PageSourceSearch

https://emelog.netlify.app/assets/version-BviGLQK7.js

js emelog.netlify.app collected 2026-10-03 10:41:53 UTC 159,288 bytes, 1 lines download raw bytes

1function e(e,t){var n={};for(var o in e)Object.prototype.hasOwnProperty.call(e,o)&&t.indexOf(o)<0&&(n[o]=e[o]);if(null!=e&&"function"==typeof Object.getOwnPropertySymbols){var r=0;for(o=Object.getOwnPropertySymbols(e);r<o.length;r++)t.indexOf(o[r])<0&&Object.prototype.propertyIsEnumerable.call(e,o[r])&&(n[o[r]]=e[o[r]])}return n}!function(){const e=document.createElement("link").relList;if(!(e&&e.supports&&e.supports("modulepreload"))){for(const e of document.querySelectorAll('link[rel="modulepreload"]'))t(e);new MutationObserver(e=>{for(const n of e)if("childList"===n.type)for(const e of n.addedNodes)"LINK"===e.tagName&&"modulepreload"===e.rel&&t(e)}).observe(document,{childList:!0,subtree:!0})}function t(e){if(e.ep)return;e.ep=!0;const t=function(e){const t={};return e.integrity&&(t.integrity=e.integrity),e.referrerPolicy&&(t.referrerPolicy=e.referrerPolicy),"use-credentials"===e.crossOrigin?t.credentials="include":"anonymous"===e.crossOrigin?t.credentials="omit":t.credentials="same-origin",t}(e);fetch(e.href,t)}}(),"function"==typeof SuppressedError&&SuppressedError;var t="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{},n={},o={};Object.defineProperty(o,"__esModule",{value:!0});var r=function(){function e(){var e=this;this.locked=new Map,this.addToLocked=function(t,n){var o=e.locked.get(t);void 0===o?void 0===n?e.locked.set(t,[]):e.locked.set(t,[n]):void 0!==n&&(o.unshift(n),e.locked.set(t,o))},this.isLocked=function(t){return e.locked.has(t)},this.lock=function(t){return new Promise(function(n,o){e.isLocked(t)?e.addToLocked(t,n):(e.addToLocked(t),n())})},this.unlock=function(t){var n=e.locked.get(t);if(void 0!==n&&0!==n.length){var o=n.pop();e.locked.set(t,n),void 0!==o&&setTimeout(o,0)}else e.locked.delete(t)}}return e.getInstance=function(){return void 0===e.instance&&(e.instance=new e),e.instance},e}();o.default=function(){return r.getInstance()};var i=t&&t.__awaiter||function(e,t,n,o){return new(n||(n=Promise))(function(r,i){function a(e){try{c(o.next(e))}catch(t){i(t)}}function s(e){try{c(o.throw(e))}catch(t){i(t)}}function c(e){e.done?r(e.value):new n(function(t){t(e.value)}).then(a,s)}c((o=o.apply(e,t||[])).next())})},a=t&&t.__generator||function(e,t){var n,o,r,i,a={label:0,sent:function(){if(1&r[0])throw r[1];return r[1]},trys:[],ops:[]};return i={next:s(0),throw:s(1),return:s(2)},"function"==typeof Symbol&&(i[Symbol.iterator]=function(){return this}),i;function s(i){return function(s){return function(i){if(n)throw new TypeError("Generator is already executing.");for(;a;)try{if(n=1,o&&(r=2&i[0]?o.return:i[0]?o.throw||((r=o.return)&&r.call(o),0):o.next)&&!(r=r.call(o,i[1])).done)return r;switch(o=0,r&&(i=[2&i[0],r.value]),i[0]){case 0:case 1:r=i;break;case 4:return a.label++,{value:i[1],done:!1};case 5:a.label++,o=i[1],i=[0];continue;case 7:i=a.ops.pop(),a.trys.pop();continue;default:if(!((r=(r=a.trys).length>0&&r[r.length-1])||6!==i[0]&&2!==i[0])){a=0;continue}if(3===i[0]&&(!r||i[1]>r[0]&&i[1]<r[3])){a.label=i[1];break}if(6===i[0]&&a.label<r[1]){a.label=r[1],r=i;break}if(r&&a.label<r[2]){a.label=r[2],a.ops.push(i);break}r[2]&&a.ops.pop(),a.trys.pop();continue}i=t.call(e,a)}catch(s){i=[6,s],o=0}finally{n=r=0}if(5&i[0])throw i[1];return{value:i[0]?i[1]:void 0,done:!0}}([i,s])}}},s=t;Object.defineProperty(n,"__esModule",{value:!0});var c=o,u={key:function(e){return i(s,void 0,void 0,function(){return a(this,function(e){throw new Error("Unsupported")})})},getItem:function(e){return i(s,void 0,void 0,function(){return a(this,function(e){throw new Error("Unsupported")})})},clear:function(){return i(s,void 0,void 0,function(){return a(this,function(e){return[2,window.localStorage.clear()]})})},removeItem:function(e){return i(s,void 0,void 0,function(){return a(this,function(e){throw new Error("Unsupported")})})},setItem:function(e,t){return i(s,void 0,void 0,function(){return a(this,function(e){throw new Error("Unsupported")})})},keySync:function(e){return window.localStorage.key(e)},getItemSync:function(e){return window.localStorage.getItem(e)},clearSync:function(){return window.localStorage.clear()},removeItemSync:function(e){return window.localStorage.removeItem(e)},setItemSync:function(e,t){return window.localStorage.setItem(e,t)}};function l(e){return new Promise(function(t){return setTimeout(t,e)})}function d(e){for(var t="",n=0;n<e;n++)t+="0123456789ABCDEFGHIJKLMNOPQRSTUVWXTZabcdefghiklmnopqrstuvwxyz"[Math.floor(61*Math.random())];return t}var h=function(){function e(t){this.acquiredIatSet=new Set,this.storageHandler=void 0,this.id=Date.now().toString()+d(15),this.acquireLock=this.acquireLock.bind(this),this.releaseLock=this.releaseLock.bind(this),this.releaseLock__private__=this.releaseLock__private__.bind(this),this.waitForSomethingToChange=this.waitForSomethingToChange.bind(this),this.refreshLockWhileAcquired=this.refreshLockWhileAcquired.bind(this),this.storageHandler=t,void 0===e.waiters&&(e.waiters=[])}return e.prototype.acquireLock=function(t,n){return void 0===n&&(n=5e3),i(this,void 0,void 0,function(){var o,r,i,s,c,h,p;return a(this,function(a){switch(a.label){case 0:o=Date.now()+d(4),r=Date.now()+n,i="browser-tabs-lock-key-"+t,s=void 0===this.storageHandler?u:this.storageHandler,a.label=1;case 1:return Date.now()<r?[4,l(30)]:[3,8];case 2:return a.sent(),null!==s.getItemSync(i)?[3,5]:(c=this.id+"-"+t+"-"+
vendor: 5,252 bytes, line 1
1o,[4,l(Math.floor(25*Math.random()))]);case 3:return a.sent(),s.setItemSync(i,JSON.stringify({id:this.id,iat:o,timeoutKey:c,timeAcquired:Date.now(),timeRefreshed:Date.now()})),[4,l(30)];case 4:return a.sent(),null!==(h=s.getItemSync(i))&&(p=JSON.parse(h)).id===this.id&&p.iat===o?(this.acquiredIatSet.add(o),this.refreshLockWhileAcquired(i,o),[2,!0]):[3,7];case 5:return e.lockCorrector(void 0===this.storageHandler?u:this.storageHandler),[4,this.waitForSomethingToChange(r)];case 6:a.sent(),a.label=7;case 7:return o=Date.now()+d(4),[3,1];case 8:return[2,!1]}})})},e.prototype.refreshLockWhileAcquired=function(e,t){return i(this,void 0,void 0,function(){var n=this;return a(this,function(o){return setTimeout(function(){return i(n,void 0,void 0,function(){var n,o,r;return a(this,function(i){switch(i.label){case 0:return[4,c.default().lock(t)];case 1:return i.sent(),this.acquiredIatSet.has(t)?(n=void 0===this.storageHandler?u:this.storageHandler,null===(o=n.getItemSync(e))?(c.default().unlock(t),[2]):((r=JSON.parse(o)).timeRefreshed=Date.now(),n.setItemSync(e,JSON.stringify(r)),c.default().unlock(t),this.refreshLockWhileAcquired(e,t),[2])):(c.default().unlock(t),[2])}})})},1e3),[2]})})},e.prototype.waitForSomethingToChange=function(t){return i(this,void 0,void 0,function(){return a(this,function(n){switch(n.label){case 0:return[4,new Promise(function(n){var o=!1,r=Date.now(),i=!1;function a(){if(i||(window.removeEventListener("storage",a),e.removeFromWaiting(a),clearTimeout(s),i=!0),!o){o=!0;var t=50-(Date.now()-r);t>0?setTimeout(n,t):n(null)}}window.addEventListener("storage",a),e.addToWaiting(a);var s=setTimeout(a,Math.max(0,t-Date.now()))})];case 1:return n.sent(),[2]}})})},e.addToWaiting=function(t){this.removeFromWaiting(t),void 0!==e.waiters&&e.waiters.push(t)},e.removeFromWaiting=function(t){void 0!==e.waiters&&(e.waiters=e.waiters.filter(function(e){return e!==t}))},e.notifyWaiters=function(){void 0!==e.waiters&&e.waiters.slice().forEach(function(e){return e()})},e.prototype.releaseLock=function(e){return i(this,void 0,void 0,function(){return a(this,function(t){switch(t.label){case 0:return[4,this.releaseLock__private__(e)];case 1:return[2,t.sent()]}})})},e.prototype.releaseLock__private__=function(t){return i(this,void 0,void 0,function(){var n,o,r,i;return a(this,function(a){switch(a.label){case 0:return n=void 0===this.storageHandler?u:this.storageHandler,o="browser-tabs-lock-key-"+t,null===(r=n.getItemSync(o))?[2]:(i=JSON.parse(r)).id!==this.id?[3,2]:[4,c.default().lock(i.iat)];case 1:a.sent(),this.acquiredIatSet.delete(i.iat),n.removeItemSync(o),c.default().unlock(i.iat),e.notifyWaiters(),a.label=2;case 2:return[2]}})})},e.lockCorrector=function(t){for(var n=Date.now()-5e3,o=t,r=[],i=0;;){var a=o.keySync(i);if(null===a)break;r.push(a),i++}for(var s=!1,c=0;c<r.length;c++){var u=r[c];if(u.includes("browser-tabs-lock-key")){var l=o.getItemSync(u);if(null!==l){var d=JSON.parse(l);(void 0===d.timeRefreshed&&d.timeAcquired<n||void 0!==d.timeRefreshed&&d.timeRefreshed<n)&&(o.removeItemSync(u),s=!0)}}}s&&e.notifyWaiters()},e.waiters=void 0,e}(),p=n.default=h;const f={timeoutInSeconds:60},m={name:"auth0-spa-js",version:"2.14.0"},y=()=>Date.now();class w extends Error{constructor(e,t){super(t),this.error=e,this.error_description=t,Object.setPrototypeOf(this,w.prototype)}static fromPayload(e){let{error:t,error_description:n}=e;return new w(t,n)}}class g extends w{constructor(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:null;super(e,t),this.state=n,this.appState=o,Object.setPrototypeOf(this,g.prototype)}}class v extends w{constructor(e,t,n,o){let r=arguments.length>4&&void 0!==arguments[4]?arguments[4]:null;super(e,t),this.connection=n,this.state=o,this.appState=r,Object.setPrototypeOf(this,v.prototype)}}class b extends w{constructor(){super("timeout","Timeout"),Object.setPrototypeOf(this,b.prototype)}}class _ extends b{constructor(e){super(),this.popup=e,Object.setPrototypeOf(this,_.prototype)}}class k extends w{constructor(e){super("cancelled","Popup closed"),this.popup=e,Object.setPrototypeOf(this,k.prototype)}}class S extends w{constructor(){super("popup_open","Unable to open a popup for loginWithPopup - window.open returned `null`"),Object.setPrototypeOf(this,S.prototype)}}class E extends w{constructor(e,t,n,o){super(e,t),this.mfa_token=n,this.mfa_requirements=o,Object.setPrototypeOf(this,E.prototype)}}class T extends w{constructor(e,t){super("missing_refresh_token","Missing Refresh Token (audience: '".concat(R(e,["default"]),"', scope: '").concat(R(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,T.prototype)}}class A extends w{constructor(e,t){super("missing_scopes","Missing requested scopes after refresh (audience: '".concat(R(e,["default"]),"', missing scope: '").concat(R(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,A.prototype)}}class P extends w{constructor(e){super("use_dpop_nonce","Server rejected DPoP proof: wrong nonce"),this.newDpopNonce=e,Object.setPrototypeOf(this,P.prototype)}}function R(e){return e&&!(arguments.length>1&&void 0!==arguments[1]?arguments[1]:[]).includes(e)?e:""}const I=()=>window.crypto,O=()=>{let e="";return Array.from(I().getRandomValues(new Uint8Array(43))).forEac
1h(t=>e+="0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-_~."[t%66]),e},x=e=>btoa(e),C=[{key:"name",type:["string"]},{key:"version",type:["string","number"]},{key:"env",type:["object"]}],j=function(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return Object.keys(e).reduce((n,o)=>{if(t&&"env"===o)return n;const r=C.find(e=>e.key===o);return r&&r.type.includes(typeof e[o])&&(n[o]=e[o]),n},{})},D=t=>{var n,{clientId:o}=t,r=e(t,["clientId"]);return new URLSearchParams((n=Object.assign({client_id:o},r),Object.keys(n).filter(e=>void 0!==n[e]).reduce((e,t)=>Object.assign(Object.assign({},e),{[t]:n[t]}),{}))).toString()},K=async e=>{const t=I().subtle.digest({name:"SHA-256"},(new TextEncoder).encode(e));return await t},L=e=>{return t=e.replace(/_/g,"/").replace(/-/g,"+"),decodeURIComponent(atob(t).split("").map(e=>"%"+("00"+e.charCodeAt(0).toString(16)).slice(-2)).join(""));var t},U=e=>{const t=new Uint8Array(e);return(e=>{const t={"+":"-","/":"_","=":""};return e.replace(/[+/=]/g,e=>t[e])})(window.btoa(String.fromCharCode(...Array.from(t))))},N=new TextEncoder,W=new TextDecoder;function z(e){return"string"==typeof e?N.encode(e):W.decode(e)}function H(e){if("number"!=typeof e.modulusLength||e.modulusLength<2048)throw new F(`${e.name} modulusLength must be at least 2048 bits`)}let M;if(Uint8Array.prototype.toBase64)M=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;M=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function J(e){return M(e)}class V extends Error{constructor(e){var t;super(null!=e?e:"operation not supported"),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}class F extends Error{constructor(e){var t;super(e),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}function G(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){if("SHA-256"===e.algorithm.hash.name)return"PS256";throw new V("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"RSASSA-PKCS1-v1_5":return function(e){if("SHA-256"===e.algorithm.hash.name)return"RS256";throw new V("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"ECDSA":return function(e){if("P-256"===e.algorithm.namedCurve)return"ES256";throw new V("unsupported EcKeyAlgorithm namedCurve")}(e);case"Ed25519":return"Ed25519";default:throw new V("unsupported CryptoKey algorithm name")}}function Z(e){return e instanceof CryptoKey}function q(e){return Z(e)&&"public"===e.type}async function B(e){const{kty:t,e:n,n:o,x:r,y:i,crv:a}=await crypto.subtle.exportKey("jwk",e);return{kty:t,crv:a,e:n,n:o,x:r,y:i}}const X=["authorization_code","refresh_token","urn:ietf:params:oauth:grant-type:token-exchange","http://auth0.com/oauth/grant-type/mfa-oob","http://auth0.com/oauth/grant-type/mfa-otp","http://auth0.com/oauth/grant-type/mfa-rec
1overy-code"],Y=async(e,t)=>{const n=await fetch(e,t);return{ok:n.ok,json:await n.json(),headers:(o=n.headers,[...o].reduce((e,t)=>{let[n,o]=t;return e[n]=o,e},{}))};var o},Q=async function(e,t,n,o,r,i){let a=arguments.length>6&&void 0!==arguments[6]?arguments[6]:1e4;return r?(async(e,t,n,o,r,i,a,s)=>{return c={auth:{audience:t,scope:n},timeout:r,fetchUrl:e,fetchOptions:o,useFormData:a,useMrrt:s},u=i,new Promise(function(e,t){const n=new MessageChannel;n.port1.onmessage=function(o){o.data.error?t(new Error(o.data.error)):e(o.data),n.port1.close()},u.postMessage(c,[n.port2])});var c,u})(e,t,n,o,a,r,i,arguments.length>7?arguments[7]:void 0):(async(e,t,n)=>{const o=new AbortController;let r;return t.signal=o.signal,Promise.race([Y(e,t),new Promise((e,t)=>{r=setTimeout(()=>{o.abort(),t(new Error("Timeout when executing 'fetch'"))},n)})]).finally(()=>{clearTimeout(r)})})(e,o,a)};async function $(t,n,o,r,i,a,s,c,u,l){if(u){const e=await u.generateProof({url:t,method:i.method||"GET",nonce:await u.getNonce()});i.headers=Object.assign(Object.assign({},i.headers),{dpop:e})}let d,h=null;for(let e=0;e<3;e++)try{d=await Q(t,o,r,i,a,s,n,c),h=null;break}catch(_){h=_}if(h)throw h;const p=d.json,{error:f,error_description:m}=p,y=e(p,["error","error_description"]),{headers:g,ok:v}=d;let b;if(u&&(b=g["dpop-nonce"],b&&await u.setNonce(b)),!v){const e=m||"HTTP error. Unable to fetch ".concat(t);if("mfa_required"===f)throw new E(f,e,y.mfa_token,y.mfa_requirements);if("missing_refresh_token"===f)throw new T(o,r);if("use_dpop_nonce"===f){if(!u||!b||l)throw new P(b);return $(t,n,o,r,i,a,s,c,u,!0)}throw new w(f||"request_error",e)}return y}async function ee(t,n){var{baseUrl:o,timeout:r,audience:i,scope:a,auth0Client:s,useFormData:c,useMrrt:u,dpop:l}=t,d=e(t,["baseUrl","timeout","audience","scope","auth0Client","useFormData","useMrrt","dpop"]);const h="urn:ietf:params:oauth:grant-type:token-exchange"===d.grant_type,p="refresh_token"===d.grant_type&&u,f=Object.assign(Object.assign(Object.assign(Object.assign({},d),h&&i&&{audience:i}),h&&a&&{scope:a}),p&&{audience:i,scope:a}),y=c?D(f):JSON.stringify(f),w=(g=d.grant_type,X.includes(g));var g;return await $("".concat(o,"/oauth/token"),r,i||"default",a,{method:"POST",body:y,headers:{"Content-Type":c?"application/x-www-form-urlencoded":"application/json","Auth0-Client":btoa(JSON.stringify(j(s||m)))}},n,c,u,w?l:void 0)}const te=function(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];return(e=>Array.from(new Set(e)))(t.filter(Boolean).join(" ").trim().split(/\s+/)).join(" ")},ne=(e,t,n)=>{let o;return n&&(o=e[n]),o||(o=e.default),te(o,t)};class oe{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:"@@auth0spajs@@",n=arguments.length>2?arguments[2]:void 0;this.prefix=t,this.suffix=n,this.clientId=e.clientId,this.scope=e.scope,this.audience=e.audience}toKey(){return[this.prefix,this.clientId,this.audience,this.scope,this.suffix].filter(Boolean).join("::")}static fromKey(e){const[t,n,o,r]=e.split("::");return new oe({clientId:n,scope:r,audience:o},t)}static fromCacheEntry(e){const{scope:t,audience:n,client_id:o}=e;return new oe({scope:t,audience:n,clientId:o})}}class re{set(e,t){localStorage.setItem(e,JSON.stringify(t))}get(e){const t=window.localStorage.getItem(e);if(t)try{return JSON.parse(t)}catch(n){return}}remove(e){localStorage.removeItem(e)}allKeys(){return Object.keys(window.localStorage).filter(e=>e.startsWith("@@auth0spajs@@"))}}class ie{constructor(){this.enclosedCache=function(){let e={};return{set(t,n){e[t]=n},get(t){const n=e[t];if(n)return n},remove(t){delete e[t]},allKeys:()=>Object.keys(e)}}()}}class ae{constructor(e,t,n){this.cache=e,this.keyManifest=t,this.nowProvider=n||y}async setIdToken(e,t,n){var o;const r=this.getIdTokenCacheKey(e);await this.cache.set(r,{id_token:t,decodedToken:n}),await(null===(o=this.keyManifest)||void 0===o?void 0:o.add(r))}async getIdToken(e){const t=await this.cache.get(this.getIdTokenCacheKey(e.clientId));if(!t&&e.scope&&e.audience){const t=await this.get(e);if(!t)return;if(!t.id_token||!t.decodedToken)return;return{id_token:t.id_token,decodedToken:t.decodedToken}}if(t)return{id_token:t.id_token,decodedToken:t.decodedToken}}async get(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:0,n=arguments.length>2&&void 0!==arguments[2]&&arguments[2],o=arguments.length>3?arguments[3]:void 0;var r;let i=await this.cache.get(e.toKey());if(!i){const t=await this.getCacheKeys();if(!t)return;const r=this.matchExistingCacheKey(e,t);
