1import{E as oe,am as D,_ as ie,r as se,o as ce,a as de,d as S,e as C,f as _,t as N,V as ue,h as fe}from"./Cwz_WouP.js";import"./BRxYuIZ2.js";import"./BhJfXzvr.js";import{S as pe}from"./CnUJMEDP.js";import"./u3mHYVTa.js";import"./CHBmHQ0b.js";import"./Df9Fqs_l.js";import"./ClinoSA1.js";import"./bf1TkpW5.js";import"./BQF8roka.js";import"./B4HPuSoq.js";import"./D3MWzMF6.js";import{V as le}from"./DzypJU4U.js";import{V as he,a as me}from"./3uNWqCd7.js";import"./DFGCUIv2.js";import"./U5qy42Yi.js";import"./CTdVocTC.js";import"./DW2lbNFA.js";import"./BzmqKkR-.js";import"./BEMJ86Yt.js";import"./B6ZByeEo.js";import"./CY3mqz-c.js";import"./BBor53VI.js";import"./CA_ukTPq.js";import"./BGe03BFN.js";import"./DgXOY76Q.js";import"./a5WZRLWG.js";import"./CRBiUrO-.js";const k=new TextEncoder,v=new TextDecoder;function ye(...e){const t=e.reduce((a,{length:o})=>a+o,0),r=new Uint8Array(t);let n=0;for(const a of e)r.set(a,n),n+=a.length;return r}function J(e){const t=new Uint8Array(e.length);for(let r=0;r<e.length;r++){const n=e.charCodeAt(r);if(n>127)throw new TypeError("non-ASCII string encountered in encode()");t[r]=n}return t}function X(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);const t=atob(e),r=new Uint8Array(t.length);for(let n=0;n<t.length;n++)r[n]=t.charCodeAt(n);return r}function $(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(typeof e=="string"?e:v.decode(e),{alphabet:"base64url"});let t=e;t instanceof Uint8Array&&(t=v.decode(t)),t=t.replace(/-/g,"+").replace(/_/g,"/");try{return X(t)}catch{throw new TypeError("The input to be decoded is not correctly encoded.")}}const m=(e,t="algorithm.name")=>new TypeError(`CryptoKey does not support this operation, its ${t} must be ${e}`),A=(e,t)=>
1e.name===t;function Se(e){return parseInt(e.name.slice(4),10)}function H(e,t){if(Se(e.hash)!==t)throw m(`SHA-${t}`,"algorithm.hash")}function Ee(e){switch(e){case"ES256":return"P-256";case"ES384":return"P-384";case"ES512":return"P-521";default:throw new Error("unreachable")}}function we(e,t){if(!e.usages.includes(t))throw new TypeError(`CryptoKey does not support this operation, its usages must include ${t}.`)}function Ae(e,t,r){switch(t){case"HS256":case"HS384":case"HS512":{if(!A(e.algorithm,"HMAC"))throw m("HMAC");H(e.algorithm,parseInt(t.slice(2),10));break}case"RS256":case"RS384":case"RS512":{if(!A(e.algorithm,"RSASSA-PKCS1-v1_5"))throw m("RSASSA-PKCS1-v1_5");H(e.algorithm,parseInt(t.slice(2),10));break}case"PS256":case"PS384":case"PS512":{if(!A(e.algorithm,"RSA-PSS"))throw m("RSA-PSS");H(e.algorithm,parseInt(t.slice(2),10));break}case"Ed25519":case"EdDSA":{if(!A(e.algorithm,"Ed25519"))throw m("Ed25519");break}case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":{if(!A(e.algorithm,t))throw m(t);break}case"ES256":case"ES384":case"ES512":{if(!A(e.algorithm,"ECDSA"))throw m("ECDSA");const n=Ee(t);if(e.algorithm.namedCurve!==n)throw m(n,"algorithm.namedCurve");break}default:throw new TypeError("CryptoKey does not support this operation")}we(e,r)}function z(e,t,...r){if(r=r.filter(Boolean),r.length>2){const n=r.pop();e+=`one of type ${r.join(", ")}, or ${n}.