)
|
|
)
|
|
return decorator
|
|
|
|
|
|
class _AssistantsOn(
|
|
_ResourceOn[
|
|
types.AssistantsCreate,
|
|
types.AssistantsRead,
|
|
types.AssistantsUpdate,
|
|
types.AssistantsDelete,
|
|
types.AssistantsSearch,
|
|
_ResourceAction,
|
|
]
|
|
):
|
|
value = (
|
|
types.AssistantsCreate
|
|
| types.AssistantsRead
|
|
| types.AssistantsUpdate
|
|
| types.AssistantsDelete
|
|
| types.AssistantsSearch
|
|
)
|
|
Create = types.AssistantsCreate
|
|
Read = types.AssistantsRead
|
|
Update = types.AssistantsUpdate
|
|
Delete = types.AssistantsDelete
|
|
Search = types.AssistantsSearch
|
|
|
|
|
|
class _ThreadsOn(
|
|
_ResourceOn[
|
|
types.ThreadsCreate,
|
|
types.ThreadsRead,
|
|
types.ThreadsUpdate,
|
|
types.ThreadsDelete,
|
|
types.ThreadsSearch,
|
|
_ThreadAction,
|
|
]
|
|
):
|
|
value = (
|
|
types.ThreadsCreate
|
|
| types.ThreadsRead
|
|
| types.ThreadsUpdate
|
|
| types.ThreadsDelete
|
|
| types.ThreadsSearch
|
|
| types.RunsCreate
|
|
)
|
|
Create = types.ThreadsCreate
|
|
Read = types.ThreadsRead
|
|
Update = types.ThreadsUpdate
|
|
Delete = types.ThreadsDelete
|
|
Search = types.ThreadsSearch
|
|
CreateRun = types.RunsCreate
|
|
|
|
def __init__(
|
|
self,
|
|
auth: Auth,
|
|
resource: typing.Literal["threads", "crons", "assistants"],
|
|
) -> None:
|
|
super().__init__(auth, resource)
|
|
self.create_run: _ResourceActionOn[types.RunsCreate] = _ResourceActionOn(
|
|
auth, resource, "create_run", self.CreateRun
|
|
)
|
|
|
|
|
|
class _CronsOn(
|
|
_ResourceOn[
|
|
types.CronsCreate,
|
|
types.CronsRead,
|
|
types.CronsUpdate,
|
|
types.CronsDelete,
|
|
types.CronsSearch,
|
|
_ResourceAction,
|
|
]
|
|
):
|
|
value = type[
|
|
types.CronsCreate
|
|
| types.CronsRead
|
|
| types.CronsUpdate
|
|
| types.CronsDelete
|
|
| types.CronsSearch
|
|
]
|
|
|
|
Create = types.CronsCreate
|
|
Read = types.CronsRead
|
|
Update = types.CronsUpdate
|
|
Delete = types.CronsDelete
|
|
Search = types.CronsSearch
|
|
|
|
|
|
class _StoreActionOn(typing.Generic[T]):
|
|
"""Decorator for registering a handler for a specific store action."""
|
|
|
|
def __init__(
|
|
self,
|
|
auth: Auth,
|
|
action: typing.Literal["put", "get", "search", "delete", "list_namespaces"],
|
|
value: type[T],
|
|
) -> None:
|
|
self.auth = auth
|
|
self.action = action
|
|
self.value = value
|
|
|
|
def __call__(self, fn: _ActionHandler[T]) -> _ActionHandler[T]:
|
|
_validate_handler(fn)
|
|
_register_handler(self.auth, "store", self.action, fn)
|
|
return fn
|
|
|
|
|
|
class _StoreOn:
|
|
def __init__(self, auth: Auth) -> None:
|
|
self._auth = auth
|
|
self.put = _StoreActionOn(auth, "put", types.StorePut)
|
|
"""Register a handler for store put operations.
