PageSourceSearch

https://www.learnbydo.ing/_next/static/chunks/6220-dd9f919b14ad1b10.js

js learnbydo.ing collected 2026-09-25 21:05:50 UTC 85,218 bytes, 3 lines download raw bytes

1(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[6220],{86783:function(e,t,r){"use strict";var n=r(49711);Object.defineProperty(t,"__esModule",{value:!0}),t.SessionStore=void 0,t.defaultCookies=function(e){let t=e?"__Secure-":"";return{sessionToken:{name:`${t}next-auth.session-token`,options:{httpOnly:!0,sameSite:"lax",path:"/",secure:e}},callbackUrl:{name:`${t}next-auth.callback-url`,options:{httpOnly:!0,sameSite:"lax",path:"/",secure:e}},csrfToken:{name:`${e?"__Host-":""}next-auth.csrf-token`,options:{httpOnly:!0,sameSite:"lax",path:"/",secure:e}},pkceCodeVerifier:{name:`${t}next-auth.pkce.code_verifier`,options:{httpOnly:!0,sameSite:"lax",path:"/",secure:e,maxAge:900}},state:{name:`${t}next-auth.state`,options:{httpOnly:!0,sameSite:"lax",path:"/",secure:e,maxAge:900}},nonce:{name:`${t}next-auth.nonce`,options:{httpOnly:!0,sameSite:"lax",path:"/",secure:e}}}};var a=n(r(43130)),i=n(r(39825));function o(e,t){c(e,t),t.add(e)}function s(e,t,r){c(e,t),t.set(e,r)}function c(e,t){if(t.has(e))throw TypeError("Cannot initialize the same private elements twice on an object")}function d(e,t,r){if(!t.has(e))throw TypeError("attempted to get private field on non-instance");return r}var u=new WeakMap,l=new WeakMap,p=new WeakMap,h=new WeakSet,y=new WeakSet;class f{constructor(e,t,r){o(this,y),o(this,h),s(this,u,{writable:!0,value:{}}),s(this,l,{writable:!0,value:void 0}),s(this,p,{writable:!0,value:void 0}),(0,i.default)(this,p,r),(0,i.default)(this,l,e);let{cookies:n}=t,{name:c}=e;if("function"==typeof(null==n?void 0:n.getAll))for(let{name:e,value:t}of n.getAll())e.startsWith(c)&&((0,a.default)(this,u)[e]=t);else if(n instanceof Map)for(let e of n.keys())e.startsWith(c)&&((0,a.default)(this,u)[e]=n.get(e));else for(let e in n)e.startsWith(c)&&((0,a.default)(this,u)[e]=n[e])}get value(){return Object.keys((0,a.default)(this,u)).sort((e,t)=>{var r,n;return parseInt(null!==(r=e.split(".").pop())&&void 0!==r?r:"0")-parseInt(null!==(n=t.split(".").pop())&&void 0!==n?n:"0")}).map(e=>(0,a.default)(this,u)[e]).join("")}chunk(e,t){let r=d(this,y,m).call(this);for(let n of d(this,h,w).call(this,{name:(0,a.default)(this,l).name,value:e,options:{...(0,a.default)(this,l).options,...t}}))r[n.name]=n;return Object.values(r)}clean(){return Object.values(d(this,y,m).call(this))}}function w(e){let t=Math.ceil(e.value.length/3933);if(1===t)return(0,a.default)(this,u)[e.name]=e.value,[e];let r=[];for(let n=0;n<t;n++){let t=`${e.name}.${n}`,i=e.value.substr(3933*n,3933);r.push({...e,name:t,value:i}),(0,a.default)(this,u)[t]=i}return(0,a.default)(this,p).debug("CHUNKING_SESSION_COOKIE",{message:"Session cookie exceeds allowed 4096 bytes.",emptyCookieSize:163,valueSize:e.value.length,chunks:r.map(e=>e.value.length+163)}),r}function m(){let e={};for(let r in(0,a.default)(this,u)){var t;null===(t=(0,a.default)(this,u))||void 0===t||delete t[r],e[r]={name:r,value:"",options:{...(0,a.default)(this,l).options,maxAge:0}}}return e}t.SessionStore=f},30859:function(e,t,r){"use strict";var n=r(28070),a=r(49711);Object.defineProperty(t,"__esModule",{value:!0});var i={encode:!0,decode:!0,getToken:!0};t.decode=h,t.encode=p,t.getToken=y;var o=r(42530),s=a(r(81631)),c=r(20200),d=r(86783),u=r(46415);Object.keys(u).forEach(function(e){!("default"===e||"__esModule"===e||Object.prototype.hasOwnProperty.call(i,e))&&(e in t&&t[e]===u[e]||Object.defineProperty(t,e,{enumerable:!0,get:function(){return u[e]}}))});let l=()=>Date.now()/1e3|0;async function p(e){let{token:t={},secret:r,maxAge:n=2592e3,salt:a=""}=e,i=await f(r,a);return await new o.EncryptJWT(t).setProtectedHeader({alg:"dir",enc:"A256GCM"}).setIssuedAt().setExpirationTime(l()+n).setJti((0,c.v4)()).encrypt(i)}async function h(e){let{token:t,secret:r,salt:n=""}=e;if(!t)return null;let a=await f(r,n),{payload:i}=await (0,o.jwtDecrypt)(t,a,{clockTolerance:15});return i}async function y(e){var t,r,a;let{req:i,secureCookie:o=null!==(t=null===(r=n.env.NEXTAUTH_URL)||void 0===r?void 0:r.startsWith("https://"))&&void 0!==t?t:!!n.env.VERCEL,cookieName:s=o?"__Secure-next-auth.session-token":"next-auth.session-token",raw:c,decode:u=h,logger:l=console,secret:p=n.env.NEXTAUTH_SECRET}=e;
1if(!i)throw Error("Must pass `req` to JWT getToken()");let y=new d.SessionStore({name:s,options:{secure:o}},{cookies:i.cookies,headers:i.headers},l).value,f=i.headers instanceof Headers?i.headers.get("authorization"):null===(a=i.headers)||void 0===a?void 0:a.authorization;if(y||(null==f?void 0:f.split(" ")[0])!=="Bearer"||(y=decodeURIComponent(f.split(" ")[1])),!y)return null;if(c)return y;try{return await u({token:y,secret:p})}catch(e){return null}}async function f(e,t){return await (0,s.default)("sha256",e,t,`NextAuth.js Generated Encryption Key${t?` (${t})`:""}`,32)}},46415:function(e,t){"use strict";Object.defineProperty(t,"__esModule",{value:!0})},33134:function(e){"use strict";var t=Object.defineProperty,r=Object.getOwnPropertyDescriptor,n=Object.getOwnPropertyNames,a=Object.prototype.hasOwnProperty,i={};function o(e){var t;let r=["path"in e&&e.path&&`Path=${e.path}`,"expires"in e&&(e.expires||0===e.expires)&&`Expires=${("number"==typeof e.expires?new Date(e.expires):e.expires).toUTCString()}`,"maxAge"in e&&"number"==typeof e.maxAge&&`Max-Age=${e.maxAge}`,"domain"in e&&e.domain&&`Domain=${e.domain}`,"secure"in e&&e.secure&&"Secure","httpOnly"in e&&e.httpOnly&&"HttpOnly","sameSite"in e&&e.sameSite&&`SameSite=${e.sameSite}`,"partitioned"in e&&e.partitioned&&"Partitioned","priority"in e&&e.priority&&`Priority=${e.priority}`].filter(Boolean),n=`${e.name}=${encodeURIComponent(null!=(t=e.value)?t:"")}`;return 0===r.length?n:`${n}; ${r.join("; ")}`}function s(e){let t=new Map;for(let r of e.split(/; */)){if(!r)continue;let e=r.indexOf("=");if(-1===e){t.set(r,"true");continue}let[n,a]=[r.slice(0,e),r.slice(e+1)];try{t.set(n,decodeURIComponent(null!=a?a:"true"))}catch{}}return t}function c(e){var t,r;if(!e)return;let[[n,a],...i]=s(e),{domain:o,expires:c,httponly:l,maxage:p,path:h,samesite:y,secure:f,partitioned:w,priority:m}=Object.fromEntries(i.map(([e,t])=>[e.toLowerCase(),t]));return function(e){let t={};for(let r in e)e[r]&&(t[r]=e[r]);return t}({name:n,value:decodeURIComponent(a),domain:o,...c&&{expires:new Date(c)},...l&&{httpOnly:!0},..."string"==typeof p&&{maxAge:Number(p)},path:h,...y&&{sameSite:d.includes(t=(t=y).toLowerCase())?t:void 0},...f&&{secure:!0},...m&&{priority:u.includes(r=(r=m).toLowerCase())?r:void 0},...w&&{partitioned:!0}})}((e,r)=>{for(var n in r)t(e,n,{get:r[n],enumerable:!0})})(i,{RequestCookies:()=>l,ResponseCookies:()=>p,parseCookie:()=>s,parseSetCookie:()=>c,stringifyCookie:()=>o}),e.exports=((e,i,o,s)=>{if(i&&"object"==typeof i||"function"==typeof i)for(let c of n(i))a.call(e,c)||c===o||t(e,c,{get:()=>i[c],enumerable:!(s=r(i,c))||s.enumerable});return e})(t({},"__esModule",{value:!0}),i);var d=["strict","lax","none"],u=["low","medium","high"],l=class{constructor(e){this._parsed=new Map,this._headers=e;let t=e.get("cookie");if(t)for(let[e,r]of s(t))this._parsed.set(e,{name:e,value:r})}[Symbol.iterator](){return this._parsed[Symbol.iterator]()}get size(){return this._parsed.size}get(...e){let t="string"==typeof e[0]?e[0]:e[0].name;return this._parsed.get(t)}getAll(...e){var t;let r=Array.from(this._parsed);if(!e.length)return r.map(([e,t])=>t);let n="string"==typeof e[0]?e[0]:null==(t=e[0])?void 0:t.name;return r.filter(([e])=>e===n).map(([e,t])=>t)}has(e){return this._parsed.has(e)}set(...e){let[t,r]=1===e.length?[e[0].name,e[0].value]:e,n=this._parsed;return n.set(t,{name:t,value:r}),this._headers.set("cookie",Array.from(n).map(([e,t])=>o(t)).join("; ")),this}delete(e){let t=this._parsed,r=Array.isArray(e)?e.map(e=>t.delete(e)):t.delete(e);return this._headers.set("cookie",Array.from(t).map(([e,t])=>o(t)).join("; ")),r}clear(){return this.delete(Array.from(this._parsed.keys())),this}[Symbol.for("edge-runtime.inspect.custom")](){return`RequestCookies ${JSON.stringify(Object.fromEntries(this._parsed))}`}toString(){return[...this._parsed.values()].map(e=>`${e.name}=${encodeURIComponent(e.value)}`).join("; ")}},p=class{constructor(e){var t,r,n;this._parsed=new Map,this._headers=e;let a=null!=(n=null!=(r=null==(t=e.getSetCookie)?void 0:t.call(e))?r:e.get("set-cookie"))?n:[];for(let e of Array.isArray(a)?a:function(e){if(!e)return[];var t,r,n,a,i,o=[],s=0;function c(){for(;s<e.length&&/\s/.test(e.charAt(s));)s+=1;return s<e.length}for(;s<e.length;){for(t=s,i=!1;c();)if(","===(r=e.charAt(s))){for(n=s,s+=1,c(),a=s;s<e.length&&"="!==(r=e.charAt(s))&&";"!==r&&","!==r;)s+=1;s<e.length&&"="===e.charAt(s)?(i=!0,s=a,o.push(e.substring(t,n)),t=s):s=n+1}else s+=1;(!i||s>=e.length)&&o.push(e.substring(t,e.length))}return o}(a)){let t=c(e);t&&this._parsed.set(t.name,t)}}get(...e){let t="string"==typeof e[0]?e[0]:e[0].name;return this._parsed.get(t)}getAll(...e){var t;let r=Array.from(this._parsed.values());if(!e.length)return r;let n="string"==typeof e[0]?e[0]:null==(t=e[0])?void 0:t.name;return r.filter(e=>e.name===n)}has(e){return this._parsed.has(e)}set(...e){let[t,r,n]=1===e.length?[e[0].name,e[0].value,e[0]]:e,a=this._parsed;return a.set(t,function(e={name:"",value:""}){return"number"==typeof e.expires&&(e.expires=new Date(e.expires)),e.maxAge&&(e.expires=new Date(Date.now()+1e3*e.maxAge)),(null===e.path||void 0===e.path)&&(e.path="/"),e}
