1;!function(){try { var e="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof global?global:"undefined"!=typeof window?window:"undefined"!=typeof self?self:{},n=(new e.Error).stack;n&&((e._debugIds|| (e._debugIds={}))[n]="6ed49639-25ed-5eff-be18-4232a987c32d")}catch(e){}}(); 2(globalThis["TURBOPACK"] || (globalThis["TURBOPACK"] = [])).push([typeof document === "object" ? document.currentScript : undefined, 3765472, ((__turbopack_context__) => { 4"use strict"; 5 6// MERGED MODULE: [project]/src/auth/utils.ts [app-client] (ecmascript) 7; 8// MERGED MODULE: [project]/node_modules/jose/dist/webapi/util/decode_jwt.js [app-client] (ecmascript) 9; 10// MERGED MODULE: [project]/node_modules/jose/dist/webapi/util/base64url.js [app-client] (ecmascript) 11; 12// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/buffer_utils.js [app-client] (ecmascript) 13; 14const encoder = new TextEncoder(), decoder = new TextDecoder(), strictDecoder = new TextDecoder("utf-8", { 15 fatal: !0 16}), MAX_INT32 = 2 ** 32; 17function concat() { 18 for(var _len = arguments.length, buffers = new Array(_len), _key = 0; _key < _len; _key++){ 19 buffers[_key] = arguments[_key]; 20 } 21 const size = buffers.reduce((acc, param)=>{ 22 let { length } = param; 23 return acc + length; 24 }, 0), buf = new Uint8Array(size); 25 let i = 0; 26 for (const buffer of buffers)buf.set(buffer, i), i += buffer.length; 27 return buf; 28} 29function writeUInt32BE(buf, value, offset) { 30 if (value < 0 || value >= MAX_INT32) throw new RangeError("value must be >= 0 and <= ".concat(MAX_INT32 - 1, ". Received ").concat(value)); 31 buf.set([ 32 value >>> 24, 33 value >>> 16, 34 value >>> 8, 35 value & 255 36 ], offset); 37} 38function uint64be(value) { 39 const high = Math.floor(value / MAX_INT32), low = value % MAX_INT32, buf = new Uint8Array(8); 40 return writeUInt32BE(buf, high, 0), writeUInt32BE(buf, low, 4), buf; 41} 42function uint32be(value) { 43 const buf = new Uint8Array(4); 44 return writeUInt32BE(buf, value), buf; 45} 46const NON_ASCII = /[^\x00-\x7f]/; 47function encode(string) { 48 if (typeof string == "string" && string.length >= 128) { 49 if (NON_ASCII.test(string)) throw new TypeError("non-ASCII string encountered in encode()"); 50 return encoder.encode(string); 51 } 52 const bytes = new Uint8Array(string.length); 53 for(let i = 0; i < string.length; i++){ 54 const code = string.charCodeAt(i); 55 if (code > 127) throw new TypeError("non-ASCII string encountered in encode()"); 56 bytes[i] = code; 57 } 58 return bytes; 59} 60function encodeBase64(input) { 61 let url = arguments.length > 1 && arguments[1] !== void 0 ? arguments[1] : !1; 62 if (Uint8Array.prototype.toBase64) return input.toBase64({ 63 alphabet: url ? "base64url" : "base64", 64 omitPadding: url 65 }); 66 const CHUNK_SIZE = 32768, arr = []; 67 for(let i = 0; i < input.length; i += CHUNK_SIZE)arr.push(String.fromCharCode.apply(null, input.subarray(i, i + CHUNK_SIZE))); 68 const encoded = btoa(arr.join("")); 69 return url ? encoded.replace(/=/g, "").replace(/\+/g, "-").replace(/\//g, "_") : encoded; 70} 71function decodeBase64(encoded) { 72 let url = arguments.length > 1 && arguments[1] !== void 0 ? arguments[1] : !1; 73 if (Uint8Array.fromBase64) return Uint8Array.fromBase64(encoded, { 74 alphabet: url ? "base64url" : "base64" 75 }); 76 if (url) { 77 if (encoded.includes("+") || encoded.includes("/")) throw new TypeError("Invalid base64url"); 78 encoded = encoded.replace(/-/g, "+").replace(/_/g, "/"); 79 } 80 const binary = atob(encoded), bytes = new Uint8Array(binary.length); 81 for(let i = 0; i < binary.length; i++)bytes[i] = binary.charCodeAt(i); 82 return bytes; 83} 84async function digest(algorithm, data) { 85 const subtleDigest = "SHA-".concat(algorithm.slice(-3)); 86 return new Uint8Array(await crypto.subtle.digest(subtleDigest, data)); 87} 88; 89; 90const invalid = "The input to be decoded is not correctly encoded."; 91function decode(input) { 92 try { 93 return decodeBase64(typeof input == "string" ? input : decoder.decode(input), !0); 94 } catch (cause) { 95 throw new TypeError(invalid, { 96 cause 97 }); 98 } 99} 100function encode1(input) { 101 return encodeBase64(typeof input == "string" ? encoder.encode(input) : input, !0); 102} 103; 104// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/vali
104date.js [app-client] (ecmascript) 105; 106// MERGED MODULE: [project]/node_modules/jose/dist/webapi/util/errors.js [app-client] (ecmascript) 107; 108var __TURBOPACK__imported__module__540151__ = __turbopack_context__.i(540151); 109; 110class JOSEError extends Error { 111 constructor(message, options){ 112 var _Error_captureStackTrace, _Error; 113 super(message, options), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JOSE_GENERIC"), this.name = this.constructor.name, (_Error_captureStackTrace = (_Error = Error).captureStackTrace) === null || _Error_captureStackTrace === void 0 ? void 0 : _Error_captureStackTrace.call(_Error, this, this.constructor); 114 } 115} 116(0, __TURBOPACK__imported__module__540151__["_"])(JOSEError, "code", "ERR_JOSE_GENERIC"); 117class JWTClaimValidationFailed extends JOSEError { 118 constructor(message, payload, claim = "unspecified", reason = "unspecified"){ 119 super(message, { 120 cause: { 121 claim, 122 reason, 123 payload 124 } 125 }), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWT_CLAIM_VALIDATION_FAILED"), (0, __TURBOPACK__imported__module__540151__["_"])(this, "claim", void 0), (0, __TURBOPACK__imported__module__540151__["_"])(this, "reason", void 0), (0, __TURBOPACK__imported__module__540151__["_"])(this, "payload", void 0), this.claim = claim, this.reason = reason, this.payload = payload; 126 } 127} 128(0, __TURBOPACK__imported__module__540151__["_"])(JWTClaimValidationFailed, "code", "ERR_JWT_CLAIM_VALIDATION_FAILED"); 129class JWTExpired extends JOSEError { 130 constructor(message, payload, claim = "unspecified", reason = "unspecified"){ 131 super(message, { 132 cause: { 133 claim, 134 reason, 135 payload 136 } 137 }), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWT_EXPIRED"), (0, __TURBOPACK__imported__module__540151__["_"])(this, "claim", void 0), (0, __TURBOPACK__imported__module__540151__["_"])(this, "reason", void 0), (0, __TURBOPACK__imported__module__540151__["_"])(this, "payload", void 0), this.claim = claim, this.reason = reason, this.payload = payload; 138 } 139} 140(0, __TURBOPACK__imported__module__540151__["_"])(JWTExpired, "code", "ERR_JWT_EXPIRED"); 141class JOSEAlgNotAllowed extends JOSEError { 142 constructor(...args){ 143 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JOSE_ALG_NOT_ALLOWED"); 144 } 145} 146(0, __TURBOPACK__imported__module__540151__["_"])(JOSEAlgNotAllowed, "code", "ERR_JOSE_ALG_NOT_ALLOWED"); 147class JOSENotSupported extends JOSEError { 148 constructor(...args){ 149 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JOSE_NOT_SUPPORTED"); 150 } 151} 152(0, __TURBOPACK__imported__module__540151__["_"])(JOSENotSupported, "code", "ERR_JOSE_NOT_SUPPORTED"); 153class JWEDecryptionFailed extends JOSEError { 154 constructor(message = "decryption operation failed", options){ 155 super(message, options), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWE_DECRYPTION_FAILED"); 156 } 157} 158(0, __TURBOPACK__imported__module__540151__["_"])(JWEDecryptionFailed, "code", "ERR_JWE_DECRYPTION_FAILED"); 159class JWEInvalid extends JOSEError { 160 constructor(...args){ 161 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWE_INVALID"); 162 } 163} 164(0, __TURBOPACK__imported__module__540151__["_"])(JWEInvalid, "code", "ERR_JWE_INVALID"); 165class JWSInvalid extends JOSEError { 166 constructor(...args){ 167 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWS_INVALID"); 168 } 169} 170(0, __TURBOPACK__imported__module__540151__["_"])(JWSInvalid, "code", "ERR_JWS_INVALID"); 171class JWTInvalid extends JOSEError { 172 constructor(...args){ 173 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWT_INVALID"); 174 } 175} 176(0, __TURBOPACK__imported__module__540151__["_"])(JWTInvalid, "code", "ERR_JWT_INVALID"); 177class JWKInvalid extends JOSEError { 178 constructor(...args){ 179 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ER