1if(r&&(i=await this.cache.get(r)),!i&&n&&"cache-only"!==o)return this.getEntryWithRefreshToken(e,t)}if(!i)return;const a=await this.nowProvider(),s=Math.floor(a/1e3);return i.expiresAt-t<s?i.body.refresh_token?this.modifiedCachedEntry(i,e):(await this.cache.remove(e.toKey()),void(await(null===(r=this.keyManifest)||void 0===r?void 0:r.remove(e.toKey())))):i.body}async modifiedCachedEntry(e,t){return e.body={refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope},await this.cache.set(t.toKey(),e),{refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope}}async set(e){var t;const n=new oe({clientId:e.client_id,scope:e.scope,audience:e.audience}),o=await this.wrapCacheEntry(e);await this.cache.set(n.toKey(),o),await(null===(t=this.keyManifest)||void 0===t?void 0:t.add(n.toKey()))}async remove(e,t,n){const o=new oe({clientId:e,scope:n,audience:t});await this.cache.remove(o.toKey())}async clear(e){var t;const n=await this.getCacheKeys();n&&(await n.filter(t=>!e||t.includes(e)).reduce(async(e,t)=>{await e,await this.cache.remove(t)},Promise.resolve()),await(null===(t=this.keyManifest)||void 0===t?void 0:t.clear()))}async wrapCacheEntry(e){const t=await this.nowProvider();return{body:e,expiresAt:Math.floor(t/1e3)+e.expires_in}}async getCacheKeys(){var e;return this.keyManifest?null===(e=await this.keyManifest.get())||void 0===e?void 0:e.keys:this.cache.allKeys?this.cache.allKeys():void 0}getIdTokenCacheKey(e){return new oe({clientId:e},"@@auth0spajs@@","@@user@@").toKey()}matchExistingCacheKey(e,t){return t.filter(t=>{var n;const o=oe.fromKey(t),r=new Set(o.scope&&o.scope.split(" ")),i=(null===(n=e.scope)||void 0===n?void 0:n.split(" "))||[],a=o.scope&&i.reduce((e,t)=>e&&r.has(t),!0);return"@@auth0spajs@@"===o.prefix&&o.clientId===e.clientId&&o.audience===e.audience&&a})[0]}async getEntryWithRefreshToken(e,t){var n;for(const o of t){const t=oe.fromKey(o);if("@@auth0spajs@@"===t.prefix&&t.clientId===e.clientId){const t=await this.cache.get(o);if(null===(n=null==t?void 0:t.body)||void 0===n?void 0:n.refresh_token)return this.modifiedCachedEntry(t,e)}}}async updateEntry(e,t){var n;const o=await this.getCacheKeys();if(o)for(const r of o){const o=await this.cache.get(r);if((null===(n=null==o?void 0:o.body)||void 0===n?void 0:n.refresh_token)===e){const e=Object.assign(Object.assign({},o.body),{refresh_token:t});await this.set(e)}}}}class se{constructor(e,t,n){this.storage=e,this.clientId=t,this.cookieDomain=n,this.storageKey="".concat("a0.spajs.txs",".").concat(this.clientId)}create(e){this.storage.save(this.storageKey,e,{daysUntilExpire:1,cookieDomain:this.cookieDomain})}get(){return this.storage.get(this.storageKey)}remove(){this.storage.remove(this.storageKey,{cookieDomain:this.cookieDomain})}}const ce=e=>"number"==typeof e,ue=["iss","aud","exp","nbf","iat","jti","azp","nonce","auth_time","at_hash","c_hash","acr","amr","sub_jwk","cnf","sip_from_tag","sip_date","sip_callid","sip_cseq_num","sip_via_branch","orig","dest","mky","events","toe","txn","rph","sid","vot","vtm"];var le=t&&t.__assign||function(){return le=Object.assign||function(e){for(var t,n=1,o=arguments.length;n<o;n++)for(var r in t=arguments[n])Object.prototype.hasOwnProperty.call(t,r)&&(e[r]=t[r]);return e},le.apply(this,arguments)};function de(e,t){if(!t)return"";var n="; "+e;return!0===t?n:n+"="+t}function he(e,t,n){document.cookie=function(e,t,n){return encodeURIComponent(e).replace(/%(23|24|26|2B|5E|60|7C)/g,decodeURIComponent).replace(/\(/g,"%28").replace(/\)/g,"%29")+"="+encodeURIComponent(t).replace(/%(23|24|26|2B|3A|3C|3E|3D|2F|3F|40|5B|5D|5E|60|7B|7D|7C)/g,decodeURIComponent)+function(e){if("number"==typeof e.expires){var t=new Date;t.setMilliseconds(t.getMilliseconds()+864e5*e.expires),e.expires=t}return de("Expires",e.expires?e.expires.toUTCString():"")+de("Domain",e.domain)+de("Path",e.path)+de("Secure",e.secure)+de("SameSite",e.sameSite)}(n)}(e,t,le({path:"/"},n))}var pe=he,fe=function(e,t){he(e,"",le(le({},t),{expires:-1}))};const me={get(e){const t=function(e){return function(e){for(var t={},n=e?e.split("; "):[],o=/(%[\dA-F]{2})+/gi,r=0;r<n.length;r++){var i=n[r].split("="),a=i.slice(1).join("=");'"'===a.charAt(0)&&(a=a.slice(1,-1));try{t[i[0].replace(o,decodeURIComponent)]=a.replace(o,decodeURIComponent)}catch(s){}}return t}(document.cookie)[e]}(e);if(void 0!==t)return JSON.parse(t)},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0,sameSite:"none"}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),pe(e,JSON.stringify(t),o)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),fe(e,n)}},ye={get:e=>me.get(e)||me.get("".concat("_legacy_").concat(e)),save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),pe("".concat("_legacy_").concat(e),JSON.stringify(t),o),me.save(e,t,n)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),fe(e,n),me.remove(e,t),me.remove("".concat("_legacy_").concat(e),t)}},we={get(e){if("undefined"==typeof sessionStorage)return;const t=sessionStorage.getItem(e);return null!=t?JSON.parse(t):void 0},save(e,t){sessionStorage.setItem(e,JSON.stringify(t))},remove(e){sessionStorage.removeItem(e)}};var ge,ve;(ve=ge||(ge={})).Code="code",ve.ConnectCode="connect_code";var be,_e=function(e){return be=be||(t=atob("Lyogcm9sbHVwLXBsdWdpbi13ZWItd29ya2VyLWxvYWRlciAqLwohZnVuY3Rpb24oKXsidXNlIHN0cmljdCI7Y2xhc3MgZSBleHRlbmRzIEVycm9ye2NvbnN0cnVjdG9yKHQscil7c3VwZXIociksdGhpcy5lcnJvcj10LHRoaXMuZXJyb3JfZGVzY3JpcHRpb249cixPYmplY3Quc2V0UHJvdG90eXBlT2YodGhpcyxlLnByb3RvdHlwZSl9c3Rh
1dGljIGZyb21QYXlsb2FkKHQpe2xldHtlcnJvcjpyLGVycm9yX2Rlc2NyaXB0aW9uOnN9PXQ7cmV0dXJuIG5ldyBlKHIscyl9fWNsYXNzIHQgZXh0ZW5kcyBle2NvbnN0cnVjdG9yKGUscyl7c3VwZXIoIm1pc3NpbmdfcmVmcmVzaF90b2tlbiIsIk1pc3NpbmcgUmVmcmVzaCBUb2tlbiAoYXVkaWVuY2U6ICciLmNvbmNhdChyKGUsWyJkZWZhdWx0Il0pLCInLCBzY29wZTogJyIpLmNvbmNhdChyKHMpLCInKSIpKSx0aGlzLmF1ZGllbmNlPWUsdGhpcy5zY29wZT1zLE9iamVjdC5zZXRQcm90b3R5cGVPZih0aGlzLHQucHJvdG90eXBlKX19ZnVuY3Rpb24gcihlKXtsZXQgdD1hcmd1bWVudHMubGVuZ3RoPjEmJnZvaWQgMCE9PWFyZ3VtZW50c1sxXT9hcmd1bWVudHNbMV06W107cmV0dXJuIGUmJiF0LmluY2x1ZGVzKGUpP2U6IiJ9ImZ1bmN0aW9uIj09dHlwZW9mIFN1cHByZXNzZWRFcnJvciYmU3VwcHJlc3NlZEVycm9yO2NvbnN0IHM9ZT0+e3ZhcntjbGllbnRJZDp0fT1lLHI9ZnVuY3Rpb24oZSx0KXt2YXIgcj17fTtmb3IodmFyIHMgaW4gZSlPYmplY3QucHJvdG90eXBlLmhhc093blByb3BlcnR5LmNhbGwoZSxzKSYmdC5pbmRleE9mKHMpPDAmJihyW3NdPWVbc10pO2lmKG51bGwhPWUmJiJmdW5jdGlvbiI9PXR5cGVvZiBPYmplY3QuZ2V0T3duUHJvcGVydHlTeW1ib2xzKXt2YXIgbz0wO2ZvcihzPU9iamVjdC5nZXRPd25Qcm9wZXJ0eVN5bWJvbHMoZSk7bzxzLmxlbmd0aDtvKyspdC5pbmRleE9mKHNbb10pPDAmJk9iamVjdC5wcm90b3R5cGUucHJvcGVydHlJc0VudW1lcmFibGUuY2FsbChlLHNbb10pJiYocltzW29dXT1lW3Nbb11dKX1yZXR1cm4gcn0oZSxbImNsaWVudElkIl0pO3JldHVybiBuZXcgVVJMU2VhcmNoUGFyYW1zKChlPT5PYmplY3Qua2V5cyhlKS5maWx0ZXIoKHQ9PnZvaWQgMCE9PWVbdF0pKS5yZWR1Y2UoKCh0LHIpPT5PYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30sdCkse1tyXTplW3JdfSkpLHt9KSkoT2JqZWN0LmFzc2lnbih7Y2xpZW50X2lkOnR9LHIpKSkudG9TdHJpbmcoKX07bGV0IG89e307Y29uc3Qgbj0oZSx0KT0+IiIuY29uY2F0KGUsInwiKS5jb25jYXQodCk7YWRkRXZlbnRMaXN0ZW5lcigibWVzc2FnZSIsKGFzeW5jIGU9PntsZXQgcixjLHtkYXRhOnt0aW1lb3V0OmksYXV0aDphLGZldGNoVXJsOmYsZmV0Y2hPcHRpb25zOmwsdXNlRm9ybURhdGE6cCx1c2VNcnJ0Omh9LHBvcnRzOlt1XX09ZSxkPXt9O2NvbnN0e2F1ZGllbmNlOmcsc2NvcGU6eX09YXx8e307dHJ5e2NvbnN0IGU9cD8oZT0+e2NvbnN0IHQ9bmV3IFVSTFNlYXJjaFBhcmFtcyhlKSxyPXt9O3JldHVybiB0LmZvckVhY2goKChlLHQpPT57clt0XT1lfSkpLHJ9KShsLmJvZHkpOkpTT04ucGFyc2UobC5ib2R5KTtpZighZS5yZWZyZXNoX3Rva2VuJiYicmVmcmVzaF90b2tlbiI9PT1lLmdyYW50X3R5cGUpe2lmKGM9KChlLHQpPT5vW24oZSx0KV0pKGcseSksIWMmJmgpe2NvbnN0IGU9by5sYXRlc3RfcmVmcmVzaF90b2tlbix0PSgoZSx0KT0+e2NvbnN0IHI9T2JqZWN0LmtleXMobykuZmluZCgocj0+e2lmKCJsYXRlc3RfcmVmcmVzaF90b2tlbiIhPT1yKXtjb25zdCBzPSgoZSx0KT0+dC5zdGFydHNXaXRoKCIiLmNvbmNhdChlLCJ8IikpKSh0LHIpLG89ci5zcGxpdCgifCIpWzFdLnNwbGl0KCIgIiksbj1lLnNwbGl0KCIgIikuZXZlcnkoKGU9Pm8uaW5jbHVkZXMoZSkpKTtyZXR1cm4gcyYmbn19KSk7cmV0dXJuISFyfSkoeSxnKTtlJiYhdCYmKGM9ZSl9aWYoIWMpdGhyb3cgbmV3IHQoZyx5KTtsLmJvZHk9cD9zKE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpjfSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpjfSkpfWxldCBhLGs7ImZ1bmN0aW9uIj09dHlwZW9mIEFib3J0Q29udHJvbGxlciYmKGE9bmV3IEFib3J0Q29udHJvbGxlcixsLnNpZ25hbD1hLnNpZ25hbCk7dHJ5e2s9YXdhaXQgUHJvbWlzZS5yYWNlKFsoaj1pLG5ldyBQcm9taXNlKChlPT5zZXRUaW1lb3V0KGUsaikpKSksZmV0Y2goZixPYmplY3QuYXNzaWduKHt9LGwpKV0pfWNhdGNoKGUpe3JldHVybiB2b2lkIHUucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZX0pfWlmKCFrKXJldHVybiBhJiZhLmFib3J0KCksdm9pZCB1LnBvc3RNZXNzYWdlKHtlcnJvcjoiVGltZW91dCB3aGVuIGV4ZWN1dGluZyAnZmV0Y2gnIn0pO189ay5oZWFkZXJzLGQ9Wy4uLl9dLnJlZHVjZSgoKGUsdCk9PntsZXRbcixzXT10O3JldHVybiBlW3JdPXMsZX0pLHt9KSxyPWF3YWl0IGsuanNvbigpLHIucmVmcmVzaF90b2tlbj8oaCYmKG8ubGF0ZXN0X3JlZnJlc2hfdG9rZW49ci5yZWZyZXNoX3Rva2VuLE89YyxiPXIucmVmcmVzaF90b2tlbixPYmplY3QuZW50cmllcyhvKS5mb3JFYWNoKChlPT57bGV0W3Qscl09ZTtyPT09TyYmKG9bdF09Yil9KSkpLCgoZSx0LHIpPT57b1tuKHQscildPWV9KShyLnJlZnJlc2hfdG9rZW4sZyx5KSxkZWxldGUgci5yZWZyZXNoX3Rva2VuKTooKGUsdCk9PntkZWxldGUgb1tuKGUsdCldfSkoZyx5KSx1LnBvc3RNZXNzYWdlKHtvazprLm9rLGpzb246cixoZWFkZXJzOmR9KX1jYXRjaChlKXt1LnBvc3RNZXNzYWdlKHtvazohMSxqc29uOntlcnJvcjplLmVycm9yLGVycm9yX2Rlc2NyaXB0aW9uOmUubWVzc2FnZX0saGVhZGVyczpkfSl9dmFyIE8sYixfLGp9KSl9KCk7Cgo="),n=t.indexOf("\n",10)+1,o=t.substring(n)+"",r=new Blob([o],{type:"application/javascript"}),URL.createObjectURL(r)),new Worker(be,e);var t,n,o,r};const ke={},Se=async function(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:3;for(let n=0;n<t;n++)if(await e())return!0;return!1};class Ee{constructor(e,t){this.cache=e,this.clientId=t,this.manifestKey=this.createManifestKeyFrom(this.clientId)}async add(e){var t;const n=new Set((null===(t=await this.cache.get(this.manifestKey))||void 0===t?void 0:t.keys)||[]);n.add(e),await this.cache.set(this.manifestKey,{keys:[...n]})}async remove(e){const t=await this.cache.get(this.manifestKey);if(t){const n=new Set(t.keys);return n.delete(e),n.size>0?await this.cache.set(this.manifestKey,{keys:[...n]}):await this.cache.remove(this.manifestKey)}}get(){return this.cache.get(this.manifestKey)}clear(){return this.cache.remove(this.manifestKey)}createManifestKeyFrom(e){return"".concat("@@auth0spajs@@","::").concat(e)}}const Te={memory:()=>(new ie).enclosedCache,localstorage:()=>new re},Ae=e=>Te[e],Pe=t=>{const{openUrl:n,onRedirect:o}=t,r=e(t,["openUrl","onRedirect"]);return Object.assign(Object.assign({},r),{openUrl:!1===n||n?n:o})},Re=(e,t)=>{const n=(null==t?void 0:t.split(" "))||[];return((null==e?void 0:e.split(" "))||[]).every(e=>n.includes(e))},Ie={NONCE:"nonce",KEYPAIR:"keypair"};class Oe{constructor(e){this.clientId=e}getVersion(){return 1}createDbHandle(){const e=window.indexedDB.open("auth0-spa-js",this.getVersion());return new Promise((t,n)=>{e.onupgradeneeded=()=>Object.values(Ie).forEach(t=>e.result.createObjectStore(t)),e.onerror=()=>n(e.error),e.onsuccess=()=>t(e.result)})}async getDbHandle(){return this.dbHandle||(this.dbHandle=await this.createDbHandle()),this.dbHandle}async executeDbRequest(e,t,n){const o=n((await this.getDbHandle()).transaction(e,t).objectStore(e));return new Promise((e,t)=>
1{o.onsuccess=()=>e(o.result),o.onerror=()=>t(o.error)})}buildKey(e){const t=e?"_".concat(e):"auth0";return"".concat(this.clientId,"::").concat(t)}setNonce(e,t){return this.save(Ie.NONCE,this.buildKey(t),e)}setKeyPair(e){return this.save(Ie.KEYPAIR,this.buildKey(),e)}async save(e,t,n){await this.executeDbRequest(e,"readwrite",e=>e.put(n,t))}findNonce(e){return this.find(Ie.NONCE,this.buildKey(e))}findKeyPair(){return this.find(Ie.KEYPAIR,this.buildKey())}find(e,t){return this.executeDbRequest(e,"readonly",e=>e.get(t))}async deleteBy(e,t){const n=await this.executeDbRequest(e,"readonly",e=>e.getAllKeys());null==n||n.filter(t).map(t=>this.executeDbRequest(e,"readwrite",e=>e.delete(t)))}deleteByClientId(e,t){return this.deleteBy(e,e=>"string"==typeof e&&e.startsWith("".concat(t,"::")))}clearNonces(){return this.deleteByClientId(Ie.NONCE,this.clientId)}clearKeyPairs(){return this.deleteByClientId(Ie.KEYPAIR,this.clientId)}}class xe{constructor(e){this.storage=new Oe(e)}getNonce(e){return this.storage.findNonce(e)}setNonce(e,t){return this.storage.setNonce(e,t)}async getOrGenerateKeyPair(){let e=await this.storage.findKeyPair();return e||(e=await async function(e,t){var n;let o;return o={name:"ECDSA",namedCurve:"P-256"},crypto.subtle.generateKey(o,null!==(n=null==t?void 0:t.extractable)&&void 0!==n&&n,["sign","verify"])}(0,{extractable:!1}),await this.storage.setKeyPair(e)),e}async generateProof(e){const t=await this.getOrGenerateKeyPair();return function(e){let{keyPair:t,url:n,method:o,nonce:r,accessToken:i}=e;return async function(e,t,n,o,r,i){const a=null==e?void 0:e.privateKey,s=null==e?void 0:e.publicKey;if(!Z(c=a)||"private"!==c.type)throw new TypeError('"keypair.privateKey" must be a private CryptoKey');var c;if(!q(s))throw new TypeError('"keypair.publicKey" must be a public CryptoKey');if(!0!==s.extractable)throw new TypeError('"keypair.publicKey.extractable" must be true');if("string"!=typeof t)throw new TypeError('"htu" must be a string');if("string"!=typeof n)throw new TypeError('"htm" must be a string');if(void 0!==o&&"string"!=typeof o)throw new TypeError('"nonce" must be a string or undefined');if(void 0!==r&&"string"!=typeof r)throw new TypeError('"accessToken" must be a string or undefined');return async function(e,t,n){if(!1===n.usages.includes("sign"))throw new TypeError('private CryptoKey instances used for signing assertions must include "sign" in their "usages"');const o=`${J(z(JSON.stringify(e)))}.${J(z(JSON.stringify(t)))}`;return`${o}.${J(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:"SHA-256"};case"RSA-PSS":return H(e.algorithm),{name:e.algorithm.name,saltLength:32};case"RSASSA-PKCS1-v1_5":return H(e.algorithm),{name:e.algorithm.name};case"Ed25519":return{name:e.algorithm.name}}throw new V}(n),n,z(o)))}`}({alg:G(a),typ:"dpop+jwt",jwk:await B(s)},Object.assign(Object.assign({},i),{iat:Math.floor(Date.now()/1e3),jti:crypto.randomUUID(),htm:n,nonce:o,htu:t,ath:r?J(await crypto.subtle.digest("SHA-256",z(r))):void 0}),a)}(t,function(e){const t=new URL(e);return t.search="",t.hash="",t.href}(n),o,r,i)}(Object.assign({keyPair:t},e))}async calculateThumbprint(){return function(e){return async function(e){if(!q(e))throw new TypeError('"publicKey" must be a public CryptoKey');if(!0!==e.extractable)throw new TypeError('"publicKey.extractable" must be true');const t=await B(e);let n;switch(t.kty){case"EC":n={crv:t.crv,kty:t.kty,x:t.x,y:t.y};break;case"OKP":n={crv:t.crv,kty:t.kty,x:t.x};break;case"RSA":n={e:t.e,kty:t.kty,n:t.n};break;default:throw new V("unsupported JWK kty")}return J(await crypto.subtle.digest({name:"SHA-256"},z(JSON.stringify(n))))}(e.publicKey)}(await this.getOrGenerateKeyPair())}async clear(){await Promise.all([this.storage.clearNonces(),this.storage.clearKeyPairs()])}}var Ce;!function(e){e.Bearer="Bearer",e.DPoP="DPoP"}(Ce||(Ce={}));class je{constructor(e,t){this.hooks=t,this.config=Object.assign(Object.assign({},e),{fetch:e.fetch||("undefined"==typeof window?fetch:window.fetch.bind(window))})}isAbsoluteUrl(e){return/^(https?:)?\/\//i.test(e)}buildUrl(e,t){if(t){if(this.isAbsoluteUrl(t))return t;if(e)return"".concat(e.replace(/\/?\/$/,""),"/").concat(t.replace(/^\/+/,""))}throw new TypeError("`url` must be absolute or `baseUrl` non-empty.")}getAccessToken(e){return this.config.getAccessToken?this.config.getAccessToken(e):this.hooks.getAccessToken(e)}extractUrl(e){return"string"==typeof e?e:e instanceof URL?e.href:e.url}
