From a5396fe0f35402e1ce22ec5323139f7f785490c1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Pedro=20Brun?= Date: Thu, 10 Sep 2026 17:20:36 -0300 Subject: [PATCH 1/6] first changes --- .../core/auditlog_ng/user-guide.md | 66 ++++++++----------- 1 file changed, 28 insertions(+), 38 deletions(-) diff --git a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md index 3052f85d..8aa3116b 100644 --- a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md +++ b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md @@ -1,9 +1,6 @@ -# Using the `auditlog_ng` Client in an Agent +# Audit Log NG User Guide -This module provides an OTLP/gRPC client for sending structured audit log events - to the SAP Audit Log Service (v3/NG). It supports mTLS, insecure mode for local - testing, and both binary protobuf and JSON serialization formats. ---- +This module provides an OTLP/gRPC client for sending structured audit log events to the SAP Audit Log Service (v3/NG). It supports mTLS, insecure mode for local testing, and both binary protobuf and JSON serialization formats. ## Overview @@ -39,17 +36,18 @@ The client depends on generated protobuf classes. `create_client` supports three mutually exclusive ways to provide configuration, evaluated in this order: -1. **Explicit config object** — pass a pre-built `AuditLogNGConfig` via `config=`. -2. **Destination-based resolution** — pass `destination_name` and `destination_instance`; connection parameters are resolved from the named SAP Destination automatically. +1. **Destination-based resolution (recommended)** — pass `tenant`; connection parameters are resolved from the named SAP Destination automatically. This is the recommended path for SPII-based deployments. +2. **Explicit config object** — pass a pre-built `AuditLogNGConfig` via `config=`. 3. **Explicit keyword arguments** — pass `endpoint`, `deployment_id`, and `namespace` directly. ### Destination-based configuration parameters -| Parameter | Type | Required | Description | -|------------------------|--------|----------|-------------| -| `destination_name` | `str` | ✅ Yes | Name of the SAP Destination to resolve. | -| `destination_instance` | `str` | ❌ No | Destination service binding instance name. | -| `fragment_name` | `str` | ❌ No | Destination fragment merged before resolution (for tenant-specific overrides). | +| Parameter | Type | Required | Default | Description | +|------------------------|--------|----------|----------------------------|-------------| +| `tenant` | `str` | ✅ Yes | — | Tenant subdomain. **Required to activate destination-based resolution.** | +| `destination_name` | `str` | ❌ No | `"AuditLogV3_Destination"` | Name of the SAP Destination to resolve. | +| `destination_instance` | `str` | ❌ No | `"default"` | Destination service binding instance name. | +| `fragment_name` | `str` | ❌ No | `None` | Destination fragment merged before resolution (for tenant-specific overrides). Follows the pattern `AuditLogV3_Fragment_{tenant_subdomain}`. | The destination must expose these custom properties: @@ -109,27 +107,31 @@ from sap_cloud_sdk.core.auditlog_ng.gen.sap.auditlog.auditevent.v2 import ( **From a Destination (SPII-based deployments):** +The minimal recommended call is just `tenant` — `destination_name` and `destination_instance` +default to the values provisioned for SPII-based deployments: + ```python -client = create_client( - destination_name="my_destination", - destination_instance="my-destination-binding", - # fragment_name="prod-fragment", # optional: merge a tenant-specific fragment -) +client = create_client(tenant="tenant_subdomain") ``` The SDK resolves `endpoint`, `deployment_id`, and `namespace` from the destination automatically. -You can still pass connection options alongside the destination parameters: +You can spell out the destination parameters and pass connection options alongside: ```python client = create_client( - destination_name="my_destination", - destination_instance="my-destination-binding", - fragment_name="prod-fragment", + tenant="tenant_subdomain", # required to activate destination resolution + destination_name="AuditLogV3_Destination", # optional — this is the default + destination_instance="default", # optional — this is the default + # fragment_name="AuditLogV3_Fragment_tenant_subdomain", # optional tenant-specific fragment service_name="my-agent", batch=True, ) ``` +> **Note:** Omitting `tenant` disables destination resolution — `create_client` then expects +> `endpoint`, `deployment_id`, and `namespace` (or a `config=` object) and raises `ValueError` +> otherwise. + **With mTLS (explicit configuration):** ```python @@ -154,7 +156,7 @@ client = create_client( ) ``` -> ⚠️ **Important:** `deployment_id` and `namespace` are validated at construction time. +> **Important:** `deployment_id` and `namespace` are validated at construction time. > Invalid values (e.g. containing spaces) will raise a `ValueError`. ### Step 3: Build an Audit Event @@ -211,14 +213,8 @@ from datetime import datetime, timezone class AgentAuditLogger: - def __init__(self): - self.client = create_client( - endpoint="us30.als.services.cloud.sap:443", - deployment_id="us30-staging", - namespace="sap.als", - cert_file="/path/to/client-certificate_chain.pem", - key_file="/path/to/private-key.pem", - ) + def __init__(self, tenant: str): + self.client = create_client(tenant=tenant) def log_data_access(self, user: str, tenant_id: str, resource: str): event = pb.DataAccess() @@ -238,7 +234,7 @@ class AgentAuditLogger: # In your agent main loop -audit_logger = AgentAuditLogger() +audit_logger = AgentAuditLogger(tenant="tenant_subdomain") try: event_id = audit_logger.log_data_access( user="agent-user@example.com", @@ -259,13 +255,7 @@ For simple, one-off audit events without managing a persistent client: ```python from sap_cloud_sdk.core.auditlog_ng import create_client -with create_client( - endpoint="us30.als.services.cloud.sap:443", - deployment_id="us30-staging", - namespace="sap.als", - cert_file="/path/to/cert.pem", - key_file="/path/to/key.pem", -) as client: +with create_client(tenant="tenant_subdomain") as client: event_id = client.send(event) ``` From 13cafbd1e971f6e0be651c5f10c2b1f20ef2b7a6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Pedro=20Brun?= Date: Fri, 11 Sep 2026 16:40:13 -0300 Subject: [PATCH 2/6] docs(auditlog_ng): align user-guide with repo conventions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - fold Overview into intro; drop duplicate section - normalize headings to Title Case; drop stray trailing colon - replace ✅/❌ with plain Yes/No in config tables - correct config-path precedence ordering (config > tenant > kwargs) - fix Validation section: ValidationError for schema failures, RuntimeError for closed client; remove nonexistent tenant_id UUID-validation claim - remove duplicate Import section and idiosyncratic 'Running the Unit Tests' section --- .../core/auditlog_ng/user-guide.md | 60 ++++++++----------- 1 file changed, 24 insertions(+), 36 deletions(-) diff --git a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md index 8aa3116b..d2797c24 100644 --- a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md +++ b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md @@ -1,10 +1,6 @@ # Audit Log NG User Guide -This module provides an OTLP/gRPC client for sending structured audit log events to the SAP Audit Log Service (v3/NG). It supports mTLS, insecure mode for local testing, and both binary