`}else r.length===2?e+=`one of type ${r[0]} or ${r[1]}.`:e+=`of type ${r[0]}.`;return t==null?e+=` Received ${t}`:typeof t=="function"&&t.name?e+=` Received function ${t.name}`:typeof t=="object"&&t!=null&&t.constructor?.name&&(e+=` Received an instance of ${t.constructor.name}`),e}const be=(e,...t)=>z("Key must be ",e,...t),Q=(e,t,...r)=>z(`Key for the ${e} algorithm must be `,t,...r);class E extends Error{static code="ERR_JOSE_GENERIC";code="ERR_JOSE_GENERIC";constructor(t,r){super(t,r),this.name=this.constructor.name,Error.captureStackTrace?.(this,this.constructor)}}class f extends E{static code="ERR_JWT_CLAIM_VALIDATION_FAILED";code="ERR_JWT_CLAIM_VALIDATION_FAILED";claim;reason;payload;constructor(t,r,n="unspecified",a="unspecified"){super(t,{cause:{claim:n,reason:a,payload:r}}),this.claim=n,this.reason=a,this.payload=r}}class B extends E{static code="ERR_JWT_EXPIRED";code="ERR_JWT_EXPIRED";claim;reason;payload;constructor(t,r,n="unspecified",a="unspecified"){super(t,{cause:{claim:n,reason:a,payload:r}}),this.claim=n,this.reason=a,this.payload=r}}class ge extends E{static code="ERR_JOSE_ALG_NOT_ALLOWED";code="ERR_JOSE_ALG_NOT_ALLOWED"}
1class h extends E{static code="ERR_JOSE_NOT_SUPPORTED";code="ERR_JOSE_NOT_SUPPORTED"}class d extends E{static code="ERR_JWS_INVALID";code="ERR_JWS_INVALID"}class Y extends E{static code="ERR_JWT_INVALID";code="ERR_JWT_INVALID"}class Ke extends E{static code="ERR_JWS_SIGNATURE_VERIFICATION_FAILED";code="ERR_JWS_SIGNATURE_VERIFICATION_FAILED";constructor(t="signature verification failed",r){super(t,r)}}const Z=e=>{if(e?.[Symbol.toStringTag]==="CryptoKey")return!0;try{return e instanceof CryptoKey}catch{return!1}},j=e=>e?.[Symbol.toStringTag]==="KeyObject",ee=e=>Z(e)||j(e);function V(e,t,r){try{return $(e)}catch{throw new r(`Failed to base64url decode the ${t}`)}}const Ce=e=>typeof e=="object"&&e!==null;function x(e){if(!Ce(e)||Object.prototype.toString.call(e)!=="[object Object]")return!1;if(Object.getPrototypeOf(e)===null)return!0;let t=e;for(;Object.getPrototypeOf(t)!==null;)t=Object.getPrototypeOf(t);return Object.getPrototypeOf(e)===t}function ve(...e){const t=e.filter(Boolean);if(t.length===0||t.length===1)return!0;let r;for(const n of t){const a=Object.keys(n);if(!r||r.size===0){r=new Set(a);continue}for(const o of a){if(r.has(o))return!1;r.add(o)}}return!0}const M=e=>x(e)&&typeof e.kty=="string",Pe=e=>e.kty!=="oct"&&(e.kty==="AKP"&&typeof e.priv=="string"||typeof e.d=="string"),Te=e=>e.kty!=="oct"&&e.d===void 0&&e.priv===void 0,Re=e=>e.kty==="oct"&&typeof e.k=="string";function xe(e,t){if(e.startsWith("RS")||e.startsWith("PS")){const{modulusLength:r}=t.algorithm;if(typeof r!="number"||r<2048)throw new TypeError(`${e} requires key modulusLength to be 2048 bits or larger`)}}function Ie(e,t){const r=`SHA-${e.slice(-3)}`;switch(e){case"HS256":case"HS384":case"HS512":return{hash:r,name:"HMAC"};case"PS256":case"PS384":case"PS512":return{hash:r,name:"RSA-PSS",saltLength:parseInt(e.slice(-3),10)>>3};case"RS256":case"RS384":case"RS512":return{hash:r,name:"RSASSA-PKCS1-v1_5"};case"ES256":case"ES384":case"ES512":return{hash:r,name:"ECDSA",namedCurve:t.namedCurve};