1({name:t,value:r,...n})),function(e,t){for(let[,r]of(t.delete("set-cookie"),e)){let e=o(r);t.append("set-cookie",e)}}(a,this._headers),this}delete(...e){let[t,r,n]="string"==typeof e[0]?[e[0]]:[e[0].name,e[0].path,e[0].domain];return this.set({name:t,path:r,domain:n,value:"",expires:new Date(0)})}[Symbol.for("edge-runtime.inspect.custom")](){return`ResponseCookies ${JSON.stringify(Object.fromEntries(this._parsed))}`}toString(){return[...this._parsed.values()].map(o).join("; ")}}},82985:function(e,t,r){"use strict";Object.defineProperty(t,"__esModule",{value:!0}),function(e,t){for(var r in t)Object.defineProperty(e,r,{enumerable:!0,get:t[r]})}(t,{RequestCookies:function(){return n.RequestCookies},ResponseCookies:function(){return n.ResponseCookies},stringifyCookie:function(){return n.stringifyCookie}});let n=r(33134)},20200:function(e,t,r){"use strict";r.r(t),r.d(t,{NIL:function(){return K},parse:function(){return w},stringify:function(){return p},v1:function(){return f},v3:function(){return H},v4:function(){return C},v5:function(){return P},validate:function(){return d},version:function(){return W}});var n,a,i,o=new Uint8Array(16);function s(){if(!n&&!(n="undefined"!=typeof crypto&&crypto.getRandomValues&&crypto.getRandomValues.bind(crypto)||"undefined"!=typeof msCrypto&&"function"==typeof msCrypto.getRandomValues&&msCrypto.getRandomValues.bind(msCrypto)))throw Error("crypto.getRandomValues() not supported. See https://github.com/uuidjs/uuid#getrandomvalues-not-supported");return n(o)}for(var c=/^(?:[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|00000000-0000-0000-0000-000000000000)$/i,d=function(e){return"string"==typeof e&&c.test(e)},u=[],l=0;l<256;++l)u.push((l+256).toString(16).substr(1));var p=function(e){var t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:0,r=(u[e[t+0]]+u[e[t+1]]+u[e[t+2]]+u[e[t+3]]+"-"+u[e[t+4]]+u[e[t+5]]+"-"+u[e[t+6]]+u[e[t+7]]+"-"+u[e[t+8]]+u[e[t+9]]+"-"+u[e[t+10]]+u[e[t+11]]+u[e[t+12]]+u[e[t+13]]+u[e[t+14]]+u[e[t+15]]).toLowerCase();if(!d(r))throw TypeError("Stringified UUID is invalid");return r},h=0,y=0,f=function(e,t,r){var n=t&&r||0,o=t||Array(16),c=(e=e||{}).node||a,d=void 0!==e.clockseq?e.clockseq:i;if(null==c||null==d){var u=e.random||(e.rng||s)();null==c&&(c=a=[1|u[0],u[1],u[2],u[3],u[4],u[5]]),null==d&&(d=i=(u[6]<<8|u[7])&16383)}var l=void 0!==e.msecs?e.msecs:Date.now(),f=void 0!==e.nsecs?e.nsecs:y+1,w=l-h+(f-y)/1e4;if(w<0&&void 0===e.clockseq&&(d=d+1&16383),(w<0||l>h)&&void 0===e.nsecs&&(f=0),f>=1e4)throw Error("uuid.v1(): Can't create more than 10M uuids/sec");h=l,y=f,i=d;var m=((268435455&(l+=122192928e5))*1e4+f)%4294967296;o[n++]=m>>>24&255,o[n++]=m>>>16&255,o[n++]=m>>>8&255,o[n++]=255&m;var g=l/4294967296*1e4&268435455;o[n++]=g>>>8&255,o[n++]=255&g,o[n++]=g>>>24&15|16,o[n++]=g>>>16&255,o[n++]=d>>>8|128,o[n++]=255&d;for(var E=0;E<6;++E)o[n+E]=c[E];return t||p(o)},w=function(e){if(!d(e))throw TypeError("Invalid UUID");var t,r=new Uint8Array(16);return r[0]=(t=parseInt(e.slice(0,8),16))>>>24,r[1]=t>>>16&255,r[2]=t>>>8&255,r[3]=255&t,r[4]=(t=parseInt(e.slice(9,13),16))>>>8,r[5]=255&t,r[6]=(t=parseInt(e.slice(14,18),16))>>>8,r[7]=255&t,r[8]=(t=parseInt(e.slice(19,23),16))>>>8,r[9]=255&t,r[10]=(t=parseInt(e.slice(24,36),16))/1099511627776&255,r[11]=t/4294967296&255,r[12]=t>>>24&255,r[13]=t>>>16&255,r[14]=t>>>8&255,r[15]=255&t,r};function m(e,t,r){function n(e,n,a,i){if("string"==typeof e&&(e=function(e){e=unescape(encodeURIComponent(e));for(var t=[],r=0;r<e.length;++r)t.push(e.charCodeAt(r));return t}(e)),"string"==typeof n&&(n=w(n)),16!==n.length)throw TypeError("Namespace must be array-like (16 iterable integer values, 0-255)");var o=new Uint8Array(16+e.length);if(o.set(n),o.set(e,n.length),(o=r(o))[6]=15&o[6]|t,o[8]=63&o[8]|128,a){i=i||0;for(var s=0;s<16;++s)a[i+s]=o[s];return a}return p(o)}try{n.name=e}catch(e){}return n.DNS="6ba7b810-9dad-11d1-80b4-00c04fd430c8",n.URL="6ba7b811-9dad-11d1-80b4-00c04fd430c8",n}function g(e){return(e+64>>>9<<4)+14+1}function E(e,t){var r=(65535&e)+(65535&t);return(e>>16)+(t>>16)+(r>>16)<<16|65535&r}function A(e,t,r,n,a,i){var o;return E((o=E(E(t,e),E(n,i)))<<a|o>>>32-a,r)}function v(e,t,r,n,a,i,o){return A(t&r|~t&n,e,t,a,i,o)}function S(e,t,r,n,a,i,o){return A(t&n|r&~n,e,t,a,i,o)}function b(e,t,r,n,a,i,o){return A(t^r^n,e,t,a,i,o)}function _(e,t,r,n,a,i,o){return A(r^(t|~n),e,t,a,i,o)}var H=m("v3",48,function(e){if("string"==typeof e){var t=unescape(encodeURIComponent(e));e=new Uint8Array(t.length);for(var r=0;r<t.length;++r)e[r]=t.charCodeAt(r)}return function(e){for(var t=[],r=32*e.length,n="0123456789abcdef",a=0;a<r;a+=8){var i=e[a>>5]>>>a%32&255,o=parseInt(n.charAt(i>>>4&15)+n.charAt(15&i),16);t.push(o)}return t}(function(e,t){e[t>>5]|=128<<t%32,e[g(t)-1]=t;
1for(var r=1732584193,n=-271733879,a=-1732584194,i=271733878,o=0;o<e.length;o+=16){var s=r,c=n,d=a,u=i;r=v(r,n,a,i,e[o],7,-680876936),i=v(i,r,n,a,e[o+1],12,-389564586),a=v(a,i,r,n,e[o+2],17,606105819),n=v(n,a,i,r,e[o+3],22,-1044525330),r=v(r,n,a,i,e[o+4],7,-176418897),i=v(i,r,n,a,e[o+5],12,1200080426),a=v(a,i,r,n,e[o+6],17,-1473231341),n=v(n,a,i,r,e[o+7],22,-45705983),r=v(r,n,a,i,e[o+8],7,1770035416),i=v(i,r,n,a,e[o+9],12,-1958414417),a=v(a,i,r,n,e[o+10],17,-42063),n=v(n,a,i,r,e[o+11],22,-1990404162),r=v(r,n,a,i,e[o+12],7,1804603682),i=v(i,r,n,a,e[o+13],12,-40341101),a=v(a,i,r,n,e[o+14],17,-1502002290),n=v(n,a,i,r,e[o+15],22,1236535329),r=S(r,n,a,i,e[o+1],5,-165796510),i=S(i,r,n,a,e[o+6],9,-1069501632),a=S(a,i,r,n,e[o+11],14,643717713),n=S(n,a,i,r,e[o],20,-373897302),r=S(r,n,a,i,e[o+5],5,-701558691),i=S(i,r,n,a,e[o+10],9,38016083),a=S(a,i,r,n,e[o+15],14,-660478335),n=S(n,a,i,r,e[o+4],20,-405537848),r=S(r,n,a,i,e[o+9],5,568446438),i=S(i,r,n,a,e[o+14],9,-1019803690),a=S(a,i,r,n,e[o+3],14,-187363961),n=S(n,a,i,r,e[o+8],20,1163531501),r=S(r,n,a,i,e[o+13],5,-1444681467),i=S(i,r,n,a,e[o+2],9,-51403784),a=S(a,i,r,n,e[o+7],14,1735328473),n=S(n,a,i,r,e[o+12],20,-1926607734),r=b(r,n,a,i,e[o+5],4,-378558),i=b(i,r,n,a,e[o+8],11,-2022574463),a=b(a,i,r,n,e[o+11],16,1839030562),n=b(n,a,i,r,e[o+14],23,-35309556),r=b(r,n,a,i,e[o+1],4,-1530992060),i=b(i,r,n,a,e[o+4],11,1272893353),a=b(a,i,r,n,e[o+7],16,-155497632),n=b(n,a,i,r,e[o+10],23,-1094730640),r=b(r,n,a,i,e[o+13],4,681279174),i=b(i,r,n,a,e[o],11,-358537222),a=b(a,i,r,n,e[o+3],16,-722521979),n=b(n,a,i,r,e[o+6],23,76029189),r=b(r,n,a,i,e[o+9],4,-640364487),i=b(i,r,n,a,e[o+12],11,-421815835),a=b(a,i,r,n,e[o+15],16,530742520),n=b(n,a,i,r,e[o+2],23,-995338651),r=_(r,n,a,i,e[o],6,-198630844),i=_(i,r,n,a,e[o+7],10,1126891415),a=_(a,i,r,n,e[o+14],15,-1416354905),n=_(n,a,i,r,e[o+5],21,-57434055),r=_(r,n,a,i,e[o+12],6,1700485571),i=_(i,r,n,a,e[o+3],10,-1894986606),a=_(a,i,r,n,e[o+10],15,-1051523),n=_(n,a,i,r,e[o+1],21,-2054922799),r=_(r,n,a,i,e[o+8],6,1873313359),i=_(i,r,n,a,e[o+15],10,-30611744),a=_(a,i,r,n,e[o+6],15,-1560198380),n=_(n,a,i,r,e[o+13],21,1309151649),r=_(r,n,a,i,e[o+4],6,-145523070),i=_(i,r,n,a,e[o+11],10,-1120210379),a=_(a,i,r,n,e[o+2],15,718787259),n=_(n,a,i,r,e[o+9],21,-343485551),r=E(r,s),n=E(n,c),a=E(a,d),i=E(i,u)}return[r,n,a,i]}(function(e){if(0===e.length)return[];for(var t=8*e.length,r=new Uint32Array(g(t)),n=0;n<t;n+=8)r[n>>5]|=(255&e[n/8])<<n%32;return r}(e),8*e.length))}),C=function(e,t,r){var n=(e=e||{}).random||(e.rng||s)();if(n[6]=15&n[6]|64,n[8]=63&n[8]|128,t){r=r||0;for(var a=0;a<16;++a)t[r+a]=n[a];return t}return p(n)};function k(e,t){return e<<t|e>>>32-t}var P=m("v5",80,function(e){var t=[1518500249,1859775393,2400959708,3395469782],r=[1732584193,4023233417,2562383102,271733878,3285377520];if("string"==typeof e){var n=unescape(encodeURIComponent(e));e=[];for(var a=0;a<n.length;++a)e.push(n.charCodeAt(a))}else Array.isArray(e)||(e=Array.prototype.slice.call(e));e.push(128);for(var i=Math.ceil((e.length/4+2)/16),o=Array(i),s=0;s<i;++s){for(var c=new Uint32Array(16),d=0;d<16;++d)c[d]=e[64*s+4*d]<<24|e[64*s+4*d+1]<<16|e[64*s+4*d+2]<<8|e[64*s+4*d+3];o[s]=c}o[i-1][14]=(e.length-1)*8/4294967296,o[i-1][14]=Math.floor(o[i-1][14]),o[i-1][15]=(e.length-1)*8&4294967295;for(var u=0;u<i;++u){for(var l=new Uint32Array(80),p=0;p<16;++p)l[p]=o[u][p];for(var h=16;h<80;++h)l[h]=k(l[h-3]^l[h-8]^l[h-14]^l[h-16],1);for(var y=r[0],f=r[1],w=r[2],m=r[3],g=r[4],E=0;E<80;++E){var A=Math.floor(E/20),v=k(y,5)+function(e,t,r,n){switch(e){case 0:return t&r^~t&n;case 1:case 3:return t^r^n;case 2:return t&r^t&n^r&n}}(A,f,w,m)+g+t[A]+l[E]>>>0;g=m,m=w,w=k(f,30)>>>0,f=y,y=v}r[0]=r[0]+y>>>0,r[1]=r[1]+f>>>0,r[2]=r[2]+w>>>0,r[3]=r[3]+m>>>0,r[4]=r[4]+g>>>0}return[r[0]>>24&255,r[0]>>16&255,r[0]>>8&255,255&r[0],r[1]>>24&255,r[1]>>16&255,r[1]>>8&255,255&r[1],r[2]>>24&255,r[2]>>16&255,r[2]>>8&255,255&r[2],r[3]>>24&255,r[3]>>16&255,r[3]>>8&255,255&r[3],r[4]>>24&255,r[4]>>16&255,r[4]>>8&255,255&r[4]]}),K="00000000-0000-0000-0000-000000000000",W=function(e){if(!d(e))throw TypeError("Invalid UUID");return parseInt(e.substr(14,1),16)}},45244:function(e){e.exports=function(e,t,r){if("function"==typeof e?e===t:e.has(t))return arguments.length<3?t:r;throw TypeError("Private element is not present on this object")},e.exports.__esModule=!0,e.exports.default=e.exports},23223:function(e){e.exports=function(e,t){return t.get?t.get.call(e):t.value},e.exports.__esModule=!0,e.exports.default=e.exports},44172:function(e){e.exports=function(e,t,r){if(t.set)t.set.call(e,r);else{if(!t.writable)throw TypeError("attempted to set read only private field");t.value=r}},e.exports.__esModule=!0,e.exports.default=e.exports},43130:function(e,t,r){var n=r(23223),a=r(83334);e.exports=function(e,t){var r=a(t,e);return n(e,r)},e.exports.__esModule=!0,e.exports.default=e.exports},83334:function(e,t,r){var n=r(45244);e.exports=function(e,t){return e.get(n(e,t))},e.exports.__esModule=!0,e.exports.default=e.exports},39825:function(e,t,r){var n=r(44172),a=r(83334);e.exports=function(e,t,r){var i=a(t,e);return n(e,i,r),r},e.exports.__esModule=!0,e.exports.default=e.exports},81631:function(e,t,r){"use strict";r.r(t),r.d(t,{default:function(){return o},hkdf:function(){return o}});let n=()=>
1{if("undefined"!=typeof globalThis)return globalThis;if("undefined"!=typeof self)return self;if("undefined"!=typeof window)return window;throw Error("unable to locate global object")};var a=async(e,t,r,a,i)=>{let{crypto:{subtle:o}}=n();return new Uint8Array(await o.deriveBits({name:"HKDF",hash:`SHA-${e.substr(3)}`,salt:r,info:a},await o.importKey("raw",t,"HKDF",!1,["deriveBits"]),i<<3))};function i(e,t){if("string"==typeof e)return new TextEncoder().encode(e);if(!(e instanceof Uint8Array))throw TypeError(`"${t}"" must be an instance of Uint8Array or a string`);return e}async function o(e,t,r,n,o){return a(function(e){switch(e){case"sha256":case"sha384":case"sha512":case"sha1":return e;default:throw TypeError('unsupported "digest" value')}}(e),function(e){let t=i(e,"ikm");if(!t.byteLength)throw TypeError('"ikm" must be at least one byte in length');return t}(t),i(r,"salt"),function(e){let t=i(e,"info");if(t.byteLength>1024)throw TypeError('"info" must not contain more than 1024 bytes');return t}(n),function(e,t){if("number"!