179R_JWK_INVALID"); 180 } 181} 182(0, __TURBOPACK__imported__module__540151__["_"])(JWKInvalid, "code", "ERR_JWK_INVALID"); 183class JWKSInvalid extends JOSEError { 184 constructor(...args){ 185 super(...args), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWKS_INVALID"); 186 } 187} 188(0, __TURBOPACK__imported__module__540151__["_"])(JWKSInvalid, "code", "ERR_JWKS_INVALID"); 189class JWKSNoMatchingKey extends JOSEError { 190 constructor(message = "no applicable key found in the JSON Web Key Set", options){ 191 super(message, options), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWKS_NO_MATCHING_KEY"); 192 } 193} 194(0, __TURBOPACK__imported__module__540151__["_"])(JWKSNoMatchingKey, "code", "ERR_JWKS_NO_MATCHING_KEY"); 195class JWKSMultipleMatchingKeys extends JOSEError { 196 constructor(message = "multiple matching keys found in the JSON Web Key Set", options){ 197 super(message, options), (0, __TURBOPACK__imported__module__540151__["_"])(this, Symbol.asyncIterator, async function*() {}), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWKS_MULTIPLE_MATCHING_KEYS"); 198 } 199} 200(0, __TURBOPACK__imported__module__540151__["_"])(JWKSMultipleMatchingKeys, "code", "ERR_JWKS_MULTIPLE_MATCHING_KEYS"); 201class JWKSTimeout extends JOSEError { 202 constructor(message = "request timed out", options){ 203 super(message, options), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWKS_TIMEOUT"); 204 } 205} 206(0, __TURBOPACK__imported__module__540151__["_"])(JWKSTimeout, "code", "ERR_JWKS_TIMEOUT"); 207class JWSSignatureVerificationFailed extends JOSEError { 208 constructor(message = "signature verification failed", options){ 209 super(message, options), (0, __TURBOPACK__imported__module__540151__["_"])(this, "code", "ERR_JWS_SIGNATURE_VERIFICATION_FAILED"); 210 } 211} 212(0, __TURBOPACK__imported__module__540151__["_"])(JWSSignatureVerificationFailed, "code", "ERR_JWS_SIGNATURE_VERIFICATION_FAILED"); 213; 214; 215; 216; 217function assertUint8Array(input, label) { 218 if (!(input instanceof Uint8Array)) throw new TypeError("".concat(label, " must be an instance of Uint8Array")); 219} 220function isObject(input) { 221 if (typeof input != "object" || input === null || Object.prototype.toString.call(input) !== "[object Object]") return !1; 222 const prototype = Object.getPrototypeOf(input); 223 return prototype === null || Object.getPrototypeOf(prototype) === null; 224} 225function isJwkSet(input) { 226 return isObject(input) && Array.isArray(input.keys) && Array.from(input.keys).every(isObject); 227} 228function isDisjoint() { 229 for(var _len = arguments.length, headers = new Array(_len), _key = 0; _key < _len; _key++){ 230 headers[_key] = arguments[_key]; 231 } 232 const parameters = /* @__PURE__ */ new Set(); 233 for (const header of headers)if (header) for (const parameter of Object.keys(header)){ 234 if (parameters.has(parameter)) return !1; 235 parameters.add(parameter); 236 } 237 return !0; 238} 239function assertNotSet(value, name) { 240 if (value !== void 0) throw new TypeError("".concat(name, " can only be called once")); 241} 242function decodeBase64url(value, label, ErrorClass) { 243 try { 244 return decode(value); 245 } catch (unused) { 246 throw new ErrorClass("Failed to base64url decode the ".concat(label)); 247 } 248} 249function encodeBase64url(value, label, ErrorClass) { 250 try { 251 return encode(value); 252 } catch (unused) { 253 throw new ErrorClass("The ".concat(label, " is not a valid base64url string")); 254 } 255} 256function parseJoseHeader(b64, ErrorClass, message) { 257 let parsed; 258 try { 259 parsed = JSON.parse(strictDecoder.decode(decode(b64))); 260 } catch (unused) { 261 throw new ErrorClass(message); 262 } 263 if (!isObject(parsed)) throw new ErrorClass(message); 264 return parsed; 265} 266const JWS_RECOGNIZED = { 267 __proto__: null, 268 b64: !0 269}, JWE_RECOGNIZED = { 270 __proto__: null 271}; 272function validateAlgorithms(option, algorithms) { 273 if (algorithms !== void 0 && (!Array.isArray(algorithms) || algorithms.some((s)=>typeof s != "string"))) throw new TypeError('"'.concat(option, '" option must be an array of str
273ings')); 274 return algorithms === void 0 ? void 0 : new Set(algorithms); 275} 276function validateCritDuplicates(Err, protectedHeader) { 277 const { crit } = protectedHeader !== null && protectedHeader !== void 0 ? protectedHeader : {}; 278 if (Array.isArray(crit) && new Set(crit).size !== crit.length) throw new Err('"crit" (Critical) Header Parameter MUST NOT contain duplicate values'); 279} 280function validateCrit(Err, recognizedDefault, recognizedOption, protectedHeader, joseHeader) { 281 if (joseHeader.crit !== void 0 && (protectedHeader === null || protectedHeader === void 0 ? void 0 : protectedHeader.crit) === void 0) throw new Err('"crit" (Critical) Header Parameter MUST be integrity protected'); 282 if (!protectedHeader || protectedHeader.crit === void 0) return []; 283 if (!Array.isArray(protectedHeader.crit) || protectedHeader.crit.length === 0 || protectedHeader.crit.some((input)=>typeof input != "string" || input.length === 0)) throw new Err('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present'); 284 const recognized = recognizedOption === void 0 ? recognizedDefault : { 285 __proto__: null, 286 ...recognizedOption, 287 ...recognizedDefault 288 }; 289 for (const parameter of protectedHeader.crit){ 290 if (!(parameter in recognized)) throw new JOSENotSupported('Extension Header Parameter "'.concat(parameter, '" is not recognized')); 291 if (!Object.hasOwn(joseHeader, parameter) || joseHeader[parameter] === void 0) throw new Err('Extension Header Parameter "'.concat(parameter, '" is missing')); 292 if (recognized[parameter] && (!Object.hasOwn(protectedHeader, parameter) || protectedHeader[parameter] === void 0)) throw new Err('Extension Header Parameter "'.concat(parameter, '" MUST be integrity protected')); 293 } 294 return protectedHeader.crit; 295} 296function validateB64(protectedHeader, extensions) { 297 if (extensions.includes("b64")) { 298 const b64 = protectedHeader.b64; 299 if (typeof b64 != "boolean") throw new JWSInvalid('The "b64" (base64url-encode payload) Header Parameter must be a boolean'); 300 return b64; 301 } 302 return !0; 303} 304function serializeJoseHeader(Err, header) { 305 let serialized, parsed; 306 try { 307 serialized = JSON.stringify(header), parsed = JSON.parse(serialized); 308 } catch (cause) { 309 throw new Err("JOSE Header is not valid JSON", { 310 cause 311 }); 312 } 313 if (!isObject(parsed)) throw new Err("JOSE Header is not a JSON object"); 314 return [ 315 parsed, 316 serialized 317 ]; 318} 319; 320; 321; 322; 323; 324function decodeJwt(jwt) { 325 if (typeof jwt != "string") throw new JWTInvalid("JWTs must use Compact JWS serialization, JWT must be a string"); 326 const { 1: payload, length } = jwt.split("."); 327 if (length === 5) throw new JWTInvalid("Only JWTs using Compact JWS serialization can be decoded"); 328 if (length !