1case"Ed25519":case"EdDSA":return{name:"Ed25519"};case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return{name:e};default:throw new h(`alg ${e} is not supported either by JOSE or your javascript runtime`)}}async function We(e,t,r){if(t instanceof Uint8Array){if(!e.startsWith("HS"))throw new TypeError(be(t,"CryptoKey","KeyObject","JSON Web Key"));return crypto.subtle.importKey("raw",t,{hash:`SHA-${e.slice(-3)}`,name:"HMAC"},!1,[r])}return Ae(t,e,r),t}async function De(e,t,r,n){const a=await We(e,t,"verify");xe(e,a);const o=Ie(e,a.algorithm);try{return await crypto.subtle.verify(o,a,r,n)}catch{return!1}}const R='Invalid or unsupported JWK "alg" (Algorithm) Parameter value';function _e(e){let t,r;switch(e.kty){case"AKP":{switch(e.alg){case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":t={name:e.alg},r=e.priv?["sign"]:["verify"];break;default:throw new h(R)}break}case"RSA":{switch(e.alg){case"PS256":case"PS384":case"PS512":t={name:"RSA-PSS",hash:`SHA-${e.alg.slice(-3)}`},r=e.d?["sign"]:["verify"];break;case"RS256":case"RS384":case"RS512":t={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${e.alg.slice(-3)}`},r=e.d?["sign"]:["verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":t={name:"RSA-OAEP",hash:`SHA-${parseInt(e.alg.slice(-3),10)||1}`},r=e.d?["decrypt","unwrapKey"]:["encrypt","wrapKey"];break;default:throw new h(R)}break}case"EC":{switch(e.alg){case"ES256":case"ES384":case"ES512":t={name:"ECDSA",namedCurve:{ES256:"P-256",ES384:"P-384",ES512:"P-521"}[e.alg]},r=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:"ECDH",namedCurve:e.crv},r=e.d?["deriveBits"]:[];break;default:throw new h(R)}break}
1case"OKP":{switch(e.alg){case"Ed25519":case"EdDSA":t={name:"Ed25519"},r=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:e.crv},r=e.d?["deriveBits"]:[];break;default:throw new h(R)}break}default:throw new h('Invalid or unsupported JWK "kty" (Key Type) Parameter value')}return{algorithm:t,keyUsages:r}}async function Je(e){if(!e.alg)throw new TypeError('"alg" argument is required when "jwk.alg" is not present');const{algorithm:t,keyUsages:r}=_e(e),n={...e};return n.kty!=="AKP"&&delete n.alg,delete n.use,crypto.subtle.importKey("jwk",n,t,e.ext??!(e.d||e.priv),e.key_ops??r)}const b="given KeyObject instance cannot be used for this algorithm";let K;const F=async(e,t,r,n=!1)=>{K||=new WeakMap;let a=K.get(e);if(a?.[r])return a[r];const o=await Je({...t,alg:r});return n&&Object.freeze(e),a?a[r]=o:K.set(e,{[r]:o}),o},He=(e,t)=>{K||=new WeakMap;let r=K.get(e);if(r?.[t])return r[t];const n=e.type==="public",a=!!n;let o;if(e.asymmetricKeyType==="x25519"){switch(t){case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":break;default:throw new TypeError(b)}o=e.toCryptoKey(e.asymmetricKeyType,a,n?[]:["deriveBits"])}if(e.asymmetricKeyType==="ed25519"){if(t!=="EdDSA"&&t!