=typeof e||!Number.isInteger(e)||e<1)throw TypeError('"keylen" must be a positive integer');if(e>255*(parseInt(t.substr(3),10)>>3||20))throw TypeError('"keylen" too large');return e}(o,e))}},42530:function(e,t,r){"use strict";r.r(t),r.d(t,{CompactEncrypt:function(){return tp},CompactSign:function(){return tf},EmbeddedJWK:function(){return t_},EncryptJWT:function(){return tA},FlattenedEncrypt:function(){return e4},FlattenedSign:function(){return ty},GeneralEncrypt:function(){return e6},GeneralSign:function(){return tm},SignJWT:function(){return tE},UnsecuredJWT:function(){return tJ},base64url:function(){return a},calculateJwkThumbprint:function(){return tS},calculateJwkThumbprintUri:function(){return tb},compactDecrypt:function(){return eq},compactVerify:function(){return tr},createLocalJWKSet:function(){return tK},createRemoteJWKSet:function(){return tR},cryptoRuntime:function(){return tB},decodeJwt:function(){return tO},decodeProtectedHeader:function(){return tx},errors:function(){return n},exportJWK:function(){return e2},exportPKCS8:function(){return e1},exportSPKI:function(){return e0},flattenedDecrypt:function(){return eY},flattenedVerify:function(){return tt},generalDecrypt:function(){return eQ},generalVerify:function(){return tn},generateKeyPair:function(){return t$},generateSecret:function(){return tN},importJWK:function(){return eD},importPKCS8:function(){return eO},importSPKI:function(){return eU},importX509:function(){return ex},jwtDecrypt:function(){return tl},jwtVerify:function(){return tu}});var n={};r.r(n),r.d(n,{JOSEAlgNotAllowed:function(){return b},JOSEError:function(){return A},JOSENotSupported:function(){return _},JWEDecompressionFailed:function(){return C},JWEDecryptionFailed:function(){return H},JWEInvalid:function(){return k},JWKInvalid:function(){return W},JWKSInvalid:function(){return T},JWKSMultipleMatchingKeys:function(){return J},JWKSNoMatchingKey:function(){return R},JWKSTimeout:function(){return I},JWSInvalid:function(){return P},JWSSignatureVerificationFailed:function(){return U},JWTClaimValidationFailed:function(){return v},JWTExpired:function(){return S},JWTInvalid:function(){return K}});var a={};r.r(a),r.d(a,{decode:function(){return tU},encode:function(){return tI}});var i=crypto;let o=e=>e instanceof CryptoKey,s=async(e,t)=>{let r=`SHA-${e.slice(-3)}`;return new Uint8Array(await i.subtle.digest(r,t))},c=new TextEncoder,d=new TextDecoder;function u(...e){let t=new Uint8Array(e.reduce((e,{length:t})=>e+t,0)),r=0;return e.forEach(e=>{t.set(e,r),r+=e.length}),t}function l(e,t,r){if(t<0||t>=4294967296)throw RangeError(`value must be >= 0 and <= ${4294967296-1}. Received ${t}`);e.set([t>>>24,t>>>16,t>>>8,255&t],r)}function p(e){let t=new Uint8Array(8);return l(t,Math.floor(e/4294967296),0),l(t,e%4294967296,4),t}function h(e){let t=new Uint8Array(4);return l(t,e),t}function y(e){return u(h(e.length),e)}async function f(e,t,r){let n=Math.ceil((t>>3)/32),a=new Uint8Array(32*n);for(let t=0;t<n;t++){let n=new Uint8Array(4+e.length+r.length);n.set(h(t+1)),n.set(e,4),n.set(r,4+e.length),a.set(await s("sha256",n),32*t)}return a.slice(0,t>>3)}let w=e=>{let t=e;"string"==typeof t&&(t=c.encode(t));let r=[];for(let e=0;e<t.length;e+=32768)r.push(String.fromCharCode.apply(null,t.subarray(e,e+32768)));return btoa(r.join(""))},m=e=>w(e).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_"),g=e=>{let t=atob(e),r=new Uint8Array(t.length);for(let e=0;e<t.length;e++)r[e]=t.charCodeAt(e);return r},E=e=>{let t=e;t instanceof Uint8Array&&(t=d.decode(t)),t=t.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"");try{return g(t)}catch(e){throw TypeError("The input to be decoded is not correctly encoded.")}};
1class A extends Error{static get code(){return"ERR_JOSE_GENERIC"}constructor(e){var t;super(e),this.code="ERR_JOSE_GENERIC",this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}class v extends A{static get code(){return"ERR_JWT_CLAIM_VALIDATION_FAILED"}constructor(e,t="unspecified",r="unspecified"){super(e),this.code="ERR_JWT_CLAIM_VALIDATION_FAILED",this.claim=t,this.reason=r}}class S extends A{static get code(){return"ERR_JWT_EXPIRED"}constructor(e,t="unspecified",r="unspecified"){super(e),this.code="ERR_JWT_EXPIRED",this.claim=t,this.reason=r}}class b extends A{constructor(){super(...arguments),this.code="ERR_JOSE_ALG_NOT_ALLOWED"}static get code(){return"ERR_JOSE_ALG_NOT_ALLOWED"}}class _ extends A{constructor(){super(...arguments),this.code="ERR_JOSE_NOT_SUPPORTED"}static get code(){return"ERR_JOSE_NOT_SUPPORTED"}}class H extends A{constructor(){super(...arguments),this.code="ERR_JWE_DECRYPTION_FAILED",this.message="decryption operation failed"}static get code(){return"ERR_JWE_DECRYPTION_FAILED"}}class C extends A{constructor(){super(...arguments),this.code="ERR_JWE_DECOMPRESSION_FAILED",this.message="decompression operation failed"}static get code(){return"ERR_JWE_DECOMPRESSION_FAILED"}}class k extends A{constructor(){super(...arguments),this.code="ERR_JWE_INVALID"}static get code(){return"ERR_JWE_INVALID"}}class P extends A{constructor(){super(...arguments),this.code="ERR_JWS_INVALID"}static get code(){return"ERR_JWS_INVALID"}}class K extends A{constructor(){super(...arguments),this.code="ERR_JWT_INVALID"}static get code(){return"ERR_JWT_INVALID"}}class W extends A{constructor(){super(...arguments),this.code="ERR_JWK_INVALID"}static get code(){return"ERR_JWK_INVALID"}}class T extends A{constructor(){super(...arguments),this.code="ERR_JWKS_INVALID"}static get code(){return"ERR_JWKS_INVALID"}}class R extends A{constructor(){super(...arguments),this.code="ERR_JWKS_NO_MATCHING_KEY",this.message="no applicable key found in the JSON Web Key Set"}static get code(){return"ERR_JWKS_NO_MATCHING_KEY"}}class J extends A{constructor(){super(...arguments),this.code="ERR_JWKS_MULTIPLE_MATCHING_KEYS",this.message="multiple matching keys found in the JSON Web Key Set"}static get code(){return"ERR_JWKS_MULTIPLE_MATCHING_KEYS"}}class I extends A{constructor(){super(...arguments),this.code="ERR_JWKS_TIMEOUT",this.message="request timed out"}static get code(){return"ERR_JWKS_TIMEOUT"}}class U extends A{constructor(){super(...arguments),this.code="ERR_JWS_SIGNATURE_VERIFICATION_FAILED",this.message="signature verification failed"}static get code(){return"ERR_JWS_SIGNATURE_VERIFICATION_FAILED"}}var x=i.getRandomValues.bind(i);function O(e){switch(e){case"A128GCM":case"A128GCMKW":case"A192GCM":case"A192GCMKW":case"A256GCM":case"A256GCMKW":return 96;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return 128;default:throw new _(`Unsupported JWE Algorithm: ${e}`)}}var D=e=>x(new Uint8Array(O(e)>>3)),M=(e,t)=>{if(t.length<<3!==O(e))throw new k("Invalid Initialization Vector length")},j=(e,t)=>{let r=e.byteLength<<3;if(r!==t)throw new k(`Invalid Content Encryption Key length. Expected ${t} bits, got ${r} bits`)},$=(e,t)=>{if(!(e instanceof Uint8Array))throw TypeError("First argument must be a buffer");if(!(t instanceof Uint8Array))throw TypeError("Second argument must be a buffer");if(e.length!==t.length)throw TypeError("Input buffers must have the same length");let r=e.length,n=0,a=-1;for(;++a<r;)n|=e[a]^t[a];return 0===n};function N(e,t="algorithm.name"){return TypeError(`CryptoKey does not support this operation, its ${t} must be ${e}`)}function B(e,t){return e.name===t}function G(e){return parseInt(e.name.slice(4),10)}function L(e,t){if(t.length&&!t.some(t=>e.usages.includes(t))){let e="CryptoKey does not support this operation, its usages must include ";if(t.length>2){let r=t.pop();e+=`one of ${t.join(", ")}, or ${r}.`}else 2===t.length?e+=`one of ${t[0]} or ${t[1]}.`:e+=`${t[0]}.`;throw TypeError(e)}}function F(e,t,...r){switch(t){case"A128GCM":case"A192GCM":case"A256GCM":{if(!B(e.algorithm,"AES-GCM"))throw N("AES-GCM");let r=parseInt(t.slice(1,4),10);if(e.algorithm.length!==r)throw N(r,"algorithm.length");break}
1case"A128KW":case"A192KW":case"A256KW":{if(!B(e.algorithm,"AES-KW"))throw N("AES-KW");let r=parseInt(t.slice(1,4),10);if(e.algorithm.length!==r)throw N(r,"algorithm.length");break}case"ECDH":switch(e.algorithm.name){case"ECDH":case"X25519":case"X448":break;default:throw N("ECDH, X25519, or X448")}break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":if(!B(e.algorithm,"PBKDF2"))throw N("PBKDF2");break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":{if(!B(e.algorithm,"RSA-OAEP"))throw N("RSA-OAEP");let r=parseInt(t.slice(9),10)||1;if(G(e.algorithm.hash)!==r)throw N(`SHA-${r}`,"algorithm.hash");break}default:throw TypeError("CryptoKey does not support this operation")}L(e,r)}function V(e,t,...r){if(r.length>2){let t=r.pop();e+=`one of type ${r.join(", ")}, or ${t}.`}else 2===r.length?e+=`one of type ${r[0]} or ${r[1]}.`:e+=`of type ${r[0]}.`;return null==t?e+=` Received ${t}`:"function"==typeof t&&t.name?e+=` Received function ${t.name}`:"object"==typeof t&&null!=t&&t.constructor&&t.constructor.name&&(e+=` Received an instance of ${t.constructor.name}`),e}var z=(e,...t)=>V("Key must be ",e,...t);function X(e,t,...r){return V(`Key for the ${e} algorithm must be `,t,...r)}var Y=e=>o(e);let q=["CryptoKey"];async function Q(e,t,r,n,a,o){let s,c;if(!(t instanceof Uint8Array))throw TypeError(z(t,"Uint8Array"));let d=parseInt(e.slice(1,4),10),l=await i.subtle.importKey("raw",t.subarray(d>>3),"AES-CBC",!1,["decrypt"]),h=await i.subtle.importKey("raw",t.subarray(0,d>>3),{hash:`SHA-${d<<1}`,name:"HMAC"},!1,["sign"]),y=u(o,n,r,p(o.length<<3)),f=new Uint8Array((await i.subtle.sign("HMAC",h,y)).slice(0,d>>3));try{s=$(a,f)}catch(e){}if(!s)throw new H;try{c=new Uint8Array(await i.subtle.decrypt({iv:n,name:"AES-CBC"},l,r))}catch(e){}if(!c)throw new H;return c}async function Z(e,t,r,n,a,o){let s;t instanceof Uint8Array?s=await i.subtle.importKey("raw",t,"AES-GCM",!1,["decrypt"]):(F(t,e,"decrypt"),s=t);try{return new Uint8Array(await i.subtle.decrypt({additionalData:o,iv:n,name:"AES-GCM",tagLength:128},s,u(r,a)))}catch(e){throw new H}}let ee=async(e,t,r,n,a,i)=>{if(!o(t)&&!(t instanceof Uint8Array))throw TypeError(z(t,...q,"Uint8Array"));switch(M(e,n),e){case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return t instanceof Uint8Array&&j(t,parseInt(e.slice(-3),10)),Q(e,t,r,n,a,i);case"A128GCM":case"A192GCM":case"A256GCM":return t instanceof Uint8Array&&j(t,parseInt(e.slice(1,4),10)),Z(e,t,r,n,a,i);default:throw new _("Unsupported JWE Content Encryption Algorithm")}},et=async()=>{throw new _('JWE "zip" (Compression Algorithm) Header Parameter is not supported by your javascript runtime. You need to use the `inflateRaw` decrypt option to provide Inflate Raw implementation.')},er=async()=>{throw new _('JWE "zip" (Compression Algorithm) Header Parameter is not supported by your javascript runtime. You need to use the `deflateRaw` encrypt option to provide Deflate Raw implementation.')};var en=(...e)=>{let t;let r=e.filter(Boolean);if(0===r.length||1===r.length)return!0;for(let e of r){let r=Object.keys(e);if(!t||0===t.size){t=new Set(r);continue}for(let e of r){if(t.has(e))return!1;t.add(e)}}return!0};function ea(e){if(!("object"==typeof e&&null!==e)||"[object Object]"!