== 3) throw new JWTInvalid("Invalid JWT"); 329 if (!payload) throw new JWTInvalid("JWTs must contain a payload"); 330 let decoded; 331 try { 332 decoded = decode(payload); 333 } catch (unused) { 334 throw new JWTInvalid("Failed to base64url decode the payload"); 335 } 336 let result; 337 try { 338 result = JSON.parse(strictDecoder.decode(decoded)); 339 } catch (unused) { 340 throw new JWTInvalid("Failed to parse the decoded payload as JSON"); 341 } 342 if (!isObject(result)) throw new JWTInvalid("Invalid JWT Claims Set"); 343 return result; 344} 345; 346// MERGED MODULE: [project]/node_modules/jose/dist/webapi/jwt/sign.js [app-client] (ecmascript) 347; 348var __TURBOPACK__imported__module__229032__ = __turbopack_context__.i(229032); 349var __TURBOPACK__imported__module__567928__ = __turbopack_context__.i(567928); 350var __TURBOPACK__imported__module__523474__ = __turbopack_context__.i(523474); 351// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/jws_sign.js [app-client] (ecmascript) 352; 353// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/jws_algorithms.js [app-client] (ecmascript) 354; 355// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/key_descriptor.js [app-client] (ecmascript) 356; 357function table(entries) { 358 const out = { 359 __proto__: null 360 }; 361 for(const alg in entries)out[alg] = { 362 ...entries[alg], 363 alg 364 }; 365 return out; 366} 367; 368; 369; 370const sig = [ 371 [ 372 "verify" 373 ], 374 [ 375 "sign" 376 ] 377]; 378function hmac(bits) { 379 const subtle = { 380 name: "HMAC", 381 hash: "SHA-".concat(bits) 382 }; 383 return { 384 kty: [ 385 "oct" 386 ], 387 secret: !0, 388 subtle, 389 signing: subtle, 390 usages: sig 391 }; 392} 393function rsa(bits, saltLength) { 394 const subtle = { 395 name: saltLength ? "RSA-PSS" : "RSASSA-PKCS1-v1_5", 396 hash: "SHA-".concat(bits) 397 }; 398 return { 399 kty: [ 400 "RSA" 401 ], 402 subtle, 403 signing: saltLength ? { 404 ...subtle, 405 saltLength 406 } : subtle, 407 usages: sig, 408 minRsaBits: 2048 409 }; 410} 411function ecdsa(crv, bits) { 412 return { 413 kty: [ 414 "EC" 415 ], 416 crv, 417 subtle: { 418 name: "ECDSA", 419 namedCurve: crv 420 }, 421 signing: { 422 name: "ECDSA", 423 hash: "SHA-".concat(bits) 424 }, 425 usages: sig 426 }; 427} 428function eddsa() { 429 const subtle = { 430 name: "Ed25519" 431 }; 432 return { 433 kty: [ 434 "OKP" 435 ], 436 crv: "Ed25519", 437 subtle, 438 signing: subtle, 439 usages: sig 440 }; 441} 442function mldsa(bits) { 443 const subtle = { 444 name: "ML-DSA-".concat(bits) 445 }; 446 return { 447 kty: [ 448 "AKP" 449 ], 450 subtle, 451 signing: subtle, 452 usages: sig 453 }; 454} 455const JWS = table({ 456 HS256: hmac(256), 457 HS384: hmac(384), 458 HS512: hmac(512), 459 RS256: rsa(256), 460 RS384: rsa(384), 461 RS512: rsa(512),
462 PS256: rsa(256, 32), 463 PS384: rsa(384, 48), 464 PS512: rsa(512, 64), 465 ES256: ecdsa("P-256", 256), 466 ES384: ecdsa("P-384", 384), 467 ES512: ecdsa("P-521", 512), 468 EdDSA: eddsa(), 469 Ed25519: eddsa(), 470 "ML-DSA-44": mldsa(44), 471 "ML-DSA-65": mldsa(65), 472 "ML-DSA-87": mldsa(87) 473}); 474function jwsAlgorithm(alg) { 475 const entry = typeof alg == "string" ? JWS[alg] : void 0; 476 if (!entry) throw new JOSENotSupported("alg ".concat(alg, " is not supported either by JOSE or your javascript runtime")); 477 return entry; 478} 479; 480// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/key.js [app-client] (ecmascript) 481; 482; 483; 484; 485const tag = (key)=>key[Symbol.toStringTag], jwkMatchesOp = (entry, key, usage)=>{ 486 const { alg } = entry; 487 if (key.use !== void 0) { 488 const expected = usage === "sign" || usage === "verify" ? "sig" : "enc"; 489 if (key.use !== expected) throw new TypeError('Invalid key for this operation, its "use" must be "'.concat(expected, '" when present')); 490 } 491 if (key.alg !== void 0 && key.alg !== alg) throw new TypeError('Invalid key for this operation, its "alg" must be "'.concat(alg, '" when present')); 492 if (Array.isArray(key.key_ops)) { 493 var _entry_ops; 494 const expectedKeyOp = usage === "encrypt" || usage === "decrypt" ? (_entry_ops = entry.ops) === null || _entry_ops === void 0 ? void 0 : _entry_ops[usage === "encrypt" ? 0 : 1] : usage; 495 if (expectedKeyOp && !key.key_ops.includes(expectedKeyOp)) throw new TypeError('Invalid key for this operation, its "key_ops" must include "'.concat(expectedKeyOp, '" when present')); 496 } 497}; 498async function prepareKey(entry, key, usage) { 499 const { alg, secret } = entry, privateKey = usage === "decrypt" || usage === "sign"; 500 if (secret && key instanceof Uint8Array) return key; 501 let normalized, keyObject; 502 if (isObject(key)) { 503 if (normalized = normalizeJwk(key), typeof normalized.kty != "string") throw invalidKeyType(alg, key, secret); 504 if (!(secret ? normalized.kty === "oct" && typeof normalized.k == "string" : normalized.kty !== "oct" && (privateKey ? normalized.kty === "AKP" && typeof normalized.priv == "string" || typeof normalized.d == "string" : normalized.d === void 0 && normalized.priv === void 0))) throw new TypeError(secret ? 'JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present' : "JSON Web Key for this operation must be a ".concat(privateKey ? "private" : "public", " JWK")); 505 if (jwkMatchesOp(entry, normalized, usage), normalized.kty === "oct") return decode(normalized.k); 506 if (!Object.isFrozen(key)) { 507 const { key_ops } = key; 508 Array.isArray(key_ops) && Object.freeze(key_ops), Object.freeze(key); 509 } 510 } else { 511 if (!isKeyLike(key)) throw invalidKeyType(alg, key, secret); 512 const expectedType = secret ? "secret" : privateKey ? "private" : "public"; 513 if (key.type !== expectedType && (secret || [ 514 "secret", 515 "public", 516 "private" 517 ].includes(key.type))) throw new TypeError("".concat(tag(key), ' instances must be of type "').concat(expectedType, '" for the ').concat(alg, " algorithm")); 518 if (isCryptoKey(key)) return key; 519 if (keyObject = key, keyObject.type === "secret") return keyObject.export(); 520 } 521 cache || (cache = /* @__PURE__ */ new WeakMap()); 522 const cacheKey = key; 523 let cached = cache.get(cacheKey); 524 if (cached === null || cached === void 0 ? void 0 : cached[alg]) return cached[alg]; 525 if (cached || cache.set(cacheKey, cached = {}), keyObject && typeof keyObject.toCryptoKey == "function") { 526 var _ref; 527 var _keyObject_asymmetricKeyDetails, _entry_resolve; 528 const isPublic = keyObject.type === "public", crv = nist[(_keyObject_asymmetricKeyDetails = keyObject.asymmetricKeyDetails) === null || _keyObject_asymmetricKeyDetails === void 0 ? void 0 : _keyObject_asymmetricKeyDetails.namedCurve], params = (_ref = (_entry_resolve = entry.resolve) === null || _entry_resolve === void 0 ? void 0 : _entry_resolve.call(entry, { 529 crv, 530 asymmetricKeyType: keyObject.asymmetricKeyType 531 })) !== null && _ref !== void 0 ? _ref : entry.subtle; 532 return cached[alg] = keyObject.toCryptoKey(params, isPublic, entry.usages[isPublic ? 0 : 1]); 533 } 534 return normalized !== null && normalized !== void 0 ? normalized : normalized = keyObject.export({ 535 format: "jwk" 536 }), normalized.alg = alg, cached[alg] = await jwkToKey(entry, normalized); 537} 538let cache; 539const nist = { 540 __proto__: null, 541 prime256v1: "P-256", 542 secp384r1: "P-384", 543 secp521r1: "P-521" 544}; 545function assertCryptoKey(key) { 546 if (!isCryptoKey(key)) throw new Error("CryptoKey instance expected"); 547} 548const isCryptoKey = (key)=>{
549 if ((key === null || key === void 0 ? void 0 : key[Symbol.toStringTag]) === "CryptoKey") return !0; 550 try { 551 return key instanceof CryptoKey; 552 } catch (unused) { 553 return !1; 554 } 555}, isKeyObject = (key)=>(key === null || key === void 0 ? void 0 : key[Symbol.toStringTag]) === "KeyObject", isKeyLike = (key)=>isCryptoKey(key) || isKeyObject(key); 556function message(msg, actual) { 557 for(var _len = arguments.length, types = new Array(_len > 2 ? _len - 2 : 0), _key = 2; _key < _len; _key++){ 558 types[_key - 2] = arguments[_key]; 559 } 560 var _actual_constructor; 561 if (types.length > 2) { 562 const last = types.pop(); 563 msg += "one of type ".concat(types.join(", "), ", or ").concat(last, "."); 564 } else types.length === 2 ? msg += "one of type ".concat(types[0], " or ").concat(types[1], ".") : msg += "of type ".concat(types[0], "."); 565 return actual == null ? msg += " Received ".concat(actual) : typeof actual == "function" && actual.name ? msg += " Received function ".concat(actual.name) : typeof actual == "object" && actual != null && ((_actual_constructor = actual.constructor) === null || _actual_constructor === void 0 ? void 0 : _actual_constructor.name) && (msg += " Received an instance of ".concat(actual.constructor.name)), msg; 566} 567const invalidKeyInput = function(actual) { 568 for(var _len = arguments.length, types = new Array(_len > 1 ? _len - 1 : 0), _key = 1; _key < _len; _key++){ 569 types[_key - 1] = arguments[_key]; 570 } 571 return message("Key must be ", actual, ...types); 572};