=="Ed25519")throw new TypeError(b);o=e.toCryptoKey(e.asymmetricKeyType,a,[n?"verify":"sign"])}switch(e.asymmetricKeyType){case"ml-dsa-44":case"ml-dsa-65":case"ml-dsa-87":{if(t!==e.asymmetricKeyType.toUpperCase())throw new TypeError(b);o=e.toCryptoKey(e.asymmetricKeyType,a,[n?"verify":"sign"])}}if(e.asymmetricKeyType==="rsa"){let i;switch(t){case"RSA-OAEP":i="SHA-1";break;case"RS256":case"PS256":case"RSA-OAEP-256":i="SHA-256";break;case"RS384":case"PS384":case"RSA-OAEP-384":i="SHA-384";break;case"RS512":case"PS512":case"RSA-OAEP-512":i="SHA-512";break;default:throw new TypeError(b)}if(t.startsWith("RSA-OAEP"))return e.toCryptoKey({name:"RSA-OAEP",hash:i},a,n?["encrypt"]:["decrypt"]);o=e.toCryptoKey({name:t.startsWith("PS")?"RSA-PSS":"RSASSA-PKCS1-v1_5",hash:i},a,[n?"verify":"sign"])}if(e.asymmetricKeyType==="ec"){const s=new Map([["prime256v1","P-256"],["secp384r1","P-384"],["secp521r1","P-521"]]).get(e.asymmetricKeyDetails?.namedCurve);if(!s)throw new TypeError(b);const c={ES256:"P-256",ES384:"P-384",ES512:"P-521"};c[t]&&s===c[t]&&(o=e.toCryptoKey({name:"ECDSA",namedCurve:s},a,[n?"verify":"sign"])),t.startsWith("ECDH-ES")&&(o=e.toCryptoKey({name:"ECDH",namedCurve:s},a,n?[]:["deriveBits"]))}if(!o)throw new TypeError(b);return r?r[t]=o:K.set(e,{[t]:o}),o};async function Oe(e,t){if(e instanceof Uint8Array||Z(e))return e;if(j(e)){if(e.type==="secret")return e.export();if("toCryptoKey"in e&&typeof e.toCryptoKey=="function")try{return He(e,t)}catch(n){if(n instanceof TypeError)throw n}let r=e.export({format:"jwk"});return F(e,r,t)}if(M(e))return e.k?$(e.k):F(e,e,t,!0);throw new Error("unreachable")}const O=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let r=0;r<e.byteLength;r++)if(e[r]!==t[r])return!1;return!0},Le=e=>({data:e,pos:0}),I=e=>{const t=e.data[e.pos++];if(t&128){const r=t&127;let n=0;for(let a=0;a<r;a++)n=n<<8|e.data[e.pos++];return n}return t},W=(e,t,r)=>{if(e.data[e.pos++]!==t)throw new Error(r)},te=(e,t)=>{const r=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,r},$e=e=>{W(e,6,"Expected algorithm OID");const t=I(e);return te(e,t)};function Me(e){W(e,48,"Invalid SPKI structure"),I(e),W(e,48,"Expected algorithm identifier");const t=I(e);return{algIdStart:e.pos,algIdLength:t}}const Ue=e=>{const t=$e(e);if(O(t,[43,101,110]))return"X25519";if(!O(t,[42,134,72,206,61,2,1]))throw new Error("Unsupported key algorithm");W(e,6,"Expected curve OID");const r=I(e),n=te(e,r);for(const{name:a,oid:o}of[{name:"P-256",oid:[42,134,72,206,61,3,1,7]},{name:"P-384",oid:[43,129,4,0,34]},{name:"P-521",oid:[43,129,4,0,35]}])if(O(n,o))return a;throw new Error("Unsupported named curve")},Ne=async(e,t,r,n)=>{let a,o;const i=()=>["verify"],s=()=>["encrypt","wrapKey"];switch(r){case"PS256":case"PS384":case"PS512":a={name:"RSA-PSS",hash:`SHA-${r.slice(-3)}`},o=i();break;case"RS256":case"RS384":case"RS512":a={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${r.slice(-3)}`},o=i();break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":a={name:"RSA-OAEP",hash:`SHA-${parseInt(r.slice(-3),10)||1}`},o=s();break;case"ES256":case"ES384":case"ES512":{a={name:"ECDSA",namedCurve:{ES256:"P-256",ES384:"P-384",ES512:"P-521"}[r]},o=i();break}case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{try{const c=n.getNamedCurve(t);a=c==="X25519"?{name:"X25519"}:{name:"ECDH",namedCurve:c}}catch{throw new h("Invalid or unsupported key format")}o=[];break}