==Object.prototype.toString.call(e))return!1;if(null===Object.getPrototypeOf(e))return!0;let t=e;for(;null!==Object.getPrototypeOf(t);)t=Object.getPrototypeOf(t);return Object.getPrototypeOf(e)===t}var ei=[{hash:"SHA-256",name:"HMAC"},!0,["sign"]];function eo(e,t){if(e.algorithm.length!==parseInt(t.slice(1,4),10))throw TypeError(`Invalid key size for alg: ${t}`)}function es(e,t,r){if(o(e))return F(e,t,r),e;if(e instanceof Uint8Array)return i.subtle.importKey("raw",e,"AES-KW",!0,[r]);throw TypeError(z(e,...q,"Uint8Array"))}let ec=async(e,t,r)=>{let n=await es(t,e,"wrapKey");eo(n,e);let a=await i.subtle.importKey("raw",r,...ei);return new Uint8Array(await i.subtle.wrapKey("raw",a,n,"AES-KW"))},ed=async(e,t,r)=>{let n=await es(t,e,"unwrapKey");eo(n,e);let a=await i.subtle.unwrapKey("raw",r,n,"AES-KW",...ei);return new Uint8Array(await i.subtle.exportKey("raw",a))};async function eu(e,t,r,n,a=new Uint8Array(0),s=new Uint8Array(0)){let d;if(!o(e))throw TypeError(z(e,...q));if(F(e,"ECDH"),!o(t))throw TypeError(z(t,...q));F(t,"ECDH","deriveBits");let l=u(y(c.encode(r)),y(a),y(s),h(n));return d="X25519"===e.algorithm.name?256:"X448"===e.algorithm.name?448:Math.ceil(parseInt(e.algorithm.namedCurve.substr(-3),10)/8)<<3,f(new Uint8Array(await i.subtle.deriveBits({name:e.algorithm.name,public:e},t,d)),n,l)}async function el(e){if(!o(e))throw TypeError(z(e,...q));return i.subtle.generateKey(e.algorithm,!0,["deriveBits"])}function ep(e){if(!o(e))throw TypeError(z(e,...q));return["P-256","P-384","P-521"].includes(e.algorithm.namedCurve)||"X25519"===e.algorithm.name||"X448"===e.algorithm.name}async function eh(e,t,r,n){!function(e){if(!(e instanceof Uint8Array)||e.length<8)throw new k("PBES2 Salt Input must be 8 or more octets")}(e);let a=u(c.encode(t),new Uint8Array([0]),e),s=parseInt(t.slice(13,16),10),d={hash:`SHA-${t.slice(8,11)}`,iterations:r,name:"PBKDF2",salt:a},l=await function(e,t){if(e instanceof Uint8Array)return i.subtle.importKey("raw",e,"PBKDF2",!1,["deriveBits"]);if(o(e))return F(e,t,"deriveBits","deriveKey"),e;throw TypeError(z(e,...q,"Uint8Array"))}(n,t);if(l.usages.includes("deriveBits"))return new Uint8Array(await i.subtle.deriveBits(d,l,s));if(l.usages.includes("deriveKey"))return i.subtle.deriveKey(d,l,{length:s,name:"AES-KW"},!1,["wrapKey","unwrapKey"]);throw TypeError('PBKDF2 key "usages" must include "deriveBits" or "deriveKey"')}let ey=async(e,t,r,n=2048,a=x(new Uint8Array(16)))=>{let i=await eh(a,e,n,t);
1return{encryptedKey:await ec(e.slice(-6),i,r),p2c:n,p2s:m(a)}},ef=async(e,t,r,n,a)=>{let i=await eh(a,e,n,t);return ed(e.slice(-6),i,r)};function ew(e){switch(e){case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":return"RSA-OAEP";default:throw new _(`alg ${e} is not supported either by JOSE or your javascript runtime`)}}var em=(e,t)=>{if(e.startsWith("RS")||e.startsWith("PS")){let{modulusLength:r}=t.algorithm;if("number"!=typeof r||r<2048)throw TypeError(`${e} requires key modulusLength to be 2048 bits or larger`)}};let eg=async(e,t,r)=>{if(!o(t))throw TypeError(z(t,...q));if(F(t,e,"encrypt","wrapKey"),em(e,t),t.usages.includes("encrypt"))return new Uint8Array(await i.subtle.encrypt(ew(e),t,r));if(t.usages.includes("wrapKey")){let n=await i.subtle.importKey("raw",r,...ei);return new Uint8Array(await i.subtle.wrapKey("raw",n,t,ew(e)))}throw TypeError('RSA-OAEP key "usages" must include "encrypt" or "wrapKey" for this operation')},eE=async(e,t,r)=>{if(!o(t))throw TypeError(z(t,...q));if(F(t,e,"decrypt","unwrapKey"),em(e,t),t.usages.includes("decrypt"))return new Uint8Array(await i.subtle.decrypt(ew(e),t,r));if(t.usages.includes("unwrapKey")){let n=await i.subtle.unwrapKey("raw",r,t,ew(e),...ei);return new Uint8Array(await i.subtle.exportKey("raw",n))}throw TypeError('RSA-OAEP key "usages" must include "decrypt" or "unwrapKey" for this operation')};function eA(e){switch(e){case"A128GCM":return 128;case"A192GCM":return 192;case"A256GCM":case"A128CBC-HS256":return 256;case"A192CBC-HS384":return 384;case"A256CBC-HS512":return 512;default:throw new _(`Unsupported JWE Algorithm: ${e}`)}}var ev=e=>x(new Uint8Array(eA(e)>>3)),eS=(e,t)=>{let r=(e.match(/.{1,64}/g)||[]).join("\n");return`-----BEGIN ${t}-----
2${r}
3-----END ${t}-----`};let eb=async(e,t,r)=>{if(!o(r))throw TypeError(z(r,...q));if(!r.extractable)throw TypeError("CryptoKey is not extractable");if(r.type!==e)throw TypeError(`key is not a ${e} key`);return eS(w(new Uint8Array(await i.subtle.exportKey(t,r))),`${e.toUpperCase()} KEY`)},e_=e=>eb("public","spki",e),eH=e=>eb("private","pkcs8",e),eC=(e,t,r=0)=>{0===r&&(t.unshift(t.length),t.unshift(6));let n=e.indexOf(t[0],r);if(-1===n)return!1;let a=e.subarray(n,n+t.length);return a.length===t.length&&(a.every((e,r)=>e===t[r])||eC(e,t,n+1))},ek=e=>{switch(!0){case eC(e,[42,134,72,206,61,3,1,7]):return"P-256";case eC(e,[43,129,4,0,34]):return"P-384";case eC(e,[43,129,4,0,35]):return"P-521";case eC(e,[43,101,110]):return"X25519";case eC(e,[43,101,111]):return"X448";case eC(e,[43,101,112]):return"Ed25519";case eC(e,[43,101,113]):return"Ed448";default:throw new _("Invalid or unsupported EC Key Curve or OKP Key Sub Type")}},eP=async(e,t,r,n,a)=>{var o;let s,c;let d=new Uint8Array(atob(r.replace(e,"")).split("").map(e=>e.charCodeAt(0))),u="spki"===t;switch(n){case"PS256":case"PS384":case"PS512":s={name:"RSA-PSS",hash:`SHA-${n.slice(-3)}`},c=u?["verify"]:["sign"];break;case"RS256":case"RS384":case"RS512":s={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${n.slice(-3)}`},c=u?["verify"]:["sign"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":s={name:"RSA-OAEP",hash:`SHA-${parseInt(n.slice(-3),10)||1}`},c=u?["encrypt","wrapKey"]:["decrypt","unwrapKey"];break;case"ES256":s={name:"ECDSA",namedCurve:"P-256"},c=u?["verify"]:["sign"];break;case"ES384":s={name:"ECDSA",namedCurve:"P-384"},c=u?["verify"]:["sign"];break;case"ES512":s={name:"ECDSA",namedCurve:"P-521"},c=u?["verify"]:["sign"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{let e=ek(d);s=e.startsWith("P-")?{name:"ECDH",namedCurve:e}:{name:e},c=u?[]:["deriveBits"];break}
3case"EdDSA":s={name:ek(d)},c=u?["verify"]:["sign"];break;default:throw new _('Invalid or unsupported "alg" (Algorithm) value')}return i.subtle.importKey(t,d,s,null!==(o=null==a?void 0:a.extractable)&&void 0!==o&&o,c)},eK=(e,t,r)=>eP(/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g,"pkcs8",e,t,r),eW=(e,t,r)=>eP(/(?:-----(?:BEGIN|END) PUBLIC KEY-----|\s)/g,"spki",e,t,r);function eT(e){let t=[],r=0;for(;r<e.length;){let n=eR(e.subarray(r));t.push(n),r+=n.byteLength}return t}function eR(e){let t=0,r=31&e[0];if(t++,31===r){for(r=0;e[t]>=128;)r=128*r+e[t]-128,t++;r=128*r+e[t]-128,t++}let n=0;if(e[t]<128)n=e[t],t++;else if(128===n){for(n=0;0!==e[t+n]||0!==e[t+n+1];){if(n>e.byteLength)throw TypeError("invalid indefinite form length");n++}let r=t+n+2;return{byteLength:r,contents:e.subarray(t,t+n),raw:e.subarray(0,r)}}else{let r=127&e[t];t++,n=0;for(let a=0;a<r;a++)n=256*n+e[t],t++}let a=t+n;return{byteLength:a,contents:e.subarray(t,a),raw:e.subarray(0,a)}}let eJ=(e,t,r)=>{let n;try{n=eS(function(e){let t=eT(eT(eR(e).contents)[0].contents);return w(t[160===t[0].raw[0]?6:5].raw)}(g(e.replace(/(?:-----(?:BEGIN|END) CERTIFICATE-----|\s)/g,""))),"PUBLIC KEY")}catch(e){throw TypeError("Failed to parse the X.509 certificate",{cause:e})}return eW(n,t,r)},eI=async e=>{var t,r;if(!e.alg)throw TypeError('"alg" argument is required when "jwk.alg" is not present');let{algorithm:n,keyUsages:a}=function(e){let t,r;switch(e.kty){case"oct":switch(e.alg){case"HS256":case"HS384":case"HS512":t={name:"HMAC",hash:`SHA-${e.alg.slice(-3)}`},r=["sign","verify"];break;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":throw new _(`${e.alg} keys cannot be imported as CryptoKey instances`);case"A128GCM":case"A192GCM":case"A256GCM":case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":t={name:"AES-GCM"},r=["encrypt","decrypt"];break;case"A128KW":case"A192KW":case"A256KW":t={name:"AES-KW"},r=["wrapKey","unwrapKey"];break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":t={name:"PBKDF2"},r=["deriveBits"];break;default:throw new _('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"RSA":switch(e.alg){case"PS256":case"PS384":case"PS512":t={name:"RSA-PSS",hash:`SHA-${e.alg.slice(-3)}`},r=e.d?["sign"]:["verify"];break;case"RS256":case"RS384":case"RS512":t={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${e.alg.slice(-3)}`},r=e.d?["sign"]:["verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":t={name:"RSA-OAEP",hash:`SHA-${parseInt(e.alg.slice(-3),10)||1}`},r=e.d?["decrypt","unwrapKey"]:["encrypt","wrapKey"];break;default:throw new _('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"EC":switch(e.alg){case"ES256":t={name:"ECDSA",namedCurve:"P-256"},r=e.d?["sign"]:["verify"];break;case"ES384":t={name:"ECDSA",namedCurve:"P-384"},r=e.d?["sign"]:["verify"];break;case"ES512":t={name:"ECDSA",namedCurve:"P-521"},r=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:"ECDH",namedCurve:e.crv},r=e.d?["deriveBits"]:[];break;default:throw new _('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"OKP":switch(e.alg){case"EdDSA":t={name:e.crv},r=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:e.crv},r=e.d?["deriveBits"]:[];break;default:throw new _('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;default:throw new _('Invalid or unsupported JWK "kty" (Key Type) Parameter value')}return{algorithm:t,keyUsages:r}}(e),o=[n,null!==(t=e.ext)&&void 0!==t&&t,null!==(r=e.key_ops)&&void 0!==r?r:a];if("PBKDF2"===n.name)return i.subtle.importKey("raw",E(e.k),...o);let s={...e};return delete s.alg,delete s.use,i.subtle.importKey("jwk",s,...o)};async function eU(e,t,r){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PUBLIC KEY-----"))throw TypeError('"spki" must be SPKI formatted string');return eW(e,t,r)}async function ex(e,t,r){if("string"!=typeof e||0!==e.indexOf("-----BEGIN CERTIFICATE-----"))throw TypeError('"x509" must be X.509 formatted string');return eJ(e,t,r)}async function eO(e,t,r){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw TypeError('"pkcs8" must be PKCS#8 formatted string');return eK(e,t,r)}async function eD(e,t,r){var n;if(!ea(e))throw TypeError("JWK must be an object");switch(t||(t=e.alg),e.kty){case"oct":if("string"!=typeof e.k||!e.k)throw TypeError('missing "k" (Key Value) Parameter value');