vendor: 3,383 bytes, line 1
1buildBaseRequest(e,t){if(!this.config.baseUrl)return new Request(e,t);const n=this.buildUrl(this.config.baseUrl,this.extractUrl(e)),o=e instanceof Request?new Request(n,e):n;return new Request(o,t)}setAuthorizationHeader(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:Ce.Bearer;e.headers.set("authorization","".concat(n," ").concat(t))}async setDpopProofHeader(e,t){if(!this.config.dpopNonceId)return;const n=await this.hooks.getDpopNonce(),o=await this.hooks.generateDpopProof({accessToken:t,method:e.method,nonce:n,url:e.url});e.headers.set("dpop",o)}async prepareRequest(e,t){const n=await this.getAccessToken(t);let o,r;"string"==typeof n?(o=this.config.dpopNonceId?Ce.DPoP:Ce.Bearer,r=n):(o=n.token_type,r=n.access_token),this.setAuthorizationHeader(e,r,o),o===Ce.DPoP&&await this.setDpopProofHeader(e,r)}getHeader(e,t){return Array.isArray(e)?new Headers(e).get(t)||"":"function"==typeof e.get?e.get(t)||"":e[t]||""}hasUseDpopNonceError(e){if(401!==e.status)return!1;const t=this.getHeader(e.headers,"www-authenticate");return t.includes("invalid_dpop_nonce")||t.includes("use_dpop_nonce")}async handleResponse(e,t){const n=this.getHeader(e.headers,"dpop-nonce");if(n&&await this.hooks.setDpopNonce(n),!this.hasUseDpopNonceError(e))return e;if(!n||!t.onUseDpopNonceError)throw new P(n);return t.onUseDpopNonceError()}async internalFetchWithAuth(e,t,n,o){const r=this.buildBaseRequest(e,t);await this.prepareRequest(r,o);const i=await this.config.fetch(r);return this.handleResponse(i,n)}fetchWithAuth(e,t,n){const o={onUseDpopNonceError:()=>this.internalFetchWithAuth(e,t,Object.assign(Object.assign({},o),{onUseDpopNonceError:void 0}),n)};return this.internalFetchWithAuth(e,t,o,n)}}class De{constructor(e,t){this.myAccountFetcher=e,this.apiBase=t}async connectAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/connect"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)});return this._handleResponse(t)}async completeAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/complete"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)});return this._handleResponse(t)}async _handleResponse(e){let t;try{t=await e.text(),t=JSON.parse(t)}catch(n){throw new Ke({type:"invalid_json",status:e.status,title:"Invalid JSON response",detail:t||String(n)})}if(e.ok)return t;throw new Ke(t)}}class Ke extends Error{constructor(e){let{type:t,status:n,title:o,detail:r,validation_errors:i}=e;super(r),this.name="MyAccountApiError",this.type=t,this.status=n,this.title=o,this.detail=r,this.validation_errors=i,Object.setPrototypeOf(this,Ke.prototype)}}const Le={otp:{authenticatorTypes:["otp"]},sms:{authenticatorTypes:["oob"],oobChannels:["sms"]},email:{authenticatorTypes:["oob"],oobChannels:["email"]},push:{authenticatorTypes:["oob"],oobChannels:["auth0"]},voice:{authenticatorTypes:["oob"],oobChannels:["voice"]}};function Ue(e,t){this.v=e,this.k=t}function Ne(e,t,n){if("function"==typeof e?e===t:e.has(t))return arguments.length<3?t:n;throw new TypeError("Private element is not present on this object")}function We(e){return new Ue(e,0)}function ze(e,t){if(t.has(e))throw new TypeError("Cannot initialize the same private elements twice on an object")}function He(e,t){return e.get(Ne(e,t))}
1function Me(e,t,n){ze(e,t),t.set(e,n)}function Je(e,t,n){return e.set(Ne(e,t),n),n}function Ve(e,t,n){return(t="symbol"==typeof(o=function(e){if("object"!=typeof e||!e)return e;var t=e[Symbol.toPrimitive];if(void 0!==t){var n=t.call(e,"string");if("object"!=typeof n)return n;throw new TypeError("@@toPrimitive must return a primitive value.")}return String(e)}(t))?o:o+"")in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e;var o}function Fe(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);t&&(o=o.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,o)}return n}function Ge(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?Fe(Object(n),!0).forEach(function(t){Ve(e,t,n[t])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):Fe(Object(n)).forEach(function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))})}return e}function Ze(e,t){if(null==e)return{};var n,o,r=function(e,t){if(null==e)return{};var n={};for(var o in e)if({}.hasOwnProperty.call(e,o)){if(-1!==t.indexOf(o))continue;n[o]=e[o]}return n}(e,t);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);for(o=0;o<i.length;o++)n=i[o],-1===t.indexOf(n)&&{}.propertyIsEnumerable.call(e,n)&&(r[n]=e[n])}return r}function qe(e){var t,n;function o(t,n){try{var i=e[t](n),a=i.value,s=a instanceof Ue;Promise.resolve(s?a.v:a).then(function(n){if(s){var c="return"===t?"return":"next";if(!a.k||n.done)return o(c,n);n=e[c](n).value}r(i.done?"return":"normal",n)},function(e){o("throw",e)})}catch(c){r("throw",c)}}function r(e,r){switch(e){case"return":t.resolve({value:r,done:!0});break;case"throw":t.reject(r);break;default:t.resolve({value:r,done:!1})}(t=t.next)?o(t.key,t.arg):n=null}this._invoke=function(e,r){return new Promise(function(i,a){var s={key:e,arg:r,resolve:i,reject:a,next:null};n?n=n.next=s:(t=n=s,o(e,r))})},"function"!=typeof e.return&&(this.return=void 0)}var Be,Xe;let Ye;if(qe.prototype["function"==typeof Symbol&&Symbol.asyncIterator||"@@asyncIterator"]=function(){return this},qe.prototype.next=function(e){return this._invoke("next",e)},qe.prototype.throw=function(e){return this._invoke("throw",e)},qe.prototype.return=function(e){return this._invoke("return",e)},"undefined"==typeof navigator||null===(Be=navigator.userAgent)||void 0===Be||null===(Xe=Be.startsWith)||void 0===Xe||!Xe.call(Be,"Mozilla/5.0 ")){const e="v3.8.3";Ye="".concat("oauth4webapi","/").concat(e)}function Qe(e,t){if(null==e)return!1;try{return e instanceof t||Object.getPrototypeOf(e)[Symbol.toStringTag]===t.prototype[Symbol.toStringTag]}catch(n){return!1}}function $e(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}const et=Symbol(),tt=Symbol(),nt=Symbol(),ot=Symbol(),rt=Symbol(),it=new TextEncoder,at=new TextDecoder;function st(e){return"string"==typeof e?it.encode(e):at.decode(e)}let ct,ut;if(Uint8Array.prototype.toBase64)ct=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;ct=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function lt(e){return"string"==typeof e?ut(e):ct(e)}ut=Uint8Array.fromBase64?e=>{try{return Uint8Array.fromBase64(e,{alphabet:"base64url"})}catch(t){throw $e("The input to be decoded is not correctly encoded.","ERR_INVALID_ARG_VALUE",t)}}:e=>{try{const t=atob(e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"")),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}catch(t){throw $e("The input to be decoded is not correctly encoded.","ERR_INVALID_ARG_VALUE",t)}};class dt extends Error{constructor(e,t){var n;super(e,t),Ve(this,"code",void 0),this.name=this.constructor.name,this.code=an,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}
vendor: 11,437 bytes, line 1
1class ht extends Error{constructor(e,t){var n;super(e,t),Ve(this,"code",void 0),this.name=this.constructor.name,null!=t&&t.code&&(this.code=null==t?void 0:t.code),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function pt(e,t,n){return new ht(e,{code:t,cause:n})}function ft(e){return null!==e&&"object"==typeof e&&!Array.isArray(e)}function mt(e){Qe(e,Headers)&&(e=Object.fromEntries(e.entries()));const t=new Headers(null!=e?e:{});if(Ye&&!t.has("user-agent")&&t.set("user-agent",Ye),t.has("authorization"))throw $e('"options.headers" must not include the "authorization" header name',"ERR_INVALID_ARG_VALUE");return t}function yt(e,t){if(void 0!==t){if("function"==typeof t&&(t=t(e.href)),!(t instanceof AbortSignal))throw $e('"options.signal" must return or be an instance of AbortSignal',"ERR_INVALID_ARG_TYPE");return t}}function wt(e){return e.includes("//")?e.replace("//","/"):e}function gt(e,t,n,o,r){try{if("number"!=typeof e||!Number.isFinite(e))throw $e("".concat(n," must be a number"),"ERR_INVALID_ARG_TYPE",r);if(e>0)return;if(t){if(0!==e)throw $e("".concat(n," must be a non-negative number"),"ERR_INVALID_ARG_VALUE",r);return}throw $e("".concat(n," must be a positive number"),"ERR_INVALID_ARG_VALUE",r)}catch(i){if(o)throw pt(i.message,o,r);throw i}}function vt(e,t,n,o){try{if("string"!=typeof e)throw $e("".concat(t," must be a string"),"ERR_INVALID_ARG_TYPE",o);if(0===e.length)throw $e("".concat(t," must not be empty"),"ERR_INVALID_ARG_VALUE",o)}catch(r){if(n)throw pt(r.message,n,o);throw r}}function bt(e){!function(e,t){if(Mt(e)!==t)throw function(e){let t='"response" content-type must be ';for(var n=arguments.length,o=new Array(n>1?n-1:0),r=1;r<n;r++)o[r-1]=arguments[r];if(o.length>2){const e=o.pop();t+="".concat(o.join(", "),", or ").concat(e)}else 2===o.length?t+="".concat(o[0]," or ").concat(o[1]):t+=o[0];return pt(t,ln,e)}(e,t)}(e,"application/json")}function _t(){return lt(crypto.getRandomValues(new Uint8Array(32)))}function kt(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"PS256";case"SHA-384":return"PS384";case"SHA-512":return"PS512";default:throw new dt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"RSASSA-PKCS1-v1_5":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"RS256";case"SHA-384":return"RS384";case"SHA-512":return"RS512";default:throw new dt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"ECDSA":return function(e){switch(e.algorithm.namedCurve){case"P-256":return"ES256";case"P-384":return"ES384";case"P-521":return"ES512";default:throw new dt("unsupported EcKeyAlgorithm namedCurve",{cause:e})}}(e);case"Ed25519":case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return e.algorithm.name;case"EdDSA":return"Ed25519";default:throw new dt("unsupported CryptoKey algorithm name",{cause:e})}}function St(e){const t=null==e?void 0:e[tt];return"number"==typeof t&&Number.isFinite(t)?t:0}function Et(e){const t=null==e?void 0:e[nt];return"number"==typeof t&&Number.isFinite(t)&&-1!==Math.sign(t)?t:30}function Tt(){return Math.floor(Date.now()/1e3)}function At(e){if("object"!=typeof e||null===e)throw $e('"as" must be an object',"ERR_INVALID_ARG_TYPE");vt(e.issuer,'"as.issuer"')}function Pt(e){if("object"!=typeof e||null===e)throw $e('"client" must be an object',"ERR_INVALID_ARG_TYPE");vt(e.client_id,'"client.client_id"')}function Rt(e){return vt(e,'"clientSecret"'),(t,n,o,r)=>{o.set("client_id",n.client_id),o.set("client_secret",e)}}const It=URL.parse?(e,t)=>URL.parse(e,t):(e,t)=>{try{return new URL(e,t)}catch(n){return null}};function Ot(e,t){if(t&&"https:"!==e.protocol)throw pt("only requests to HTTPS are allowed",hn,e);if("https:"!==e.protocol&&"http:"!==e.protocol)throw pt("only HTTP and HTTPS requests are allowed",pn,e)}function xt(e,t,n,o){let r;if("string"!=typeof e||!(r=It(e)))throw pt("authorization server metadata does not contain a valid ".concat(n?'"as.mtls_endpoint_aliases.'.concat(t,'"'):'"as.'.concat(t,'"')),void 0===e?wn:gn,{attribute:n?"mtls_endpoint_aliases.".concat(t):t});return Ot(r,o),r}function Ct(e,t,n,o){return n&&e.mtls_endpoint_aliases&&t in e.mtls_endpoint_aliases?xt(e.mtls_endpoint_aliases[t],t,n,o):xt(e[t],t,n,o)}class jt extends Error{constructor(e,t){var n;super(e,t),Ve(this,"cause",void 0),Ve(this,"code",void 0),Ve(this,"error",void 0),Ve(this,"status",void 0),Ve(this,"error_description",void 0),Ve(this,"response",void 0),this.name=this.constructor.name,this.code=rn,this.cause=t.cause,this.error=t.cause.error,this.status=t.response.status,this.error_description=t.cause.error_description,Object.defineProperty(this,"response",{enumerable:!1,value:t.response}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class Dt extends Error{constructor(e,t){var n,o;super(e,t),Ve(this,"cause",void 0),Ve(this,"code",void 0),Ve(this,"error",void 0),Ve(this,"error_description",void 0),this.name=this.constructor.name,this.code=sn,this.cause=t.cause,this.error=t.cause.get("error"),this.error_description=null!==(n=t.cause.get("error_description"))&&void 0!==n?n:void 0,null===(o=Error.captureStackTrace)||void 0===o||o.call(Error,this,this.constructor)}}class Kt extends Error{constructor(e,t){var n;super(e,t),Ve(this,"cause",void 0),Ve(this,"code",void 0),Ve(this,"response",void 0),Ve(this,"status",void 0),this.name=this.constructor.name,this.code=on,this.cause=t.cause,this.status=t.response.status,this.response=t.response,Object.defineProperty(this,"response",{enumerable:!1}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}const Lt=new RegExp("^[,\\s]*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+)"),Ut=new RegExp('^[,\\s]*([a-zA-Z0-9!#$%&\\\'\\*\\+\\-\\.\\^_`\\|~]+)\\s*=\\s*"((?:[^"\\\\]|\\\\[\\s\\S])*)"[,\\s]*(.*)'),Nt=new RegExp("^[,\\s]*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+)\\s*=\\s*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+)[,\\s]*(.*)"),Wt=new RegExp("^([a-zA-Z0-9\\-\\._\\~\\+\\/]+={0,2})(?:$|[,\\s])(.*)");async function zt(e,t,n){if(e.status!==t){let t;var o;if(function(e){let t;if(t=function(e){if(!Qe(e,Response))throw $e('"response" must be an instance of Response',"ERR_INVALID_ARG_TYPE");const t=e.headers.get("www-authenticate");if(null===t)return;const n=[];let o=t;for(;o;){var r;let e=o.match(Lt);const t=null===(r=e)||void 0===r?void 0:r[1].toLowerCase();if(!t)return;const a=o.substring(e[0].length);if(a&&!a.match(/^[\s,]/))return;const s=a.match(/^\s+(.*)$/),c=!!s;o=s?s[1]:void 0;const u={};let l;if(c)for(;o;){let t,n;if(e=o.match(Ut)){if([,t,n,o]=e,n.includes("\\"))try{n=JSON.parse('"'.concat(n,'"'))}catch(i){}u[t.toLowerCase()]=n}else{if(!(e=o.match(Nt))){if(e=o.match(Wt)){if(Object.keys(u).length)break;[,l,o]=e;break}return}[,t,n,o]=e,u[t.toLowerCase()]=n}}else o=a||void 0;const d={scheme:t,parameters:u};l&&(d.token68=l),n.push(d)}return n.length?n:void 0}(e))throw new Kt("server responded with a challenge in the WWW-Authenticate HTTP Header",{cause:t,response:e})}(e),t=await async function(e){if(e.status>399&&e.status<500){vn(e),bt(e);try{const t=await e.clone().json();if(ft(t)&&"string"==typeof t.error&&t.error.length)return t}catch(t){}}}(e))throw await(null===(o=e.body)||void 0===o?void 0:o.cancel()),new jt("server responded with an error in the response body",{cause:t,response:e});throw pt('"response" is not a conform '.concat(n," response (unexpected HTTP status code)"),dn,e)}}function Ht(e){if(!Yt.has(e))throw $e('"options.DPoP" is not a valid DPoPHandle',"ERR_INVALID_ARG_VALUE")}function Mt(e){var t;return null===(t=e.headers.get("content-type"))||void 0===t?void 0:t.split(";")[0]}async function Jt(e,t,n,o,r,i,a){return await n(e,t,r,i),i.set("content-type","application/x-www-form-urlencoded;charset=UTF-8"),((null==a?void 0:a[ot])||fetch)(o.href,{body:r,headers:Object.fromEntries(i.entries()),method:"POST",redirect:"manual",signal:yt(o,null==a?void 0:a.signal)})}async function Vt(e,t,n,o,r,i){var a;const s=Ct(e,"token_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[et]));r.set("grant_type",o);const c=mt(null==i?void 0:i.headers);c.set("accept","application/json"),void 0!