protobuf and JSON serialization formats. - -## Overview - -The Auditlog NG client sends audit log events as OpenTelemetry (OTLP) LogRecords over gRPC to the SAP Audit Log Service. It supports: +This module provides an OTLP/gRPC client for sending structured audit log events to the SAP Audit Log Service (v3/NG). It sends events as OpenTelemetry (OTLP) LogRecords over gRPC and supports: - **mTLS** (mutual TLS with client certificates) - **Insecure** mode (local testing / no-auth) @@ -34,46 +30,46 @@ The client depends on generated protobuf classes. ## Configuration -`create_client` supports three mutually exclusive ways to provide configuration, evaluated in this order: +`create_client` supports three mutually exclusive ways to provide configuration. They are evaluated in this order of precedence: -1. **Destination-based resolution (recommended)** — pass `tenant`; connection parameters are resolved from the named SAP Destination automatically. This is the recommended path for SPII-based deployments. -2. **Explicit config object** — pass a pre-built `AuditLogNGConfig` via `config=`. +1. **Explicit config object** — pass a pre-built `AuditLogNGConfig` via `config=`. When provided, it takes precedence over the other paths. +2. **Destination-based resolution (recommended)** — pass `tenant`; connection parameters are resolved from the named SAP Destination automatically. This is the recommended path for SPII-based deployments. 3. **Explicit keyword arguments** — pass `endpoint`, `deployment_id`, and `namespace` directly. ### Destination-based configuration parameters | Parameter | Type | Required | Default | Description | |------------------------|--------|----------|----------------------------|-------------| -| `tenant` | `str` | ✅ Yes | — | Tenant subdomain. **Required to activate destination-based resolution.** | -| `destination_name` | `str` | ❌ No | `"AuditLogV3_Destination"` | Name of the SAP Destination to resolve. | -| `destination_instance` | `str` | ❌ No | `"default"` | Destination service binding instance name. | -| `fragment_name` | `str` | ❌ No | `None` | Destination fragment merged before resolution (for tenant-specific overrides). Follows the pattern `AuditLogV3_Fragment_{tenant_subdomain}`. | +| `tenant` | `str` | Yes | — | Tenant subdomain. **Required to activate destination-based resolution.** | +| `destination_name` | `str` | No | `"AuditLogV3_Destination"` | Name of the SAP Destination to resolve. | +| `destination_instance` | `str` | No | `"default"` | Destination service binding instance name. | +| `fragment_name` | `str` | No | `None` | Destination fragment merged before resolution (for tenant-specific overrides). Follows the pattern `AuditLogV3_Fragment_{tenant_subdomain}`. | The destination must expose these custom properties: | Property | Required | Description | |--------------------|----------|-------------| -| `deploymentId` | ✅ Yes (or `deploymentRegion`) | Deployment identifier. Falls back to `deploymentRegion` when absent or empty. | -| `deploymentRegion` | ✅ Fallback | Used as `deployment_id` when `deploymentId` is missing or empty. | -| `namespace` | ✅ Yes | Audit log namespace (e.g. `sap.als`). | +| `deploymentId` | Yes (or `deploymentRegion`) | Deployment identifier. Falls back to `deploymentRegion` when absent or empty. | +| `deploymentRegion` | Fallback | Used as `deployment_id` when `deploymentId` is missing or empty. | +| `namespace` | Yes | Audit log namespace (e.g. `sap.als`). | The destination `url` is used as the OTLP endpoint. The lookup is always performed at subaccount level. -### Explicit configuration parameters for `AuditClient`: +### Explicit configuration parameters for `AuditClient` | Parameter | Type | Required | Default | Description | |-----------------|---------|----------|----------------|-------------------------------------------------------------------------------------------------------| -| `endpoint` | `str` | ✅ Yes | — | OTLP endpoint of the Audit Log Service (`host:port`) | -| `deployment_id` | `str` | ✅ Yes | — | Deployment/region identifier. Validated: only `[a-zA-Z0-9._-/~]` allowed. Raises `ValueError` if invalid. | -| `namespace` | `str` | ✅ Yes | — | Audit log namespace (e.g. `sap.als`). Same character-set validation as `deployment_id`. | -| `cert_file` | `str` | ❌ No | `None` | Path to the mTLS client certificate file (PEM). Required together with `key_file` for mTLS. | -| `key_file` | `str` | ❌ No | `None` | Path to the mTLS client private key file (PEM). Required together with `cert_file` for mTLS. | -| `ca_file` | `str` | ❌ No | `None` | Path to a custom CA certificate (PEM) for server verification. Uses system trust store if omitted. | -| `insecure` | `bool` | ❌ No | `False` | Disable TLS entirely (plaintext gRPC). | -| `service_name` | `str` | ❌ No | `"audit-client"` | OpenTelemetry `service.name` resource attribute attached to every log record. | -| `batch` | `bool` | ❌ No | `False` | When `True`, uses `BatchLogRecordProcessor` (better throughput, small delay). When `False`, uses `SimpleLogRecordProcessor` (immediate, lower throughput). | -| `compression` | `bool` | ❌ No | `True` | Enable gzip compression on the gRPC channel (`grpc.Compression.Gzip`). Set to `False` to disable. | -| `schema_url` | `str` | ❌ No | `SCHEMA_URL` | OpenTelemetry schema URL attached to the logger. Defaults to the canonical ALS proto schema URL. | +| `endpoint` | `str` | Yes | — | OTLP endpoint of the Audit Log Service (`host:port`) | +| `deployment_id` | `str` | Yes | — | Deployment/region identifier. Validated: only `[a-zA-Z0-9._-/~]` allowed. Raises `ValueError` if invalid. | +| `namespace` | `str` | Yes | — | Audit log namespace (e.g. `sap.als`). Same character-set validation as `deployment_id`. | +| `cert_file` | `str` | No | `None` | Path to the mTLS client certificate file (PEM). Required together with `key_file` for mTLS. | +| `key_file` | `str` | No | `None` | Path to the mTLS client private key file (PEM). Required together with `cert_file` for mTLS. | +| `ca_file` | `str` | No | `None` | Path to a custom CA certificate (PEM) for server verification. Uses system trust store if omitted. | +| `insecure` | `bool` | No | `False` | Disable TLS entirely (plaintext gRPC). | +| `service_name` | `str` | No | `"audit-client"` | OpenTelemetry `service.name` resource attribute attached to every log record. | +| `batch` | `bool` | No | `False` | When `True`, uses `BatchLogRecordProcessor` (better throughput, small delay). When `False`, uses `SimpleLogRecordProcessor` (immediate, lower throughput). | +| `compression` | `bool` | No | `True` | Enable gzip compression on the gRPC channel (`grpc.Compression.Gzip`). Set to `False` to disable. | +| `schema_url` | `str` | No | `SCHEMA_URL` | OpenTelemetry schema URL attached to the logger. Defaults to the canonical ALS proto schema URL. | ### Example values @@ -288,7 +284,7 @@ Events are validated against protobuf constraints using `protovalidate` before s --- -## Automatic tenant and user injection +## Automatic Tenant and User Injection When `StarletteIASTelemetryMiddleware` is registered on your app, it parses the incoming `Authorization: Bearer ` header on every request and stores the @@ -334,11 +330,3 @@ event_id = client.send(event) If neither the middleware nor an explicit value provides `tenant_id`, the event will fail `protovalidate` validation and raise a `ValidationError`. - ---- - -## Running the Unit Tests - -```bash - uv run pytest tests/core/unit/auditlog_ng/ -``` From f58fa41cb092a382d81a2e2c6c4442d3f4165e3a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Pedro=20Brun?