3if(null!=r||(r=!0!==e.ext),r)return eI({...e,alg:t,ext:null!==(n=e.ext)&&void 0!==n&&n});return E(e.k);case"RSA":if(void 0!==e.oth)throw new _('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');case"EC":case"OKP":return eI({...e,alg:t});default:throw new _('Unsupported "kty" (Key Type) Parameter value')}}let eM=(e,t)=>{if(!(t instanceof Uint8Array)){if(!Y(t))throw TypeError(X(e,t,...q,"Uint8Array"));if("secret"!==t.type)throw TypeError(`${q.join(" or ")} instances for symmetric algorithms must be of type "secret"`)}},ej=(e,t,r)=>{if(!Y(t))throw TypeError(X(e,t,...q));if("secret"===t.type)throw TypeError(`${q.join(" or ")} instances for asymmetric algorithms must not be of type "secret"`);if("sign"===r&&"public"===t.type)throw TypeError(`${q.join(" or ")} instances for asymmetric algorithm signing must be of type "private"`);if("decrypt"===r&&"public"===t.type)throw TypeError(`${q.join(" or ")} instances for asymmetric algorithm decryption must be of type "private"`);if(t.algorithm&&"verify"===r&&"private"===t.type)throw TypeError(`${q.join(" or ")} instances for asymmetric algorithm verifying must be of type "public"`);if(t.algorithm&&"encrypt"===r&&"private"===t.type)throw TypeError(`${q.join(" or ")} instances for asymmetric algorithm encryption must be of type "public"`)};var e$=(e,t,r)=>{e.startsWith("HS")||"dir"===e||e.startsWith("PBES2")||/^A\d{3}(?:GCM)?KW$/.test(e)?eM(e,t):ej(e,t,r)};async function eN(e,t,r,n,a){if(!(r instanceof Uint8Array))throw TypeError(z(r,"Uint8Array"));let o=parseInt(e.slice(1,4),10),s=await i.subtle.importKey("raw",r.subarray(o>>3),"AES-CBC",!1,["encrypt"]),c=await i.subtle.importKey("raw",r.subarray(0,o>>3),{hash:`SHA-${o<<1}`,name:"HMAC"},!1,["sign"]),d=new Uint8Array(await i.subtle.encrypt({iv:n,name:"AES-CBC"},s,t)),l=u(a,n,d,p(a.length<<3));return{ciphertext:d,tag:new Uint8Array((await i.subtle.sign("HMAC",c,l)).slice(0,o>>3))}}async function eB(e,t,r,n,a){let o;r instanceof Uint8Array?o=await i.subtle.importKey("raw",r,"AES-GCM",!1,["encrypt"]):(F(r,e,"encrypt"),o=r);let s=new Uint8Array(await i.subtle.encrypt({additionalData:a,iv:n,name:"AES-GCM",tagLength:128},o,t)),c=s.slice(-16);return{ciphertext:s.slice(0,-16),tag:c}}let eG=async(e,t,r,n,a)=>{if(!o(r)&&!(r instanceof Uint8Array))throw TypeError(z(r,...q,"Uint8Array"));switch(M(e,n),e){case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return r instanceof Uint8Array&&j(r,parseInt(e.slice(-3),10)),eN(e,t,r,n,a);case"A128GCM":case"A192GCM":case"A256GCM":return r instanceof Uint8Array&&j(r,parseInt(e.slice(1,4),10)),eB(e,t,r,n,a);default:throw new _("Unsupported JWE Content Encryption Algorithm")}};async function eL(e,t,r,n){let a=e.slice(0,7);n||(n=D(a));let{ciphertext:i,tag:o}=await eG(a,r,t,n,new Uint8Array(0));return{encryptedKey:i,iv:m(n),tag:m(o)}}async function eF(e,t,r,n,a){return ee(e.slice(0,7),t,r,n,a,new Uint8Array(0))}async function eV(e,t,r,n,a){switch(e$(e,t,"decrypt"),e){case"dir":if(void 0!==r)throw new k("Encountered unexpected JWE Encrypted Key");return t;case"ECDH-ES":if(void 0!==r)throw new k("Encountered unexpected JWE Encrypted Key");case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{let a,i;if(!ea(n.epk))throw new k('JOSE Header "epk" (Ephemeral Public Key) missing or invalid');if(!ep(t))throw new _("ECDH with the provided key is not allowed or not supported by your javascript runtime");let o=await eD(n.epk,e);if(void 0!==n.apu){if("string"!=typeof n.apu)throw new k('JOSE Header "apu" (Agreement PartyUInfo) invalid');try{a=E(n.apu)}catch(e){throw new k("Failed to base64url decode the apu")}}if(void 0!==n.apv){if("string"!=typeof n.apv)throw new k('JOSE Header "apv" (Agreement PartyVInfo) invalid');try{i=E(n.apv)}catch(e){throw new k("Failed to base64url decode the apv")}}let s=await eu(o,t,"ECDH-ES"===e?n.enc:e,"ECDH-ES"===e?eA(n.enc):parseInt(e.slice(-5,-2),10),a,i);if("ECDH-ES"===e)return s;if(void 0===r)throw new k("JWE Encrypted Key missing");return ed(e.slice(-6),s,r)}case"RSA1_5":case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":if(void 0===r)throw new k("JWE Encrypted Key missing");return eE(e,t,r);case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":{let i;if(void 0===r)throw new k("JWE Encrypted Key missing");if("number"!=typeof n.p2c)throw new k('JOSE Header "p2c" (PBES2 Count) missing or invalid');let o=(null==a?void 0:a.maxPBES2Count)||1e4;if(n.p2c>o)throw new k('JOSE Header "p2c" (PBES2 Count) out is of acceptable bounds');if("string"!=typeof n.p2s)throw new k('JOSE Header "p2s" (PBES2 Salt) missing or invalid');try{i=E(n.p2s)}catch(e){throw new k("Failed to base64url decode the p2s")}return ef(e,t,r,n.p2c,i)}
3case"A128KW":case"A192KW":case"A256KW":if(void 0===r)throw new k("JWE Encrypted Key missing");return ed(e,t,r);case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":{let a,i;if(void 0===r)throw new k("JWE Encrypted Key missing");if("string"!=typeof n.iv)throw new k('JOSE Header "iv" (Initialization Vector) missing or invalid');if("string"!=typeof n.tag)throw new k('JOSE Header "tag" (Authentication Tag) missing or invalid');try{a=E(n.iv)}catch(e){throw new k("Failed to base64url decode the iv")}try{i=E(n.tag)}catch(e){throw new k("Failed to base64url decode the tag")}return eF(e,t,r,a,i)}default:throw new _('Invalid or unsupported "alg" (JWE Algorithm) header value')}}var ez=function(e,t,r,n,a){let i;if(void 0!==a.crit&&void 0===n.crit)throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!n||void 0===n.crit)return new Set;if(!Array.isArray(n.crit)||0===n.crit.length||n.crit.some(e=>"string"!=typeof e||0===e.length))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');for(let o of(i=void 0!==r?new Map([...Object.entries(r),...t.entries()]):t,n.crit)){if(!i.has(o))throw new _(`Extension Header Parameter "${o}" is not recognized`);if(void 0===a[o])throw new e(`Extension Header Parameter "${o}" is missing`);if(i.get(o)&&void 0===n[o])throw new e(`Extension Header Parameter "${o}" MUST be integrity protected`)}return new Set(n.crit)},eX=(e,t)=>{if(void 0!==t&&(!Array.isArray(t)||t.some(e=>"string"!=typeof e)))throw TypeError(`"${e}" option must be an array of strings`);if(t)return new Set(t)};async function eY(e,t,r){var n;let a,i,o,s,l,p,h;if(!ea(e))throw new k("Flattened JWE must be an object");if(void 0===e.protected&&void 0===e.header&&void 0===e.unprotected)throw new k("JOSE Header missing");if("string"!=typeof e.iv)throw new k("JWE Initialization Vector missing or incorrect type");if("string"!=typeof e.ciphertext)throw new k("JWE Ciphertext missing or incorrect type");if("string"!=typeof e.tag)throw new k("JWE Authentication Tag missing or incorrect type");if(void 0!==e.protected&&"string"!=typeof e.protected)throw new k("JWE Protected Header incorrect type");if(void 0!==e.encrypted_key&&"string"!=typeof e.encrypted_key)throw new k("JWE Encrypted Key incorrect type");if(void 0!==e.aad&&"string"!=typeof e.aad)throw new k("JWE AAD incorrect type");if(void 0!==e.header&&!ea(e.header))throw new k("JWE Shared Unprotected Header incorrect type");if(void 0!==e.unprotected&&!ea(e.unprotected))throw new k("JWE Per-Recipient Unprotected Header incorrect type");if(e.protected)try{let t=E(e.protected);a=JSON.parse(d.decode(t))}catch(e){throw new k("JWE Protected Header is invalid")}if(!en(a,e.header,e.unprotected))throw new k("JWE Protected, JWE Unprotected Header, and JWE Per-Recipient Unprotected Header Parameter names must be disjoint");let y={...a,...e.header,...e.unprotected};if(ez(k,new Map,null==r?void 0:r.crit,a,y),void 0!==y.zip){if(!a||!a.zip)throw new k('JWE "zip" (Compression Algorithm) Header MUST be integrity protected');if("DEF"!==y.zip)throw new _('Unsupported JWE "zip" (Compression Algorithm) Header Parameter value')}let{alg:f,enc:w}=y;if("string"!=typeof f||!f)throw new k("missing JWE Algorithm (alg) in JWE Header");if("string"!=typeof w||!w)throw new k("missing JWE Encryption Algorithm (enc) in JWE Header");let m=r&&eX("keyManagementAlgorithms",r.keyManagementAlgorithms),g=r&&eX("contentEncryptionAlgorithms",r.contentEncryptionAlgorithms);if(m&&!m.has(f))throw new b('"alg" (Algorithm) Header Parameter not allowed');if(g&&!g.has(w))throw new b('"enc" (Encryption Algorithm) Header Parameter not allowed');if(void 0!==e.encrypted_key)try{i=E(e.encrypted_key)}catch(e){throw new k("Failed to base64url decode the encrypted_key")}let A=!1;"function"==typeof t&&(t=await t(a,e),A=!0);try{o=await eV(f,t,i,y,r)}catch(e){if(e instanceof TypeError||e instanceof k||e instanceof _)throw e;o=ev(w)}try{s=E(e.iv)}catch(e){throw new k("Failed to base64url decode the iv")}try{l=E(e.tag)}catch(e){throw new k("Failed to base64url decode the tag")}let v=c.encode(null!==(n=e.protected)&&void 0!==n?n:"");p=void 0!==e.aad?u(v,c.encode("."),c.encode(e.aad)):v;try{h=E(e.ciphertext)}catch(e){throw new k("Failed to base64url decode the ciphertext")}let S=await ee(w,o,h,s,l,p);"DEF"===y.zip&&(S=await ((null==r?void 0:r.inflateRaw)||et)(S));let H={plaintext:S};if(void 0!==e.protected&&(H.protectedHeader=a),void 0!==e.aad)try{H.additionalAuthenticatedData=E(e.aad)}catch(e){throw new k("Failed to base64url decode the aad")}return(void 0!==e.unprotected&&(H.sharedUnprotectedHeader=e.unprotected),void 0!==e.header&&(H.unprotectedHeader=e.header),A)?{...H,key:t}:H}async function eq(e,t,r){if(e instanceof Uint8Array&&(e=d.decode(e)),"string"!=typeof e)throw new k("Compact JWE must be a string or Uint8Array");let{0:n,1:a,2:i,3:o,4:s,length:c}=e.split(".");if(5!==c)throw new k("Invalid Compact JWE");let u=await eY({ciphertext:o,iv:i||void 0,protected:n||void 0,tag:s||void 0,encrypted_key:a||void 0},t,r),l={plaintext:u.plaintext,protectedHeader:u.protectedHeader};return"function"==typeof t?{...l,key:u.key}:l}async function eQ(e,t,r){if(!ea(e))throw new k("General JWE must be an object");