==(null==i?void 0:i.DPoP)&&(Ht(i.DPoP),await i.DPoP.addProof(s,c,"POST"));const u=await Jt(e,t,n,s,r,c,i);return null==i||null===(a=i.DPoP)||void 0===a||a.cacheNonce(u,s),u}const Ft=new WeakMap,Gt=new WeakMap;function Zt(e){if(!e.id_token)return;const t=Ft.get(e);if(!t)throw $e('"ref" was already garbage collected or did not resolve from the proper sources',"ERR_INVALID_ARG_VALUE");return t}async function qt(e,t,n,o,r,i){if(At(e),Pt(t),!Qe(n,Response))throw $e('"response" must be an instance of Response',"ERR_INVALID_ARG_TYPE");await zt(n,200,"Token Endpoint"),vn(n);const a=await An(n);if(vt(a.access_token,'"response" body "access_token" property',un,{body:a}),vt(a.token_type,'"response" body "token_type" property',un,{body:a}),a.token_type=a.token_type.toLowerCase(),void 0!==a.expires_in){let e="number"!=typeof a.expires_in?parseFloat(a.expires_in):a.expires_in;gt(e,!0,'"response" body "expires_in" property',un,{body:a}),a.expires_in=e}if(void 0!==a.refresh_token&&vt(a.refresh_token,'"response" body "refresh_token" property',un,{body:a}),void 0!==a.scope&&"string"!=typeof a.scope)throw pt('"response" body "scope" property must be a string',un,{body:a});if(void 0!==a.id_token){vt(a.id_token,'"response" body "id_token" property',un,{body:a});const i=["aud","exp","iat","iss","sub"];!0===t.require_auth_time&&i.push("auth_time"),void 0!==t.default_max_age&&(gt(t.default_max_age,!0,'"client.default_max_age"'),i.push("auth_time")),null!=o&&o.length&&i.push(...o);const{claims:s,jwt:c}=await async function(e,t,n,o,r){let i,a,{0:s,1:c,length:u}=e.split(".");if(5===u){if(void 0===r)throw new dt("JWE decryption is not configured",{cause:e});e=await r(e),({0:s,1:c,length:u}=e.split("."))}if(3!==u)throw pt("Invalid JWT",un,e);try{i=JSON.parse(st(lt(s)))}catch(d){throw pt("failed to parse JWT Header body as base64url encoded JSON",cn,d)}if(!ft(i))throw pt("JWT Header must be a top level object",un,e);if(t(i),void 0!==i.crit)throw new dt('no JWT "crit" header parameter extensions are supported',{cause:{header:i}});try{a=JSON.parse(st(lt(c)))}catch(d){throw pt("failed to parse JWT Payload body as base64url encoded JSON",cn,d)}if(!ft(a))throw pt("JWT Payload must be a top level object",un,e);const l=Tt()+n;if(void 0!==a.exp){if("number"!=typeof a.exp)throw pt('unexpected JWT "exp" (expiration time) claim type',un,{claims:a});if(a.exp<=l-o)throw pt('unexpected JWT "exp" (expiration time) claim value, expiration is past current timestamp',fn,{claims:a,now:l,tolerance:o,claim:"exp"})}if(void 0!==a.iat&&"number"!=typeof a.iat)throw pt('unexpected JWT "iat" (issued at) claim type',un,{claims:a});if(void 0!==a.iss&&"string"!=typeof a.iss)throw pt('unexpected JWT "iss" (issuer) claim type',un,{claims:a});if(void 0!==a.nbf){if("number"!=typeof a.nbf)throw pt('unexpected JWT "nbf" (not before) claim type',un,{claims:a});if(a.nbf>l+o)throw pt('unexpected JWT "nbf" (not before) claim value',fn,{claims:a,now:l,tolerance:o,claim:"nbf"})}if(void 0!==a.aud&&"string"!=typeof a.aud&&!Array.isArray(a.aud))throw pt('unexpected JWT "aud" (audience) claim type',un,{claims:a});return{header:i,claims:a,jwt:e}}(a.id_token,kn.bind(void 0,t.id_token_signed_response_alg,e.id_token_signing_alg_values_supported,"RS256"),St
1(t),Et(t),r).then(en.bind(void 0,i)).then(Xt.bind(void 0,e)).then(Bt.bind(void 0,t.client_id));if(Array.isArray(s.aud)&&1!==s.aud.length){if(void 0===s.azp)throw pt('ID Token "aud" (audience) claim includes additional untrusted audiences',mn,{claims:s,claim:"aud"});if(s.azp!==t.client_id)throw pt('unexpected ID Token "azp" (authorized party) claim value',mn,{expected:t.client_id,claims:s,claim:"azp"})}void 0!==s.auth_time&&gt(s.auth_time,!0,'ID Token "auth_time" (authentication time)',un,{claims:s}),Gt.set(n,c),Ft.set(a,s)}if(void 0!==(null==i?void 0:i[a.token_type]))i[a.token_type](n,a);else if("dpop"!==a.token_type&&"bearer"!==a.token_type)throw new dt("unsupported `token_type` value",{cause:{body:a}});return a}function Bt(e,t){if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e))throw pt('unexpected JWT "aud" (audience) claim value',mn,{expected:e,claims:t.claims,claim:"aud"})}else if(t.claims.aud!==e)throw pt('unexpected JWT "aud" (audience) claim value',mn,{expected:e,claims:t.claims,claim:"aud"});return t}function Xt(e,t){var n,o;const r=null!==(n=null===(o=e[Rn])||void 0===o?void 0:o.call(e,t))&&void 0!==n?n:e.issuer;if(t.claims.iss!==r)throw pt('unexpected JWT "iss" (issuer) claim value',mn,{expected:r,claims:t.claims,claim:"iss"});return t}const Yt=new WeakSet,Qt=Symbol(),$t={aud:"audience",c_hash:"code hash",client_id:"client id",exp:"expiration time",iat:"issued at",iss:"issuer",jti:"jwt id",nonce:"nonce",s_hash:"state hash",sub:"subject",ath:"access token hash",htm:"http method",htu:"http uri",cnf:"confirmation",auth_time:"authentication time"};function en(e,t){for(const n of e)if(void 0===t.claims[n])throw pt('JWT "'.concat(n,'" (').concat($t[n],") claim missing"),un,{claims:t.claims});return t}const tn=Symbol(),nn=Symbol(),on="OAUTH_WWW_AUTHENTICATE_CHALLENGE",rn="OAUTH_RESPONSE_BODY_ERROR",an="OAUTH_UNSUPPORTED_OPERATION",sn="OAUTH_AUTHORIZATION_RESPONSE_ERROR",cn="OAUTH_PARSE_ERROR",un="OAUTH_INVALID_RESPONSE",ln="OAUTH_RESPONSE_IS_NOT_JSON",dn="OAUTH_RESPONSE_IS_NOT_CONFORM",hn="OAUTH_HTTP_REQUEST_FORBIDDEN",pn="OAUTH_REQUEST_PROTOCOL_FORBIDDEN",fn="OAUTH_JWT_TIMESTAMP_CHECK_FAILED",mn="OAUTH_JWT_CLAIM_COMPARISON_FAILED",yn="OAUTH_JSON_ATTRIBUTE_COMPARISON_FAILED",wn="OAUTH_MISSING_SERVER_METADATA",gn="OAUTH_INVALID_SERVER_METADATA";function vn(e){if(e.bodyUsed)throw $e('"response" body has been used already',"ERR_INVALID_ARG_VALUE")}function bn(e){const{algorithm:t}=e;if("number"!=typeof t.modulusLength||t.modulusLength<2048)throw new dt("unsupported ".concat(t.name," modulusLength"),{cause:e})}function _n(e){const{algorithm:t}=e;switch(t.namedCurve){case"P-256":return"SHA-256";case"P-384":return"SHA-384";case"P-521":return"SHA-512";default:throw new dt("unsupported ECDSA namedCurve",{cause:e})}}function kn(e,t,n,o){if(void 0===e)if(Array.isArray(t)){if(!t.includes(o.alg))throw pt('unexpected JWT "alg" header parameter',un,{header:o,expected:t,reason:"authorization server metadata"})}else{if(void 0===n)throw pt('missing client or server configuration to verify used JWT "alg" header parameter',void 0,{client:e,issuer:t,fallback:n});if("string"==typeof n?o.alg!==n:"function"==typeof n?!n(o.alg):!n.includes(o.alg))throw pt('unexpected JWT "alg" header parameter',un,{header:o,expected:n,reason:"default value"})}else if("string"==typeof e?o.alg!==e:!e.includes(o.alg))throw pt('unexpected JWT "alg" header parameter',un,{header:o,expected:e,reason:"client configuration"})}function Sn(e,t){const{0:n,length:o}=e.getAll(t);if(o>1)throw pt('"'.concat(t,'" parameter must be provided only once'),un);return n}const En=Symbol(),Tn=Symbol();async function An(e){let t,n=arguments.length>1&&void 0!==arguments[1]?arguments[1]:bt;try{t=await e.json()}catch(o){throw n(e),pt('failed to parse "response" body as JSON',cn,o)}if(!ft(t))throw pt('"response" body must be a top level object',un,{body:t});return t}const Pn=Symbol(),Rn=Symbol(),In=new TextEncoder,On=new TextDecoder;function xn(e){const t=new Uint8Array(e.length);for(let n=0;n<e.length;n++){const o=e.charCodeAt(n);if(o>127)throw new TypeError("non-ASCII string encountered in encode()");t[n]=o}return t}function Cn(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);const t=atob(e),n=new Uint8Array(t.length);for(let o=0;o<t.length;o++)n[o]=t.charCodeAt(o);return n}function jn(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64("string"==typeof e?e:On.decode(e),{alphabet:"base64url"});let t=e;t instanceof Uint8Array&&(t=On.decode(t)),t=t.replace(/-/g,"+").replace(/_/g,"/");try{return Cn(t)}catch(n){throw new TypeError("The input to be decoded is not correctly encoded.")}}
1class Dn extends Error{constructor(e,t){var n;super(e,t),Ve(this,"code","ERR_JOSE_GENERIC"),this.name=this.constructor.name,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}Ve(Dn,"code","ERR_JOSE_GENERIC");class Kn extends Dn{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),Ve(this,"code","ERR_JWT_CLAIM_VALIDATION_FAILED"),Ve(this,"claim",void 0),Ve(this,"reason",void 0),Ve(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}Ve(Kn,"code","ERR_JWT_CLAIM_VALIDATION_FAILED");class Ln extends Dn{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),Ve(this,"code","ERR_JWT_EXPIRED"),Ve(this,"claim",void 0),Ve(this,"reason",void 0),Ve(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}Ve(Ln,"code","ERR_JWT_EXPIRED");class Un extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JOSE_ALG_NOT_ALLOWED")}}Ve(Un,"code","ERR_JOSE_ALG_NOT_ALLOWED");class Nn extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JOSE_NOT_SUPPORTED")}}Ve(Nn,"code","ERR_JOSE_NOT_SUPPORTED"),Ve(class extends Dn{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"decryption operation failed",arguments.length>1?arguments[1]:void 0),Ve(this,"code","ERR_JWE_DECRYPTION_FAILED")}},"code","ERR_JWE_DECRYPTION_FAILED"),Ve(class extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JWE_INVALID")}},"code","ERR_JWE_INVALID");class Wn extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JWS_INVALID")}}Ve(Wn,"code","ERR_JWS_INVALID");class zn extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JWT_INVALID")}}Ve(zn,"code","ERR_JWT_INVALID"),Ve(class extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JWK_INVALID")}},"code","ERR_JWK_INVALID");class Hn extends Dn{constructor(){super(...arguments),Ve(this,"code","ERR_JWKS_INVALID")}}Ve(Hn,"code","ERR_JWKS_INVALID");class Mn extends Dn{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"no applicable key found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),Ve(this,"code","ERR_JWKS_NO_MATCHING_KEY")}}Ve(Mn,"code","ERR_JWKS_NO_MATCHING_KEY");class Jn extends Dn{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"multiple matching keys found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),Ve(this,Symbol.asyncIterator,void 0),Ve(this,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS")}}Ve(Jn,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS");class Vn extends Dn{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"request timed out",arguments.length>1?arguments[1]:void 0),Ve(this,"code","ERR_JWKS_TIMEOUT")}}Ve(Vn,"code","ERR_JWKS_TIMEOUT");class Fn extends Dn{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"signature verification failed",arguments.length>1?arguments[1]:void 0),Ve(this,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED")}}Ve(Fn,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED");const Gn=function(e){return new TypeError("CryptoKey does not support this operation, its ".concat(arguments.length>1&&void 0!==arguments[1]?arguments[1]:"algorithm.name"," must be ").concat(e))},Zn=(e,t)=>e.name===t;function qn(e){return parseInt(e.name.slice(4),10)}function Bn(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),r=2;r<n;r++)o[r-2]=arguments[r];if((o=o.filter(Boolean)).length>2){const t=o.pop();e+="one of type ".concat(o.join(", "),", or ").concat(t,".")}else 2===o.length?e+="one of type ".concat(o[0]," or ").concat(o[1],"."):e+="of type ".concat(o[0],".");if(null==t)e+=" Received ".concat(t);else if("function"==typeof t&&t.name)e+=" Received function ".concat(t.name);else if("object"==typeof t&&null!=t){var i;null!==(i=t.constructor)&&void 0!==i&&i.name&&(e+=" Received an instance of ".concat(t.constructor.name))}return e}const Xn=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),r=2;r<n;r++)o[r-2]=arguments[r];return Bn("Key for the ".concat(e," algorithm must be "),t,...o)},Yn=e=>{if("CryptoKey"===(null==e?void 0:e[Symbol.toStringTag]))return!0;try{return e instanceof CryptoKey}catch(t){return!1}},Qn=e=>"KeyObject"===(null==e?void 0:e[Symbol.toStringTag]),$n=e=>Yn(e)||Qn(e);function eo(e){if("object"!=typeof(t=e)||null===t||"[object Object]"!==Object.prototype.toString.call(e))return!1;var t;if(null===Object.getPrototypeOf(e))return!0;let n=e;for(;null!==Object.getPrototypeOf(n);)n=Object.getPrototypeOf(n);return Object.getPrototypeOf(e)===n}const to=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let n=0;n<e.byteLength;n++)if(e[n]!==t[n])return!1;return!0},no=e=>{const t=e.data[e.pos++];if(128&t){const n=127&t;let o=0;for(let t=0;t<n;t++)o=o<<8|e.data[e.pos++];return o}return t},oo=(e,t,n)=>{if(e.data[e.pos++]!==t)throw new Error(n)},ro=(e,t)=>{const n=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,n};async function io(e){var t,n;if(!e.alg)throw new TypeError('"alg" argument is required when "jwk.alg" is not present');const{algorithm:o,keyUsages:r}=function(e){let t,n;switch(e.kty){case"AKP":switch(e.alg){case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":t={name:e.alg},n=e.priv?["sign"]:["verify"];break;default:throw new Nn('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"RSA":switch(e.alg){case"PS256":case"PS384":case"PS512":t={name:"RSA-PSS",hash:"SHA-".concat(e.alg.slice(-3))},n=e.d?["sign"]:["verify"];break;case"RS256":case"RS384":case"RS512":t={name:"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(e.alg.slice(-3))},n=e.d?["sign"]:["verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":t={name:"RSA-OAEP",hash:"SHA-".concat(parseInt(e.alg.slice(-3),10)||1)},n=e.d?["decrypt","unwrapKey"]:["encrypt","wrapKey"];break;default:throw new Nn('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"EC":switch(e.alg){case"ES256":t={name:"ECDSA",namedCurve:"P-256"},n=e.d?["sign"]:["verify"];break;case"ES384":t={name:"ECDSA",namedCurve:"P-384"},n=e.d?["sign"]:["verify"];break;case"ES512":t={name:"ECDSA",namedCurve:"P-521"},n=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:"ECDH",namedCurve:e.crv},n=e.d?["deriveBits"]:[];break;default:throw new Nn('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;