573function invalidKeyType(alg, actual, secret) { 574 const types = [ 575 "CryptoKey", 576 "KeyObject", 577 "JSON Web Key" 578 ]; 579 return secret && types.push("Uint8Array"), new TypeError(message("Key for the ".concat(alg, " algorithm must be "), actual, ...types)); 580} 581const unusable = function(name) { 582 let prop = arguments.length > 1 && arguments[1] !== void 0 ? arguments[1] : "algorithm.name"; 583 return new TypeError("CryptoKey does not support this operation, its ".concat(prop, " must be ").concat(name)); 584}; 585function checkUsage(key, usage) { 586 if (usage && !key.usages.includes(usage)) throw new TypeError("CryptoKey does not support this operation, its usages must include ".concat(usage, ".")); 587} 588function checkModulusLength(alg, key) { 589 const { modulusLength } = key.algorithm; 590 if (typeof modulusLength != "number" || modulusLength < 2048) throw new TypeError("".concat(alg, " requires key modulusLength to be 2048 bits or larger")); 591} 592function checkCryptoKey(key, expected, usage) { 593 var _algorithm_hash; 594 const algorithm = key.algorithm; 595 if (algorithm.name !== expected.name) throw unusable(expected.name); 596 if (expected.hash && ((_algorithm_hash = algorithm.hash) === null || _algorithm_hash === void 0 ? void 0 : _algorithm_hash.name) !== expected.hash) throw unusable(expected.hash, "algorithm.hash"); 597 if (expected.namedCurve && algorithm.namedCurve !== expected.namedCurve) throw unusable(expected.namedCurve, "algorithm.namedCurve"); 598 if (expected.length !== void 0 && algorithm.length !== expected.length) throw unusable(expected.length, "algorithm.length"); 599 checkUsage(key, usage); 600} 601function snapshotJwk(jwk) { 602 return { 603 __proto__: null, 604 ...jwk 605 }; 606} 607function normalizeJwk(jwk) { 608 const normalized = snapshotJwk(jwk); 609 if (normalized.ext !== void 0 && typeof normalized.ext != "boolean") throw new TypeError('"ext" (Extractable) Parameter must be a boolean'); 610 if (normalized.key_ops !== void 0) { 611 const value = normalized.key_ops, keyOps = Array.isArray(value) ? [ 612 ...value 613 ] : void 0; 614 if (!keyOps || keyOps.some((operation)=>typeof operation != "string") || new Set(keyOps).size !== keyOps.length) throw new TypeError('"key_ops" (Key Operations) Parameter must be an array of unique strings'); 615 normalized.key_ops = keyOps; 616 } 617 return normalized; 618} 619function validateExtractableOption(extractable) { 620 if (extractable !== void 0 && typeof extractable != "boolean") throw new TypeError('"extractable" option must be a boolean'); 621 return extractable; 622} 623async function jwkToKey(entry, jwk, extractable) { 624 var _ref, _keyData_ext, _jwk_key_ops; 625 var _entry_resolve; 626 if (!entry.kty.includes(jwk.kty)) throw new JOSENotSupported('Invalid or unsupported JWK "alg" (Algorithm) Parameter value'); 627 const algorithm = (_ref = (_entry_resolve = entry.resolve) === null || _entry_resolve === void 0 ? void 0 : _entry_resolve.call(entry, { 628 kty: jwk.kty, 629 crv: jwk.crv 630 })) !== null && _ref !== void 0 ? _ref : entry.subtle, isPrivate = !!(jwk.d || jwk.priv), keyData = { 631 ...jwk, 632 ext: extractable !== null && extractable !== void 0 ? extractable : jwk.ext 633 }; 634 return keyData.kty !== "AKP" && delete keyData.alg, delete keyData.use, crypto.subtle.importKey("jwk", keyData, algorithm, (_keyData_ext = keyData.ext) !== null && _keyData_ext !== void 0 ? _keyData_ext : !isPrivate, (_jwk_key_ops = jwk.key_ops) !== null && _jwk_key_ops !== void 0 ? _jwk_key_ops : entry.usages[isPrivate ? 1 : 0]); 635} 636async function rawKey(key, expected, usage) { 637 let extractable = arguments.length > 3 && arguments[3] !== void 0 ? arguments[3] : !1; 638 return key instanceof Uint8Array && (key = await crypto.subtle.importKey("raw", key, expected, extractable, [ 639 usage 640 ])), checkCryptoKey(key, expected, usage), key; 641} 642; 643; 644; 645; 646; 647; 648; 649async function createSignature(input, key, rejectUnencoded) { 650 let [payload, protectedHeader, unprotectedHeader, crit] = input, protectedHeaderString = ""; 651 if (protectedHeader !== void 0) { 652 const normalized = serializeJoseHeader(JWSInvalid, protectedHeader); 653 protectedHeader = normalized[0], protectedHeaderString = encode1(normalized[1]); 654 } 655 if (unprotectedHeader !== void 0 && (unprotectedHeader = serializeJoseHeader(JWSInvalid, unprotectedHeader)[0]), !protectedHeader && !unprotectedHeader) throw new JWSInvalid("either setProtectedHeader or setUnprotectedHeader must be called before #sign()"); 656 if (!isDisjoint(protectedHeader, unprotectedHeader)) throw new JWSInvalid("JWS Protected and JWS Unprotected Header Parameter names must be disjoint"); 657 const joseHeader = { 658 ...protectedHeader, 659 ...unprotectedHeader 660 }; 661 validateCritDuplicates(JWSInvalid, protectedHeader); 662 const b64 = validateB64(protectedHeader, validateCrit(JWSInvalid, JWS_RECOGNIZED, crit, protectedHeader, joseHeader)); 663 b64 || (rejectUnencoded === null || rejectUnencoded === void 0 ? void 0 : rejectUnencoded()); 664 const { alg } = joseHeader; 665 if (typeof alg != "string" || !alg) throw new JWSInvalid('JWS "alg" (Algorithm) Header Parameter missing or invalid'); 666 const entry = jwsAlgorithm(alg); 667 let payloadS = "", payloadB = payload, data; 668 if (b64) { 669 var _encoded, _ref, _, _encoded1, _ref1, _1; 670 const encoded = input[4]; 671 encoded ? (payloadS = (_ = (_encoded = encoded)[_ref = 0]) !== null && _ !== void 0 ? _ : _encoded[_ref] = encode1(payload), payloadB = (_1 = (_encoded1 = encoded)[_ref1 = 1]) !== null && _1 !== void 0 ? _1 : _encoded1[_ref1] = encode(payloadS)) : (payloadS = encode1(payload), data = encoder.encode("".concat(protectedHeaderString, ".").concat(payloadS))); 672 } 673 data !== null && data !== void 0 ? data : data = concat(encode(protectedHeaderString), encode("."), payloadB);
674 const k = await rawKey(await prepareKey(entry, key, "sign"), entry.subtle, "sign"); 675 entry.minRsaBits && checkModulusLength(entry.alg, k); 676 const jws = { 677 signature: encode1(new Uint8Array(await crypto.subtle.sign(entry.signing, k, data))), 678 payload: payloadS 679 }; 680 return protectedHeader && (jws.protected = protectedHeaderString), unprotectedHeader && (jws.header = unprotectedHeader), [ 681 jws, 682 b64 683 ]; 684} 685async function createCompactSignature(payload, protectedHeader, crit, key, rejectUnencoded) { 686 const [jws] = await createSignature([ 687 payload, 688 protectedHeader, 689 void 0, 690 crit 691 ], key, rejectUnencoded); 692 return "".concat(jws.protected, ".").concat(jws.payload, ".").concat(jws.signature); 693} 694; 695// MERGED MODULE: [project]/node_modules/jose/dist/webapi/lib/jwt_claims_set.js [app-client] (ecmascript) 696; 697; 698; 699; 700const epoch = (date)=>Math.floor(date.getTime() / 1e3), multipliers = { 701 s: 1, 702 m: 60, 703 h: 3600, 704 d: 86400, 705 w: 604800, 706 y: 31557600 707}, REGEX = /^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i, checkFailed = "check_failed";