3if(!Array.isArray(e.recipients)||!e.recipients.every(ea))throw new k("JWE Recipients missing or incorrect type");if(!e.recipients.length)throw new k("JWE Recipients has no members");for(let n of e.recipients)try{return await eY({aad:e.aad,ciphertext:e.ciphertext,encrypted_key:n.encrypted_key,header:n.header,iv:e.iv,protected:e.protected,tag:e.tag,unprotected:e.unprotected},t,r)}catch(e){}throw new H}let eZ=async e=>{if(e instanceof Uint8Array)return{kty:"oct",k:m(e)};if(!o(e))throw TypeError(z(e,...q,"Uint8Array"));if(!e.extractable)throw TypeError("non-extractable CryptoKey cannot be exported as a JWK");let{ext:t,key_ops:r,alg:n,use:a,...s}=await i.subtle.exportKey("jwk",e);return s};async function e0(e){return e_(e)}async function e1(e){return eH(e)}async function e2(e){return eZ(e)}async function e5(e,t,r,n,a={}){let i,o,s;switch(e$(e,r,"encrypt"),e){case"dir":s=r;break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{if(!ep(r))throw new _("ECDH with the provided key is not allowed or not supported by your javascript runtime");let{apu:c,apv:d}=a,{epk:u}=a;u||(u=(await el(r)).privateKey);let{x:l,y:p,crv:h,kty:y}=await e2(u),f=await eu(r,u,"ECDH-ES"===e?t:e,"ECDH-ES"===e?eA(t):parseInt(e.slice(-5,-2),10),c,d);if(o={epk:{x:l,crv:h,kty:y}},"EC"===y&&(o.epk.y=p),c&&(o.apu=m(c)),d&&(o.apv=m(d)),"ECDH-ES"===e){s=f;break}s=n||ev(t);let w=e.slice(-6);i=await ec(w,f,s);break}case"RSA1_5":case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":s=n||ev(t),i=await eg(e,r,s);break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":{s=n||ev(t);let{p2c:c,p2s:d}=a;({encryptedKey:i,...o}=await ey(e,r,s,c,d));break}case"A128KW":case"A192KW":case"A256KW":s=n||ev(t),i=await ec(e,r,s);break;case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":{s=n||ev(t);let{iv:c}=a;({encryptedKey:i,...o}=await eL(e,r,s,c));break}default:throw new _('Invalid or unsupported "alg" (JWE Algorithm) header value')}return{cek:s,encryptedKey:i,parameters:o}}let e8=Symbol();class e4{constructor(e){if(!(e instanceof Uint8Array))throw TypeError("plaintext must be an instance of Uint8Array");this._plaintext=e}setKeyManagementParameters(e){if(this._keyManagementParameters)throw TypeError("setKeyManagementParameters can only be called once");return this._keyManagementParameters=e,this}setProtectedHeader(e){if(this._protectedHeader)throw TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setSharedUnprotectedHeader(e){if(this._sharedUnprotectedHeader)throw TypeError("setSharedUnprotectedHeader can only be called once");return this._sharedUnprotectedHeader=e,this}setUnprotectedHeader(e){if(this._unprotectedHeader)throw TypeError("setUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}setAdditionalAuthenticatedData(e){return this._aad=e,this}setContentEncryptionKey(e){if(this._cek)throw TypeError("setContentEncryptionKey can only be called once");return this._cek=e,this}setInitializationVector(e){if(this._iv)throw TypeError("setInitializationVector can only be called once");return this._iv=e,this}async encrypt(e,t){let r,n,a,i,o,s,l;if(!this._protectedHeader&&!this._unprotectedHeader&&!this._sharedUnprotectedHeader)throw new k("either setProtectedHeader, setUnprotectedHeader, or sharedUnprotectedHeader must be called before #encrypt()");if(!en(this._protectedHeader,this._unprotectedHeader,this._sharedUnprotectedHeader))throw new k("JWE Protected, JWE Shared Unprotected and JWE Per-Recipient Header Parameter names must be disjoint");let p={...this._protectedHeader,...this._unprotectedHeader,...this._sharedUnprotectedHeader};if(ez(k,new Map,null==t?void 0:t.crit,this._protectedHeader,p),void 0!==p.zip){if(!this._protectedHeader||!this._protectedHeader.zip)throw new k('JWE "zip" (Compression Algorithm) Header MUST be integrity protected');if("DEF"!==p.zip)throw new _('Unsupported JWE "zip" (Compression Algorithm) Header Parameter value')}let{alg:h,enc:y}=p;if("string"!=typeof h||!h)throw new k('JWE "alg" (Algorithm) Header Parameter missing or invalid');if("string"!=typeof y||!y)throw new k('JWE "enc" (Encryption Algorithm) Header Parameter missing or invalid');if("dir"===h){if(this._cek)throw TypeError("setContentEncryptionKey cannot be called when using Direct Encryption")}else if("ECDH-ES"===h&&this._cek)throw TypeError("setContentEncryptionKey cannot be called when using Direct Key Agreement");{let a;({cek:n,encryptedKey:r,parameters:a}=await e5(h,y,e,this._cek,this._keyManagementParameters)),a&&(t&&e8 in t?this._unprotectedHeader?this._unprotectedHeader={...this._unprotectedHeader,...a}:this.setUnprotectedHeader(a):this._protectedHeader?this._protectedHeader={...this._protectedHeader,...a}:this.setProtectedHeader(a))}if(this._iv||(this._iv=D(y)),i=this._protectedHeader?c.encode(m(JSON.stringify(this._protectedHeader))):c.encode(""),this._aad?(o=m(this._aad),a=u(i,c.encode("."),c.encode(o))):a=i,"DEF"===p.zip){let e=await ((null==t?void 0:t.deflateRaw)||er)(this._plaintext);({ciphertext:s,tag:l}=await eG(y,e,n,this._iv,a))}else({ciphertext:s,tag:l}=await eG(y,this._plaintext,n,this._iv,a));let f={ciphertext:m(s),iv:m(this._iv),tag:m(l)};return r&&(f.encrypted_key=m(r)),o&&(f.aad=o),this._protectedHeader&&(f.protected=d.decode(i)),this._sharedUnprotectedHeader&&(f.unprotected=this._sharedUnprotectedHeader),this._unprotectedHeader&&(f.header=this._unprotectedHeader),f}}class e3{constructor(e,t,r){this.parent=e,this.key=t,this.options=r}setUnprotectedHeader(e){if(this.unprotectedHeader)throw TypeError("setUnprotectedHeader can only be called once");return this.unprotectedHeader=e,this}addRecipient(...e){return this.parent.addRecipient(...e)}encrypt(...e){return this.parent.encrypt(...e)}done(){return this.parent}}class e6{constructor(e){this._recipients=[],this._plaintext=e}addRecipient(e,t){let r=new e3(this,e,{crit:null==t?void 0:t.crit});return this._recipients.push(r),r}setProtectedHeader(e){if(this._protectedHeader)throw TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setSharedUnprotectedHeader(e){if(this._unprotectedHeader)throw TypeError("setSharedUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}setAdditionalAuthenticatedData(e){return this._aad=e,this}async encrypt(e){var t,r,n;let a;if(!this._recipients.length)throw new k("at least one recipient must be added");if(e={deflateRaw:null==e?void 0:e.deflateRaw},1===this._recipients.length){let[t]=this._recipients,r=await new e4(this._plaintext).setAdditionalAuthenticatedData(this._aad).setProtectedHeader(this._protectedHeader).setSharedUnprotectedHeader(this._unprotectedHeader).setUnprotectedHeader(t.unprotectedHeader).encrypt
3(t.key,{...t.options,...e}),n={ciphertext:r.ciphertext,iv:r.iv,recipients:[{}],tag:r.tag};return r.aad&&(n.aad=r.aad),r.protected&&(n.protected=r.protected),r.unprotected&&(n.unprotected=r.unprotected),r.encrypted_key&&(n.recipients[0].encrypted_key=r.encrypted_key),r.header&&(n.recipients[0].header=r.header),n}for(let e=0;e<this._recipients.length;e++){let t=this._recipients[e];if(!en(this._protectedHeader,this._unprotectedHeader,t.unprotectedHeader))throw new k("JWE Protected, JWE Shared Unprotected and JWE Per-Recipient Header Parameter names must be disjoint");let r={...this._protectedHeader,...this._unprotectedHeader,...t.unprotectedHeader},{alg:n}=r;if("string"!=typeof n||!n)throw new k('JWE "alg" (Algorithm) Header Parameter missing or invalid');if("dir"===n||"ECDH-ES"===n)throw new k('"dir" and "ECDH-ES" alg may only be used with a single recipient');if("string"!=typeof r.enc||!r.enc)throw new k('JWE "enc" (Encryption Algorithm) Header Parameter missing or invalid');if(a){if(a!==r.enc)throw new k('JWE "enc" (Encryption Algorithm) Header Parameter must be the same for all recipients')}else a=r.enc;if(ez(k,new Map,t.options.crit,this._protectedHeader,r),void 0!==r.zip&&(!this._protectedHeader||!this._protectedHeader.zip))throw new k('JWE "zip" (Compression Algorithm) Header MUST be integrity protected')}let i=ev(a),o={ciphertext:"",iv:"",recipients:[],tag:""};for(let s=0;s<this._recipients.length;s++){let c=this._recipients[s],d={};o.recipients.push(d);let u=({...this._protectedHeader,...this._unprotectedHeader,...c.unprotectedHeader}).alg.startsWith("PBES2")?2048+s:void 0;if(0===s){let t=await new e4(this._plaintext).setAdditionalAuthenticatedData(this._aad).setContentEncryptionKey(i).setProtectedHeader(this._protectedHeader).setSharedUnprotectedHeader(this._unprotectedHeader).setUnprotectedHeader(c.unprotectedHeader).setKeyManagementParameters({p2c:u}).encrypt(c.key,{...c.options,...e,[e8]:!0});o.ciphertext=t.ciphertext,o.iv=t.iv,o.tag=t.tag,t.aad&&(o.aad=t.aad),t.protected&&(o.protected=t.protected),t.unprotected&&(o.unprotected=t.unprotected),d.encrypted_key=t.encrypted_key,t.header&&(d.header=t.header);continue}let{encryptedKey:l,parameters:p}=await e5((null===(t=c.unprotectedHeader)||void 0===t?void 0:t.alg)||(null===(r=this._protectedHeader)||void 0===r?void 0:r.alg)||(null===(n=this._unprotectedHeader)||void 0===n?void 0:n.alg),a,c.key,i,{p2c:u});d.encrypted_key=m(l),(c.unprotectedHeader||p)&&(d.header={...c.unprotectedHeader,...p})}return o}}function e9(e,t){let r=`SHA-${e.slice(-3)}`;switch(e){case"HS256":case"HS384":case"HS512":return{hash:r,name:"HMAC"};case"PS256":case"PS384":case"PS512":return{hash:r,name:"RSA-PSS",saltLength:e.slice(-3)>>3};case"RS256":case"RS384":case"RS512":return{hash:r,name:"RSASSA-PKCS1-v1_5"};case"ES256":case"ES384":case"ES512":return{hash:r,name:"ECDSA",namedCurve:t.namedCurve};case"EdDSA":return{name:t.name};default:throw new _(`alg ${e} is not supported either by JOSE or your javascript runtime`)}}function e7(e,t,r){if(o(t))return!function(e,t,...r){switch(t){case"HS256":case"HS384":case"HS512":{if(!B(e.algorithm,"HMAC"))throw N("HMAC");let r=parseInt(t.slice(2),10);if(G(e.algorithm.hash)!==r)throw N(`SHA-${r}`,"algorithm.hash");break}case"RS256":case"RS384":case"RS512":{if(!B(e.algorithm,"RSASSA-PKCS1-v1_5"))throw N("RSASSA-PKCS1-v1_5");let r=parseInt(t.slice(2),10);if(G(e.algorithm.hash)!==r)throw N(`SHA-${r}`,"algorithm.hash");break}