1case"OKP":switch(e.alg){case"Ed25519":case"EdDSA":t={name:"Ed25519"},n=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:e.crv},n=e.d?["deriveBits"]:[];break;default:throw new Nn('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;default:throw new Nn('Invalid or unsupported JWK "kty" (Key Type) Parameter value')}return{algorithm:t,keyUsages:n}}(e),i=Ge({},e);return"AKP"!==i.kty&&delete i.alg,delete i.use,crypto.subtle.importKey("jwk",i,o,null!==(t=e.ext)&&void 0!==t?t:!e.d&&!e.priv,null!==(n=e.key_ops)&&void 0!==n?n:r)}const ao=e=>eo(e)&&"string"==typeof e.kty;let so;const co=async function(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]&&arguments[3];so||(so=new WeakMap);let r=so.get(e);if(null!=r&&r[n])return r[n];const i=await io(Ge(Ge({},t),{},{alg:n}));return o&&Object.freeze(e),r?r[n]=i:so.set(e,{[n]:i}),i},uo=e=>null==e?void 0:e[Symbol.toStringTag],lo=(e,t,n)=>{if(void 0!==t.use){let e;switch(n){case"sign":case"verify":e="sig";break;case"encrypt":case"decrypt":e="enc"}if(t.use!==e)throw new TypeError('Invalid key for this operation, its "use" must be "'.concat(e,'" when present'))}if(void 0!==t.alg&&t.alg!==e)throw new TypeError('Invalid key for this operation, its "alg" must be "'.concat(e,'" when present'));if(Array.isArray(t.key_ops)){var o,r;let i;switch(!0){case"verify"===n:case"dir"===e:case e.includes("CBC-HS"):i=n;break;case e.startsWith("PBES2"):i="deriveBits";break;case/^A\d{3}(?:GCM)?(?:KW)?$/.test(e):i=!e.includes("GCM")&&e.endsWith("KW")?"unwrapKey":n;break;case"encrypt"===n:i="wrapKey";break;case"decrypt"===n:i=e.startsWith("RSA")?"unwrapKey":"deriveBits"}if(i&&!1===(null===(o=t.key_ops)||void 0===o||null===(r=o.includes)||void 0===r?void 0:r.call(o,i)))throw new TypeError('Invalid key for this operation, its "key_ops" must include "'.concat(i,'" when present'))}return!0};var ho,po;let fo,mo;if("undefined"==typeof navigator||null===(ho=navigator.userAgent)||void 0===ho||null===(po=ho.startsWith)||void 0===po||!po.call(ho,"Mozilla/5.0 ")){const e="v6.8.1";mo="".concat("openid-client","/").concat(e),fo={"user-agent":mo}}const yo=e=>wo.get(e);let wo,go;function vo(e){return void 0!==e?Rt(e):(go||(go=new WeakMap),(e,t,n,o)=>{let r;return(r=go.get(t))||(function(e,t){if("string"!=typeof e)throw So("".concat(t," must be a string"),ko);if(0===e.length)throw So("".concat(t," must not be empty"),_o)}(t.client_secret,'"metadata.client_secret"'),r=Rt(t.client_secret),go.set(t,r)),r(e,t,n,o)})}const bo=ot,_o="ERR_INVALID_ARG_VALUE",ko="ERR_INVALID_ARG_TYPE";function So(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}class Eo extends Error{constructor(e,t){var n;super(e,t),Ve(this,"code",void 0),this.name=this.constructor.name,this.code=null==t?void 0:t.code,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function To(e,t,n){return new Eo(e,{cause:t,code:n})}function Ao(e){if(e instanceof TypeError||e instanceof Eo||e instanceof jt||e instanceof Dt||e instanceof Kt)throw e;if(e instanceof ht)switch(e.code){case hn:throw To("only requests to HTTPS are allowed",e,e.code);case pn:throw To("only requests to HTTP or HTTPS are allowed",e,e.code);case dn:throw To("unexpected HTTP response status code",e.cause,e.code);case ln:throw To("unexpected response content-type",e.cause,e.code);case cn:throw To("parsing error occured",e,e.code);case un:throw To("invalid response encountered",e,e.code);case mn:throw To("unexpected JWT claim value encountered",e,e.code);case yn:throw To("unexpected JSON attribute value encountered",e,e.code);case fn:throw To("JWT timestamp claim value failed validation",e,e.code);default:throw To(e.message,e,e.code)}if(e instanceof dt)throw To("unsupported operation",e,e.code);if(e instanceof DOMException)switch(e.name){case"OperationError":throw To("runtime operation error",e,an);case"NotSupportedError":throw To("runtime unsupported operation",e,an);case"TimeoutError":throw To("operation timed out",e,"OAUTH_TIMEOUT");case"AbortError":throw To("operation aborted",e,"OAUTH_ABORT")}throw new Eo("something went wrong",{cause:e})}new TextDecoder;const Po=Symbol();class Ro{constructor(e,t,n,o){var r,i,a,s,c;if("string"!=typeof t||!t.length)throw So('"clientId" must be a non-empty string',ko);if("string"==typeof n&&(n={client_secret:n}),void 0!==(null===(r=n)||void 0===r?void 0:r.client_id)&&t!==n.client_id)throw So('"clientId" and "metadata.client_id" must be the same',_o);const u=Ge(Ge({},structuredClone(n)),{},{client_id:t});let l;u[tt]=null!==(i=null===(a=n)||void 0===a?void 0:a[tt])&&void 0!==i?i:0,u[nt]=null!==(s=null===(c=n)||void 0===c?void 0:c[nt])&&void 0!==s?s:30,l=o||("string"==typeof u.client_secret&&u.client_secret.length?vo(u.client_secret):(e,t,n,o)=>{n.set("client_id",t.client_id)});let d=Object.freeze(u);const h=structuredClone(e);Po in e&&(h[Rn]=t=>{let{claims:{tid:n}}=t;return e.issuer.replace("{tenantid}",n)});let p=Object.freeze(h);wo||(wo=new WeakMap),wo.set(this,{__proto__:null,as:p,c:d,auth:l,tlsOnly:!0,jwksCache:{}})}serverMetadata(){const e=structuredClone(yo(this).as);return t=e,Object.defineProperties(t,function(e){return{supportsPKCE:{__proto__:null,value(){var t;let n=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"S256";return!0===(null===(t=e.code_challenge_methods_supported)||void 0===t?void 0:t.includes(n))}}}}(t)),e;var t}clientMetadata(){return structuredClone(yo(this).c)}get timeout(){return yo(this).timeout}set timeout(e){yo(this).timeout=e}get[bo](){return yo(this).fetch}set[bo](e){yo(this).fetch=e}}function Io(e){Object.defineProperties(e,function(e){let t;if(void 0!==e.expires_in){const n=new Date;n.setSeconds(n.getSeconds()+e.expires_in),t=n.getTime()}
1return{expiresIn:{__proto__:null,value(){if(t){const e=Date.now();return t>e?Math.floor((t-e)/1e3):0}}},claims:{__proto__:null,value(){try{return Zt(this)}catch(e){return}}}}}(e))}async function Oo(e,t,n){var o;let r=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const i=null===(o=e.headers.get("retry-after"))||void 0===o?void 0:o.trim();if(void 0===i)return;let a;if(/^\d+$/.test(i))a=parseInt(i,10);else{const e=new Date(i);if(Number.isFinite(e.getTime())){const t=new Date,n=e.getTime()-t.getTime();n>0&&(a=Math.ceil(n/1e3))}}if(r&&!Number.isFinite(a))throw new ht("invalid Retry-After header value",{cause:e});a>t&&await xo(a-t,n)}function xo(e,t){return new Promise((n,o)=>{const r=e=>{try{t.throwIfAborted()}catch(a){return void o(a)}if(e<=0)return void n();const i=Math.min(e,5);setTimeout(()=>r(e-i),1e3*i)};r(e)})}async function Co(e,t){zo(e);const{as:n,c:o,auth:r,fetch:i,tlsOnly:a,timeout:s}=yo(e);return async function(e,t,n,o,r){At(e),Pt(t);const i=Ct(e,"backchannel_authentication_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==r?void 0:r[et])),a=new URLSearchParams(o);a.set("client_id",t.client_id);const s=mt(null==r?void 0:r.headers);return s.set("accept","application/json"),Jt(e,t,n,i,a,s,r)}(n,o,r,t,{[ot]:i,[et]:!a,headers:new Headers(fo),signal:Ho(s)}).then(e=>async function(e,t,n){if(At(e),Pt(t),!Qe(n,Response))throw $e('"response" must be an instance of Response',"ERR_INVALID_ARG_TYPE");await zt(n,200,"Backchannel Authentication Endpoint"),vn(n);const o=await An(n);vt(o.auth_req_id,'"response" body "auth_req_id" property',un,{body:o});let r="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return gt(r,!0,'"response" body "expires_in" property',un,{body:o}),o.expires_in=r,void 0!==o.interval&&gt(o.interval,!1,'"response" body "interval" property',un,{body:o}),o}(n,o,e)).catch(Ao)}async function jo(e,t,n,o){var r,i;zo(e),n=new URLSearchParams(n);let a=null!==(r=t.interval)&&void 0!==r?r:5;const s=null!==(i=null==o?void 0:o.signal)&&void 0!==i?i:AbortSignal.timeout(1e3*t.expires_in);try{await xo(a,s)}catch(_){Ao(_)}const{as:c,c:u,auth:l,fetch:d,tlsOnly:h,nonRepudiation:p,timeout:f,decrypt:m}=yo(e),y=(r,i)=>jo(e,Ge(Ge({},t),{},{interval:r}),n,Ge(Ge({},o),{},{signal:s,flag:i})),w=await async function(e,t,n,o,r){At(e),Pt(t),vt(o,'"authReqId"');const i=new URLSearchParams(null==r?void 0:r.additionalParameters);return i.set("auth_req_id",o),Vt(e,t,n,"urn:openid:params:grant-type:ciba",i,r)}(c,u,l,t.auth_req_id,{[ot]:d,[et]:!h,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(fo),signal:s.aborted?s:Ho(f)}).catch(Ao);var g;if(503===w.status&&w.headers.has("retry-after"))return await Oo(w,a,s,!0),await(null===(g=w.body)||void 0===g?void 0:g.cancel()),y(a);const v=async function(e,t,n,o){return qt(e,t,n,void 0,null==o?void 0:o[rt],null==o?void 0:o.recognizedTokenTypes)}(c,u,w,{[rt]:m});let b;try{b=await v}catch(_){if(Mo(_,o))return y(a,Jo);if(_ instanceof jt)switch(_.error){case"slow_down":a+=5;case"authorization_pending":return await Oo(_.response,a,s),y(a)}Ao(_)}return b.id_token&&await(null==p?void 0:p(w)),Io(b),b}function Do(e){yo(e).tlsOnly=!1}async function Ko(e,t,n,o,r){if(zo(e),!((null==r?void 0:r.flag)===Jo||t instanceof URL||function(e){try{return"Request"===Object.getPrototypeOf(e)[Symbol.toStringTag]}catch(t){return!1}}(t)))throw So('"currentUrl" must be an instance of URL, or Request',ko);let i,a;const{as:s,c:c,auth:u,fetch:l,tlsOnly:d,jarm:h,hybrid:p,nonRepudiation:f,timeout:m,decrypt:y,implicit:w}=yo(e);if((null==r?void 0:r.flag)===Jo)i=r.authResponse,a=r.redirectUri;else{if(!(t instanceof URL)){const e=t;switch(t=new URL(t.url),e.method){case"GET":break;case"POST":const n=new URLSearchParams(await async function(e){if("POST"!==e.method)throw $e("form_post responses are expected to use the POST method","ERR_INVALID_ARG_VALUE",{cause:e});if("application/x-www-form-urlencoded"!==Mt(e))throw $e("form_post responses are expected to use the application/x-www-form-urlencoded content-type","ERR_INVALID_ARG_VALUE",{cause:e});return async function(e){if(e.bodyUsed)throw $e("form_post Request instances must contain a readable body","ERR_INVALID_ARG_VALUE",{cause:e});return e.text()}(e)}(e));if(p)t.hash=n.toString();else for(const[e,o]of n.entries())t.searchParams.append(e,o);break;default:throw So("unexpected Request HTTP method",_o)}}switch(g=t,(g=new URL(g)).search="",g.hash="",a=g.href,!0){case!!h:i=await h(t,null==n?void 0:n.expectedState);break;case!!p:i=await p(t,null==n?void 0:n.expectedNonce,null==n?void 0:n.expectedState,null==n?void 0:n.maxAge);break;case!!w:throw new TypeError("authorizationCodeGrant() cannot be used by response_type=id_token clients");default:try{i=function(e,t,n,o){if(At(e),Pt(t),n instanceof URL&&(n=n.searchParams),!(n instanceof URLSearchParams))throw $e('"parameters" must be an instance of URLSearchParams, or URL',"ERR_INVALID_ARG_TYPE");if(Sn(n,"response"))throw pt('"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()',un,{parameters:n});const r=Sn(n,"iss"),i=Sn(n,"state");if(!r&&e.authorization_response_iss_parameter_supported)throw pt('response parameter "iss" (issuer) missing',un,{parameters:n});if(r&&r!==e.issuer)throw pt('unexpected "iss" (issuer) response parameter value',un,{expected:e.issuer,parameters:n});switch(o){case void 0:case Tn:if(void 0!==i)throw pt('unexpected "state" response parameter encountered',un,{expected:void 0,parameters:n});break;case En:break;default:if(vt(o,'"expectedState" argument'),i!==o)throw pt(void 0===i?'response parameter "state" missing':'unexpected "state" response parameter value',un,{expected:o,parameters:n})}if(Sn(n,"error"))throw new Dt("authorization response from the server is an error",{cause:n});const a=Sn(n,"id_token"),s=Sn(n,"token");if(void 0!==a||void 0!==s)throw new dt("implicit and hybrid flows are not supported");return c=new URLSearchParams(n),Yt.add(c),c;var c}(s,c,t.searchParams,null==n?void 0:n.expectedState)}catch(g){Ao(g)}}}var g;const v=await async function(e,t,n,o,r,i,a){if(At(e),Pt(t),!Yt.has(o))throw $e('"callbackParameters" must be an instance of URLSearchParams obtained from "validateAuthResponse()", or "validateJwtAuthResponse()',"E
1RR_INVALID_ARG_VALUE");vt(r,'"redirectUri"');const s=Sn(o,"code");if(!s)throw pt('no authorization code in "callbackParameters"',un);const c=new URLSearchParams(null==a?void 0:a.additionalParameters);return c.set("redirect_uri",r),c.set("code",s),i!==Qt&&(vt(i,'"codeVerifier"'),c.set("code_verifier",i)),Vt(e,t,n,"authorization_code",c,a)}(s,c,u,i,a,(null==n?void 0:n.pkceCodeVerifier)||Qt,{additionalParameters:o,[ot]:l,[et]:!d,DPoP:null==r?void 0:r.DPoP,headers:new Headers(fo),signal:Ho(m)}).catch(Ao);"string"!=typeof(null==n?void 0:n.expectedNonce)&&"number"!=typeof(null==n?void 0:n.maxAge)||(n.idTokenExpected=!0);const b=async function(e,t,n,o){return"string"==typeof(null==o?void 0:o.expectedNonce)||"number"==typeof(null==o?void 0:o.maxAge)||null!=o&&o.requireIdToken?async function(e,t,n,o,r,i,a){const s=[];switch(o){case void 0:o=tn;break;case tn:break;default:vt(o,'"expectedNonce" argument'),s.push("nonce")}switch(null!=r||(r=t.default_max_age),r){case void 0:r=nn;break;case nn:break;default:gt(r,!0,'"maxAge" argument'),s.push("auth_time")}const c=await qt(e,t,n,s,i,a);vt(c.id_token,'"response" body "id_token" property',un,{body:c});const u=Zt(c);if(r!==nn){const e=Tt()+St(t),n=Et(t);if(u.auth_time+r<e-n)throw pt("too much time has elapsed since the last End-User authentication",fn,{claims:u,now:e,tolerance:n,claim:"auth_time"})}if(o===tn){if(void 0!==u.nonce)throw pt('unexpected ID Token "nonce" claim value',mn,{expected:void 0,claims:u,claim:"nonce"})}else if(u.nonce!==o)throw pt('unexpected ID Token "nonce" claim value',mn,{expected:o,claims:u,claim:"nonce"});return c}(e,t,n,o.expectedNonce,o.maxAge,o[rt],o.recognizedTokenTypes):async function(e,t,n,o,r){const i=await qt(e,t,n,void 0,o,r),a=Zt(i);if(a){if(void 0!==t.default_max_age){gt(t.default_max_age,!0,'"client.default_max_age"');const e=Tt()+St(t),n=Et(t);if(a.auth_time+t.default_max_age<e-n)throw pt("too much time has elapsed since the last End-User authentication",fn,{claims:a,now:e,tolerance:n,claim:"auth_time"})}if(void 0!==a.nonce)throw pt('unexpected ID Token "nonce" claim value',mn,{expected:void 0,claims:a,claim:"nonce"})}return i}(e,t,n,null==o?void 0:o[rt],null==o?void 0:o.recognizedTokenTypes)}(s,c,v,{expectedNonce:null==n?void 0:n.expectedNonce,maxAge:null==n?void 0:n.maxAge,requireIdToken:null==n?void 0:n.idTokenExpected,[rt]:y});let _;try{_=await b}catch(k){if(Mo(k,r))return Ko(e,void 0,n,o,Ge(Ge({},r),{},{flag:Jo,authResponse:i,redirectUri:a}));Ao(k)}return _.id_token&&await(null==f?void 0:f(v)),Io(_),_}async function Lo(e,t,n,o){zo(e),n=new URLSearchParams(n);const{as:r,c:i,auth:a,fetch:s,tlsOnly:c,nonRepudiation:u,timeout:l,decrypt:d}=yo(e),h=await async function(e,t,n,o,r){At(e),Pt(t),vt(o,'"refreshToken"');const i=new URLSearchParams(null==r?void 0:r.additionalParameters);return i.set("refresh_token",o),Vt(e,t,n,"refresh_token",i,r)}(r,i,a,t,{[ot]:s,[et]:!c,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(fo),signal:Ho(l)}).catch(Ao),p=async function(e,t,n,o){return qt(e,t,n,void 0,null==o?void 0:o[rt],null==o?void 0:o.recognizedTokenTypes)}(r,i,h,{[rt]:d});let f;try{f=await p}catch(m){if(Mo(m,o))return Lo(e,t,n,Ge(Ge({},o),{},{flag:Jo}));Ao(m)}return f.id_token&&await(null==u?void 0:u(h)),Io(f),f}async function Uo(e,t,n){zo(e),t=new URLSearchParams(t);const{as:o,c:r,auth:i,fetch:a,tlsOnly:s,timeout:c}=yo(e),u=async function(e,t,n){return qt(e,t,n,void 0,void 0,void 0)}(o,r,await async function(e,t,n,o,r){return At(e),Pt(t),Vt(e,t,n,"client_credentials",new URLSearchParams(o),r)}(o,r,i,t,{[ot]:a,[et]:!s,DPoP:null==n?void 0:n.DPoP,headers:new Headers(fo),signal:Ho(c)}).catch(Ao));let l;try{l=await u}catch(d){if(Mo(d,n))return Uo(e,t,Ge(Ge({},n),{},{flag:Jo}));Ao(d)}return Io(l),l}function No(e,t){zo(e);const{as:n,c:o,tlsOnly:r,hybrid:i,jarm:a,implicit:s}=yo(e),c=Ct(n,"authorization_endpoint",!1,r);if((t=new URLSearchParams(t)).has("client_id")||t.set("client_id",o.client_id),!t.has("request_uri")&&!t.has("request")){if(t.has("response_type")||t.set("response_type",i?"code id_token":s?"id_token":"code"),s&&!t.has("nonce"))throw So("response_type=id_token clients must provide a nonce parameter in their authorization request parameters",_o);a&&t.set("response_mode","jwt")}for(const[u,l]of t.entries())c.searchParams.append(u,l);return c}async function Wo(e,t,n){zo(e);const o=No(e,t),{as:r,c:i,auth:a,fetch:s,tlsOnly:c,timeout:u}=yo(e),l=async function(e,t,n){if(At(e),Pt(t),!Qe(n,Response))throw $e('"response" must be an instance of Response',"ERR_INVALID_ARG_TYPE");await zt(n,201,"Pushed Authorization Request Endpoint"),vn(n);const o=await An(n);vt(o.request_uri,'"response" body "request_uri" property',un,{body:o});let r="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return gt(r,!0,'"response" body "expires_in" property',un,{body:o}),o.expires_in=r,o}(r,i,await async function(e,t,n,o,r){var i;At(e),Pt(t);const a=Ct(e,"pushed_authorization_request_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==r?void 0:r[et])),s=new URLSearchParams(o);s.set("client_id",t.client_id);const c=mt(null==r?void 0:r.headers);c.set("accept","application/json"),void 0!==(null==r?void 0:r.DPoP)&&(Ht(r.DPoP),await r.DPoP.addProof(a,c,"POST"));const u=await Jt(e,t,n,a,s,c,r);return null==r||null===(i=r.DPoP)||void 0===i||i.cacheNonce(u,a),u}(r,i,a,o.searchParams,{[ot]:s,[et]:!c,DPoP:null==n?void 0:n.DPoP,headers:new Headers(fo),signal:Ho(u)}).catch(Ao));let d;try{d=await l}catch(h){if(Mo(h,n))return Wo(e,t,Ge(Ge({},n),{},{flag:Jo}));Ao(h)}return No(e,{request_uri:d.request_uri})}function zo(e){if(!(e instanceof Ro))throw So('"config" must be an instance of Configuration',ko);if(Object.getPrototypeOf(e)!==Ro.prototype)throw So("subclassing Configuration is not allowed",_o)}function Ho(e){return e?AbortSignal.timeout(1e3*e):void 0}function Mo(e,t){return!(null==t||!t.DPoP||t.flag===Jo)&&function(e){if(e instanceof Kt){const{0:t,length:n}=e.cause;return 1===n&&"dpop"===t.scheme&&"use_dpop_nonce"===t.parameters.error}return e instanceof jt&&"use_dpop_nonce"===e.error}(e)}Object.freeze(Ro.prototype);const Jo=Symbol();async function Vo(e,t,n,o){zo(e);const{as:r,c:i,auth:a,fetch:s,tlsOnly:c,timeout:u,decrypt:l}=yo(e),d=await async function(e,t,n,o,r,i){return At(e),Pt(t),vt(o,'"grantType"'),Vt(e,t,n,o,new URLSearchParams(r),i)}(r,i,a,t,new URLSearchParams(n),{[ot]:s,[et]:!c,DPoP:void 0,headers:new Headers(fo),signal:Ho(u)}).then(e=>{let n;return"urn:ietf:params:oauth:grant-type:token-exchange"===t&&(n={n_a:()=>{}}),async function(e,t,n,o){return qt(e,t,n,void 0,null==o?void 0:o[rt],null==o?void 0:o.recognizedTokenTypes)}(r,i,e,{[rt]:l,recognizedTokenTypes:n})}).catch(Ao);return Io(d),d}