= Date: Fri, 11 Sep 2026 17:15:18 -0300 Subject: [PATCH 3/6] padronize user-guide --- .../core/auditlog_ng/user-guide.md | 225 +++++++++--------- 1 file changed, 110 insertions(+), 115 deletions(-) diff --git a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md index d2797c24..bdfd41e2 100644 --- a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md +++ b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md @@ -7,11 +7,9 @@ This module provides an OTLP/gRPC client for sending structured audit log events - **Binary protobuf** and **JSON** serialization formats - **Destination-based configuration** — resolve connection parameters automatically from a named SAP Destination (SPII-based deployments) ---- +## Installation -## Prerequisites - -### 1. Required Dependencies +### Required Dependencies ``` grpcio>=1.60.0 @@ -22,95 +20,45 @@ opentelemetry-sdk>=1.28.0 opentelemetry-exporter-otlp-proto-grpc>=1.28.0 ``` -### 2. Generated Protobuf Code +### Generated Protobuf Code The client depends on generated protobuf classes. ---- - -## Configuration - -`create_client` supports three mutually exclusive ways to provide configuration. They are evaluated in this order of precedence: - -1. **Explicit config object** — pass a pre-built `AuditLogNGConfig` via `config=`. When provided, it takes precedence over the other paths. -2. **Destination-based resolution (recommended)** — pass `tenant`; connection parameters are resolved from the named SAP Destination automatically. This is the recommended path for SPII-based deployments. -3. **Explicit keyword arguments** — pass `endpoint`, `deployment_id`, and `namespace` directly. - -### Destination-based configuration parameters - -| Parameter | Type | Required | Default | Description | -|------------------------|--------|----------|----------------------------|-------------| -| `tenant` | `str` | Yes | — | Tenant subdomain. **Required to activate destination-based resolution.** | -| `destination_name` | `str` | No | `"AuditLogV3_Destination"` | Name of the SAP Destination to resolve. | -| `destination_instance` | `str` | No | `"default"` | Destination service binding instance name. | -| `fragment_name` | `str` | No | `None` | Destination fragment merged before resolution (for tenant-specific overrides). Follows the pattern `AuditLogV3_Fragment_{tenant_subdomain}`. | - -The destination must expose these custom properties: - -| Property | Required | Description | -|--------------------|----------|-------------| -| `deploymentId` | Yes (or `deploymentRegion`) | Deployment identifier. Falls back to `deploymentRegion` when absent or empty. | -| `deploymentRegion` | Fallback | Used as `deployment_id` when `deploymentId` is missing or empty. | -| `namespace` | Yes | Audit log namespace (e.g. `sap.als`). | - -The destination `url` is used as the OTLP endpoint. The lookup is always performed at subaccount level. - -### Explicit configuration parameters for `AuditClient` - -| Parameter | Type | Required | Default | Description | -|-----------------|---------|----------|----------------|-------------------------------------------------------------------------------------------------------| -| `endpoint` | `str` | Yes | — | OTLP endpoint of the Audit Log Service (`host:port`) | -| `deployment_id` | `str` | Yes | — | Deployment/region identifier. Validated: only `[a-zA-Z0-9._-/~]` allowed. Raises `ValueError` if invalid. | -| `namespace` | `str` | Yes | — | Audit log namespace (e.g. `sap.als`). Same character-set validation as `deployment_id`. | -| `cert_file` | `str` | No | `None` | Path to the mTLS client certificate file (PEM). Required together with `key_file` for mTLS. | -| `key_file` | `str` | No | `None` | Path to the mTLS client private key file (PEM). Required together with `cert_file` for mTLS. | -| `ca_file` | `str` | No | `None` | Path to a custom CA certificate (PEM) for server verification. Uses system trust store if omitted. | -| `insecure` | `bool` | No | `False` | Disable TLS entirely (plaintext gRPC). | -| `service_name` | `str` | No | `"audit-client"` | OpenTelemetry `service.name` resource attribute attached to every log record. | -| `batch` | `bool` | No | `False` | When `True`, uses `BatchLogRecordProcessor` (better throughput, small delay). When `False`, uses `SimpleLogRecordProcessor` (immediate, lower throughput). | -| `compression` | `bool` | No | `True` | Enable gzip compression on the gRPC channel (`grpc.Compression.Gzip`). Set to `False` to disable. | -| `schema_url` | `str` | No | `SCHEMA_URL` | OpenTelemetry schema URL attached to the logger. Defaults to the canonical ALS proto schema URL. | - -### Example values +## Quick Start -| Parameter | Production example | -|-----------------|---------------------------------------------------| -| `endpoint` | `us30.als.services.cloud.sap:443` | -| `deployment_id` | `us30-staging` | -| `namespace` | `sap.als` | -| `cert_file` | `/path/to/client-certificate_chain.pem` | -| `key_file` | `/path/to/private-key.pem` | -| `ca_file` | `/path/to/ca.pem` | -| `insecure` | `False` | -| `service_name` | `"my-agent"` | -| `batch` | `True` (high-throughput agents) | -| `compression` | `True` | - ---- - -## Usage in an Agent - -### Step 1: Import the Client and Generated Protobuf +The minimal recommended call is just `tenant` — `destination_name` and `destination_instance` +default to the values provisioned for SPII-based deployments: ```python -from sap_cloud_sdk.core.auditlog_ng import create_client, AuditLogNGConfig +from sap_cloud_sdk.core.auditlog_ng import create_client from sap_cloud_sdk.core.auditlog_ng.gen.sap.auditlog.auditevent.v2 import ( auditevent_pb2 as pb, ) -``` - -### Step 2: Initialize the Client +from datetime import datetime, timezone -**From a Destination (SPII-based deployments):** +client = create_client(tenant="tenant_subdomain") -The minimal recommended call is just `tenant` — `destination_name` and `destination_instance` -default to the values provisioned for SPII-based deployments: +event = pb.DataAccess() +event.common.timestamp.FromDatetime(datetime.now(timezone.utc)) +event.common.user_initiator_id = "agent@example.com" +event.common.tenant_id = "9e0d89c9-17cd-439d-8a8b-9c44d3d272f0" +event.channel_type = "API" +event.channel_id = "agent-v1" +event.object_type = "resource" +event.object_id = "resource-001" -```python -client = create_client(tenant="tenant_subdomain") +event_id = client.send(event) +client.close() ``` The SDK resolves `endpoint`, `deployment_id`, and `namespace` from the destination automatically. + +## Usage + +### Initialize the Client + +**From a Destination (SPII-based deployments):** + You can spell out the destination parameters and pass connection options alongside: ```python @@ -155,7 +103,7 @@ client = create_client( > **Important:** `deployment_id` and `namespace` are validated at construction time. > Invalid values (e.g. containing spaces) will raise a `ValueError`. -### Step 3: Build an Audit Event +### Build an Audit Event ```python event = pb.DataAccess() @@ -168,9 +116,9 @@ event.object_type = "resource" event.object_id = "resource-001" ``` -> **Tip:** When using `StarletteIASTelemetryMiddleware` (see [Automatic tenant and user injection](#automatic-tenant-and-user-injection)), `common.tenant_id` and `common.user_initiator_id` are filled automatically from the incoming IAS JWT. You only