3case"PS256":case"PS384":case"PS512":{if(!B(e.algorithm,"RSA-PSS"))throw N("RSA-PSS");let r=parseInt(t.slice(2),10);if(G(e.algorithm.hash)!==r)throw N(`SHA-${r}`,"algorithm.hash");break}case"EdDSA":if("Ed25519"!==e.algorithm.name&&"Ed448"!==e.algorithm.name)throw N("Ed25519 or Ed448");break;case"ES256":case"ES384":case"ES512":{if(!B(e.algorithm,"ECDSA"))throw N("ECDSA");let r=function(e){switch(e){case"ES256":return"P-256";case"ES384":return"P-384";case"ES512":return"P-521";default:throw Error("unreachable")}}(t);if(e.algorithm.namedCurve!==r)throw N(r,"algorithm.namedCurve");break}default:throw TypeError("CryptoKey does not support this operation")}L(e,r)}(t,e,r),t;if(t instanceof Uint8Array){if(!e.startsWith("HS"))throw TypeError(z(t,...q));return i.subtle.importKey("raw",t,{hash:`SHA-${e.slice(-3)}`,name:"HMAC"},!1,[r])}throw TypeError(z(t,...q,"Uint8Array"))}let te=async(e,t,r,n)=>{let a=await e7(e,t,"verify");em(e,a);let o=e9(e,a.algorithm);try{return await i.subtle.verify(o,a,r,n)}catch(e){return!1}};async function tt(e,t,r){var n;let a,i;if(!ea(e))throw new P("Flattened JWS must be an object");if(void 0===e.protected&&void 0===e.header)throw new P('Flattened JWS must have either of the "protected" or "header" members');if(void 0!==e.protected&&"string"!=typeof e.protected)throw new P("JWS Protected Header incorrect type");if(void 0===e.payload)throw new P("JWS Payload missing");if("string"!=typeof e.signature)throw new P("JWS Signature missing or incorrect type");if(void 0!==e.header&&!ea(e.header))throw new P("JWS Unprotected Header incorrect type");let o={};if(e.protected)try{let t=E(e.protected);o=JSON.parse(d.decode(t))}catch(e){throw new P("JWS Protected Header is invalid")}if(!en(o,e.header))throw new P("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");let s={...o,...e.header},l=ez(P,new Map([["b64",!0]]),null==r?void 0:r.crit,o,s),p=!0;if(l.has("b64")&&"boolean"!=typeof(p=o.b64))throw new P('The "b64" (base64url-encode payload) Header Parameter must be a boolean');let{alg:h}=s;if("string"!=typeof h||!h)throw new P('JWS "alg" (Algorithm) Header Parameter missing or invalid');let y=r&&eX("algorithms",r.algorithms);if(y&&!y.has(h))throw new b('"alg" (Algorithm) Header Parameter not allowed');if(p){if("string"!=typeof e.payload)throw new P("JWS Payload must be a string")}else if("string"!=typeof e.payload&&!(e.payload instanceof Uint8Array))throw new P("JWS Payload must be a string or an Uint8Array instance");let f=!1;"function"==typeof t&&(t=await t(o,e),f=!0),e$(h,t,"verify");let w=u(c.encode(null!==(n=e.protected)&&void 0!==n?n:""),c.encode("."),"string"==typeof e.payload?c.encode(e.payload):e.payload);try{a=E(e.signature)}catch(e){throw new P("Failed to base64url decode the signature")}if(!await te(h,t,a,w))throw new U;if(p)try{i=E(e.payload)}catch(e){throw new P("Failed to base64url decode the payload")}else i="string"==typeof e.payload?c.encode(e.payload):e.payload;let m={payload:i};return(void 0!==e.protected&&(m.protectedHeader=o),void 0!==e.header&&(m.unprotectedHeader=e.header),f)?{...m,key:t}:m}async function tr(e,t,r){if(e instanceof Uint8Array&&(e=d.decode(e)),"string"!=typeof e)throw new P("Compact JWS must be a string or Uint8Array");let{0:n,1:a,2:i,length:o}=e.split(".");if(3!==o)throw new P("Invalid Compact JWS");let s=await tt({payload:a,protected:n,signature:i},t,r),c={payload:s.payload,protectedHeader:s.protectedHeader};return"function"==typeof t?{...c,key:s.key}:c}async function tn(e,t,r){if(!ea(e))throw new P("General JWS must be an object");if(!Array.isArray(e.signatures)||!e.signatures.every(ea))throw new P("JWS Signatures missing or incorrect type");for(let n of e.signatures)try{return await tt({header:n.header,payload:e.payload,protected:n.protected,signature:n.signature},t,r)}catch(e){}throw new U}var ta=e=>Math.floor(e.getTime()/1e3);let ti=/^(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)$/i;var to=e=>{let t=ti.exec(e);if(!t)throw TypeError("Invalid time period format");let r=parseFloat(t[1]);switch(t[2].toLowerCase()){case"sec":case"secs":case"second":case"seconds":case"s":return Math.round(r);case"minute":case"minutes":case"min":case"mins":case"m":return Math.round(60*r);case"hour":case"hours":case"hr":case"hrs":case"h":return Math.round(3600*r);case"day":case"days":case"d":return Math.round(86400*r);case"week":case"weeks":case"w":return Math.round(604800*r);default:return Math.round(31557600*r)}};let ts=e=>e.toLowerCase().replace(/^application\//,""),tc=(e,t)=>"string"==typeof e?t.includes(e):!!Array.isArray(e)&&t.some(Set.prototype.has.bind(new Set(e)));var td=(e,t,r={})=>{let n,a;let{typ:i}=r;if(i&&("string"!=typeof e.typ||ts(e.typ)!==ts(i)))throw new v('unexpected "typ" JWT header value',"typ","check_failed");try{n=JSON.parse(d.decode(t))}catch(e){}if(!ea(n))throw new K("JWT Claims Set must be a top-level JSON object");let{requiredClaims:o=[],issuer:s,subject:c,audience:u,maxTokenAge:l}=r;for(let e of(void 0!==l&&o.push("iat"),void 0!==u&&o.push("aud"),void 0!==c&&o.push("sub"),void 0!==s&&o.push("iss"),new Set(o.reverse())))if(!(e in n))throw new v(`missing required "${e}" claim`,e,"missing");if(s&&!(Array.isArray(s)?s:[s]).includes(n.iss))throw new v('unexpected "iss" claim value',"iss","check_failed");if(c&&n.sub!==c)throw new v('unexpected "sub" claim value',"sub","check_failed");if(u&&!tc(n.aud,"string"==typeof u?[u]:u))throw new v('unexpected "aud" claim value',"aud","check_failed");switch(typeof r.clockTolerance){case"string":a=to(r.clockTolerance);break;case"number":a=r.clockTolerance;break;case"undefined":a=0;break;default:throw TypeError("Invalid clockTolerance option type")}let{currentDate:p}=r,h=ta(p||new Date);if((void 0!==n.iat||l)&&"number"!=typeof n.iat)throw new v('"iat" claim must be a number',"iat","invali
3d");if(void 0!==n.nbf){if("number"!=typeof n.nbf)throw new v('"nbf" claim must be a number',"nbf","invalid");if(n.nbf>h+a)throw new v('"nbf" claim timestamp check failed',"nbf","check_failed")}if(void 0!==n.exp){if("number"!=typeof n.exp)throw new v('"exp" claim must be a number',"exp","invalid");if(n.exp<=h-a)throw new S('"exp" claim timestamp check failed',"exp","check_failed")}if(l){let e=h-n.iat;if(e-a>("number"==typeof l?l:to(l)))throw new S('"iat" claim timestamp check failed (too far in the past)',"iat","check_failed");if(e<0-a)throw new v('"iat" claim timestamp check failed (it should be in the past)',"iat","check_failed")}return n};async function tu(e,t,r){var n;let a=await tr(e,t,r);if((null===(n=a.protectedHeader.crit)||void 0===n?void 0:n.includes("b64"))&&!1===a.protectedHeader.b64)throw new K("JWTs MUST NOT use unencoded payload");let i={payload:td(a.protectedHeader,a.payload,r),protectedHeader:a.protectedHeader};return"function"==typeof t?{...i,key:a.key}:i}async function tl(e,t,r){let n=await eq(e,t,r),a=td(n.protectedHeader,n.plaintext,r),{protectedHeader:i}=n;if(void 0!==i.iss&&i.iss!==a.iss)throw new v('replicated "iss" claim header parameter mismatch',"iss","mismatch");if(void 0!==i.sub&&i.sub!==a.sub)throw new v('replicated "sub" claim header parameter mismatch',"sub","mismatch");if(void 0!==i.aud&&JSON.stringify(i.aud)!==JSON.stringify(a.aud))throw new v('replicated "aud" claim header parameter mismatch',"aud","mismatch");let o={payload:a,protectedHeader:i};return"function"==typeof t?{...o,key:n.key}:o}class tp{constructor(e){this._flattened=new e4(e)}setContentEncryptionKey(e){return this._flattened.setContentEncryptionKey(e),this}setInitializationVector(e){return this._flattened.setInitializationVector(e),this}setProtectedHeader(e){return this._flattened.setProtectedHeader(e),this}setKeyManagementParameters(e){return this._flattened.setKeyManagementParameters(e),this}async encrypt(e,t){let r=await this._flattened.encrypt(e,t);return[r.protected,r.encrypted_key,r.iv,r.ciphertext,r.tag].join(".")}}let th=async(e,t,r)=>{let n=await e7(e,t,"sign");return em(e,n),new Uint8Array(await i.subtle.sign(e9(e,n.algorithm),n,r))};class ty{constructor(e){if(!(e instanceof Uint8Array))throw TypeError("payload must be an instance of Uint8Array");this._payload=e}setProtectedHeader(e){if(this._protectedHeader)throw TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setUnprotectedHeader(e){if(this._unprotectedHeader)throw TypeError("setUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}async sign(e,t){let r;if(!this._protectedHeader&&!this._unprotectedHeader)throw new P("either setProtectedHeader or setUnprotectedHeader must be called before #sign()");if(!en(this._protectedHeader,this._unprotectedHeader))throw new P("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");let n={...this._protectedHeader,...this._unprotectedHeader},a=ez(P,new Map([["b64",!0]]),null==t?void 0:t.crit,this._protectedHeader,n),i=!0;if(a.has("b64")&&"boolean"!=typeof(i=this._protectedHeader.b64))throw new P('The "b64" (base64url-encode payload) Header Parameter must be a boolean');let{alg:o}=n;if("string"!=typeof o||!o)throw new P('JWS "alg" (Algorithm) Header Parameter missing or invalid');e$(o,e,"sign");let s=this._payload;i&&(s=c.encode(m(s)));let l=u(r=this._protectedHeader?c.encode(m(JSON.stringify(this._protectedHeader))):c.encode(""),c.encode("."),s),p={signature:m(await th(o,e,l)),payload:""};return i&&(p.payload=d.decode(s)),this._unprotectedHeader&&(p.header=this._unprotectedHeader),this._protectedHeader&&(p.protected=d.decode(r)),p}}class tf{constructor(e){this._flattened=new ty(e)}setProtectedHeader(e){return this._flattened.setProtectedHeader(e),this}async sign(e,t){let r=await this._flattened.sign(e,t);if(void 0===r.payload)throw TypeError("use the flattened module for creating JWS with b64: false");return`${r.protected}.${r.payload}.${r.signature}`}}class tw{constructor(e,t,r){this.parent=e,this.key=t,this.options=r}setProtectedHeader(e){if(this.protectedHeader)throw TypeError("setProtectedHeader can only be called once");return this.protectedHeader=e,this}setUnprotectedHeader(e){if(this.unprotectedHeader)throw TypeError("setUnprotectedHeader can only be called once");return this.unprotectedHeader=e,this}addSignature(...e){return this.parent.addSignature(...e)}sign(...e){return this.parent.sign(...e)}done(){return this.parent}}class tm{constructor(e){this._signatures=[],this._payload=e}addSignature(e,t){let r=new tw(this,e,t);return this._signatures.push(r),r}async sign(){if(!this._signatures.length)throw new P("at least one signature must be added");let e={signatures:[],payload:""};for(let t=0;t<this._signatures.length;t++){let r=this._signatures[t],n=new ty(this._payload);n.setProtectedHeader(r.protectedHeader),n.setUnprotectedHeader(r.unprotectedHeader);let{payload:a,...i}=await n.sign(r.key,r.options);if(0===t)e.payload=a;else if(e.payload!==a)throw new P("inconsistent use of JWS Unencoded Payload (RFC7797)");e.signatures.push(i)}return e}}class tg{constructor(e){if(!ea(e))throw TypeError("JWT Claims Set MUST be an object");this._payload=e}setIssuer(e){return this._payload={...this._payload,iss:e},this}setSubject(e){return this._payload={...this._payload,sub:e},this}setAudience(e){return this._payload={...this._payload,aud:e},this}setJti(e){return this._payload={...this._payload,jti:e},this}setNotBefore(e){return"number"==typeof e?this._payload={...this._payload,nbf:e}:this._payload={...this._payload,nbf:ta(new Date)+to(e)},this}setExpirationTime(e){return"number"==typeof e?this._payload={...this._payload,exp:e}:this._payload={...this._payload,exp:ta(new Date)+to(e)},this}setIssuedAt(e){return void 0===e?this._payload={...this._payload,iat:ta(new Date)}:this._payload={...this._payload,iat:e},this}}class tE extends tg{setProtectedHeader(e){return this._protectedHeader=e,this}async sign(e,t){var r;let n=new tf(c.encode(JSON.stringify(this._payload)));if(n.setProtectedHeader(this._protectedHeader),Array.isArray(null===(r=this._protectedHeader)||void 0===r?void 0:r.crit)&&this._protectedHeader.crit.includes("b64")&&!1===this._protectedHeader.b64)throw new K("JWTs MUST NOT use unencoded payload");return n.sign(e,t)}}class tA extends tg{setProtectedHeader(e){if(this._protectedHeader)throw TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setKeyManagementParameters(e){if(this._keyManagementParameters)throw TypeError("setKeyManagementParameters can only be called once");return this._keyManagementParameters=e,this}setContentEncryptionKey(e){if(this._cek)throw TypeError("setContentEncryptionKey can only be called once");return this._cek=e,this}setInitializationVector(e){if(this._iv)throw TypeError("setInitializationVector can only be called once");return this._iv=e,this}replicateIssuerAsHeader(){return this._replicateIssuerAsHeader=!0,this}replicateSubjectAsHeader(){return this._replicateSubjectAsHeader=!0,this}replicateAudienceAsHeader(){return this._replicateAudienceAsHeader=!0,this}async encrypt(e,t){let r=new tp(c.encode(JSON.stringify(this._payload)));return this._replicateIssuerAsHeader&&(this._protectedHeader={...this._protectedHeader,iss:this._payload.iss}),this._replicateSubjectAsHeader&&(this._protectedHeader={...this._protectedHeader,sub:this._payload.sub}),this._replicateAudienceAsHeader&&(this._protectedHeader={...this._protectedHeader,aud:this._payload.aud}),r.setProtectedHeader(this._protectedHeader),this._iv&&r.setInitializationVector(this._iv),this._cek&&r.setContentEncryptionKey(this._cek),this._keyManagementParameters&&r.setKeyManagementParameters(this._keyManagementParameters),r.encrypt(e,t)}}let tv=(e,t)=>