708function invalidDuration() { 709 throw new TypeError("Invalid time period format"); 710} 711function secs(str) { 712 typeof str != "string" && invalidDuration(); 713 const matched = REGEX.exec(str); 714 (!matched || matched[4] && matched[1]) && invalidDuration(); 715 const value = parseFloat(matched[2]), numericDate2 = Math.round(value * multipliers[matched[3][0].toLowerCase()]); 716 return Number.isFinite(numericDate2) || invalidDuration(), matched[1] === "-" || matched[4] === "ago" ? -numericDate2 : numericDate2; 717} 718function validateInput(label, input) { 719 if (!Number.isFinite(input)) throw new TypeError("Invalid ".concat(label, " input")); 720 return input; 721} 722function validateStringClaim(claim, value) { 723 if (typeof value != "string") throw new TypeError('"'.concat(claim, '" claim must be a string')); 724} 725function validateAudienceClaim(value) { 726 if (typeof value != "string" && (!Array.isArray(value) || Array.from(value).some((member)=>typeof member != "string"))) throw new TypeError('"aud" claim must be a string or an array of strings'); 727} 728function numericDate(value, label) { 729 return typeof value == "number" ? validateInput(label, value) : value instanceof Date ? validateInput(label, epoch(value)) : epoch(/* @__PURE__ */ new Date()) + secs(value); 730} 731const normalizeTyp = (value)=>{ 732 const normalized = value.toLowerCase(); 733 return value.includes("/") ? normalized : "application/".concat(normalized); 734}, checkAudiencePresence = (audPayload, audOption)=>typeof audPayload == "string" ? audOption.includes(audPayload) : Array.isArray(audPayload) ? audOption.some((aud)=>audPayload.includes(aud)) : !1; 735function validateNumericDate(payload, claim) { 736 let required = arguments.length > 2 && arguments[2] !== void 0 ? arguments[2] : !1; 737 const value = payload[claim]; 738 if (!(value === void 0 && !required)) { 739 if (typeof value != "number") throw new JWTClaimValidationFailed('"'.concat(claim, '" claim must be a number'), payload, claim, "invalid"); 740 return value; 741 } 742} 743function unexpectedClaim(payload, claim) { 744 throw new JWTClaimValidationFailed('unexpected "'.concat(claim, '" claim value'), payload, claim, checkFailed); 745} 746function validateClaimsSet(protectedHeader, encodedPayload) { 747 let options = arguments.length > 2 && arguments[2] !== void 0 ? arguments[2] : {}; 748 let payload; 749 try { 750 payload = JSON.parse(strictDecoder.decode(encodedPayload)); 751 } catch (unused) {} 752 if (!isObject(payload)) throw new JWTInvalid("JWT Claims Set must be a top-level JSON object"); 753 const { typ } = options; 754 if (typ !== void 0 && (typeof protectedHeader.typ != "string" || normalizeTyp(protectedHeader.typ) !== normalizeTyp(typ))) throw new JWTClaimValidationFailed('unexpected "typ" JWT header value', payload, "typ", checkFailed); 755 const { requiredClaims = [], issuer, subject, audience, maxTokenAge } = options, presenceCheck = [ 756 ...requiredClaims 757 ]; 758 maxTokenAge !== void 0 && presenceCheck.push("iat"), audience !== void 0 && presenceCheck.push("aud"), subject !== void 0 && presenceCheck.push("sub"), issuer !== void 0 && presenceCheck.push("iss"); 759 for (const claim of new Set(presenceCheck.reverse()))if (!Object.hasOwn(payload, claim)) throw new JWTClaimValidationFailed('missing required "'.concat(claim, '" claim'), payload, claim, "missing"); 760 issuer !== void 0 && !(Array.isArray(issuer) ? issuer : [ 761 issuer 762 ]).includes(payload.iss) && unexpectedClaim(payload, "iss"), subject !== void 0 && payload.sub !== subject && unexpectedClaim(payload, "sub"), audience !== void 0 && !checkAudiencePresence(payload.aud, typeof audience == "string" ? [ 763 audience 764 ] : audience) && unexpectedClaim(payload, "aud"); 765 const { clockTolerance } = options; 766 let tolerance = 0; 767 if (typeof clockTolerance == "string") tolerance = secs(clockTolerance); 768 else if (clockTolerance !== void 0) { 769 if (typeof clockTolerance != "number") throw new TypeError("Invalid clockTolerance option type"); 770 tolerance = clockTolerance; 771 } 772 validateInput("clockTolerance option", tolerance); 773 const { currentDate } = options, now = validateInput("currentDate option", epoch(currentDate === void 0 ? /* @__P
773URE__ */ new Date() : currentDate)), iat = validateNumericDate(payload, "iat", maxTokenAge !== void 0), nbf = validateNumericDate(payload, "nbf"); 774 if (nbf !== void 0 && nbf > now + tolerance) throw new JWTClaimValidationFailed('"nbf" claim timestamp check failed', payload, "nbf", checkFailed); 775 const exp = validateNumericDate(payload, "exp"); 776 if (exp !== void 0 && exp <= now - tolerance) throw new JWTExpired('"exp" claim timestamp check failed', payload, "exp", checkFailed); 777 if (maxTokenAge !== void 0) { 778 const age = now - iat, max = validateInput("maxTokenAge option", typeof maxTokenAge == "number" ? maxTokenAge : secs(maxTokenAge)); 779 if (age - tolerance > max) throw new JWTExpired('"iat" claim timestamp check failed (too far in the past)', payload, "iat", checkFailed); 780 if (age < -tolerance) throw new JWTClaimValidationFailed('"iat" claim timestamp check failed (it should be in the past)', payload, "iat", checkFailed); 781 } 782 return payload; 783} 784let producerPayloads; 785function producerPayload(producer) { 786 return producerPayloads.get(producer); 787} 788function jwtData(producer) { 789 const payload = producerPayload(producer); 790 for (const claim of [ 791 "iat", 792 "nbf", 793 "exp" 794 ]){ 795 const value = payload[claim]; 796 if (typeof value == "number" && !Number.isFinite(value)) throw new TypeError('"'.concat(claim, '" claim must be a finite number')); 797 } 798 return encoder.encode(JSON.stringify(payload)); 799} 800function jwtClaim(producer, claim) { 801 return producerPayload(producer)[claim]; 802} 803class JWTClaimsBuilder { 804 setIssuer(value) { 805 return validateStringClaim("iss", value), producerPayload(this).iss = value, this; 806 } 807 setSubject(value) { 808 return validateStringClaim("sub", value), producerPayload(this).sub = value, this; 809 } 810 setAudience(value) { 811 return validateAudienceClaim(value), producerPayload(this).aud = value, this; 812 } 813 setJti(value) { 814 return validateStringClaim("jti", value), producerPayload(this).jti = value, this; 815 } 816 setNotBefore(value) { 817 return producerPayload(this).nbf = numericDate(value, "setNotBefore"), this; 818 } 819 setExpirationTime(value) { 820 return producerPayload(this).exp = numericDate(value, "setExpirationTime"), this; 821 } 822 setIssuedAt(value) { 823 const payload = producerPayload(this); 824 return value === void 0 ? payload.iat = epoch(/* @__PURE__ */ new Date()) : typeof value == "string" ? payload.iat = validateInput("setIssuedAt", epoch(/* @__PURE__ */ new Date()) + secs(value)) : payload.iat = numericDate(value, "setIssuedAt"), this; 825 } 826 constructor(payload = {}){ 827 if (!isObject(payload)) throw new TypeError("JWT Claims Set MUST be an object"); 828 (producerPayloads || (producerPayloads = /* @__PURE__ */ new WeakMap())).set(this, structuredClone(payload)); 829 } 830} 831; 832; 833; 834; 835; 836; 837; 838; 839const SignJWT_base = JWTClaimsBuilder; 840var _protectedHeader = new WeakMap(); 841class SignJWT extends SignJWT_base { 842 setProtectedHeader(protectedHeader) { 843 return assertNotSet((0, __TURBOPACK__imported__module__229032__["_"])(this, _protectedHeader), "setProtectedHeader"), (0, __TURBOPACK__imported__module__523474__["_"])(this, _protectedHeader, protectedHeader), this; 844 } 845 async sign(key, options) { 846 return createCompactSignature(jwtData(this), (0, __TURBOPACK__imported__module__229032__["_"])(this, _protectedHeader), options === null || options === void 0 ? void 0 : options.crit, key, ()=>{ 847 throw new JWTInvalid("JWTs MUST NOT use unencoded payload"); 848 }); 849 } 850 constructor(...args){ 851 super(...args), (0, __TURBOPACK__imported__module__567928__["_"])(this, _protectedHeader, { 852 writable: true, 853 value: void 0 854 }); 855 } 856} 857; 858; 859; 860function decodeToken(token) { 861 const payload = decodeJwt(token); 862 return { 863 value: token, 864 decoded: payload 865 }; 866} 867function decodeTokenPair(tokenPair) { 868 return { 869 accessToken: decodeToken(tokenPair.accessToken), 870 refreshToken: decodeToken(tokenPair.refreshToken) 871 }; 872} 873function isTokenValid(token, options) { 874 const expiryDate = getTokenExpiryDate(token); 875 return !!expiryDate && expiryDate.getTime() - options.leeway > new Date().getTime(); 876} 877function getTokenExpiryDate(token) { 878 const { decoded } = typeof token === "string" ? decodeToken(token) : token; 879 return new Date(decoded.exp * 1000); 880} 881async function createTestToken(options) { 882 var _ref; 883 const secret = new TextEncoder().encode("TEST_SECRET"); 884 const alg = "HS256"; 885 return await new SignJWT({ 886 compasSessionAccessToken: (0, __TURBOPACK__imported__module__614677__["v4"])() 887 }).setProtectedHeader({ 888 alg, 889 typ: "JWT" 890 }).setExpirationTime((_ref = options === null || options === void 0 ? void 0 : options.exp