1async function Fo(e,t,n){if(!eo(e))throw new Wn("Flattened JWS must be an object");if(void 0===e.protected&&void 0===e.header)throw new Wn('Flattened JWS must have either of the "protected" or "header" members');if(void 0!==e.protected&&"string"!=typeof e.protected)throw new Wn("JWS Protected Header incorrect type");if(void 0===e.payload)throw new Wn("JWS Payload missing");if("string"!=typeof e.signature)throw new Wn("JWS Signature missing or incorrect type");if(void 0!==e.header&&!eo(e.header))throw new Wn("JWS Unprotected Header incorrect type");let o={};if(e.protected)try{const t=jn(e.protected);o=JSON.parse(On.decode(t))}catch(f){throw new Wn("JWS Protected Header is invalid")}if(!function(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];const o=t.filter(Boolean);if(0===o.length||1===o.length)return!0;let r;for(const i of o){const e=Object.keys(i);if(r&&0!==r.size)for(const t of e){if(r.has(t))return!1;r.add(t)}else r=new Set(e)}return!0}(o,e.header))throw new Wn("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");const r=Ge(Ge({},o),e.header);let i=!0;if(function(e,t,n,o,r){if(void 0!==r.crit&&void 0===(null==o?void 0:o.crit))throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!o||void 0===o.crit)return new Set;if(!Array.isArray(o.crit)||0===o.crit.length||o.crit.some(e=>"string"!=typeof e||0===e.length))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');let i;i=void 0!==n?new Map([...Object.entries(n),...t.entries()]):t;for(const a of o.crit){if(!i.has(a))throw new Nn('Extension Header Parameter "'.concat(a,'" is not recognized'));if(void 0===r[a])throw new e('Extension Header Parameter "'.concat(a,'" is missing'));if(i.get(a)&&void 0===o[a])throw new e('Extension Header Parameter "'.concat(a,'" MUST be integrity protected'))}return new Set(o.crit)}(Wn,new Map([["b64",!0]]),null==n?void 0:n.crit,o,r).has("b64")&&(i=o.b64,"boolean"!=typeof i))throw new Wn('The "b64" (base64url-encode payload) Header Parameter must be a boolean');const{alg:a}=r;if("string"!=typeof a||!a)throw new Wn('JWS "alg" (Algorithm) Header Parameter missing or invalid');const s=n&&function(e,t){if(void 0!==t&&(!Array.isArray(t)||t.some(e=>"string"!=typeof e)))throw new TypeError('"'.concat("algorithms",'" option must be an array of strings'));if(t)return new Set(t)}(0,n.algorithms);if(s&&!s.has(a))throw new Un('"alg" (Algorithm) Header Parameter value not allowed');if(i){if("string"!=typeof e.payload)throw new Wn("JWS Payload must be a string")}else if("string"!=typeof e.payload&&!(e.payload instanceof Uint8Array))throw new Wn("JWS Payload must be a string or an Uint8Array instance");let c=!1;"function"==typeof t&&(t=await t(o,e),c=!0),function(e,t,n){switch(e.substring(0,2)){case"A1":case"A2":case"di":case"HS":case"PB":((e,t,n)=>{if(!(t instanceof Uint8Array)){if(ao(t)){if("oct"===(o=t).kty&&"string"==typeof o.k&&lo(e,t,n))return;throw new TypeError('JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present')}if(!$n(t))throw new TypeError(Xn(e,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"));if("secret"!==t.type)throw new TypeError("".concat(uo(t),' instances for symmetric algorithms must be of type "secret"'))}var o})(e,t,n);break;default:((e,t,n)=>{if(ao(t))switch(n){case"decrypt":case"sign":if("oct"!==(o=t).kty&&("AKP"===o.kty&&"string"==typeof o.priv||"string"==typeof o.d)&&lo(e,t,n))return;throw new TypeError("JSON Web Key for this operation must be a private JWK");case"encrypt":case"verify":if((e=>"oct"!==e.kty&&void 0===e.d&&void 0===e.priv)(t)&&lo(e,t,n))return;throw new TypeError("JSON Web Key for this operation must be a public JWK")}var o;if(!$n(t))throw new TypeError(Xn(e,t,"CryptoKey","KeyObject","JSON Web Key"));if("secret"===t.type)throw new TypeError("".concat(uo(t),' instances for asymmetric algorithms must not be of type "secret"'));if("public"===t.type)switch(n){case"sign":throw new TypeError("".concat(uo(t),' instances for asymmetric algorithm signing must be of type "private"'));case"decrypt":throw new TypeError("".concat(uo(t),' instances for asymmetric algorithm decryption must be of type "private"'))}if("private"===t.type)switch(n){case"verify":throw new TypeError("".concat(uo(t),' instances for asymmetric algorithm verifying must be of type "public"'));case"encrypt":throw new TypeError("".concat(uo(t),' instances for asymmetric algorithm encryption must be of type "public"'))}})(e,t,n)}}(a,t,"verify");const u=function(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];const o=t.reduce((e,t)=>
1{let{length:n}=t;return e+n},0),r=new Uint8Array(o);let i=0;for(const a of t)r.set(a,i),i+=a.length;return r}(void 0!==e.protected?xn(e.protected):new Uint8Array,xn("."),"string"==typeof e.payload?i?xn(e.payload):In.encode(e.payload):e.payload);let l;try{l=jn(e.signature)}catch(f){throw new Wn("Failed to base64url decode the signature")}const d=await async function(e,t){if(e instanceof Uint8Array)return e;if(Yn(e))return e;if(Qn(e)){if("secret"===e.type)return e.export();if("toCryptoKey"in e&&"function"==typeof e.toCryptoKey)try{return((e,t)=>{so||(so=new WeakMap);let n=so.get(e);if(null!=n&&n[t])return n[t];const o="public"===e.type,r=!!o;let i;if("x25519"===e.asymmetricKeyType){switch(t){case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":break;default:throw new TypeError("given KeyObject instance cannot be used for this algorithm")}i=e.toCryptoKey(e.asymmetricKeyType,r,o?[]:["deriveBits"])}if("ed25519"===e.asymmetricKeyType){if("EdDSA"!==t&&"Ed25519"!==t)throw new TypeError("given KeyObject instance cannot be used for this algorithm");i=e.toCryptoKey(e.asymmetricKeyType,r,[o?"verify":"sign"])}switch(e.asymmetricKeyType){case"ml-dsa-44":case"ml-dsa-65":case"ml-dsa-87":if(t!==e.asymmetricKeyType.toUpperCase())throw new TypeError("given KeyObject instance cannot be used for this algorithm");i=e.toCryptoKey(e.asymmetricKeyType,r,[o?"verify":"sign"])}if("rsa"===e.asymmetricKeyType){let n;switch(t){case"RSA-OAEP":n="SHA-1";break;case"RS256":case"PS256":case"RSA-OAEP-256":n="SHA-256";break;case"RS384":case"PS384":case"RSA-OAEP-384":n="SHA-384";break;case"RS512":case"PS512":case"RSA-OAEP-512":n="SHA-512";break;default:throw new TypeError("given KeyObject instance cannot be used for this algorithm")}if(t.startsWith("RSA-OAEP"))return e.toCryptoKey({name:"RSA-OAEP",hash:n},r,o?["encrypt"]:["decrypt"]);i=e.toCryptoKey({name:t.startsWith("PS")?"RSA-PSS":"RSASSA-PKCS1-v1_5",hash:n},r,[o?"verify":"sign"])}if("ec"===e.asymmetricKeyType){var a;const n=new Map([["prime256v1","P-256"],["secp384r1","P-384"],["secp521r1","P-521"]]).get(null===(a=e.asymmetricKeyDetails)||void 0===a?void 0:a.namedCurve);if(!n)throw new TypeError("given KeyObject instance cannot be used for this algorithm");"ES256"===t&&"P-256"===n&&(i=e.toCryptoKey({name:"ECDSA",namedCurve:n},r,[o?"verify":"sign"])),"ES384"===t&&"P-384"===n&&(i=e.toCryptoKey({name:"ECDSA",namedCurve:n},r,[o?"verify":"sign"])),"ES512"===t&&"P-521"===n&&(i=e.toCryptoKey({name:"ECDSA",namedCurve:n},r,[o?"verify":"sign"])),t.startsWith("ECDH-ES")&&(i=e.toCryptoKey({name:"ECDH",namedCurve:n},r,o?[]:["deriveBits"]))}if(!i)throw new TypeError("given KeyObject instance cannot be used for this algorithm");return n?n[t]=i:so.set(e,{[t]:i}),i})(e,t)}catch(f){if(f instanceof TypeError)throw f}let n=e.export({format:"jwk"});return co(e,n,t)}if(ao(e))return e.k?jn(e.k):co(e,e,t,!0);throw new Error("unreachable")}(t,a);if(!(await async function(e,t,n,o){const r=await async function(e,t,n){if(t instanceof Uint8Array){if(!e.startsWith("HS"))throw new TypeError(function(e){for(var t=arguments.length,n=new Array(t>1?t-1:0),o=1;o<t;o++)n[o-1]=arguments[o];return Bn("Key must be ",e,...n)}(t,"CryptoKey","KeyObject","JSON Web Key"));return crypto.subtle.importKey("raw",t,{hash:"SHA-".concat(e.slice(-3)),name:"HMAC"},!1,[n])}return function(e,t,n){switch(t){case"HS256":case"HS384":case"HS512":{if(!Zn(e.algorithm,"HMAC"))throw Gn("HMAC");const n=parseInt(t.slice(2),10);if(qn(e.algorithm.hash)!==n)throw Gn("SHA-".concat(n),"algorithm.hash");break}case"RS256":case"RS384":case"RS512":{if(!Zn(e.algorithm,"RSASSA-PKCS1-v1_5"))throw Gn("RSASSA-PKCS1-v1_5");const n=parseInt(t.slice(2),10);if(qn(e.algorithm.hash)!==n)throw Gn("SHA-".concat(n),"algorithm.hash");break}
1case"PS256":case"PS384":case"PS512":{if(!Zn(e.algorithm,"RSA-PSS"))throw Gn("RSA-PSS");const n=parseInt(t.slice(2),10);if(qn(e.algorithm.hash)!==n)throw Gn("SHA-".concat(n),"algorithm.hash");break}case"Ed25519":case"EdDSA":if(!Zn(e.algorithm,"Ed25519"))throw Gn("Ed25519");break;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":if(!Zn(e.algorithm,t))throw Gn(t);break;case"ES256":case"ES384":case"ES512":{if(!Zn(e.algorithm,"ECDSA"))throw Gn("ECDSA");const n=function(e){switch(e){case"ES256":return"P-256";case"ES384":return"P-384";case"ES512":return"P-521";default:throw new Error("unreachable")}}(t);if(e.algorithm.namedCurve!==n)throw Gn(n,"algorithm.namedCurve");break}default:throw new TypeError("CryptoKey does not support this operation")}!function(e,t){if(!e.usages.includes(t))throw new TypeError("CryptoKey does not support this operation, its usages must include ".concat(t,"."))}(e,n)}(t,e,n),t}(e,t,"verify");!function(e,t){if(e.startsWith("RS")||e.startsWith("PS")){const{modulusLength:n}=t.algorithm;if("number"!=typeof n||n<2048)throw new TypeError("".concat(e," requires key modulusLength to be 2048 bits or larger"))}}(e,r);const i=function(e,t){const n="SHA-".concat(e.slice(-3));switch(e){case"HS256":case"HS384":case"HS512":return{hash:n,name:"HMAC"};case"PS256":case"PS384":case"PS512":return{hash:n,name:"RSA-PSS",saltLength:parseInt(e.slice(-3),10)>>3};case"RS256":case"RS384":case"RS512":return{hash:n,name:"RSASSA-PKCS1-v1_5"};case"ES256":case"ES384":case"ES512":return{hash:n,name:"ECDSA",namedCurve:t.namedCurve};
1case"Ed25519":case"EdDSA":return{name:"Ed25519"};case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return{name:e};default:throw new Nn("alg ".concat(e," is not supported either by JOSE or your javascript runtime"))}}(e,r.algorithm);try{return await crypto.subtle.verify(i,r,n,o)}catch(f){return!1}}(a,d,l,u)))throw new Fn;let h;if(i)try{h=jn(e.payload)}catch(f){throw new Wn("Failed to base64url decode the payload")}else h="string"==typeof e.payload?In.encode(e.payload):e.payload;const p={payload:h};return void 0!==e.protected&&(p.protectedHeader=o),void 0!==e.header&&(p.unprotectedHeader=e.header),c?Ge(Ge({},p),{},{key:d}):p}const Go=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i;function Zo(e){const t=Go.exec(e);if(!t||t[4]&&t[1])throw new TypeError("Invalid time period format");const n=parseFloat(t[2]);let o;switch(t[3].toLowerCase()){case"sec":case"secs":case"second":case"seconds":case"s":o=Math.round(n);break;case"minute":case"minutes":case"min":case"mins":case"m":o=Math.round(60*n);break;case"hour":case"hours":case"hr":case"hrs":case"h":o=Math.round(3600*n);break;case"day":case"days":case"d":o=Math.round(86400*n);break;case"week":case"weeks":case"w":o=Math.round(604800*n);break;default:o=Math.round(31557600*n)}return"-"===t[1]||"ago"===t[4]?-o:o}const qo=e=>e.includes("/")?e.toLowerCase():"application/".concat(e.toLowerCase());function Bo(e){return eo(e)}var Xo,Yo,Qo=new WeakMap,$o=new WeakMap;class er{constructor(e){if(Me(this,Qo,void 0),Me(this,$o,new WeakMap),!((t=e)&&"object"==typeof t&&Array.isArray(t.keys)&&t.keys.every(Bo)))throw new Hn("JSON Web Key Set malformed");var t;Je(Qo,this,structuredClone(e))}jwks(){return He(Qo,this)}async getKey(e,t){const{alg:n,kid:o}=Ge(Ge({},e),null==t?void 0:t.header),r=function(e){switch("string"==typeof e&&e.slice(0,2)){case"RS":case"PS":return"RSA";case"ES":return"EC";case"Ed":return"OKP";case"ML":return"AKP";default:throw new Nn('Unsupported "alg" value for a JSON Web Key Set')}}(n),i=He(Qo,this).keys.filter(e=>{let t=r===e.kty;if(t&&"string"==typeof o&&(t=o===e.kid),!t||"string"!=typeof e.alg&&"AKP"!==r||(t=n===e.alg),t&&"string"==typeof e.use&&(t="sig"===e.use),t&&Array.isArray(e.key_ops)&&(t=e.key_ops.includes("verify")),t)switch(n){case"ES256":t="P-256"===e.crv;break;case"ES384":t="P-384"===e.crv;break;case"ES512":t="P-521"===e.crv;break;
1case"Ed25519":case"EdDSA":t="Ed25519"===e.crv}return t}),{0:a,length:s}=i;if(0===s)throw new Mn;if(1!==s){const e=new Jn,t=He($o,this);throw e[Symbol.asyncIterator]=function(e){return function(){return new qe(e.apply(this,arguments))}}(function*(){for(const o of i)try{yield yield We(tr(t,o,n))}catch(e){}}),e}return tr(He($o,this),a,n)}}async function tr(e,t,n){const o=e.get(t)||e.set(t,{}).get(t);if(void 0===o[n]){const e=await async function(e,t){if(!eo(e))throw new TypeError("JWK must be an object");let n;switch(null!=t||(t=e.alg),null!=n||(n=e.ext),e.kty){case"oct":if("string"!=typeof e.k||!e.k)throw new TypeError('missing "k" (Key Value) Parameter value');return jn(e.k);case"RSA":if("oth"in e&&void 0!==e.oth)throw new Nn('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');return io(Ge(Ge({},e),{},{alg:t,ext:n}));case"AKP":if("string"!=typeof e.alg||!e.alg)throw new TypeError('missing "alg" (Algorithm) Parameter value');if(void 0!==t&&t!==e.alg)throw new TypeError("JWK alg and alg option value mismatch");return io(Ge(Ge({},e),{},{ext:n}));case"EC":case"OKP":return io(Ge(Ge({},e),{},{alg:t,ext:n}));default:throw new Nn('Unsupported "kty" (Key Type) Parameter value')}}(Ge(Ge({},t),{},{ext:!0}),n);if(e instanceof Uint8Array||"public"!==e.type)throw new Hn("JSON Web Key Set members must be public keys");o[n]=e}return o[n]}function nr(e){const t=new er(e),n=async(e,n)=>t.getKey(e,n);return Object.defineProperties(n,{jwks:{value:()=>structuredClone(t.jwks()),enumerable:!1,configurable:!1,writable:!1}}),n}let or;if("undefined"==typeof navigator||null===(Xo=navigator.userAgent)||void 0===Xo||null===(Yo=Xo.startsWith)||void 0===Yo||!Yo.call(Xo,"Mozilla/5.0 ")){const e="v6.1.3";or="".concat("jose","/").concat(e)}const rr=Symbol(),ir=Symbol();var ar=new WeakMap,sr=new WeakMap,cr=new WeakMap,ur=new WeakMap,lr=new WeakMap,dr=new WeakMap,hr=new WeakMap,pr=new WeakMap,fr=new WeakMap,mr=new WeakMap;class yr{constructor(e,t){if(Me(this,ar,void 0),Me(this,sr,void 0),Me(this,cr,void 0),Me(this,ur,void 0),Me(this,lr,void 0),Me(this,dr,void 0),Me(this,hr,void 0),Me(this,pr,void 0),Me(this,fr,void 0),Me(this,mr,void 0),!(e instanceof URL))throw new TypeError("url must be an instance of URL");var n,o;Je(ar,this,new URL(e.href)),Je(sr,this,"number"==typeof(null==t?void 0:t.timeoutDuration)?null==t?void 0:t.timeoutDuration:5e3),Je(cr,this,"number"==typeof(null==t?void 0:t.cooldownDuration)?null==t?void 0:t.cooldownDuration:3e4),Je(ur,this,"number"==typeof(null==t?void 0:t.cacheMaxAge)?null==t?void 0:t.cacheMaxAge:6e5),Je(hr,this,new Headers(null==t?void 0:t.headers)),or&&!He(hr,this).has("User-Agent")&&He(hr,this).set("User-Agent",or),He(hr,this).has("accept")||(He(hr,this).set("accept","application/json"),He(hr,this).append("accept","application/jwk-set+json")),Je(pr,this,null==t?void 0:t[rr]),void 0!==(null==t?void 0:t[ir])&&(Je(mr,this,null==t?void 0:t[ir]),n=null==t?void 0:t[ir],o=He(ur,this),"object"==typeof n&&null!==n&&"uat"in n&&"number"==typeof n.uat&&!(Date.now()-n.uat>=o)&&"jwks"in n&&eo(n.jwks)&&Array.isArray(n.jwks.keys)&&Array.prototype.every.call(n.jwks.keys,eo)&&(Je(lr,this,He(mr,this).uat),Je(fr,this,nr(He(mr,this).jwks))))}pendingFetch(){return!!He(dr,this)}coolingDown(){return"number"==typeof He(lr,this)&&Date.now()<He(lr,this)+He(cr,this)}fresh(){return"number"==typeof He(lr,this)&&Date.now()<He(lr,this)+He(ur,this)}jwks(){var e;return null===(e=He(fr,this))||void 0===e?void 0:e.jwks()}async getKey(e,t){He(fr,this)&&this.fresh()||await this.reload();try{return await He(fr,this).call(this,e,t)}catch(n){if(n instanceof Mn&&!1===this.coolingDown())return await this.reload(),He(fr,this).call(this,e,t);throw n}}async reload(){He(dr,this)&&("undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime)&&Je(dr,this,void 0),He(dr,this)||Je(dr,this,async function(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:fetch;const r=await o(e,{method:"GET",signal:n,redirect:"manual",headers:t}).catch(e=>{if("TimeoutError"===e.name)throw new Vn;throw e});if(200!==r.status)throw new Dn("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await r.json()}catch(i){throw new Dn("Failed to parse the JSON Web Key Set HTTP response as JSON")}}(He(ar,this).href,He(hr,this),AbortSignal.timeout(He(sr,this)),He(pr,this)).then(e=>{Je(fr,this,nr(e)),He(mr,this)&&(He(mr,this).uat=Date.now(),He(mr,this).jwks=e),Je(lr,this,Date.now()),Je(dr,this,void 0)}).catch(e=>{throw Je(dr,this,void 0),e})),await He(dr,this)}}const wr=["mfaToken"],gr=["mfaToken"];