1case"Ed25519":case"EdDSA":a={name:"Ed25519"},o=i();break;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":a={name:r},o=i();break;default:throw new h('Invalid or unsupported "alg" (Algorithm) value')}return crypto.subtle.importKey(e,t,a,n?.extractable??!0,o)},ke=(e,t)=>X(e.replace(t,"")),Be=(e,t,r)=>{const n=ke(e,/(?:-----(?:BEGIN|END) PUBLIC KEY-----|\s)/g);let a=r;return t?.startsWith?.("ECDH-ES")&&(a||={},a.getNamedCurve=o=>{const i=Le(o);return Me(i),Ue(i)}),Ne("spki",n,t,a)};async function Ve(e,t,r){if(e.indexOf("-----BEGIN PUBLIC KEY-----")!==0)throw new TypeError('"spki" must be SPKI formatted string');return Be(e,t,r)}function Fe(e,t,r,n,a){if(a.crit!==void 0&&n?.crit===void 0)throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!n||n.crit===void 0)return new Set;if(!Array.isArray(n.crit)||n.crit.length===0||n.crit.some(i=>typeof i!="string"||i.length===0))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');let o;r!==void 0?o=new Map([...Object.entries(r),...t.entries()]):o=t;for(const i of n.crit){if(!o.has(i))throw new h(`Extension Header Parameter "${i}" is not recognized`);if(a[i]===void 0)throw new e(`Extension Header Parameter "${i}" is missing`);if(o.get(i)&&n[i]===void 0)throw new e(`Extension Header Parameter "${i}" MUST be integrity protected`)}return new Set(n.crit)}function qe(e,t){if(t!==void 0&&(!Array.isArray(t)||t.some(r=>typeof r!="string")))throw new TypeError(`"${e}" option must be an array of strings`);if(t)return new Set(t)}const g=e=>e?.[Symbol.toStringTag],L=(e,t,r)=>{if(t.use!==void 0){let n;switch(r){case"sign":case"verify":n="sig";break;case"encrypt":case"decrypt":n="enc";break}if(t.use!==n)throw new TypeError(`Invalid key for this operation, its "use" must be "${n}" when present`)}if(t.alg!==void 0&&t.alg!==e)throw new TypeError(`Invalid key for this operation, its "alg" must be "${e}" when present`);if(Array.isArray(t.key_ops)){let n;switch(!0){case r==="verify":case e==="dir":case e.includes("CBC-HS"):n=r;break;case e.startsWith("PBES2"):n="deriveBits";break;case/^A\d{3}(?:GCM)?(?:KW)?$/.test(e):!e.includes("GCM")&&e.endsWith("KW")?n="unwrapKey":n=r;break;case r==="encrypt":n="wrapKey";break;case r==="decrypt":n=e.startsWith("RSA")?"unwrapKey":"deriveBits";break}if(n&&t.key_ops?.includes?.(n)===!1)throw new TypeError(`Invalid key for this operation, its "key_ops" must include "${n}" when present`)}return!0},Ge=(e,t,r)=>{if(!(t instanceof Uint8Array)){if(M(t)){if(Re(t)&&L(e,t,r))return;throw new TypeError('JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present')}if(!ee(t))throw new TypeError(Q(e,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"));if(t.type!