890) !== null && _ref !== void 0 ? _ref : "2h").sign(secret); 891} 892__turbopack_context__.s([ 893 "decodeToken", 894 0, 895 decodeToken, 896 "decodeTokenPair", 897 0, 898 decodeTokenPair, 899 "getTokenExpiryDate", 900 0, 901 getTokenExpiryDate, 902 "isTokenValid", 903 0, 904 isTokenValid 905], 765472); 906}), 907541378, 609963, 908((__turbopack_context__) => { 909"use strict"; 910 911// MERGED MODULE: [project]/src/auth/cookies.ts [app-client] (ecmascript) 912; 913var __TURBOPACK__imported__module__595727__ = __turbopack_context__.i(595727); 914var __TURBOPACK__imported__module__126476__ = __turbopack_context__.i(126476); 915// MERGED MODULE: [project]/src/auth/config.ts [app-client] (ecmascript) 916; 917var __TURBOPACK__imported__module__685149__ = __turbopack_context__.i(685149); 918; 919const config = { 920 session: { 921 cache: { 922 cookie: { 923 name: "diks_authenticated" 924 } 925 }, 926 accessToken: { 927 // The amount of ms before the actual access token expiry to consider it to be expired. 928 // Useful to make sure an access token does not expire mid-request server-side. 929 // When running the Next.js development server, compiling a page or route handler might 930 // take longer than the configured leeway causing a 401 response. 931 leeway: 60000, 932 cookie: { 933 name: "diks_access_token" 934 } 935 }, 936 refreshToken: { 937 // The amount of ms before the actual refresh token expiry to consider it to be expired. 938 // Useful to make sure a refresh token does not expire mid-request server-side. 939 // When running the Next.js development server, compiling a page or route handler might 940 // take longer than the configured leeway causing a 401 response. 941 leeway: 60000, 942 cookie: { 943 name: "diks_refresh_token" 944 } 945 } 946 }, 947 // Default configuration options for authentication cookies 948 cookies: { 949 options: __TURBOPACK__imported__module__685149__["COOKIE_OPTIONS"], 950 encrypt: (value)=>value, 951 decrypt: (value)=>value 952 } 953}; 954__turbopack_context__.s([ 955 "config", 956 0, 957 config 958], 609963); 959var __TURBOPACK__imported__module__765472__ = __turbopack_context__.i(765472); 960; 961; 962; 963; 964function createSession(tokenPair, context) { 965 const { refreshToken } = authCreateCookiesFromTokenPair(tokenPair); 966 (0, __TURBOPACK__imported__module__126476__["setCookie"])("diks_authenticated", context.isLoggedIn ? "true" : undefined, { 967 expires: new Date(refreshToken.decoded.exp * 1000) 968 }); 969} 970function setAccountType(accountType) { 971 (0, __TURBOPACK__imported__module__126476__["setCookie"])("diks_account_type", accountType, { 972 expires: (0, __TURBOPACK__imported__module__595727__["addDays"])(new Date(), 400) 973 }); 974} 975function deleteSession() { 976 (0, __TURBOPACK__imported__module__126476__["deleteCookie"])(config.session.accessToken.cookie.name); 977 (0, __TURBOPACK__imported__module__126476__["deleteCookie"])(config.session.refreshToken.cookie.name); 978 (0, __TURBOPACK__imported__module__126476__["deleteCookie"])(config.session.cache.cookie.name); 979 (0, __TURBOPACK__imported__module__126476__["deleteCookie"])("diks_account_type"); 980} 981function authCreateCookiesFromTokenPair(tokenPair) { 982 const accessToken = (0, __TURBOPACK__imported__module__765472__["decodeToken"])(tokenPair.accessToken); 983 const refreshToken = (0, __TURBOPACK__imported__module__765472__["decodeToken"])(tokenPair.refreshToken); 984 // Leeway is applied earlier in the middleware/interceptor, there's no need to lower the expiry of 985 // the cookies. 986 (0, __TURBOPACK__imported__module__126476__["setCookie"])(config.session.accessToken.cookie.name, tokenPair.accessToken, { 987 expires: new Date(accessToken.decoded.exp * 1000) 988 }); 989 (0, __TURBOPACK__imported__module__126476__["setCookie"])(config.session.refreshToken.cookie.name, tokenPair.refreshToken, { 990 expires: new Date(refreshToken.decoded.exp * 1000) 991 }); 992 return { 993 accessToken, 994 refreshToken 995 }; 996} 997__turbopack_context__.s([ 998 "authCreateCookiesFromTokenPair", 999 0, 1000 authCreateCookiesFromTokenPair, 1001 "createSession", 1002 0, 1003 createSession, 1004 "deleteSession", 1005 0, 1006 deleteSession, 1007 "setAccountType", 1008 0, 1009 setAccountType 1010], 541378); 1011}), 1012309000, ((__turbopack_context__) => { 1013"use strict"; 1014 1015var __TURBOPACK__imported__module__935343__ = __turbopack_context__.i(935343); 1016var __TURBOPACK__imported__module__281092__ = __turbopack_context__.i(281092); 1017; 1018; 1019function formatISO(date, options) { 1020 var _ref, _ref1; 1021 const date_ = (0, __TURBOPACK__imported__module__281092__["toDate"])(date, options === null || options === void 0 ? void 0 : options.in); 1022 if (isNaN(+date_)) { 1023 throw new RangeError("Invalid time value"); 1024 } 1025 const format = (_ref = options === null || options === void 0 ? void 0 : options.format) !== null && _ref !== void 0 ? _ref : "extended"; 1026 const representation = (_ref1 = options === null || options === void 0 ? void 0 : options.representation) !== null && _ref1 !== void 0 ? _ref1 : "complete"; 1027 let result = ""; 1028 let tzOffset = ""; 1029 const dateDelimiter = format === "extended" ? "-" : ""; 1030 const timeDelimiter = format === "extended" ? ":" : ""; 1031 // Representation is either 'date' or 'complete' 1032 if (representation !== "time") { 1033 const day = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(date_.getDate(), 2);
1034 const month = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(date_.getMonth() + 1, 2); 1035 const year = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(date_.getFullYear(), 4); 1036 // yyyyMMdd or yyyy-MM-dd. 1037 result = "".concat(year).concat(dateDelimiter).concat(month).concat(dateDelimiter).concat(day); 1038 } 1039 // Representation is either 'time' or 'complete' 1040 if (representation !== "date") { 1041 // Add the timezone. 1042 const offset = date_.getTimezoneOffset(); 1043 if (offset !== 0) { 1044 const absoluteOffset = Math.abs(offset); 1045 const hourOffset = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(Math.trunc(absoluteOffset / 60), 2); 1046 const minuteOffset = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(absoluteOffset % 60, 2); 1047 // If less than 0, the sign is +, because it is ahead of time. 1048 const sign = offset < 0 ? "+" : "-"; 1049 tzOffset = "".concat(sign).concat(hourOffset, ":").concat(minuteOffset); 1050 } else { 1051 tzOffset = "Z"; 1052 } 1053 const hour = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(date_.getHours(), 2); 1054 const minute = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(date_.getMinutes(), 2); 1055 const second = (0, __TURBOPACK__imported__module__935343__["addLeadingZeros"])(date_.getSeconds(), 2); 1056 // If there's also date, separate it with time with 'T' 1057 const separator = result === "" ? "" : "T"; 1058 // Creates a time string consisting of hour, minute, and second, separated by delimiters, if defined. 