|
|
|
|
???+ example "Example"
|
|
If using `@auth.on` to deny by default, register this handler to allow
|
|
put operations (scoped to the user's namespace):
|
|
|
|
```python
|
|
@auth.on.store.put
|
|
async def allow_store_put(ctx: Auth.types.AuthContext, value: Auth.types.on.store.put.value):
|
|
# Allow puts, scoped to user's namespace
|
|
value["namespace"] = (ctx.user.identity, *value["namespace"])
|
|
```
|
|
"""
|
|
self.get = _StoreActionOn(auth, "get", types.StoreGet)
|
|
"""Register a handler for store get operations.
|
|
|
|
???+ example "Example"
|
|
If using `@auth.on` to deny by default, register this handler to allow
|
|
get operations (scoped to the user's namespace):
|
|
|
|
```python
|
|
@auth.on.store.get
|
|
async def allow_store_get(ctx: Auth.types.AuthContext, value: Auth.types.on.store.get.value):
|
|
# Allow gets, scoped to user's namespace
|
|
value["namespace"] = (ctx.user.identity, *value["namespace"])
|
|
```
|
|
"""
|
|
self.search = _StoreActionOn(auth, "search", types.StoreSearch)
|
|
"""Register a handler for store search operations.
|
|
|
|
???+ example "Example"
|
|
If using `@auth.on` to deny by default, register this handler to allow
|
|
search operations (scoped to the user's namespace):
|
|
|
|
```python
|
|
@auth.on.store.search
|
|
async def allow_store_search(ctx: Auth.types.AuthContext, value: Auth.types.on.store.search.value):
|
|
# Allow searches, scoped to user's namespace
|
|
value["namespace"] = (ctx.user.identity, *value["namespace"])
|
|
```
|
|
"""
|
|
self.delete = _StoreActionOn(auth, "delete", types.StoreDelete)
|
|
"""Register a handler for store delete operations.
|
|
|
|
???+ example "Example"
|
|
If using `@auth.on` to deny by default, register this handler to allow
|
|
delete operations (scoped to the user's namespace):
|
|
|
|
```python
|
|
@auth.on.store.delete
|
|
async def allow_store_delete(ctx: Auth.types.AuthContext, value: Auth.types.on.store.delete.value):
|
|
# Allow deletes, scoped to user's namespace
|
|
value["namespace"] = (ctx.user.identity, *value["namespace"])
|
|
```
|
|
"""
|
|
self.list_namespaces = _StoreActionOn(
|
|
auth, "list_namespaces", types.StoreListNamespaces
|
|
)
|
|
"""Register a handler for store list_namespaces operations.
|
|
|
|
???+ example "Example"
|
|
If using `@auth.on` to deny by default, register this handler to allow
|
|
namespace listing (scoped to the user's prefix):
|
|
|
|
```python
|
|
@auth.on.store.list_namespaces
|
|
async def allow_list_ns(ctx: Auth.types.AuthContext, value: Auth.types.on.store.list_namespaces.value):
|
|
# Allow listing, scoped to user's namespace prefix
|
|
value["namespace"] = (ctx.user.identity,)
|
|
```
|
|
"""
|
|
|
|
@typing.overload
|
|
def __call__(
|
|
self,
|
|
*,
|
|
actions: (
|
|
typing.Literal["put", "get", "search", "list_namespaces", "delete"]
|
|
| Sequence[
|
|
typing.Literal["put", "get", "search", "list_namespaces", "delete"]
|
|
]
|
|
| None
|
|
) = None,
|
|
) -> Callable[[AHO], AHO]: ...
|
|
|
|
@typing.overload
|
|
def __call__(self, fn: AHO) -> AHO: ...
|
|
|
|
def __call__(
|
|
self,
|
|
fn: AHO | None = None,
|
|
*,
|
|
actions: (
|
|
typing.Literal["put", "get", "search", "list_namespaces", "delete"]
|
|
| Sequence[
|
|
typing.Literal["put", "get", "search", "list_namespaces", "delete"]
|
|
]
|
|
| None
|
|
) = None,
|
|
) -> AHO | Callable[[AHO], AHO]:
|
|
"""Register a handler for specific resources and actions.