1var vr,br,_r,kr,Sr,Er,Tr,Ar,Pr=class extends Error{constructor(e,t){super(t),Ve(this,"code",void 0),this.name="NotSupportedError",this.code=e}},Rr=class extends Error{constructor(e,t,n){super(t),Ve(this,"cause",void 0),Ve(this,"code",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},Ir=class extends Rr{constructor(e,t){super("token_by_code_error",e,t),this.name="TokenByCodeError"}},Or=class extends Rr{constructor(e,t){super("token_by_client_credentials_error",e,t),this.name="TokenByClientCredentialsError"}},xr=class extends Rr{constructor(e,t){super("token_by_refresh_token_error",e,t),this.name="TokenByRefreshTokenError"}},Cr=class extends Rr{constructor(e,t){super("token_for_connection_error",e,t),this.name="TokenForConnectionErrorCode"}},jr=class extends Rr{constructor(e,t){super("token_exchange_error",e,t),this.name="TokenExchangeError"}},Dr=class extends Error{constructor(e){super(e),Ve(this,"code","verify_logout_token_error"),this.name="VerifyLogoutTokenError"}},Kr=class extends Rr{constructor(e){super("backchannel_authentication_error","There was an error when trying to use Client-Initiated Backchannel Authentication.",e),Ve(this,"code","backchannel_authentication_error"),this.name="BackchannelAuthenticationError"}},Lr=class extends Rr{constructor(e){super("build_authorization_url_error","There was an error when trying to build the authorization URL.",e),this.name="BuildAuthorizationUrlError"}},Ur=class extends Rr{constructor(e){super("build_link_user_url_error","There was an error when trying to build the Link User URL.",e),this.name="BuildLinkUserUrlError"}},Nr=class extends Rr{constructor(e){super("build_unlink_user_url_error","There was an error when trying to build the Unlink User URL.",e),this.name="BuildUnlinkUserUrlError"}},Wr=class extends Error{constructor(){super("The client secret or client assertion signing key must be provided."),Ve(this,"code","missing_client_auth_error"),this.name="MissingClientAuthError"}};function zr(e){return Object.entries(e).filter(e=>{let[,t]=e;return void 0!==t}).reduce((e,t)=>Ge(Ge({},e),{},{[t[0]]:t[1]}),{})}var Hr=class extends Error{constructor(e,t,n){super(t),Ve(this,"cause",void 0),Ve(this,"code",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},Mr=class extends Hr{constructor(e,t){super("mfa_list_authenticators_error",e,t),this.name="MfaListAuthenticatorsError"}},Jr=class extends Hr{constructor(e,t){super("mfa_enrollment_error",e,t),this.name="MfaEnrollmentError"}},Vr=class extends Hr{constructor(e,t){super("mfa_delete_authenticator_error",e,t),this.name="MfaDeleteAuthenticatorError"}},Fr=class extends Hr{constructor(e,t){super("mfa_challenge_error",e,t),this.name="MfaChallengeError"}};function Gr(e){return{id:e.id,authenticatorType:e.authenticator_type,active:e.active,name:e.name,oobChannels:e.oob_channels,type:e.type}}var Zr=(vr=new WeakMap,br=new WeakMap,_r=new WeakMap,class{constructor(e){var t;Me(this,vr,void 0),Me(this,br,void 0),Me(this,_r,void 0),Je(vr,this,"https://".concat(e.domain)),Je(br,this,e.clientId),Je(_r,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)})}async listAuthenticators(e){const t="".concat(He(vr,this),"/mfa/authenticators"),{mfaToken:n}=e,o=await He(_r,this).call(this,t,{method:"GET",headers:{Authorization:"Bearer ".concat(n),"Content-Type":"application/json"}});if(!o.ok){const e=await o.json();throw new Mr(e.error_description||"Failed to list authenticators",e)}return(await o.json()).map(Gr)}async enrollAuthenticator(e){const t="".concat(He(vr,this),"/mfa/associate"),{mfaToken:n}=e,o=Ze(e,wr),r={authenticator_types:o.authenticatorTypes};"oobChannels"in o&&(r.oob_channels=o.oobChannels),"phoneNumber"in o&&o.phoneNumber&&(r.phone_number=o.phoneNumber),"email"in o&&o.email&&(r.email=o.email);const i=await He(_r,this).call(this,t,{method:"POST",headers:{Authorization:"Bearer ".concat(n),"Content-Type":"application/json"},body:JSON.stringify(r)});if(!i.ok){const e=await i.json();throw new Jr(e.error_description||"Failed to enroll authenticator",e)}return function(e){if("otp"===e.authenticator_type)return{authenticatorType:"otp",secret:e.secret,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes,id:e.id};if("oob"===e.authenticator_type)return{authenticatorType:"oob",oobChannel:e.oob_channel,oobCode:e.oob_code,bindingMethod:e.binding_method,id:e.id};throw new Error("Unexpected authenticator type: ".concat(e.authenticator_type))}(await i.json())}async deleteAuthenticator(e){const{authenticatorId:t,mfaToken:n}=e,o="".concat(He(vr,this),"/mfa/authenticators/").concat(encodeURIComponent(t)),r=await He(_r,this).call(this,o,{method:"DELETE",headers:{Authorization:"Bearer ".concat(n),"Content-Type":"application/json"}});if(!r.ok){const e=await r.json();throw new Vr(e.error_description||"Failed to delete authenticator",e)}}async challengeAuthenticator(e){const t="".concat(He(vr,this),"/mfa/challenge"),{mfaToken:n}=e,o=Ze(e,gr),r={mfa_token:n,client_id:He(br,this),challenge_type:o.challengeType};o.authenticatorId&&(r.authenticator_id=o.authenticatorId);const i=await He(_r,this).call(this,t,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(r)});if(!i.ok){const e=await i.json();throw new Fr(e.error_description||"Failed to challenge authenticator",e)}return function(e){const t={challengeType:e.challenge_type};return void 0!==e.oob_code&&(t.oobCode=e.oob_code),void 0!==e.binding_method&&(t.bindingMethod=e.binding_method),t}(await i.json())}}),qr=class e{constructor(e,t,n,o,r,i,a){Ve(this,"accessToken",void 0),Ve(this,"idToken",void 0),Ve(this,"refreshToken",void 0),Ve(this,"expiresAt",void 0),Ve(this,"scope",void 0),Ve(this,"claims",void 0),Ve(this,"authorizationDetail
1s",void 0),Ve(this,"tokenType",void 0),Ve(this,"issuedTokenType",void 0),this.accessToken=e,this.idToken=n,this.refreshToken=o,this.expiresAt=t,this.scope=r,this.claims=i,this.authorizationDetails=a}static fromTokenEndpointResponse(t){const n=t.id_token?t.claims():void 0,o=new e(t.access_token,Math.floor(Date.now()/1e3)+Number(t.expires_in),t.id_token,t.refresh_token,t.scope,n,t.authorization_details);return o.tokenType=t.token_type,o.issuedTokenType=t.issued_token_type,o}},Br="openid profile email offline_access",Xr=Object.freeze(new Set(["grant_type","client_id","client_secret","client_assertion","client_assertion_type","subject_token","subject_token_type","requested_token_type","actor_token","actor_token_type","audience","aud","resource","resources","resource_indicator","scope","connection","login_hint","organization","assertion"]));function Yr(e){if(null==e)throw new jr("subject_token is required");if("string"!=typeof e)throw new jr("subject_token must be a string");if(0===e.trim().length)throw new jr("subject_token cannot be blank or whitespace");if(e!==e.trim())throw new jr("subject_token must not include leading or trailing whitespace");if(/^bearer\s+/i.test(e))throw new jr("subject_token must not include the 'Bearer ' prefix")}function Qr(e,t){if(t)for(const[n,o]of Object.entries(t))if(!Xr.has(n))if(Array.isArray(o)){if(o.length>20)throw new jr("Parameter '".concat(n,"' exceeds maximum array size of ").concat(20));o.forEach(t=>{e.append(n,t)})}else e.append(n,o)}var $r=(kr=new WeakMap,Sr=new WeakMap,Er=new WeakMap,Tr=new WeakMap,Ar=new WeakSet,class{constructor(e){if(ze(this,t=Ar),t.add(this),Me(this,kr,void 0),Me(this,Sr,void 0),Me(this,Er,void 0),Me(this,Tr,void 0),Ve(this,"mfa",void 0),Je(Er,this,e),e.useMtls&&!e.customFetch)throw new Pr("mtls_without_custom_fetch_not_supported","Using mTLS without a custom fetch implementation is not supported");var t;this.mfa=new Zr({domain:He(Er,this).domain,clientId:He(Er,this).clientId,customFetch:He(Er,this).customFetch})}async buildAuthorizationUrl(e){const{serverMetadata:t}=await Ne(Ar,this,ei).call(this);if(null!=e&&e.pushedAuthorizationRequests&&!t.pushed_authorization_request_endpoint)throw new Pr("par_not_supported_error","The Auth0 tenant does not have pushed authorization requests enabled. Learn how to enable it here: https://auth0.com/docs/get-started/applications/configure-par");try{return await Ne(Ar,this,ri).call(this,e)}catch(n){throw new Lr(n)}}async buildLinkUserUrl(e){try{const t=await Ne(Ar,this,ri).call(this,{authorizationParams:Ge(Ge({},e.authorizationParams),{},{requested_connection:e.connection,requested_connection_scope:e.connectionScope,scope:"openid link_account offline_access",id_token_hint:e.idToken})});return{linkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(t){throw new Ur(t)}}async buildUnlinkUserUrl(e){try{const t=await Ne(Ar,this,ri).call(this,{authorizationParams:Ge(Ge({},e.authorizationParams),{},{requested_connection:e.connection,scope:"openid unlink_account",id_token_hint:e.idToken})});return{unlinkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(t){throw new Nr(t)}}async backchannelAuthentication(e){const{configuration:t,serverMetadata:n}=await Ne(Ar,this,ei).call(this),o=zr(Ge(Ge({},He(Er,this).authorizationParams),null==e?void 0:e.authorizationParams)),r=new URLSearchParams(Ge(Ge({scope:Br},o),{},{client_id:He(Er,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:n.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&r.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&r.append("authorization_details",JSON.stringify(e.authorizationDetails));try{const e=await Co(t,r),n=await jo(t,e);return qr.fromTokenEndpointResponse(n)}catch(i){throw new Kr(i)}}async initiateBackchannelAuthentication(e){const{configuration:t,serverMetadata:n}=await Ne(Ar,this,ei).call(this),o=zr(Ge(Ge({},He(Er,this).authorizationParams),null==e?void 0:e.authorizationParams)),r=new URLSearchParams(Ge(Ge({scope:Br},o),{},{client_id:He(Er,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:n.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&r.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetail
1s&&r.append("authorization_details",JSON.stringify(e.authorizationDetails));try{const e=await Co(t,r);return{authReqId:e.auth_req_id,expiresIn:e.expires_in,interval:e.interval}}catch(i){throw new Kr(i)}}async backchannelAuthenticationGrant(e){let{authReqId:t}=e;const{configuration:n}=await Ne(Ar,this,ei).call(this),o=new URLSearchParams({auth_req_id:t});try{const e=await Vo(n,"urn:openid:params:grant-type:ciba",o);return qr.fromTokenEndpointResponse(e)}catch(r){throw new Kr(r)}}async getTokenForConnection(e){var t;if(e.refreshToken&&e.accessToken)throw new Cr("Either a refresh or access token should be specified, but not both.");const n=null!==(t=e.accessToken)&&void 0!==t?t:e.refreshToken;if(!n)throw new Cr("Either a refresh or access token must be specified.");try{return await this.exchangeToken({connection:e.connection,subjectToken:n,subjectTokenType:e.accessToken?"urn:ietf:params:oauth:token-type:access_token":"urn:ietf:params:oauth:token-type:refresh_token",loginHint:e.loginHint})}catch(o){if(o instanceof jr)throw new Cr(o.message,o.cause);throw o}}async exchangeToken(e){return"connection"in e?Ne(Ar,this,ti).call(this,e):Ne(Ar,this,ni).call(this,e)}async getTokenByCode(e,t){const{configuration:n}=await Ne(Ar,this,ei).call(this);try{const o=await Ko(n,e,{pkceCodeVerifier:t.codeVerifier});return qr.fromTokenEndpointResponse(o)}catch(o){throw new Ir("There was an error while trying to request a token.",o)}}async getTokenByRefreshToken(e){const{configuration:t}=await Ne(Ar,this,ei).call(this);try{const n=await Lo(t,e.refreshToken);return qr.fromTokenEndpointResponse(n)}catch(n){throw new xr("The access token has expired and there was an error while trying to refresh it.",n)}}async getTokenByClientCredentials(e){const{configuration:t}=await Ne(Ar,this,ei).call(this);try{const n=new URLSearchParams({audience:e.audience});e.organization&&n.append("organization",e.organization);const o=await Uo(t,n);return qr.fromTokenEndpointResponse(o)}catch(n){throw new Or("There was an error while trying to request a token.",n)}}async buildLogoutUrl(e){const{configuration:t,serverMetadata:n}=await Ne(Ar,this,ei).call(this);if(!n.end_session_endpoint){const t=new URL("https://".concat(He(Er,this).domain,"/v2/logout"));return t.searchParams.set("returnTo",e.returnTo),t.searchParams.set("client_id",He(Er,this).clientId),t}return function(e,t){zo(e);const{as:n,c:o,tlsOnly:r}=yo(e),i=Ct(n,"end_session_endpoint",!1,r);(t=new URLSearchParams(t)).has("client_id")||t.set("client_id",o.client_id);for(const[a,s]of t.entries())i.searchParams.append(a,s);return i}(t,{post_logout_redirect_uri:e.returnTo})}async verifyLogoutToken(e){const{serverMetadata:t}=await Ne(Ar,this,ei).call(this);He(Tr,this)||Je(Tr,this,function(e,t){const n=new yr(e,t),o=async(e,t)=>n.getKey(e,t);return Object.defineProperties(o,{coolingDown:{get:()=>n.coolingDown(),enumerable:!0,configurable:!1},fresh:{get:()=>n.fresh(),enumerable:!0,configurable:!1},reload:{value:()=>n.reload(),enumerable:!0,configurable:!1,writable:!1},reloading:{get:()=>n.pendingFetch(),enumerable:!0,configurable:!1},jwks:{value:()=>n.jwks(),enumerable:!0,configurable:!1,writable:!1}}),o}(new URL(t.jwks_uri),{[rr]:He(Er,this).customFetch}));const{payload:n}=await async function(e,t,n){var o;const r=await async function(e,t,n){if(e instanceof Uint8Array&&(e=On.decode(e)),"string"!=typeof e)throw new Wn("Compact JWS must be a string or Uint8Array");const{0:o,1:r,2:i,length:a}=e.split(".");if(3!==a)throw new Wn("Invalid Compact JWS");const s=await Fo({payload:r,protected:o,signature:i},t,n),c={payload:s.payload,protectedHeader:s.protectedHeader};return"function"==typeof t?Ge(Ge({},c),{},{key:s.key}):c}(e,t,n);if(null!==(o=r.protectedHeader.crit)&&void 0!==o&&o.includes("b64")&&!1===r.protectedHeader.b64)throw new zn("JWTs MUST NOT use unencoded payload");const i=function(e,t){let n,o=arguments.length>2&&void 0!==arguments[2]?arguments[2]:{};try{n=JSON.parse(On.decode(t))}catch(f){}if(!eo(n))throw new zn("JWT Claims Set must be a top-level JSON object");const{typ:r}=o;if(r&&("string"!=typeof e.typ||qo(e.typ)!==qo(r)))throw new Kn('unexpected "typ" JWT header value',n,"typ","check_failed");const{requiredClaims:i=[],issuer:a,subject:s,audience:c,maxTokenAge:u}=o,l=[...i];void 0!==u&&l.push("iat"),void 0!==c&&l.push("aud"),void 0!==s&&l.push("sub"),void 0!==a&&l.push("iss");for(const m of new Set(l.reverse()))if(!(m in n))throw new Kn('missing required "'.concat(m,'" claim'),n,m,"missing");if(a&&!(Array.isArray(a)?a:[a]).includes(n.iss))throw new Kn('unexpected "iss" claim value',n,"iss","check_failed");if(s&&n.sub!==s)throw new Kn('unexpected "sub" claim value',n,"sub","check_failed");if(c&&!((e,t)=>"string"==typeof e?t.includes(e):!!Array.isArray(e)&&t.some(Set.prototype.has.bind(new Set(e))))(n.aud,"string"==typeof c?[c]:c))throw new Kn('unexpected "aud" claim value',n,"aud","check_failed");let d;switch(typeof o.clockTolerance){case"string":d=Zo(o.clockTolerance);break;case"number":d=o.clockTolerance;break;case"undefined":d=0;break;default:throw new TypeError("Invalid clockTolerance option type")}const{currentDate:h}=o,p=(e=>Math.floor(e.getTime()/1e3))(h||new Date);if((void 0!==n.iat||u)&&"number"!=typeof n.iat)throw new Kn('"iat" claim must be a number',n,"iat","invali