1059 const time = [ 1060 hour, 1061 minute, 1062 second 1063 ].join(timeDelimiter); 1064 // HHmmss or HH:mm:ss. 1065 result = "".concat(result).concat(separator).concat(time).concat(tzOffset); 1066 } 1067 return result; 1068} 1069const __TURBOPACK__default__export__ = formatISO; 1070__turbopack_context__.s([ 1071 "formatISO", 1072 0, 1073 formatISO 1074]); 1075}), 1076909156, ((__turbopack_context__) => { 1077"use strict"; 1078 1079/** 1080 * RegExp to match cookie-name in RFC 6265 sec 4.1.1 1081 * This refers out to the obsoleted definition of token in RFC 2616 sec 2.2 1082 * which has been replaced by the token definition in RFC 7230 appendix B. 1083 * 1084 * cookie-name = token 1085 * token = 1*tchar 1086 * tchar = "!" / "#" / "$" / "%" / "&" / "'" / 1087 * "*" / "+" / "-" / "." / "^" / "_" / 1088 * "`" / "|" / "~" / DIGIT / ALPHA 1089 * 1090 * Note: Allowing more characters - https://github.com/jshttp/cookie/issues/191 1091 * Allow same range as cookie value, except `=`, which delimits end of name. 1092 */ const cookieNameRegExp = /^[\u0021-\u003A\u003C\u003E-\u007E]+$/; 1093/** 1094 * RegExp to match cookie-value in RFC 6265 sec 4.1.1 1095 * 1096 * cookie-value = *cookie-octet / ( DQUOTE *cookie-octet DQUOTE ) 1097 * cookie-octet = %x21 / %x23-2B / %x2D-3A / %x3C-5B / %x5D-7E 1098 * ; US-ASCII characters excluding CTLs, 1099 * ; whitespace DQUOTE, comma, semicolon, 1100 * ; and backslash 1101 * 1102 * Allowing more characters: https://github.com/jshttp/cookie/issues/191 1103 * Comma, backslash, and DQUOTE are not part of the parsing algorithm. 1104 */ const cookieValueRegExp = /^[\u0021-\u003A\u003C-\u007E]*$/; 1105/** 1106 * RegExp to match domain-value in RFC 6265 sec 4.1.1 1107 * 1108 * domain-value = <subdomain> 1109 * ; defined in [RFC1034], Section 3.5, as 1110 * ; enhanced by [RFC1123], Section 2.1 1111 * <subdomain> = <label> | <subdomain> "." <label> 1112 * <label> = <let-dig> [ [ <ldh-str> ] <let-dig> ] 1113 * Labels must be 63 characters or less. 1114 * 'let-dig' not 'letter' in the first char, per RFC1123 1115 * <ldh-str> = <let-dig-hyp> | <let-dig-hyp> <ldh-str> 1116 * <let-dig-hyp> = <let-dig> | "-" 1117 * <let-dig> = <letter> | <digit> 1118 * <letter> = any one of the 52 alphabetic characters A through Z in 1119 * upper case and a through z in lower case 1120 * <digit> = any one of the ten digits 0 through 9 1121 *
1122 * Keep support for leading dot: https://github.com/jshttp/cookie/issues/173 1123 * 1124 * > (Note that a leading %x2E ("."), if present, is ignored even though that 1125 * character is not permitted, but a trailing %x2E ("."), if present, will 1126 * cause the user agent to ignore the attribute.) 1127 */ const domainValueRegExp = /^([.]?[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?)([.][a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?)*$/i; 1128/** 1129 * RegExp to match path-value in RFC 6265 sec 4.1.1 1130 * 1131 * path-value = <any CHAR except CTLs or ";"> 1132 * CHAR = %x01-7F 1133 * ; defined in RFC 5234 appendix B.1 1134 */ const pathValueRegExp = /^[\u0020-\u003A\u003D-\u007E]*$/; 1135/** 1136 * RegExp to match max-age-value in RFC 6265 sec 5.6.2 1137 */ const maxAgeRegExp = /^-?\d+$/; 1138/** 1139 * RegExp to match RFC 6265 cookie-octet values (without % to preserve roundtrip) that need no URL encoding. 1140 */ const cookieOctetRegExp = /^[!#$&'()*+\-.\/0-9:<=>?@A-Z[\]\^_`a-z{|}~]*$/; 1141const NullObject = /* @__PURE__ */ (()=>{ 1142 const C = function() {}; 1143 C.prototype = Object.create(null); 1144 return C; 1145})(); 1146function parseCookie(str, options) { 1147 const obj = new NullObject(); 1148 const len = str.length; 1149 // RFC 6265 sec 4.1.1, RFC 2616 2.2 defines a cookie name consists of one char minimum, plus '='. 1150 if (len < 2) return obj; 1151 const dec = (options === null || options === void 0 ? void 0 : options.decode) || decode; 1152 let index = 0; 1153 do { 1154 const eqIdx = eqIndex(str, index, len); 1155 if (eqIdx === len) break; // No more cookie pairs. 1156 const endIdx = endIndex(str, index, len); 1157 if (eqIdx > endIdx) { 1158 // backtrack on prior semicolon 1159 index = str.lastIndexOf(";", eqIdx - 1) + 1; 1160 continue; 1161 } 1162 const key = valueSlice(str, index, eqIdx); 1163 // only assign once 1164 if (obj[key] === undefined) { 1165 obj[key] = dec(valueSlice(str, eqIdx + 1, endIdx)); 1166 } 1167 index = endIdx + 1; 1168 }while (index < len) 1169 return obj; 1170} 1171function stringifyCookie(cookie, options) { 1172 const enc = (options === null || options === void 0 ? void 0 : options.encode) || defaultEncode; 1173 const keys = Object.keys(cookie); 1174 let str = ""; 1175 for(let i = 0; i < keys.length; i++){ 1176 const name = keys[i]; 1177 const val = cookie[name]; 1178 if (val === undefined) continue; 1179 if (!cookieNameRegExp.test(name)) { 1180 throw new TypeError("cookie name is invalid: ".concat(name)); 1181 } 1182 const value = enc(val); 1183 if (!cookieValueRegExp.test(value)) { 1184 throw new TypeError("cookie val is invalid: ".concat(val)); 1185 } 1186 if (str) str += "; "; 1187 str += name + "=" + value; 1188 } 1189 return str; 1190} 1191function stringifySetCookie(cookie, options) { 1192 const enc = (options === null || options === void 0 ? void 0 : options.encode) || defaultEncode; 1193 if (!cookieNameRegExp.test(cookie.name)) { 1194 throw new TypeError("argument name is invalid: ".concat(cookie.name)); 1195 } 1196 const value = cookie.value == null ? "" : enc(cookie.value); 1197 if (!cookieValueRegExp.test(value)) { 1198 throw new TypeError("argument val is invalid: ".concat(cookie.value)); 1199 } 1200 let str = cookie.name + "=" + value; 1201 if (cookie.maxAge !== undefined) { 1202 if (!Number.isInteger(cookie.maxAge)) { 1203 throw new TypeError("option maxAge is invalid: ".concat(cookie.maxAge)); 1204 } 1205 str += "; Max-Age=" + cookie.maxAge; 1206 } 1207 if (cookie.domain) { 1208 if (!domainValueRegExp.test(cookie.domain)) { 1209 throw new TypeError("option domain is invalid: ".concat(cookie.domain)); 1210 } 1211 str += "; Domain=" + cookie.domain; 1212 } 1213 if (cookie.path) { 1214 if (!pathValueRegExp.test(cookie.path)) { 1215 throw new TypeError("option path is invalid: ".concat(cookie.path)); 1216 } 1217 str += "; Path=" + cookie.path; 1218 } 1219 if (cookie.expires) { 1220 if (!Number.isFinite(cookie.expires.valueOf())) {
1221 throw new TypeError("option expires is invalid: ".concat(cookie.expires)); 1222 } 1223 str += "; Expires=" + cookie.expires.toUTCString(); 1224 } 1225 if (cookie.httpOnly) { 1226 str += "; HttpOnly"; 1227 } 1228 if (cookie.secure) { 1229 str += "; Secure"; 1230 } 1231 if (cookie.partitioned) { 1232 str += "; Partitioned"; 1233 } 1234 if (cookie.priority) { 1235 const priority = typeof cookie.priority === "string" ? cookie.priority.toLowerCase() : undefined; 1236 switch(priority){ 1237 case "low": 1238 str += "; Priority=Low"; 1239 break; 1240 case "medium": 1241 str += "; Priority=Medium"; 1242 break; 1243 case "high": 1244 str += "; Priority=High"; 1245 break; 1246 default: 1247 throw new TypeError("option priority is invalid: ".concat(cookie.priority)); 1248 } 1249 } 1250 if (cookie.sameSite) { 1251 const sameSite = typeof cookie.sameSite === "string" ? cookie.sameSite.toLowerCase() : cookie.sameSite; 1252 switch(sameSite){ 1253 case true: 1254 case "strict": 1255 str += "; SameSite=Strict"; 1256 break; 1257 case "lax": 1258 str += "; SameSite=Lax"; 1259 break; 1260 case "none": 1261 str += "; SameSite=None"; 1262 break; 1263 default: 1264 throw new TypeError("option sameSite is invalid: ".concat(cookie.sameSite)); 1265 } 1266 } 1267 return str; 1268} 1269function parseSetCookie(str, options) { 1270 const dec = (options === null || options === void 0 ? void 0 : options.decode) || decode; 1271 const len = str.length; 1272 const endIdx = endIndex(str, 0, len); 1273 let eqIdx = eqIndex(str, 0, len);