|
|
|
|
Can be used as a decorator or with explicit resource/action parameters:
|
|
|
|
@auth.on.store
|
|
async def handler(): ... # Handle all store ops
|
|
|
|
@auth.on.store(actions=("put", "get", "search", "delete"))
|
|
async def handler(): ... # Handle specific store ops
|
|
|
|
@auth.on.store.put
|
|
async def handler(): ... # Handle store.put ops
|
|
"""
|
|
if fn is not None:
|
|
# Used as a plain decorator
|
|
_register_handler(self._auth, "store", None, fn)
|
|
return fn
|
|
|
|
# Used with parameters, return a decorator
|
|
def decorator(
|
|
handler: AHO,
|
|
) -> AHO:
|
|
if isinstance(actions, str):
|
|
action_list = [actions]
|
|
else:
|
|
action_list = list(actions) if actions is not None else ["*"]
|
|
for action in action_list:
|
|
_register_handler(self._auth, "store", action, handler)
|
|
return handler
|
|
|
|
return decorator
|
|
|
|
|
|
AHO = typing.TypeVar("AHO", bound=_ActionHandler[dict[str, typing.Any]])
|
|
|
|
|
|
class _On:
|
|
"""Entry point for authorization handlers that control access to specific resources.
|
|
|
|
The _On class provides a flexible way to define authorization rules for different resources
|
|
and actions in your application. It supports three main usage patterns:
|
|
|
|
1. Global handlers that run for all resources and actions
|
|
2. Resource-specific handlers that run for all actions on a resource
|
|
3. Resource and action specific handlers for fine-grained control
|
|
|
|
Each handler must be an async function that accepts two parameters:
|
|
- ctx (AuthContext): Contains request context and authenticated user info
|
|
- value: The data being authorized (type varies by endpoint)
|
|
|
|
The handler should return one of:
|
|
- None or True: Accept the request
|
|
- False: Reject with 403 error
|
|
- FilterType: Apply filtering rules to the response
|
|
|
|
???+ example "Examples"
|
|
|
|
Start by denying all requests by default with a global handler,
|
|
then add specific handlers to allow access:
|
|
|
|
```python
|
|
# Default deny: reject all requests without a specific handler
|
|
@auth.on
|
|
async def deny_all(ctx: AuthContext, value: Any) -> False:
|
|
return False
|
|
```
|
|
|
|
Resource-specific handler to allow access (takes precedence
|
|
over the global deny handler):
|
|
|
|
```python
|
|
@auth.on.threads
|
|
async def allow_thread_access(ctx: AuthContext, value: Any) -> Auth.types.FilterType:
|
|
# Allow access only to threads owned by the user
|
|
return {"owner": ctx.user.identity}
|
|
```
|
|
|
|
Resource and action specific handler:
|
|
|
|
```python
|
|
@auth.on.threads.create
|
|
async def allow_thread_create(ctx: AuthContext, value: Any) -> None:
|
|
# Allow thread creation, stamping the owner
|
|
value.setdefault("metadata", {})["owner"] = ctx.user.identity
|
|
```
|
|
|
|
Multiple resources or actions:
|
|
|
|
```python
|
|
@auth.on(resources=["threads", "assistants"], actions=["read", "search"])
|
|
async def allow_reads(ctx: AuthContext, value: Any) -> Auth.types.FilterType:
|
|
# Allow read/search, scoped to user's resources
|
|
return {"owner": ctx.user.identity}
|
|
```
|
|
"""
|
|
|
|
__slots__ = (
|
|
"_auth",
|
|
"assistants",
|
|
"crons",
|
|
"runs",
|
|
"store",
|
|
"threads",
|
|
"value",
|
|
)
|
|
|
|
def __init__(self, auth: Auth) -> None:
|
|
self._auth = auth
|
|
self.assistants = _AssistantsOn(auth, "assistants")
|
|
self.threads = _ThreadsOn(auth, "threads")
|
|
self.crons = _CronsOn(auth, "crons")
|
|
self.store = _StoreOn(auth)
|
|
self.value = dict[str, typing.Any]
|
|
|
|
@typing.overload
|
|
def __call__(
|
|
self,
|
|
*,
|
|
resources: str | Sequence[str],
|
|
actions: str | Sequence[str] | None = None,
|
|
) -> Callable[[AHO], AHO]: ...
|
|
|
|
@typing.overload
|
|
def __call__(self, fn: AHO) -> AHO: ...