3{if("string"!=typeof e||!e)throw new W(`${t} missing or invalid`)};async function tS(e,t){let r;if(!ea(e))throw TypeError("JWK must be an object");if(null!=t||(t="sha256"),"sha256"!==t&&"sha384"!==t&&"sha512"!==t)throw TypeError('digestAlgorithm must one of "sha256", "sha384", or "sha512"');switch(e.kty){case"EC":tv(e.crv,'"crv" (Curve) Parameter'),tv(e.x,'"x" (X Coordinate) Parameter'),tv(e.y,'"y" (Y Coordinate) Parameter'),r={crv:e.crv,kty:e.kty,x:e.x,y:e.y};break;case"OKP":tv(e.crv,'"crv" (Subtype of Key Pair) Parameter'),tv(e.x,'"x" (Public Key) Parameter'),r={crv:e.crv,kty:e.kty,x:e.x};break;case"RSA":tv(e.e,'"e" (Exponent) Parameter'),tv(e.n,'"n" (Modulus) Parameter'),r={e:e.e,kty:e.kty,n:e.n};break;case"oct":tv(e.k,'"k" (Key Value) Parameter'),r={k:e.k,kty:e.kty};break;default:throw new _('"kty" (Key Type) Parameter missing or unsupported')}let n=c.encode(JSON.stringify(r));return m(await s(t,n))}async function tb(e,t){null!=t||(t="sha256");let r=await tS(e,t);return`urn:ietf:params:oauth:jwk-thumbprint:sha-${t.slice(-3)}:${r}`}async function t_(e,t){let r={...e,...null==t?void 0:t.header};if(!ea(r.jwk))throw new P('"jwk" (JSON Web Key) Header Parameter must be a JSON object');let n=await eD({...r.jwk,ext:!0},r.alg,!0);if(n instanceof Uint8Array||"public"!==n.type)throw new P('"jwk" (JSON Web Key) Header Parameter must be a public key');return n}function tH(e){return e&&"object"==typeof e&&Array.isArray(e.keys)&&e.keys.every(tC)}function tC(e){return ea(e)}class tk{constructor(e){if(this._cached=new WeakMap,!tH(e))throw new T("JSON Web Key Set malformed");this._jwks="function"==typeof structuredClone?structuredClone(e):JSON.parse(JSON.stringify(e))}async getKey(e,t){let{alg:r,kid:n}={...e,...null==t?void 0:t.header},a=function(e){switch("string"==typeof e&&e.slice(0,2)){case"RS":case"PS":return"RSA";case"ES":return"EC";case"Ed":return"OKP";default:throw new _('Unsupported "alg" value for a JSON Web Key Set')}}(r),i=this._jwks.keys.filter(e=>{let t=a===e.kty;if(t&&"string"==typeof n&&(t=n===e.kid),t&&"string"==typeof e.alg&&(t=r===e.alg),t&&"string"==typeof e.use&&(t="sig"===e.use),t&&Array.isArray(e.key_ops)&&(t=e.key_ops.includes("verify")),t&&"EdDSA"===r&&(t="Ed25519"===e.crv||"Ed448"===e.crv),t)switch(r){case"ES256":t="P-256"===e.crv;break;case"ES256K":t="secp256k1"===e.crv;break;case"ES384":t="P-384"===e.crv;break;case"ES512":t="P-521"===e.crv}return t}),{0:o,length:s}=i;if(0===s)throw new R;if(1!==s){let e=new J,{_cached:t}=this;throw e[Symbol.asyncIterator]=async function*(){for(let e of i)try{yield await tP(t,e,r)}catch(e){continue}},e}return tP(this._cached,o,r)}}async function tP(e,t,r){let n=e.get(t)||e.set(t,{}).get(t);if(void 0===n[r]){let e=await eD({...t,ext:!0},r);if(e instanceof Uint8Array||"public"!==e.type)throw new T("JSON Web Key Set members must be public keys");n[r]=e}return n[r]}function tK(e){let t=new tk(e);return async function(e,r){return t.getKey(e,r)}}let tW=async(e,t,r)=>{let n,a;let i=!1;"function"==typeof AbortController&&(n=new AbortController,a=setTimeout(()=>{i=!0,n.abort()},t));let o=await fetch(e.href,{signal:n?n.signal:void 0,redirect:"manual",headers:r.headers}).catch(e=>{if(i)throw new I;throw e});if(void 0!==a&&clearTimeout(a),200!==o.status)throw new A("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await o.json()}catch(e){throw new A("Failed to parse the JSON Web Key Set HTTP response as JSON")}};class tT extends tk{constructor(e,t){if(super({keys:[]}),this._jwks=void 0,!(e instanceof URL))throw TypeError("url must be an instance of URL");this._url=new URL(e.href),this._options={agent:null==t?void 0:t.agent,headers:null==t?void 0:t.headers},this._timeoutDuration="number"==typeof(null==t?void 0:t.timeoutDuration)?null==t?void 0:t.timeoutDuration:5e3,this._cooldownDuration="number"==typeof(null==t?void 0:t.cooldownDuration)?null==t?void 0:t.cooldownDuration:3e4,this._cacheMaxAge="number"==typeof(null==t?void 0:t.cacheMaxAge)?null==t?void 0:t.cacheMaxAge:6e5}coolingDown(){return"number"==typeof this._jwksTimestamp&&Date.now()<this._jwksTimestamp+this._cooldownDuration}fresh(){return"number"==typeof this._jwksTimestamp&&Date.now()<this._jwksTimestamp+this._cacheMaxAge}async getKey(e,t){this._jwks&&this.fresh()||await this.reload();try{return await super.getKey(e,t)}catch(r){if(r instanceof R&&!1===this.coolingDown())return await this.reload(),super.getKey(e,t);throw r}}async reload(){this._pendingFetch&&("undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime)&&(this._pe
3ndingFetch=void 0),this._pendingFetch||(this._pendingFetch=tW(this._url,this._timeoutDuration,this._options).then(e=>{if(!tH(e))throw new T("JSON Web Key Set malformed");this._jwks={keys:e.keys},this._jwksTimestamp=Date.now(),this._pendingFetch=void 0}).catch(e=>{throw this._pendingFetch=void 0,e})),await this._pendingFetch}}function tR(e,t){let r=new tT(e,t);return async function(e,t){return r.getKey(e,t)}}class tJ extends tg{encode(){let e=m(JSON.stringify({alg:"none"})),t=m(JSON.stringify(this._payload));return`${e}.${t}.`}static decode(e,t){let r;if("string"!=typeof e)throw new K("Unsecured JWT must be a string");let{0:n,1:a,2:i,length:o}=e.split(".");if(3!==o||""!==i)throw new K("Invalid Unsecured JWT");try{if(r=JSON.parse(d.decode(E(n))),"none"!==r.alg)throw Error()}catch(e){throw new K("Invalid Unsecured JWT")}return{payload:td(r,E(a),t),header:r}}}let tI=m,tU=E;function tx(e){let t;if("string"==typeof e){let r=e.split(".");(3===r.length||5===r.length)&&([t]=r)}else if("object"==typeof e&&e){if("protected"in e)t=e.protected;else throw TypeError("Token does not contain a Protected Header")}try{if("string"!=typeof t||!t)throw Error();let e=JSON.parse(d.decode(tU(t)));if(!ea(e))throw Error();return e}catch(e){throw TypeError("Invalid Token or Protected Header formatting")}}function tO(e){let t,r;if("string"!=typeof e)throw new K("JWTs must use Compact JWS serialization, JWT must be a string");let{1:n,length:a}=e.split(".");if(5===a)throw new K("Only JWTs using Compact JWS serialization can be decoded");if(3!==a)throw new K("Invalid JWT");if(!n)throw new K("JWTs must contain a payload");try{t=tU(n)}catch(e){throw new K("Failed to base64url decode the payload")}try{r=JSON.parse(d.decode(t))}catch(e){throw new K("Failed to parse the decoded payload as JSON")}if(!ea(r))throw new K("Invalid JWT Claims Set");return r}async function tD(e,t){var r;let n,a,o;switch(e){case"HS256":case"HS384":case"HS512":n=parseInt(e.slice(-3),10),a={name:"HMAC",hash:`SHA-${n}`,length:n},o=["sign","verify"];break;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return x(new Uint8Array((n=parseInt(e.slice(-3),10))>>3));case"A128KW":case"A192KW":case"A256KW":a={name:"AES-KW",length:n=parseInt(e.slice(1,4),10)},o=["wrapKey","unwrapKey"];break;case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":case"A128GCM":case"A192GCM":case"A256GCM":a={name:"AES-GCM",length:n=parseInt(e.slice(1,4),10)},o=["encrypt","decrypt"];break;default:throw new _('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}return i.subtle.generateKey(a,null!==(r=null==t?void 0:t.extractable)&&void 0!==r&&r,o)}function tM(e){var t;let r=null!==(t=null==e?void 0:e.modulusLength)&&void 0!==t?t:2048;if("number"!=typeof r||r<2048)throw new _("Invalid or unsupported modulusLength option provided, 2048 bits or larger keys must be used");return r}async function tj(e,t){var r,n,a;let o,s;switch(e){case"PS256":case"PS384":case"PS512":o={name:"RSA-PSS",hash:`SHA-${e.slice(-3)}`,publicExponent:new Uint8Array([1,0,1]),modulusLength:tM(t)},s=["sign","verify"];break;case"RS256":case"RS384":case"RS512":o={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${e.slice(-3)}`,publicExponent:new Uint8Array([1,0,1]),modulusLength:tM(t)},s=["sign","verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":o={name:"RSA-OAEP",hash:`SHA-${parseInt(e.slice(-3),10)||1}`,publicExponent:new Uint8Array([1,0,1]),modulusLength:tM(t)},s=["decrypt","unwrapKey","encrypt","wrapKey"];break;case"ES256":o={name:"ECDSA",namedCurve:"P-256"},s=["sign","verify"];break;case"ES384":o={name:"ECDSA",namedCurve:"P-384"},s=["sign","verify"];break;case"ES512":o={name:"ECDSA",namedCurve:"P-521"},s=["sign","verify"];break;case"EdDSA":s=["sign","verify"];let c=null!==(r=null==t?void 0:t.crv)&&void 0!==r?r:"Ed25519";
3switch(c){case"Ed25519":case"Ed448":o={name:c};break;default:throw new _("Invalid or unsupported crv option provided")}break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{s=["deriveKey","deriveBits"];let e=null!==(n=null==t?void 0:t.crv)&&void 0!==n?n:"P-256";switch(e){case"P-256":case"P-384":case"P-521":o={name:"ECDH",namedCurve:e};break;case"X25519":case"X448":o={name:e};break;default:throw new _("Invalid or unsupported crv option provided, supported values are P-256, P-384, P-521, X25519, and X448")}break}default:throw new _('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}return i.subtle.generateKey(o,null!==(a=null==t?void 0:t.extractable)&&void 0!==a&&a,s)}async function t$(e,t){return tj(e,t)}async function tN(e,t){return tD(e,t)}var tB="WebCryptoAPI"}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.