need to set them explicitly if you want to override the values from the token. +> **Tip:** When using `StarletteIASTelemetryMiddleware` (see [Automatic Tenant and User Injection](#automatic-tenant-and-user-injection)), `common.tenant_id` and `common.user_initiator_id` are filled automatically from the incoming IAS JWT. You only need to set them explicitly if you want to override the values from the token. -### Step 4: Send the Event +### Send the Event **Binary protobuf:** @@ -185,8 +133,7 @@ print(f"Sent event with ID: {event_id}") event_id = client.send_json(event) ``` - -### Step 5: Close the Client +### Close the Client Always close the client when the agent shuts down to flush pending events: @@ -196,9 +143,7 @@ client.close() > Calling `send()` on a closed client raises a `RuntimeError`. ---- - -## Full Agent Integration Example +### Full Agent Integration Example ```python from sap_cloud_sdk.core.auditlog_ng import create_client @@ -242,9 +187,7 @@ finally: audit_logger.shutdown() ``` ---- - -## One-Off Sends (Convenience Function) +### One-Off Sends (Convenience Function) For simple, one-off audit events without managing a persistent client: @@ -255,36 +198,14 @@ with create_client(tenant="tenant_subdomain") as client: event_id = client.send(event) ``` ---- - -## Event Serialization Formats +### Event Serialization Formats | Method | Format | MIME Type | |---------------|--------------------|------------------------| | `send()` | Binary protobuf | `application/protobuf` | | `send_json()` | JSON | `application/json` | ---- - -## Multi-tenancy - -- **Supported:** N/A at auth level -- **Authentication:** None (uses Destination Service / SPII for transport) -- **How to use:** Tenant identity is embedded in each event payload via the `tenant_id` field. Transport and auth are handled by the Destination Service / SPII. This module is only available through SAP for ME. -- **Further reading:** - - [SAP Audit Log Service — SAP Help Portal](https://help.sap.com/docs/btp/sap-business-technology-platform/audit-log-service) - -## Validation - -Events are validated against protobuf constraints using `protovalidate` before sending. A `ValueError` is raised if: - -- The event fails schema validation -- The `tenant_id` is not a valid UUID -- The client has already been closed - ---- - -## Automatic Tenant and User Injection +### Automatic Tenant and User Injection When `StarletteIASTelemetryMiddleware` is registered on your app, it parses the incoming `Authorization: Bearer ` header on every request and stores the @@ -299,7 +220,7 @@ already set by the caller: | `common.tenant_id` | `app_tid` | | `common.user_initiator_id` | `user_uuid` | -### Setup +#### Setup Register the middleware once when your app starts: @@ -311,7 +232,7 @@ app = FastAPI(...) auto_instrument(middlewares=[StarletteIASTelemetryMiddleware(app=app)]) ``` -### Usage +#### Usage With the middleware in place, you can omit `tenant_id` and `user_initiator_id` from every event — they are injected automatically: @@ -330,3 +251,77 @@ event_id = client.send(event) If neither the middleware nor an explicit value provides `tenant_id`, the event will fail `protovalidate` validation and raise a `ValidationError`. + +## Configuration + +`create_client` supports three mutually exclusive ways to provide configuration. They are evaluated in this order of precedence: + +1. **Explicit config object** — pass a pre-built `AuditLogNGConfig` via `config=`. When provided, it takes precedence over the other paths. +2. **Destination-based resolution (recommended)** — pass `tenant`; connection parameters are resolved from the named SAP Destination automatically. This is the recommended path for SPII-based deployments. +3. **Explicit keyword arguments** — pass `endpoint`, `deployment_id`, and `namespace` directly. + +### Destination-based configuration parameters + +| Parameter | Type | Required | Default | Description | +|------------------------|--------|----------|----------------------------|-------------| +| `tenant` | `str` | Yes | — | Tenant subdomain. **Required to activate destination-based resolution.** | +| `destination_name` | `str` | No | `"AuditLogV3_Destination"` | Name of the SAP Destination to resolve. | +| `destination_instance` | `str` | No | `"default"` | Destination service binding instance name. | +| `fragment_name` | `str` | No | `None` | Destination fragment merged before resolution (for tenant-specific overrides). Follows the pattern `AuditLogV3_Fragment_{tenant_subdomain}`. | + +The destination must expose these custom properties: + +| Property | Required | Description | +|--------------------|----------|-------------| +| `deploymentId` | Yes (or `deploymentRegion`) | Deployment identifier. Falls back to `deploymentRegion` when absent or empty. | +| `deploymentRegion` | Fallback | Used as `deployment_id` when `deploymentId` is missing or empty. | +| `namespace` | Yes | Audit log namespace (e.g. `sap.als`). | + +The destination `url` is used as the OTLP endpoint. The lookup is always performed at subaccount level. + +### Explicit configuration parameters for `AuditClient` + +| Parameter | Type | Required | Default | Description | +|-----------------|---------|----------|----------------|-------------------------------------------------------------------------------------------------------| +| `endpoint` | `str` | Yes | — | OTLP endpoint of the Audit Log Service (`host:port`) | +| `deployment_id` | `str` | Yes | — | Deployment/region identifier. Validated: only `[a-zA-Z0-9._-/~]` allowed. Raises `ValueError` if invalid. | +| `namespace` | `str` | Yes | — | Audit log namespace (e.g. `sap.als`). Same character-set validation as `deployment_id`. | +| `cert_file` | `str` | No | `None` | Path to the mTLS client certificate file (PEM). Required together with `key_file` for mTLS. | +| `key_file` | `str` | No | `None` | Path to the mTLS client private key file (PEM). Required together with `cert_file` for mTLS. | +| `ca_file` | `str` | No | `None` | Path to a custom CA certificate (PEM) for server verification. Uses system trust store if omitted. | +| `insecure` | `bool` | No | `False` | Disable TLS entirely (plaintext gRPC). | +| `service_name` | `str` | No | `"audit-client"` | OpenTelemetry `service.name` resource attribute attached to every log record. | +| `batch` | `bool` | No | `False` | When `True`, uses `BatchLogRecordProcessor` (better throughput, small delay). When `False`, uses `SimpleLogRecordProcessor` (immediate, lower throughput). | +| `compression` | `bool` | No | `True` | Enable gzip compression on the gRPC channel (`grpc.Compression.Gzip`). Set to `False` to disable. | +| `schema_url` | `str` | No | `SCHEMA_URL` | OpenTelemetry schema URL attached to the logger. Defaults to the canonical ALS proto schema URL. | + +### Example values + +| Parameter | Production example | +|-----------------|---------------------------------------------------| +| `endpoint` | `us30.als.services.cloud.sap:443` | +| `deployment_id` | `us30-staging` | +| `namespace` | `sap.als` | +| `cert_file` | `/path/to/client-certificate_chain.pem` | +| `key_file` | `/path/to/private-key.pem` | +| `ca_file` | `/path/to/ca.pem` | +| `insecure` | `False` | +| `service_name` | `"my-agent"` | +| `batch` | `True` (high-throughput agents) | +| `compression` | `True` | + +## Multi-tenancy + +- **Supported:** N/A at auth level +- **Authentication:** None (uses Destination Service / SPII for transport) +- **How to use:** Tenant identity is embedded in each event payload via the `tenant_id` field. Transport and auth are handled by the Destination Service / SPII. This module is only available through SAP for ME. +- **Further reading:** + - [SAP Audit Log Service — SAP Help Portal](https://help.sap.com/docs/btp/sap-business-technology-platform/audit-log-service) + +## Error Handling + +Events are validated against protobuf constraints using `protovalidate` before sending. A `ValueError` is raised if: + +- The event fails schema validation +- The `tenant_id` is not a valid UUID +- The client has already been closed From 6bbd29dad255764f35b3ad05713cb43ce377bb92 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Pedro=20Brun?