|
|
|
|
def __call__(
|
|
self,
|
|
fn: AHO | None = None,
|
|
*,
|
|
resources: str | Sequence[str] | None = None,
|
|
actions: str | Sequence[str] | None = None,
|
|
) -> AHO | Callable[[AHO], AHO]:
|
|
"""Register a handler for specific resources and actions.
|
|
|
|
Can be used as a decorator or with explicit resource/action parameters:
|
|
|
|
@auth.on
|
|
async def handler(): ... # Global handler
|
|
|
|
@auth.on(resources="threads")
|
|
async def handler(): ... # types.Handler for all thread actions
|
|
|
|
@auth.on(resources="threads", actions="create")
|
|
async def handler(): ... # types.Handler for thread creation
|
|
"""
|
|
if fn is not None:
|
|
# Used as a plain decorator
|
|
_register_handler(self._auth, None, None, fn)
|
|
return fn
|
|
|
|
# Used with parameters, return a decorator
|
|
def decorator(
|
|
handler: AHO,
|
|
) -> AHO:
|
|
if isinstance(resources, str):
|
|
resource_list = [resources]
|
|
else:
|
|
resource_list = list(resources) if resources is not None else ["*"]
|
|
|
|
if isinstance(actions, str):
|
|
action_list = [actions]
|
|
else:
|
|
action_list = list(actions) if actions is not None else ["*"]
|
|
for resource in resource_list:
|
|
for action in action_list:
|
|
_register_handler(self._auth, resource, action, handler)
|
|
return handler
|
|
|
|
return decorator
|
|
|
|
|
|
def _register_handler(
|
|
auth: Auth,
|
|
resource: str | None,
|
|
action: str | None,
|
|
fn: types.Handler,
|
|
) -> types.Handler:
|
|
_validate_handler(fn)
|
|
resource = resource or "*"
|
|
action = action or "*"
|
|
if resource == "*" and action == "*":
|
|
if auth._global_handlers:
|
|
raise ValueError("Global handler already set.")
|
|
auth._global_handlers.append(fn)
|
|
else:
|
|
r = resource if resource is not None else "*"
|
|
a = action if action is not None else "*"
|
|
if (r, a) in auth._handlers:
|
|
raise ValueError(f"types.Handler already set for {r}, {a}.")
|
|
auth._handlers[(r, a)] = [fn]
|
|
return fn
|
|
|
|
|
|
def _validate_handler(fn: Callable[..., typing.Any]) -> None:
|
|
"""Validates that an auth handler function meets the required signature.
|
|
|
|
Auth handlers must:
|
|
1. Be async functions
|
|
2. Accept a ctx parameter of type AuthContext
|
|
3. Accept a value parameter for the data being authorized
|
|
"""
|
|
if not inspect.iscoroutinefunction(fn):
|
|
raise ValueError(
|
|
f"Auth handler '{getattr(fn, '__name__', fn)}' must be an async function. "
|
|
"Add 'async' before 'def' to make it asynchronous and ensure"
|
|
" any IO operations are non-blocking."
|
|
)
|
|
|
|
sig = inspect.signature(fn)
|
|
if "ctx" not in sig.parameters:
|
|
raise ValueError(
|
|
f"Auth handler '{getattr(fn, '__name__', fn)}' must have a 'ctx: AuthContext' parameter. "
|
|
"Update the function signature to include this required parameter."
|
|
)
|
|
if "value" not in sig.parameters:
|
|
raise ValueError(
|
|
f"Auth handler '{getattr(fn, '__name__', fn)}' must have a 'value' parameter. "
|
|
" The value contains the mutable data being sent to the endpoint."
|
|
"Update the function signature to include this required parameter."
|
|
)
|
|
|
|
|
|
def is_studio_user(
|
|
user: types.MinimalUser | types.BaseUser | types.MinimalUserDict,
|
|
) -> bool:
|
|
return isinstance(user, types.StudioUser) or (
|
|
isinstance(user, dict) and user.get("kind") == "StudioUser"
|
|
)
|
|
|
|
|
|
__all__ = ["Auth", "exceptions", "types"]
|