=="secret")throw new TypeError(`${g(t)} instances for symmetric algorithms must be of type "secret"`)}},Xe=(e,t,r)=>{if(M(t))switch(r){case"decrypt":case"sign":if(Pe(t)&&L(e,t,r))return;throw new TypeError("JSON Web Key for this operation must be a private JWK");case"encrypt":case"verify":if(Te(t)&&L(e,t,r))return;throw new TypeError("JSON Web Key for this operation must be a public JWK")}if(!ee(t))throw new TypeError(Q(e,t,"CryptoKey","KeyObject","JSON Web Key"));if(t.type==="secret")throw new TypeError(`${g(t)} instances for asymmetric algorithms must not be of type "secret"`);if(t.type==="public")switch(r){case"sign":throw new TypeError(`${g(t)} instances for asymmetric algorithm signing must be of type "private"`);case"decrypt":throw new TypeError(`${g(t)} instances for asymmetric algorithm decryption must be of type "private"`)}if(t.type==="private")switch(r){case"verify":throw new TypeError(`${g(t)} instances for asymmetric algorithm verifying must be of type "public"`);case"encrypt":throw new TypeError(`${g(t)} instances for asymmetric algorithm encryption must be of type "public"`)}};function ze(e,t,r){switch(e.substring(0,2)){case"A1":case"A2":case"di":case"HS":case"PB":Ge(e,t,r);break;default:Xe(e,t,r)}}async function Qe(e,t,r){if(!x(e))throw new d("Flattened JWS must be an object");
1if(e.protected===void 0&&e.header===void 0)throw new d('Flattened JWS must have either of the "protected" or "header" members');if(e.protected!==void 0&&typeof e.protected!="string")throw new d("JWS Protected Header incorrect type");if(e.payload===void 0)throw new d("JWS Payload missing");if(typeof e.signature!="string")throw new d("JWS Signature missing or incorrect type");if(e.header!==void 0&&!x(e.header))throw new d("JWS Unprotected Header incorrect type");let n={};if(e.protected)try{const ae=$(e.protected);n=JSON.parse(v.decode(ae))}catch{throw new d("JWS Protected Header is invalid")}if(!ve(n,e.header))throw new d("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");const a={...n,...e.header},o=Fe(d,new Map([["b64",!0]]),r?.crit,n,a);let i=!0;if(o.has("b64")&&(i=n.b64,typeof i!="boolean"))throw new d('The "b64" (base64url-encode payload) Header Parameter must be a boolean');const{alg:s}=a;if(typeof s!="string"||!s)throw new d('JWS "alg" (Algorithm) Header Parameter missing or invalid');const c=r&&qe("algorithms",r.algorithms);if(c&&!c.has(s))throw new ge('"alg" (Algorithm) Header Parameter value not allowed');if(i){if(typeof e.payload!="string")throw new d("JWS Payload must be a string")}else if(typeof e.payload!="string"&&!(e.payload instanceof Uint8Array))throw new d("JWS Payload must be a string or an Uint8Array instance");let p=!1;typeof t=="function"&&(t=await t(n,e),p=!0),ze(s,t,"verify");const y=ye(e.protected!==void 0?J(e.protected):new Uint8Array,J("."),typeof e.payload=="string"?i?J(e.payload):k.encode(e.payload):e.payload),l=V(e.signature,"signature",d),P=await Oe(t,s);if(!await De(s,P,l,y))throw new Ke;let u;i?u=V(e.payload,"payload",d):typeof e.payload=="string"?u=k.encode(e.payload):u=e.payload;const w={payload:u};return e.protected!