= Date: Fri, 11 Sep 2026 17:32:58 -0300 Subject: [PATCH 4/6] change error-handling section and regex --- src/sap_cloud_sdk/core/auditlog_ng/user-guide.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md index bdfd41e2..4110ab72 100644 --- a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md +++ b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md @@ -284,7 +284,7 @@ The destination `url` is used as the OTLP endpoint. The lookup is always perform | Parameter | Type | Required | Default | Description | |-----------------|---------|----------|----------------|-------------------------------------------------------------------------------------------------------| | `endpoint` | `str` | Yes | — | OTLP endpoint of the Audit Log Service (`host:port`) | -| `deployment_id` | `str` | Yes | — | Deployment/region identifier. Validated: only `[a-zA-Z0-9._-/~]` allowed. Raises `ValueError` if invalid. | +| `deployment_id` | `str` | Yes | — | Deployment/region identifier. Validated: only `[a-zA-Z0-9._/~-]` allowed. Raises `ValueError` if invalid. | | `namespace` | `str` | Yes | — | Audit log namespace (e.g. `sap.als`). Same character-set validation as `deployment_id`. | | `cert_file` | `str` | No | `None` | Path to the mTLS client certificate file (PEM). Required together with `key_file` for mTLS. | | `key_file` | `str` | No | `None` | Path to the mTLS client private key file (PEM). Required together with `cert_file` for mTLS. | @@ -320,8 +320,9 @@ The destination `url` is used as the OTLP endpoint. The lookup is always perform ## Error Handling -Events are validated against protobuf constraints using `protovalidate` before sending. A `ValueError` is raised if: +Events are validated against protobuf constraints using `protovalidate` before sending. +`AuditClient.send()` (and `send_json()`) can raise: -- The event fails schema validation -- The `tenant_id` is not a valid UUID -- The client has already been closed +- `ValidationError` — the event fails `protovalidate` schema validation. This is a subclass of `AuditLogNGError`. +- `ValueError` — `common.tenant_id` is not a string, or contains characters outside `[a-zA-Z0-9._/~-]`. +- `RuntimeError` — `send()` was called on a client that has already been closed. From 2bc8c51878f46090c75865ed3e3d0b4ef27336f9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Pedro=20Brun?= Date: Fri, 11 Sep 2026 18:08:25 -0300 Subject: [PATCH 5/6] recommend bootstrap for new users --- .../core/auditlog_ng/user-guide.md | 41 ++++++++++++++----- 1 file changed, 30 insertions(+), 11 deletions(-) diff --git a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md index 4110ab72..5021b9f4 100644 --- a/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md +++ b/src/sap_cloud_sdk/core/auditlog_ng/user-guide.md @@ -116,7 +116,7 @@ event.object_type = "resource" event.object_id = "resource-001" ``` -> **Tip:** When using `StarletteIASTelemetryMiddleware` (see [Automatic Tenant and User Injection](#automatic-tenant-and-user-injection)), `common.tenant_id` and `common.user_initiator_id` are filled automatically from the incoming IAS JWT. You only need to set them explicitly if you want to override the values from the token. +> **Tip:** When your app is wired with `bootstrap()` (see [Automatic Tenant and User Injection](#automatic-tenant-and-user-injection)), `common.tenant_id` and `common.user_initiator_id` are filled automatically from the incoming IAS JWT. You only need to set them explicitly if you want to override the values from the token. ### Send the Event @@ -207,9 +207,9 @@ with create_client(tenant="tenant_subdomain") as client: ### Automatic Tenant and User Injection -When `StarletteIASTelemetryMiddleware` is registered on your app, it parses the -incoming `Authorization: Bearer ` header on every request and stores the -IAS claims in the current async context. +When your app is wired with `bootstrap()`, the SDK parses the incoming +`Authorization: Bearer ` header on every request and stores the IAS +claims in the SDK runtime context for the current invocation. `AuditClient.send()` reads that context automatically before validation and back-fills two fields on the event's `common` block — only if they are not @@ -222,19 +222,21 @@ already set by the caller: #### Setup -Register the middleware once when your app starts: +Call `bootstrap()` once when your app starts: ```python -from sap_cloud_sdk.core.telemetry import auto_instrument -from sap_cloud_sdk.core.telemetry.middleware import StarletteIASTelemetryMiddleware +from sap_cloud_sdk import bootstrap app = FastAPI(...) -auto_instrument(middlewares=[StarletteIASTelemetryMiddleware(app=app)]) +bootstrap(app) ``` +A single `bootstrap(app)` call registers the IAS context provider — which reads +the incoming JWT on each request — and initializes telemetry for your app. + #### Usage -With the middleware in place, you can omit `tenant_id` and `user_initiator_id` +With `bootstrap()` in place, you can omit `tenant_id` and `user_initiator_id` from every event — they are injected automatically: ```python @@ -249,8 +251,25 @@ event.object_id = "resource-001" event_id = client.send(event) ``` -If neither the middleware nor an explicit value provides `tenant_id`, the event -will fail `protovalidate` validation and raise a `ValidationError`. +If neither the runtime context nor an explicit value provides `tenant_id`, the +event will fail `protovalidate` validation and raise a `ValidationError`. + +#### Legacy: `StarletteIASTelemetryMiddleware` + +Apps not yet using `bootstrap()` can register the telemetry middleware directly: + +```python +from sap_cloud_sdk.core.telemetry import auto_instrument +from sap_cloud_sdk.core.telemetry.middleware import StarletteIASTelemetryMiddleware + +app = FastAPI(...) +auto_instrument(middlewares=[StarletteIASTelemetryMiddleware(app=app)]) +``` + +`send()` reads the runtime context populated by `bootstrap()` first and falls +back to the IAS claims captured by this middleware when the runtime context is +empty, so automatic tenant/user injection still applies. Prefer `bootstrap()` +for new apps. ## Configuration From 1a77994eaaf15b94c02cab4661c45e7cddaee46b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Pedro=20Brun?