1274 const setCookie = eqIdx < endIdx ? { 1275 name: valueSlice(str, 0, eqIdx), 1276 value: dec(valueSlice(str, eqIdx + 1, endIdx)) 1277 } : { 1278 name: "", 1279 value: dec(valueSlice(str, 0, endIdx)) 1280 }; 1281 let index = endIdx + 1; 1282 while(index < len){ 1283 const endIdx = endIndex(str, index, len); 1284 if (eqIdx < index) eqIdx = eqIndex(str, index, len); 1285 const attr = eqIdx < endIdx ? valueSlice(str, index, eqIdx) : valueSlice(str, index, endIdx); 1286 const val = eqIdx < endIdx ? valueSlice(str, eqIdx + 1, endIdx) : undefined; 1287 switch(attr.toLowerCase()){ 1288 case "httponly": 1289 setCookie.httpOnly = true; 1290 break; 1291 case "secure": 1292 setCookie.secure = true; 1293 break; 1294 case "partitioned": 1295 setCookie.partitioned = true; 1296 break; 1297 case "domain": 1298 setCookie.domain = val; 1299 break; 1300 case "path": 1301 setCookie.path = val; 1302 break; 1303 case "max-age": 1304 if (val && maxAgeRegExp.test(val)) setCookie.maxAge = Number(val); 1305 break; 1306 case "expires": 1307 if (!val) break; 1308 const date = new Date(val); 1309 if (Number.isFinite(date.valueOf())) setCookie.expires = date; 1310 break; 1311 case "priority": 1312 if (!val) break; 1313 const priority = val.toLowerCase(); 1314 if (priority === "low" || priority === "medium" || priority === "high") { 1315 setCookie.priority = priority; 1316 } 1317 break; 1318 case "samesite": 1319 if (!val) break; 1320 const sameSite = val.toLowerCase(); 1321 if (sameSite === "lax" || sameSite === "strict" || sameSite === "none") { 1322 setCookie.sameSite = sameSite; 1323 } 1324 break; 1325 } 1326 index = endIdx + 1; 1327 } 1328 return setCookie; 1329} 1330/** 1331 * Find the next `;` character, or return `len`. 1332 */ function endIndex(str, min, len) { 1333 const index = str.indexOf(";", min); 1334 return index === -1 ? len : index; 1335} 1336/** 1337 * Find the next `=` character, or return `len`. 1338 */ function eqIndex(str, min, len) { 1339 const index = str.indexOf("=", min); 1340 return index === -1 ? len : index; 1341} 1342/** 1343 * Slice out a value between startPod to max. 1344 */ function valueSlice(str, min, max) { 1345 if (min === max) return ""; 1346 let start = min; 1347 let end = max; 1348 do { 1349 const code = str.charCodeAt(start); 1350 if (code !== 32 /* */ && code !== 9 /* \t */ ) break; 1351 }while (++start < end) 1352 while(end > start){ 1353 const code = str.charCodeAt(end - 1); 1354 if (code !== 32 /* */ && code !== 9 /* \t */ ) break; 1355 end--; 1356 } 1357 return str.slice(start, end); 1358} 1359/** 1360 * URL-decode string value. Optimized to skip native call when no %. 1361 */ function decode(str) { 1362 if (str.indexOf("%") === -1) return str; 1363 try { 1364 return decodeURIComponent(str); 1365 } catch (e) { 1366 return str; 1367 } 1368} 1369/** 1370 * URL-encode string value. Optimized to skip native call for roundtrip-safe cookie-octet values. 1371 */ function defaultEncode(str) { 1372 return cookieOctetRegExp.test(str) ? str : encodeURIComponent(str); 1373} 1374__turbopack_context__.s([ 1375 "parseCookie", 1376 0, 1377 parseCookie, 1378 "stringifySetCookie", 1379 0, 1380 stringifySetCookie 1381]); 1382}), 1383126476, ((__turbopack_context__) => { 1384"use strict"; 1385 1386var __TURBOPACK__imported__module__929387__ = __turbopack_context__.i(929387); 1387var __TURBOPACK__imported__module__109881__ = __turbopack_context__.i(109881); 1388var __TURBOPACK__imported__module__909156__ = __turbopack_context__.i(909156); 1389var __TURBOPACK__imported__module__309000__ = __turbopack_context__.i(309000); 1390var __TURBOPACK__imported__module__685149__ = __turbopack_context__.i(685149); 1391; 1392; 1393; 1394; 1395function setCookie(name, value, options) { 1396 if (value === undefined || value === null) { 1397 deleteCookie(name, options); 1398 return; 1399 } 1400 const serialized = value instanceof Date ? (0, __TURBOPACK__imported__module__309000__["formatISO"])(value, { 1401 in: (0, __TURBOPACK__imported__module__109881__["tz"])(__TURBOPACK__imported__module__685149__["TIMEZONE"]) 1402 }) : value.toString(); 1403 document.cookie = (0, __TURBOPACK__imported__module__909156__["stringifySetCookie"])({ 1404 name, 1405 value: serialized, 1406 ...__TURBOPACK__imported__module__685149__["COOKIE_OPTIONS"], 1407 ...options 1408 }); 1409} 1410function deleteCookie(name, options) { 1411 document.cookie = (0, __TURBOPACK__imported__module__909156__["stringifySetCookie"])({ 1412 name, 1413 value: "", 1414 ...__TURBOPACK__imported__module__685149__["COOKIE_OPTIONS"], 1415 ...options, 1416 maxAge: 0 1417 }); 1418} 1419function parseCookieNumber(value) { 1420 if (!value) { 1421 return undefined; 1422 } 1423 const parsed = Number(value); 1424 return isNaN(parsed) ? undefined : parsed; 1425} 1426function parseCookieDate(value) { 1427 if (!value) { 1428 return undefined; 1429 } 1430 const parsed = (0, __TURBOPACK__imported__module__826514__["parseISO"])(value);
1431 return (0, __TURBOPACK__imported__module__368977__["isValid"])(parsed) ? parsed : undefined; 1432} 1433__turbopack_context__.s([ 1434 "deleteCookie", 1435 0, 1436 deleteCookie, 1437 "setCookie", 1438 0, 1439 setCookie 1440]); 1441}), 1442408155, ((__turbopack_context__) => { 1443"use strict"; 1444 1445const createStoreImpl = (createState)=>{ 1446 let state; 1447 const listeners = /* @__PURE__ */ new Set(); 1448 const setState = (partial, replace)=>{ 1449 const nextState = typeof partial === "function" ? partial(state) : partial; 1450 if (!Object.is(nextState, state)) { 1451 const previousState = state; 1452 state = (replace != null ? replace : typeof nextState !== "object" || nextState === null) ? nextState : Object.assign({}, state, nextState); 1453 listeners.forEach((listener)=>listener(state, previousState)); 1454 } 1455 }; 1456 const getState = ()=>state; 1457 const getInitialState = ()=>initialState; 1458 const subscribe = (listener)=>{ 1459 listeners.add(listener); 1460 return ()=>listeners.delete(listener); 1461 }; 1462 const api = { 1463 setState, 1464 getState, 1465 getInitialState, 1466 subscribe 1467 }; 1468 const initialState = state = createState(setState, getState, api); 1469 return api; 1470}; 1471const createStore = (createState)=>createState ? createStoreImpl(createState) : createStoreImpl; 1472; 1473__turbopack_context__.s([ 1474 "createStore", 1475 0, 1476 createStore 1477]); 1478}), 1479768834, ((__turbopack_context__) => { 1480"use strict"; 1481 1482var __TURBOPACK__imported__module__271645__ = __turbopack_context__.i(271645); 1483var __TURBOPACK__imported__module__408155__ = __turbopack_context__.i(408155); 1484; 1485; 1486const identity = (arg)=>arg; 1487function useStore(api) { 1488 let selector = arguments.length > 1 && arguments[1] !== void 0 ? arguments[1] : identity; 1489 const slice = __TURBOPACK__imported__module__271645__["default"].useSyncExternalStore(api.subscribe, __TURBOPACK__imported__module__271645__["default"].useCallback(()=>selector(api.getState()), [ 1490 api, 1491 selector 1492 ]), __TURBOPACK__imported__module__271645__["default"].useCallback(()=>selector(api.getInitialState()), [ 1493 api, 1494 selector 1495 ])); 1496 __TURBOPACK__imported__module__271645__["default"].useDebugValue(slice); 1497 return slice; 1498} 1499const createImpl = (createState)=>{ 1500 const api = (0, __TURBOPACK__imported__module__408155__["createStore"])(createState); 1501 const useBoundStore = (selector)=>useStore(api, selector); 1502 Object.assign(useBoundStore, api); 1503 return useBoundStore; 1504}; 1505const create = (createState)=>createState ? createImpl(createState) : createImpl; 1506; 1507__turbopack_context__.s([ 1508 "create", 1509 0, 1510 create, 1511 "useStore", 1512 0, 1513 useStore 1514]); 1515}), 1516]); 1517 1518//# debugId=6ed49639-25ed-5eff-be18-4232a987c32d
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.