==void 0&&(w.protectedHeader=n),e.header!==void 0&&(w.unprotectedHeader=e.header),p?{...w,key:P}:w}async function Ye(e,t,r){if(e instanceof Uint8Array&&(e=v.decode(e)),typeof e!="string")throw new d("Compact JWS must be a string or Uint8Array");const{0:n,1:a,2:o,length:i}=e.split(".");if(i!==3)throw new d("Invalid Compact JWS");const s=await Qe({payload:a,protected:n,signature:o},t,r),c={payload:s.payload,protectedHeader:s.protectedHeader};return typeof t=="function"?{...c,key:s.key}:c}const Ze=e=>Math.floor(e.getTime()/1e3),re=60,ne=re*60,U=ne*24,je=U*7,et=U*365.25,tt=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i;function q(e){const t=tt.exec(e);if(!t||t[4]&&t[1])throw new TypeError("Invalid time period format");const r=parseFloat(t[2]),n=t[3].toLowerCase();let a;switch(n){case"sec":case"secs":case"second":case"seconds":case"s":a=Math.round(r);break;case"minute":case"minutes":case"min":case"mins":case"m":a=Math.round(r*re);break;case"hour":case"hours":case"hr":case"hrs":case"h":a=Math.round(r*ne);break;case"day":case"days":case"d":a=Math.round(r*U);break;case"week":case"weeks":case"w":a=Math.round(r*je);break;default:a=Math.round(r*et);break}return t[1]==="-"||t[4]==="ago"?-a:a}const G=e=>e.includes("/")?e.toLowerCase():`application/${e.toLowerCase()}`,rt=(e,t)=>typeof e=="string"?t.includes(e):Array.isArray(e)?t.some(Set.prototype.has.bind(new Set(e))):!1;function nt(e,t,r={}){let n;try{n=JSON.parse(v.decode(t))}catch{}if(!x(n))throw new Y("JWT Claims Set must be a top-level JSON object");const{typ:a}=r;if(a&&(typeof e.typ!="string"||G(e.typ)!==G(a)))throw new f('unexpected "typ" JWT header value',n,"typ","check_failed");const{requiredClaims:o=[],issuer:i,subject:s,audience:c,maxTokenAge:p}=r,y=[...o];p!==void 0&&y.push("iat"),c!==void 0&&y.push("aud"),s!==void 0&&y.push("sub"),i!==void 0&&y.push("iss");for(const u of new Set(y.reverse()))if(!(u in n))throw new f(`missing required "${u}" claim`,n,u,"missing");if(i&&!(Array.isArray(i)?i:[i]).includes(n.iss))throw new f('unexpected "iss" claim value',n,"iss","check_failed");if(s&&n.sub!==s)throw new f('unexpected "sub" claim value',n,"sub","check_failed");if(c&&!rt(n.aud,typeof c=="string"?[c]:c))throw new f('unexpected "aud" claim value',n,"aud","check_failed");let l;switch(typeof r.clockTolerance){case"string":l=q(r.clockTolerance);break;case"number":l=r.clockTolerance;break;case"undefined":l=0;break;default:throw new TypeError("Invalid clockTolerance option type")}const{currentDate:P}=r,T=Ze(P||new Date);if((n.iat!==void 0||p)&&typeof n.iat!="number")throw new f('"iat" claim must be a number',n,"iat","invali