= Date: Fri, 11 Sep 2026 18:21:12 -0300 Subject: [PATCH 6/6] version bump --- pyproject.toml | 2 +- uv.lock | 34 ++++++++++------------------------ 2 files changed, 11 insertions(+), 25 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index 459b7ff6..40bacf4f 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "sap-cloud-sdk" -version = "0.51.1" +version = "0.53.0" description = "SAP Cloud SDK for Python" readme = "README.md" license = "Apache-2.0" diff --git a/uv.lock b/uv.lock index 3a4bed22..86b2d0d6 100644 --- a/uv.lock +++ b/uv.lock @@ -1186,9 +1186,7 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/4e/a3/07297917485ee2ca85bc3c8dc6ed85ad3fffcf424047fba62671dba68e97/greenlet-3.5.5-cp311-cp311-macosx_11_0_universal2.whl", hash = "sha256:be63afcbbccfad3dd95a1ba12ada84dab2ef32031973d80b5b92df67fa763a61", size = 294165, upload-time = "2026-08-10T13:25:17.987Z" }, { url = "https://files.pythonhosted.org/packages/db/51/6f732f9314cda54c5fd48a7620c7160f4f286967e8045ad94b9d66ce80b7/greenlet-3.5.5-cp311-cp311-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:8a268024ce2d7d2b04694bf1594058981a9fa663d1df4b762dee499211ed7c1c", size = 613610, upload-time = "2026-08-10T14:14:33.829Z" }, { url = "https://files.pythonhosted.org/packages/d8/c0/b27589e25d220289edcd4d582b2b17b83058d1a56d53d971b6ea1a34f10d/greenlet-3.5.5-cp311-cp311-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:35cbb8bf55ace57fbccb4fb8622c4521713acd8691e77f4696d416ea7ca527da", size = 625481, upload-time = "2026-08-10T14:27:23.647Z" }, - { url = "https://files.pythonhosted.org/packages/39/82/5c873dbb4fb001d22fbbd50e80d4c1b0181ddae106856132160f84b94e88/greenlet-3.5.5-cp311-cp311-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:abc8bc8d9f935cd685457545b6a53863a877fdc12c2c0f5ee9beee18d9db139c", size = 633329, upload-time = "2026-08-10T14:30:06.062Z" }, { url = "https://files.pythonhosted.org/packages/51/2d/f2c928218ac52f26d7a2c188c171d1b7e728b23782cb3347e7b4fce1493a/greenlet-3.5.5-cp311-cp311-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:74cc6df89ec5302337adc9cf096221cbed2510fd444b0e0f1586cf0470740864", size = 624562, upload-time = "2026-08-10T13:40:48.064Z" }, - { url = "https://files.pythonhosted.org/packages/70/12/f7df98e72a8eb4a7edfec5a08d6d1a4ab53a52c95ba0b2ea6c10b8dd9bd0/greenlet-3.5.5-cp311-cp311-manylinux_2_39_riscv64.whl", hash = "sha256:3134291427bb0f3526e9d90311988caf336eb43730e95244997a4fb15f45144f", size = 428145, upload-time = "2026-08-10T14:30:01.071Z" }, { url = "https://files.pythonhosted.org/packages/3e/4a/92fc51d5d35912f4f06eec037ba347985defd0be47463a010a325634d9d2/greenlet-3.5.5-cp311-cp311-musllinux_1_2_aarch64.whl", hash = "sha256:6d9b454c5fc48aeaa7c4337813dbf513a6870468e426438a04d922c6d0fe63db", size = 1584909, upload-time = "2026-08-10T14:15:04.343Z" }, { url = "https://files.pythonhosted.org/packages/ac/58/ed98b80ac5738c149a5258544843c45601ade1fd70f61740cdaead6351b3/greenlet-3.5.5-cp311-cp311-musllinux_1_2_x86_64.whl", hash = "sha256:03551ed792cb1b4fc0277a0c60dfd8c343894a0ba06fe60dcd22f568b433da39", size = 1651184, upload-time = "2026-08-10T13:40:28.879Z" }, { url = "https://files.pythonhosted.org/packages/d8/be/b582ceb80cefdf9d8da34078714e4b12b3d16f509dee0f65e40a5cc8fc7d/greenlet-3.5.5-cp311-cp311-win_amd64.whl", hash = "sha256:ab3df3dffb58bf70564e93a5cec7941e4d9faa5a36cc4234a10d3131afe04f53", size = 323280, upload-time = "2026-08-10T13:26:07.495Z" }, @@ -1196,9 +1194,7 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/2e/7e/9ecd0285e3153532ae07aeb88063c43c72b4221cf0d4d123b02f3682e3ff/greenlet-3.5.5-cp312-cp312-macosx_11_0_universal2.whl", hash = "sha256:49520f0c95a48b42cf55414b8e8479beb274ea70431afc33e3f79903c71f4380", size = 295809, upload-time = "2026-08-10T13:25:34.023Z" }, { url = "https://files.pythonhosted.org/packages/35/73/60e4bbcc89252037b18087f2ec16405d5b2d5be42dde191bbf3667e96102/greenlet-3.5.5-cp312-cp312-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:55272212cbc5f43d1d723725ab931f1939969b7e9523882ca58b55061769d053", size = 611910, upload-time = "2026-08-10T14:14:35.18Z" }, { url = "https://files.pythonhosted.org/packages/a4/17/cd5134be659cd4a443e7a61ae670dabec165a814c51162916d637b6dd38e/greenlet-3.5.5-cp312-cp312-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:655bca754a2ef4efcb0eb48a94d3f4593536d0f3d48f8ed44343c01d16a92f95", size = 624198, upload-time = "2026-08-10T14:27:25.229Z" }, - { url = "https://files.pythonhosted.org/packages/9b/30/87c212b5c684d0e72974f1063b7a9687631e8985902c06e1016542c874e7/greenlet-3.5.5-cp312-cp312-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:6ca5d6ae0739e5764f2cfcfaa562ac5a990cbdaedca93251c5e3cf07c362371f", size = 629504, upload-time = "2026-08-10T14:30:07.967Z" }, { url = "https://files.pythonhosted.org/packages/78/ac/5c5b959999b6f09c3026b5dfe171575bc3121c5236ce74f495096f25b203/greenlet-3.5.5-cp312-cp312-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:147b25a42e5ca5be3d42356e8f608b37af715a1c196e9bf9d1627f3341adfe1d", size = 621439, upload-time = "2026-08-10T13:40:49.391Z" }, - { url = "https://files.pythonhosted.org/packages/63/2c/eb487fafc9f50ffff2b1e0b697f70fb34bf150821c08ab225aacf5583a7e/greenlet-3.5.5-cp312-cp312-manylinux_2_39_riscv64.whl", hash = "sha256:1b5ed9162c0c098e0bbc2cf88a94f433c1b8926f831745252e099e5d83e17759", size = 432462, upload-time = "2026-08-10T14:30:02.309Z" }, { url = "https://files.pythonhosted.org/packages/c8/8b/6acf112ed8aee499f25b4d6949820fb02ac950ff9c1f3d793bd5be0599f2/greenlet-3.5.5-cp312-cp312-musllinux_1_2_aarch64.whl", hash = "sha256:27493374cff1d1b7919dc8126547f2aea582737e3046147b434b1e12de56389b", size = 1581342, upload-time = "2026-08-10T14:15:05.653Z" }, { url = "https://files.pythonhosted.org/packages/b8/d7/734e5f198888876b42d7616ff6644c075baf6b8a2412deadd6b0e1b8b20c/greenlet-3.5.5-cp312-cp312-musllinux_1_2_x86_64.whl", hash = "sha256:12e2ee66c2aba86133f10fd99d6a8856c6d351ffb7be0e4d52ef2cc5fbb705b2", size = 1645744, upload-time = "2026-08-10T13:40:30.353Z" }, { url = "https://files.pythonhosted.org/packages/de/30/1f42b88dc587b5899ee50616ad56ee40cafaf225df4fb829f10183c62a5c/greenlet-3.5.5-cp312-cp312-win_amd64.whl", hash = "sha256:49ddacd36af37735fab103846f4ee4d18a492dde72730d1699c0c8ebe30d9f18", size = 324171, upload-time = "2026-08-10T13:28:44.472Z" }, @@ -1206,9 +1202,7 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/fb/3d/8cef5f724ec0d4add2af8961d504535ec60c3cca9e464f6d03bdba29d85b/greenlet-3.5.5-cp313-cp313-macosx_11_0_universal2.whl", hash = "sha256:b79fd2a5bc099b5e744f34c4c9a58954a5f4cb7529fb4b6e8446057d61b6edaa", size = 294730, upload-time = "2026-08-10T13:27:51.206Z" }, { url = "https://files.pythonhosted.org/packages/88/4b/8e7aa3f514273aecff30a16ab1bac09ff54cfc7e6860fdd8058c37ff2499/greenlet-3.5.5-cp313-cp313-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:634cf15a233a949136879dd388e25d3296e16f3f1e217d2456797b8579ebc6ed", size = 614536, upload-time = "2026-08-10T14:14:36.589Z" }, { url = "https://files.pythonhosted.org/packages/85/48/4e95e9dd5a8a397dc6a6345dd7f1935113d0fca4f85e89d3976da9cd988d/greenlet-3.5.5-cp313-cp313-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:499adea519f748407fc6806d20eedabac2884fd73b9f38d81236e190ba20dfef", size = 626924, upload-time = "2026-08-10T14:27:27.048Z" }, - { url = "https://files.pythonhosted.org/packages/0e/84/eaa476d6bf3816828d0d70e80dcc36bf30a058233bd889e707e693f6e860/greenlet-3.5.5-cp313-cp313-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:f7278591501941bb2456af102bb9cd59aab48c6cfd6e2dd68fa1290bb0c49a42", size = 632726, upload-time = "2026-08-10T14:30:09.874Z" }, { url = "https://files.pythonhosted.org/packages/89/5d/398a1c71fa7a277deeb376c999979de6786f08fc2d5747a0b9d6e11738dd/greenlet-3.5.5-cp313-cp313-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:2eabb980975cba5b93a95f6f69287d05fc05ac955bfd6a320a7c083eeb52c0b0", size = 623906, upload-time = "2026-08-10T13:40:50.501Z" }, - { url = "https://files.pythonhosted.org/packages/d0/f2/0cc2849ede68579291e9c59b3ab6ec1958f98681cca5b14d8fc75bf674a4/greenlet-3.5.5-cp313-cp313-manylinux_2_39_riscv64.whl", hash = "sha256:4dfc7c4470354e7b09184d1a3a985761053a2fd694ddb5b5c80242afc2c8c90b", size = 434966, upload-time = "2026-08-10T14:30:03.729Z" }, { url = "https://files.pythonhosted.org/packages/04/1b/745450fc5ea9e0cb17d840d248f284db3363de736d362c7d2d883e3eadba/greenlet-3.5.5-cp313-cp313-musllinux_1_2_aarch64.whl", hash = "sha256:03115c2e0a371999bf8ae616aa8d653f96641d4705c457aebaa187276e9f7537", size = 1581430, upload-time = "2026-08-10T14:15:06.853Z" }, { url = "https://files.pythonhosted.org/packages/d4/29/d51b296e3191bb15d3d81ec375af1909e4466c0f395d744ed475801798a9/greenlet-3.5.5-cp313-cp313-musllinux_1_2_x86_64.whl", hash = "sha256:4441153ffba21b90d3ca89fe3d31f5c093ae6c0bf0cfdfc98f54cde22f95b62e", size = 1645684, upload-time = "2026-08-10T13:40:32.133Z" }, { url = "https://files.pythonhosted.org/packages/12/63/369f1a1625e64e9e31df3963c6044056e3fdfa3fa3fdba3c54ffefa6e987/greenlet-3.5.5-cp313-cp313-win_amd64.whl", hash = "sha256:95c5b1f4b3a193f8a0c2de4bfdcb48d119f7f1063941f1de1f2168051b3e52dd", size = 324075, upload-time = "2026-08-10T13:26:58.974Z" }, @@ -1216,9 +1210,7 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/7f/8c/080e881fa2be95ff1ddbd6994b2bab3b1a78df3b3fcab39306011764fcc7/greenlet-3.5.5-cp314-cp314-macosx_11_0_universal2.whl", hash = "sha256:d4a389a852e392a6366058651a20fa5ba40d979865aa81bea2ccbdc44805070d", size = 295309, upload-time = "2026-08-10T13:26:03.032Z" }, { url = "https://files.pythonhosted.org/packages/25/cc/0ac614e6586c0e42d4cc281a5819150f4f43685744a4c5ff77139286409d/greenlet-3.5.5-cp314-cp314-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:70b157cd319873e8b544ddc2de158f55bbd0a9b0218c8ce9332039801518e328", size = 661185, upload-time = "2026-08-10T14:14:37.867Z" }, { url = "https://files.pythonhosted.org/packages/5e/b9/6808725354be8ad305dfe5172377664fc9642d4fc043be246b3314cf4482/greenlet-3.5.5-cp314-cp314-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:8bdfd1424abcf26832961e766570cae79efdb9599d709088c9cb6ef82b194926", size = 673419, upload-time = "2026-08-10T14:27:28.652Z" }, - { url = "https://files.pythonhosted.org/packages/eb/52/f005d579acde46c3d1cc3cab1c9f3d5708c8a3006a4120e8cf5da801afe9/greenlet-3.5.5-cp314-cp314-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:d98ef6f92e67c6dbf299dbfd8facc1b0d2d9cedf91e325e73b3d0373fe4309d8", size = 677863, upload-time = "2026-08-10T14:30:11.663Z" }, { url = "https://files.pythonhosted.org/packages/42/2e/40c509967da7f254680826a2fa0dd22138ec79946c70b97542d74cde8b43/greenlet-3.5.5-cp314-cp314-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:182de51c6b572a705f2fafaab2e783bcf7d2760940229dfe73086cbae037af3e", size = 670822, upload-time = "2026-08-10T13:40:51.833Z" }, - { url = "https://files.pythonhosted.org/packages/c4/8a/a75f8a2bdcef3c358a3147cdc9db3aa83755f0a038f766ab0bedb66f512c/greenlet-3.5.5-cp314-cp314-manylinux_2_39_riscv64.whl", hash = "sha256:159df1942d88e8f784cbb38d6f18bdb365cd11319cfbb3e89623de2b97892d53", size = 480554, upload-time = "2026-08-10T14:30:05.171Z" }, { url = "https://files.pythonhosted.org/packages/2d/22/c3c2eee4a8fe191d6d1d183086c56133d646024e3d70bfd414829f64560b/greenlet-3.5.5-cp314-cp314-musllinux_1_2_aarch64.whl", hash = "sha256:8fec3f165dfe332e490c3247c0f6c23b0bfc45f06496ad7f00ddb00e3d35e4dc", size = 1628469, upload-time = "2026-08-10T14:15:08.11Z" }, { url = "https://files.pythonhosted.org/packages/f7/87/25babd09b94cb1f03e71db815fde463f0262e40cfbd953d58a8d77311351/greenlet-3.5.5-cp314-cp314-musllinux_1_2_x86_64.whl", hash = "sha256:c6ce25fee6cabc8bf22cb8b52e642cbb821be5b9aec8094d07ff03378141b8e9", size = 1691952, upload-time = "2026-08-10T13:40:33.502Z" }, { url = "https://files.pythonhosted.org/packages/2e/3d/5cc9701117ea4dc0eb7bf1f4f9b7888a6e2e5277ddfae095805ace50f2b6/greenlet-3.5.5-cp314-cp314-win_amd64.whl", hash = "sha256:7dffc5c859fe6059974df1e37d7923d654a83e2ae18fdd616994270e001115e1", size = 327458, upload-time = "2026-08-10T13:27:02.868Z" }, @@ -1226,18 +1218,14 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/24/e0/50cd600b469e5734c72709b6b1838b6bc63f307b573c772c3132d6ecfe92/greenlet-3.5.5-cp314-cp314t-macosx_11_0_universal2.whl", hash = "sha256:0e5a7de979d764aea1f5b6e95cf92b5b37741b9823702041f34b126e7f690277", size = 305471, upload-time = "2026-08-10T13:26:20.568Z" }, { url = "https://files.pythonhosted.org/packages/75/a3/77acd66dfc6387b5219b2080806c0cabb73c10eb1bb44b413c40a62015ba/greenlet-3.5.5-cp314-cp314t-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:fef01bd457f11fc158b130ca0027a3c365693280e8e231b65bdaf57999f39f5b", size = 672470, upload-time = "2026-08-10T14:14:39.058Z" }, { url = "https://files.pythonhosted.org/packages/b9/71/0d178142dca3ec19f46fb2212ae73d30ad53b9d548dc64804086033a7089/greenlet-3.5.5-cp314-cp314t-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:5173a72310725a74afc82c164f0e52cb8ad0de62f2bb623f24f6c0cc07d80272", size = 679973, upload-time = "2026-08-10T14:27:30.072Z" }, - { url = "https://files.pythonhosted.org/packages/aa/ac/0d7887aa4bbfc9eba075cc428244dfc96f623478454d5ec81180d0d6bd5a/greenlet-3.5.5-cp314-cp314t-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:5e9ec2e7c98e895fcea0c5cc57b2606cf86ece6d0a56578f3eb225e2af4f0387", size = 681587, upload-time = "2026-08-10T14:30:13.519Z" }, { url = "https://files.pythonhosted.org/packages/6e/31/46eb8567302eaf787abf88d09df014e14ae3baf460af1b8b0efdbd3efcd5/greenlet-3.5.5-cp314-cp314t-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:44f08341873200ba8a60a8bc14ace3d91f1754f7fa7bc66157714a8cd420a476", size = 676634, upload-time = "2026-08-10T13:40:53.004Z" }, - { url = "https://files.pythonhosted.org/packages/4f/18/8d58ba1c429b0383e3219a3d0e0bba241d0444d8ed05b73349953c7d7c7b/greenlet-3.5.5-cp314-cp314t-manylinux_2_39_riscv64.whl", hash = "sha256:102817506f6090b5176c746a82603341a549b40e5c3d5b72a4c672228a918c41", size = 510175, upload-time = "2026-08-10T14:30:07.047Z" }, { url = "https://files.pythonhosted.org/packages/a3/e9/b88bbf5b29970cb84172dc2c32aa3e5e579ceb94c808e81c826454138850/greenlet-3.5.5-cp314-cp314t-musllinux_1_2_aarch64.whl", hash = "sha256:d246c0db9a2513cd45f019ba178ea4d4d4705bd210ee465e2c15d76a1ab13874", size = 1637320, upload-time = "2026-08-10T14:15:09.317Z" }, { url = "https://files.pythonhosted.org/packages/6d/8c/7631ed29cc6f0392f11830076e172ce4885e70b0bc2c1bce1731176d4b4e/greenlet-3.5.5-cp314-cp314t-musllinux_1_2_x86_64.whl", hash = "sha256:72507285b5caa1d17904a3f7c322ca780823a54170a0e04ec3f37bcc60d4db71", size = 1697412, upload-time = "2026-08-10T13:40:34.924Z" }, { url = "https://files.pythonhosted.org/packages/da/0f/f7dd935f9c4cb1be49098770587f54d8a78518e55c89bce86c4fb4109057/greenlet-3.5.5-cp314-cp314t-win_amd64.whl", hash = "sha256:7805655781fb8f28a55d05fe57ed61f5f10f1892fb587673e3bb5264f28041f0", size = 331514, upload-time = "2026-08-10T13:29:20.611Z" }, { url = "https://files.pythonhosted.org/packages/b7/e5/681b01f8fbc1b55232822f99e8f8afeb78a55a7c76a7bf9dbdc7ccb03a6d/greenlet-3.5.5-cp315-cp315-macosx_11_0_universal2.whl", hash = "sha256:c0db80fcd5b8aece93f66c64f78a786bbb6b96c5fe63ef5a5a4581ecf8bab206", size = 295975, upload-time = "2026-08-10T13:28:45.985Z" }, { url = "https://files.pythonhosted.org/packages/11/f2/69b488cd9e7267bf4b0fe8cdebf25d8d6df680d21bdf41150d23e23d6652/greenlet-3.5.5-cp315-cp315-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:6b241c32f912ada659808d68e308c568baf577eebf757d15471472de0c18cfad", size = 666823, upload-time = "2026-08-10T14:14:40.222Z" }, { url = "https://files.pythonhosted.org/packages/84/d4/d5bc2fdebbdda0c94555925ba79948b8395d75a7f6a36cc85dce5bab9f11/greenlet-3.5.5-cp315-cp315-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:ef6a08349401d8eaf3cb12688ac8557de95788556b8631ef17555a4a173022c0", size = 677613, upload-time = "2026-08-10T14:27:31.543Z" }, - { url = "https://files.pythonhosted.org/packages/65/53/4e13642efc4d7ad6554ecb2242a5be42666b2e1a067323e88dfc0124a04b/greenlet-3.5.5-cp315-cp315-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:37faa97daccb6d9f4c2141ce3118d023c3c5506864a7d8bdf726f665018c1f76", size = 681436, upload-time = "2026-08-10T14:30:14.839Z" }, { url = "https://files.pythonhosted.org/packages/bd/93/542d8a3a90f3b35c6ad8bf7e56a03010287f2cafa289a5b7985b5207db39/greenlet-3.5.5-cp315-cp315-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:f2e3d061b8e13aec2f0441689b3c71b244a20e5d274a52cb0f7e31bd1d139552", size = 675930, upload-time = "2026-08-10T13:40:54.205Z" }, - { url = "https://files.pythonhosted.org/packages/cd/32/188447c9a468d6977d2989397226b0c6b65ab6f4cf943f931643328512fc/greenlet-3.5.5-cp315-cp315-manylinux_2_39_riscv64.whl", hash = "sha256:b18007dc2473a7942fd157366b55f01da6fed7ce85318591005b419e0a439474", size = 487404, upload-time = "2026-08-10T14:30:08.903Z" }, { url = "https://files.pythonhosted.org/packages/52/b5/89c9f2e8460d71101037d47a1feed11928615a5edd42370be290e0657eeb/greenlet-3.5.5-cp315-cp315-musllinux_1_2_aarch64.whl", hash = "sha256:9ab5f5b93655e77fe0d6c2dfd22b5eac751bb1f876d8ec21761b7c1fb9266007", size = 1633878, upload-time = "2026-08-10T14:15:10.693Z" }, { url = "https://files.pythonhosted.org/packages/b8/60/297de93f3b02ac78a5e04d32bb8bbe3080f4a73d8ed95016561463b70618/greenlet-3.5.5-cp315-cp315-musllinux_1_2_x86_64.whl", hash = "sha256:f0e5a21bd4452a88cf032fc43c4a5b307ab1380eacb63b5988f9c0317885e773", size = 1696597, upload-time = "2026-08-10T13:40:36.252Z" }, { url = "https://files.pythonhosted.org/packages/18/25/54c6eaff4f337fb670215e89eb2d00d9499487b658e709d4b477be4a342e/greenlet-3.5.5-cp315-cp315-win_amd64.whl", hash = "sha256:469dbb0a78625642f4a626cfd0c6e8bccc0385b5e49189b6308bbe849ec88a8e", size = 327700, upload-time = "2026-08-10T13:28:06.752Z" }, @@ -1245,9 +1233,7 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/10/e2/3144c0a116067ac1e30457b0139a94d60d1d36a86e015de68e9ac87cb3bc/greenlet-3.5.5-cp315-cp315t-macosx_11_0_universal2.whl", hash = "sha256:68184dfcf50ccaa8e864770fe0633a7e27250ea9329f8192ef47ee9ecfd78e1c", size = 306387, upload-time = "2026-08-10T13:27:00.897Z" }, { url = "https://files.pythonhosted.org/packages/5c/a1/cb4223a7e9b9f43b8807e8eb212358bfe2dfaa174a9ea2889eb1714dcba2/greenlet-3.5.5-cp315-cp315t-manylinux_2_24_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:9ec0dc0e59dc9c61af5c47348365ccbbd7addfafe0a93b00336ff3da2907bdc6", size = 676472, upload-time = "2026-08-10T14:14:41.417Z" }, { url = "https://files.pythonhosted.org/packages/9e/cd/a154b4498e5d8f12ada291cfb3b8d596eadde2177f5bf09a9be699d2a446/greenlet-3.5.5-cp315-cp315t-manylinux_2_24_ppc64le.manylinux_2_28_ppc64le.whl", hash = "sha256:e604f58e35833fc46ef20302bcb314dddbfd3fcf33a4f936216d51dd678d63ae", size = 684238, upload-time = "2026-08-10T14:27:32.946Z" }, - { url = "https://files.pythonhosted.org/packages/ce/f4/e450a68a152f819491d8c7df6a8254e761d87e6a78759268961f8c5bd4dd/greenlet-3.5.5-cp315-cp315t-manylinux_2_24_s390x.manylinux_2_28_s390x.whl", hash = "sha256:2888a3a38bc5ee5bb6c438372197152e815837e4fab7ed7a1f86ef18ffd58ad1", size = 686022, upload-time = "2026-08-10T14:30:15.96Z" }, { url = "https://files.pythonhosted.org/packages/bf/bb/b0031d260c2968a3c87deebc51d80c64e499377f993aafe06ee3b7488cc2/greenlet-3.5.5-cp315-cp315t-manylinux_2_24_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:40239b5384f96da3963585cc6d7eaa9b56f8ae67e8d92cc82dd9e202fc847de3", size = 681246, upload-time = "2026-08-10T13:40:55.402Z" }, - { url = "https://files.pythonhosted.org/packages/18/23/17e63d6bf3b9c9b9dbea981b7f643a71f79603bdfb4f1c3a9cf353e22aed/greenlet-3.5.5-cp315-cp315t-manylinux_2_39_riscv64.whl", hash = "sha256:1e8d9391fe77f15649589a907cef972dbbd6352ef7ff7dc0492f658c0c26495f", size = 516951, upload-time = "2026-08-10T14:30:10.907Z" }, { url = "https://files.pythonhosted.org/packages/9a/07/da554b71ab88e649da146e1065d86a48a5c5d92e50ab74ef41b504aa7f56/greenlet-3.5.5-cp315-cp315t-musllinux_1_2_aarch64.whl", hash = "sha256:a1eaccf5c3a1d3e46dead602c72e6836731e8e245c9de6a27764567b6b62d4c0", size = 1642735, upload-time = "2026-08-10T14:15:11.92Z" }, { url = "https://files.pythonhosted.org/packages/78/76/26a3782a051677668af9d92beaa47cd87ba9dd5072f762961144a03dd4c6/greenlet-3.5.5-cp315-cp315t-musllinux_1_2_x86_64.whl", hash = "sha256:19e4e026fe20691f333b8eb1a3bc9625eceba8c3f9d62ec5a6f8581afbc6b5a5", size = 1700925, upload-time = "2026-08-10T13:40:37.656Z" }, { url = "https://files.pythonhosted.org/packages/28/d9/fe7baf4190c2ae71f267efb9de21b3172bb35bc0ed1ef53dd6027d658e33/greenlet-3.5.5-cp315-cp315t-win_amd64.whl", hash = "sha256:712aee154f648bde84634654bb38bb78c69ac640c37a45c9effed800735049d8", size = 331829, upload-time = "2026-08-10T13:26:48.851Z" }, @@ -3328,15 +3314,6 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/f1/d9/7fb5aa316bc299258e68c73ba3bddbc499654a07f151cba08f6153988714/pathspec-1.1.1-py3-none-any.whl", hash = "sha256:a00ce642f577bf7f473932318056212bc4f8bfdf53128c78bbd5af0b9b20b189", size = 57328, upload-time = "2026-04-27T01:46:07.06Z" }, ] -[[package]] -name = "platformdirs" -version = "4.11.7" -source = { registry = "https://pypi.org/simple" } -sdist = { url = "https://files.pythonhosted.org/packages/69/b7/802a56eca9f2fac455b8bab5375a2647b0f0e14a2cd63ef077de3c4a7658/platformdirs-4.11.7.tar.gz", hash = "sha256:4f41487eeeeeb07f3a6625e61d9bc0ae6809f92d3386dbd74392fbb76108104d", size = 35127, upload-time = "2026-09-01T13:35:10.502Z" } -wheels = [ - { url = "https://files.pythonhosted.org/packages/27/6e/80993e10a0482f630cef528635789233224f36b1ffd11592aa15d13ff9ce/platformdirs-4.11.7-py3-none-any.whl", hash = "sha256:8a02cb259042c79d1cd0450facc2fe6dc9d303ae7901afbe33bf8ea0b188cef6", size = 23938, upload-time = "2026-09-01T13:35:09.02Z" }, -] - [[package]] name = "pendulum" version = "3.2.0" @@ -3397,6 +3374,15 @@ wheels = [ { url = "https://files.pythonhosted.org/packages/02/fb/d65db067a67df7252f18b0cb7420dda84078b9e8bfb375215469c14a50be/pendulum-3.2.0-py3-none-any.whl", hash = "sha256:f3a9c18a89b4d9ef39c5fa6a78722aaff8d5be2597c129a3b16b9f40a561acf3", size = 114111, upload-time = "2026-01-30T11:22:22.361Z" }, ] +[[package]] +name = "platformdirs" +version = "4.11.7" +source = { registry = "https://pypi.org/simple" } +sdist = { url = "https://files.pythonhosted.org/packages/69/b7/802a56eca9f2fac455b8bab5375a2647b0f0e14a2cd63ef077de3c4a7658/platformdirs-4.11.7.tar.gz", hash = "sha256:4f41487eeeeeb07f3a6625e61d9bc0ae6809f92d3386dbd74392fbb76108104d", size = 35127, upload-time = "2026-09-01T13:35:10.502Z" } +wheels = [ + { url = "https://files.pythonhosted.org/packages/27/6e/80993e10a0482f630cef528635789233224f36b1ffd11592aa15d13ff9ce/platformdirs-4.11.7-py3-none-any.whl", hash = "sha256:8a02cb259042c79d1cd0450facc2fe6dc9d303ae7901afbe33bf8ea0b188cef6", size = 23938, upload-time = "2026-09-01T13:35:09.02Z" }, +] + [[package]] name = "pluggy" version = "1.6.0" @@ -4299,7 +4285,7 @@ wheels = [ [[package]] name = "sap-cloud-sdk" -version = "0.51.1" +version = "0.53.0" source = { editable = "." } dependencies = [ { name = "cryptography" },