1d");if(n.nbf!==void 0){if(typeof n.nbf!="number")throw new f('"nbf" claim must be a number',n,"nbf","invalid");if(n.nbf>T+l)throw new f('"nbf" claim timestamp check failed',n,"nbf","check_failed")}if(n.exp!==void 0){if(typeof n.exp!="number")throw new f('"exp" claim must be a number',n,"exp","invalid");if(n.exp<=T-l)throw new B('"exp" claim timestamp check failed',n,"exp","check_failed")}if(p){const u=T-n.iat,w=typeof p=="number"?p:q(p);if(u-l>w)throw new B('"iat" claim timestamp check failed (too far in the past)',n,"iat","check_failed");if(u<0-l)throw new f('"iat" claim timestamp check failed (it should be in the past)',n,"iat","check_failed")}return n}async function at(e,t,r){const n=await Ye(e,t,r);if(n.protectedHeader.crit?.includes("b64")&&n.protectedHeader.b64===!1)throw new Y("JWTs MUST NOT use unencoded payload");const o={payload:nt(n.protectedHeader,n.payload,r),protectedHeader:n.protectedHeader};return typeof t=="function"?{...o,key:n.key}:o}const ot=`-----BEGIN PUBLIC KEY----- 2MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoyA2UY7jqygRKmxczf/x 3h4Wp+JnkQYSF117bd0dyTHJ+ysHOmKMTObMXOAg5xIyI+HAqzhlKw47Er8EE4zoQ 4KCKC7Pyl9lpmrg0R3/bCNSa27eO/dFKhGKlXx4FkJwdEiUI474FCzu6F+LfJ3Q1x 5/2dRGKd9yNy9nVJqTymMSOoK0c2rkqepfXDQl3JJ+9R7rnCRsfDhwFQVWZpsiTu6 6X4WdH9JxgDE2C4Fu+nPMl8inobG4vE5Wbn1+k8KjUkvrrA+AQXn92CSc8VpUHotg 7wF12IYU9wcHlbj2/QPIS3N4c8qcZ05+wljRbPpFtvyBpB4sqJ+dklTs8uWFuJCSV 8CwIDAQAB 9-----END PUBLIC KEY-----`,it=oe({name:"LoginToken",components:{SpacePlanetLoader:pe},data(){return{showAlert:!1}},computed:{error(){return this.$store.state.contextui.error}},watch:{error(e){e.alertType!==void 0&&(this.showAlert=!0)}},async mounted(){try{const e=await this.extractToken();e?await this.setToken(e):await this.$router.push("/account/login")}catch(e){e?.code==="ERR_JWT_EXPIRED"?await this.$store.dispatch("contextui/reportError",this.$t("pages.account.token.index.tokenExpired")):await this.$store.dispatch("contextui/reportError",this.$t("pages.account.token.index.invalidToken"))}},methods:{async extractToken(){const e=await Ve(ot,"RS256"),t=Array.isArray((this._.provides[D]||this.$route).query.token)===!0?(this._.provides[D]||this.$route).query.token[0]:(this._.provides[D]||this.$route).query.token,{payload:r}=await at(t,e,{algorithms:["RS256"]});return r.token},async setToken(e){await this.$auth.setUserToken(e),await this.$router.push("/dashboard/posture")}}});function st(e,t,r,n,a,o){const i=se("SpacePlanetLoader");return ce(),de(me,{"align-content":"center",justify:"center","no-gutters":"",class:"token-loading-view",style:{"min-height":"100vh","background-color":"#00415d"}},{default:S(()=>[C(le,{modelValue:e.showAlert,"onUpdate:modelValue":t[1]||(t[1]=s=>e.showAlert=s),color:e.error.alertType,location:"top",timeout:"-1"},{actions:S(()=>[C(ue,{size:"small",variant:"text",onClick:t[0]||(t[0]=s=>e.$router.push("/account/login"))},{append:S(()=>[C(fe,{size:"small"},{default:S(()=>[...t[2]||(t[2]=[_("mdi-open-in-new",-1)])]),_:1})]),default:S(()=>[_(N(e.$t("pages.account.token.index.loginLink"))+" ",1)]),_:1})]),default:S(()=>[_(N(e.error.alertMessage)+" ",1)]),_:1},8,["modelValue","color"]),C(he,{cols:"6",class:"text-center"},{default:S(()=>[C(i,{message:e.$t("pages.account.token.index.loggingIn")},null,8,["message"])]),_:1})]),_:1})}const Ot=ie(it,[["render",st]]);export{Ot as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.