1d");if(void 0!==n.nbf){if("number"!=typeof n.nbf)throw new Kn('"nbf" claim must be a number',n,"nbf","invalid");if(n.nbf>p+d)throw new Kn('"nbf" claim timestamp check failed',n,"nbf","check_failed")}if(void 0!==n.exp){if("number"!=typeof n.exp)throw new Kn('"exp" claim must be a number',n,"exp","invalid");if(n.exp<=p-d)throw new Ln('"exp" claim timestamp check failed',n,"exp","check_failed")}if(u){const e=p-n.iat;if(e-d>("number"==typeof u?u:Zo(u)))throw new Ln('"iat" claim timestamp check failed (too far in the past)',n,"iat","check_failed");if(e<0-d)throw new Kn('"iat" claim timestamp check failed (it should be in the past)',n,"iat","check_failed")}return n}(r.protectedHeader,r.payload,n),a={payload:i,protectedHeader:r.protectedHeader};return"function"==typeof t?Ge(Ge({},a),{},{key:r.key}):a}(e.logoutToken,He(Tr,this),{issuer:t.issuer,audience:He(Er,this).clientId,algorithms:["RS256"],requiredClaims:["iat"]});if(!("sid"in n)&&!("sub"in n))throw new Dr('either "sid" or "sub" (or both) claims must be present');if("sid"in n&&"string"!=typeof n.sid)throw new Dr('"sid" claim must be a string');if("sub"in n&&"string"!=typeof n.sub)throw new Dr('"sub" claim must be a string');if("nonce"in n)throw new Dr('"nonce" claim is prohibited');if(!("events"in n))throw new Dr('"events" claim is missing');if("object"!=typeof n.events||null===n.events)throw new Dr('"events" claim must be an object');if(!("http://schemas.openid.net/event/backchannel-logout"in n.events))throw new Dr('"http://schemas.openid.net/event/backchannel-logout" member is missing in the "events" claim');if("object"!=typeof n.events["http://schemas.openid.net/event/backchannel-logout"])throw new Dr('"http://schemas.openid.net/event/backchannel-logout" member in the "events" claim must be an object');return{sid:n.sid,sub:n.sub}}});async function ei(){if(He(kr,this)&&He(Sr,this))return{configuration:He(kr,this),serverMetadata:He(Sr,this)};const e=await Ne(Ar,this,oi).call(this);return Je(kr,this,await async function(e,t,n,o,r){const i=await async function(e,t){var n,o;if(!(e instanceof URL))throw So('"server" must be an instance of URL',ko);const r=!e.href.includes("/.well-known/"),i=null!==(n=null==t?void 0:t.timeout)&&void 0!==n?n:30,a=AbortSignal.timeout(1e3*i),s=await(r?async function(e,t){return async function(e,n,o,r){if(!(e instanceof URL))throw $e('"'.concat("issuerIdentifier",'" must be an instance of URL'),"ERR_INVALID_ARG_TYPE");Ot(e,!0!==(null==r?void 0:r[et]));const i=(e=>{switch(null==t?void 0:t.algorithm){case void 0:case"oidc":(n=e).pathname=wt("".concat(n.pathname,"/").concat(".well-known/openid-configuration"));break;case"oauth2":!function(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];"/"===e.pathname?e.pathname=t:e.pathname=wt("".concat(t,"/").concat(n?e.pathname:e.pathname.replace(/(\/)$/,"")))}(e,".well-known/oauth-authorization-server");break;default:throw $e('"options.algorithm" must be "oidc" (default), or "oauth2"',"ERR_INVALID_ARG_VALUE")}var n;return e})(new URL(e.href)),a=mt(null==r?void 0:r.headers);return a.set("accept","application/json"),((null==r?void 0:r[ot])||fetch)(i.href,{body:void 0,headers:Object.fromEntries(a.entries()),method:"GET",redirect:"manual",signal:yt(i,null==r?void 0:r.signal)}
1)}(e,0,0,t)}(e,{algorithm:null==t?void 0:t.algorithm,[ot]:null==t?void 0:t[bo],[et]:null==t||null===(o=t.execute)||void 0===o?void 0:o.includes(Do),signal:a,headers:new Headers(fo)}):((null==t?void 0:t[bo])||fetch)((Ot(e,null==t||null===(c=t.execute)||void 0===c||!c.includes(Do)),e.href),{headers:Object.fromEntries(new Headers(Ge({accept:"application/json"},fo)).entries()),body:void 0,method:"GET",redirect:"manual",signal:a})).then(e=>async function(e,t){const n=Pn;if(!(n instanceof URL)&&n!==Pn)throw $e('"expectedIssuerIdentifier" must be an instance of URL',"ERR_INVALID_ARG_TYPE");if(!Qe(t,Response))throw $e('"response" must be an instance of Response',"ERR_INVALID_ARG_TYPE");if(200!==t.status)throw pt('"response" is not a conform Authorization Server Metadata response (unexpected HTTP status code)',dn,t);vn(t);const o=await An(t);if(vt(o.issuer,'"response" body "issuer" property',un,{body:o}),n!==Pn&&new URL(o.issuer).href!==n.href)throw pt('"response" body "issuer" property does not match the expected value',yn,{expected:n.href,body:o,attribute:"issuer"});return o}(0,e)).catch(Ao);var c,u,l;return r&&new URL(s.issuer).href!==e.href&&(u=s,l=t,!("https://login.microsoftonline.com"!==e.origin||null!=l&&l.algorithm&&"oidc"!==l.algorithm||(u[Po]=!0,0))||function(e,t){return!(!e.hostname.endsWith(".b2clogin.com")||null!=t&&t.algorithm&&"oidc"!==t.algorithm)}(e,t)||(()=>{throw new Eo("discovered metadata issuer does not match the expected issuer",{code:yn,cause:{expected:e.href,body:s,attribute:"issuer"}})})()),s}(e,r),a=new Ro(i,t,n,o);let s=yo(a);if(null!=r&&r[bo]&&(s.fetch=r[bo]),null!=r&&r.timeout&&(s.timeout=r.timeout),null!=r&&r.execute)for(const c of r.execute)c(a);return a}(new URL("https://".concat(He(Er,this).domain)),He(Er,this).clientId,{use_mtls_endpoint_aliases:He(Er,this).useMtls},e,{[bo]:He(Er,this).customFetch})),Je(Sr,this,He(kr,this).serverMetadata()),He(kr,this)[bo]=He(Er,this).customFetch||fetch,{configuration:He(kr,this),serverMetadata:He(Sr,this)}}async function ti(e){var t,n;const{configuration:o}=await Ne(Ar,this,ei).call(this);if("audience"in e||"resource"in e)throw new jr("audience and resource parameters are not supported for Token Vault exchanges");Yr(e.subjectToken);const r=new URLSearchParams({connection:e.connection,subject_token:e.subjectToken,subject_token_type:null!==(t=e.subjectTokenType)&&void 0!==t?t:"urn:ietf:params:oauth:token-type:access_token",requested_token_type:null!==(n=e.requestedTokenType)&&void 0!==n?n:"http://auth0.com/oauth/token-type/federated-connection-access-token"});e.loginHint&&r.append("login_hint",e.loginHint),e.scope&&r.append("scope",e.scope),Qr(r,e.extra);try{const e=await Vo(o,"urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token",r);return qr.fromTokenEndpointResponse(e)}catch(i){throw new jr("Failed to exchange token for connection '".concat(e.connection,"'."),i)}}async function ni(e){const{configuration:t}=await Ne(Ar,this,ei).call(this);Yr(e.subjectToken);const n=new URLSearchParams({subject_token_type:e.subjectTokenType,subject_token:e.subjectToken});e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),e.requestedTokenType&&n.append("requested_token_type",e.requestedTokenType),e.organization&&n.append("organization",e.organization),Qr(n,e.extra);try{const e=await Vo(t,"urn:ietf:params:oauth:grant-type:token-exchange",n);return qr.fromTokenEndpointResponse(e)}catch(o){throw new jr("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),o)}}async function oi(){if(!He(Er,this).clientSecret&&!He(Er,this).clientAssertionSigningKey&&!He(Er,this).useMtls)throw new Wr;if(He(Er,this).useMtls)return(e,t,n,o)=>{n.set("client_id",t.client_id)};let e=He(Er,this).clientAssertionSigningKey;return!e||e instanceof CryptoKey||(e=await async function(e,t){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw new TypeError('"pkcs8" must be PKCS#8 formatted string');return((t,n,o)=>{var r;const i=Cn(t.replace(/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)
1/g,""));let a=o;return null!=n&&null!==(r=n.startsWith)&&void 0!==r&&r.call(n,"ECDH-ES")&&(a||(a={}),a.getNamedCurve=e=>{const t={data:e,pos:0};return function(e){oo(e,48,"Invalid PKCS#8 structure"),no(e),oo(e,2,"Expected version field");const t=no(e);e.pos+=t,oo(e,48,"Expected algorithm identifier"),no(e)}(t),(e=>{const t=(e=>{oo(e,6,"Expected algorithm OID");const t=no(e);return ro(e,t)})(e);if(to(t,[43,101,110]))return"X25519";if(!to(t,[42,134,72,206,61,2,1]))throw new Error("Unsupported key algorithm");oo(e,6,"Expected curve OID");const n=no(e),o=ro(e,n);for(const{name:r,oid:i}of[{name:"P-256",oid:[42,134,72,206,61,3,1,7]},{name:"P-384",oid:[43,129,4,0,34]},{name:"P-521",oid:[43,129,4,0,35]}])if(to(o,i))return r;throw new Error("Unsupported named curve")})(t)}),(async(t,n,o,r)=>{var i;let a,s;switch(o){case"PS256":case"PS384":case"PS512":a={name:"RSA-PSS",hash:"SHA-".concat(o.slice(-3))},s=["sign"];break;case"RS256":case"RS384":case"RS512":a={name:"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(o.slice(-3))},s=["sign"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":a={name:"RSA-OAEP",hash:"SHA-".concat(parseInt(o.slice(-3),10)||1)},s=["decrypt","unwrapKey"];break;case"ES256":case"ES384":case"ES512":a={name:"ECDSA",namedCurve:{ES256:"P-256",ES384:"P-384",ES512:"P-521"}[o]},s=["sign"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":try{const e=r.getNamedCurve(n);a="X25519"===e?{name:"X25519"}:{name:"ECDH",namedCurve:e}}catch(e){throw new Nn("Invalid or unsupported key format")}s=["deriveBits"];break;
1case"Ed25519":case"EdDSA":a={name:"Ed25519"},s=["sign"];break;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":a={name:o},s=["sign"];break;default:throw new Nn('Invalid or unsupported "alg" (Algorithm) value')}return crypto.subtle.importKey("pkcs8",n,a,null!==(i=null==r?void 0:r.extractable)&&void 0!==i&&i,s)})(0,i,n,a)})(e,t,void 0)}(e,He(Er,this).clientAssertionSigningAlg||"RS256")),e?function(e){const{key:t,kid:n}=(o=e)instanceof CryptoKey?{key:o}:(null==o?void 0:o.key)instanceof CryptoKey?(void 0!==o.kid&&vt(o.kid,'"kid"'),{key:o.key,kid:o.kid}):{};var o;return function(e,t){if(function(e,t){if(!(e instanceof CryptoKey))throw $e("".concat(t," must be a CryptoKey"),"ERR_INVALID_ARG_TYPE")}(e,t),"private"!==e.type)throw $e("".concat(t," must be a private CryptoKey"),"ERR_INVALID_ARG_VALUE")}(t,'"clientPrivateKey.key"'),async(e,o,r,i)=>{const a={alg:kt(t),kid:n},s=function(e,t){const n=Tt()+St(t);return{jti:_t(),aud:e.issuer,exp:n+60,iat:n,nbf:n,iss:t.client_id,sub:t.client_id}}(e,o);r.set("client_id",o.client_id),r.set("client_assertion_type","urn:ietf:params:oauth:client-assertion-type:jwt-bearer"),r.set("client_assertion",await async function(e,t,n){if(!n.usages.includes("sign"))throw $e('CryptoKey instances used for signing assertions must include "sign" in their "usages"',"ERR_INVALID_ARG_VALUE");const o="".concat(lt(st(JSON.stringify(e))),".").concat(lt(st(JSON.stringify(t)))),r=lt(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:_n(e)};case"RSA-PSS":switch(bn(e),e.algorithm.hash.name){case"SHA-256":case"SHA-384":case"SHA-512":return{name:e.algorithm.name,saltLength:parseInt(e.algorithm.hash.name.slice(-3),10)>>3};default:throw new dt("unsupported RSA-PSS hash name",{cause:e})}case"RSASSA-PKCS1-v1_5":return bn(e),e.algorithm.name;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":case"Ed25519":return e.algorithm.name}throw new dt("unsupported CryptoKey algorithm name",{cause:e})}(n),n,st(o)));return"".concat(o,".").concat(r)}(a,s,t))}}(e):vo(He(Er,this).clientSecret)}async function ri(e){const{configuration:t}=await Ne(Ar,this,ei).call(this),n=_t(),o=await function(e){return async function(e){return vt(e,"codeVerifier"),lt(await crypto.subtle.digest("SHA-256",st(e)))}(e)}(n),r=zr(Ge(Ge({},He(Er,this).authorizationParams),null==e?void 0:e.authorizationParams)),i=new URLSearchParams(Ge(Ge({scope:Br},r),{},{client_id:He(Er,this).clientId,code_challenge:o,code_challenge_method:"S256"}));return{authorizationUrl:null!=e&&e.pushedAuthorizationRequests?await Wo(t,i):await No(t,i),codeVerifier:n}}class ii extends w{constructor(e,t){super(e,t),Object.setPrototypeOf(this,ii.prototype)}static fromPayload(e){let{error:t,error_description:n}=e;return new ii(t,n)}}class ai extends ii{constructor(e,t){super(e,t),Object.setPrototypeOf(this,ai.prototype)}}class si extends ii{constructor(e,t){super(e,t),Object.setPrototypeOf(this,si.prototype)}}class ci extends ii{constructor(e,t){super(e,t),Object.setPrototypeOf(this,ci.prototype)}}class ui extends ii{constructor(e,t){super(e,t),Object.setPrototypeOf(this,ui.prototype)}}class li extends ii{constructor(e,t){super(e,t),Object.setPrototypeOf(this,li.prototype)}}class di{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:6e5;this.contexts=new Map,this.ttlMs=e}set(e,t){this.cleanup(),this.contexts.set(e,Object.assign(Object.assign({},t),{createdAt:Date.now()}))}get(e){const t=this.contexts.get(e);if(t){if(!(Date.now()-t.createdAt>this.ttlMs))return t;this.contexts.delete(e)}}remove(e){this.contexts.delete(e)}cleanup(){const e=Date.now();for(const[t,n]of this.contexts)e-n.createdAt>this.ttlMs&&this.contexts.delete(t)}get size(){return this.contexts.size}}class hi{constructor(e,t){this.authJsMfaClient=e,this.auth0Client=t,this.contextManager=new di}setMFAAuthDetails(e,t,n,o){this.contextManager.set(e,{scope:t,audience:n,mfaRequirements:o})}async getAuthenticators(e){var t,n;const o=this.contextManager.get(e);if(!(null===(t=null==o?void 0:o.mfaRequirements)||void 0===t?void 0:t.challenge)||0===o.mfaRequirements.challenge.length)throw new ai("invalid_request","challengeType is required and must contain at least one challenge type, please check mfa_required error payload");const r=o.mfaRequirements.challenge.map(e=>e.type);try{return(await this.authJsMfaClient.listAuthenticators({mfaToken:e})).filter(e=>!!e.type&&r.includes(e.type))}catch(i){if(i instanceof Mr)throw new ai(null===(n=i.cause)||void 0===n?void 0:n.error,i.message);throw i}}async enroll(e){var t;const n=function(e){const t=Le[e.factorType];return Object.assign(Object.assign(Object.assign({mfaToken:e.mfaToken,authenticatorTypes:t.authenticatorTypes},t.oobChannels&&{oobChannels:t.oobChannels}),"phoneNumber"in e&&{phoneNumber:e.phoneNumber}),"email"in e&&{email:e.email})}(e);try{return await this.authJsMfaClient.enrollAuthenticator(n)}catch(o){if(o instanceof Jr)throw new si(null===(t=o.cause)||void 0===t?void 0:t.error,o.message);throw o}}async challenge(e){var t;try{const t={challengeType:e.challengeType,mfaToken:e.mfaToken};return e.authenticatorId&&(t.authenticatorId=e.authenticatorId),await this.authJsMfaClient.challengeAuthenticator(t)}catch(n){if(n instanceof Fr)throw new ci(null===(t=n.cause)||void 0===t?void 0:t.error,n.message);throw n}}async getEnrollmentFactors(e){const t=this.contextManager.get(e);if(!t||!t.mfaRequirements)throw new li("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");return t.mfaRequirements.enroll&&0!==t.mfaRequirements.enroll.length?t.mfaRequirements.enroll:[]}async verify(e){const t=this.contextManager.get(e.mfaToken);if(!t)throw new ui("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");const n="otp"in(o=e)&&o.otp?"http://auth0.com/oauth/grant-type/mfa-otp":"oobCode"in o&&o.oobCode?"http://auth0.com/oauth/grant-type/mfa-oob":"recoveryCode"in o&&o.recoveryCode?"http://auth0.com/oauth/grant-type/mfa-rec
1overy-code":void 0;var o;if(!n)throw new ui("invalid_request","Unable to determine grant type. Provide one of: otp, oobCode, or recoveryCode.");const r=t.scope,i=t.audience;try{const t=await this.auth0Client._requestTokenForMfa({grant_type:n,mfaToken:e.mfaToken,scope:r,audience:i,otp:e.otp,oob_code:e.oobCode,binding_code:e.bindingCode,recovery_code:e.recoveryCode});return this.contextManager.remove(e.mfaToken),t}catch(o){if(o instanceof E)this.setMFAAuthDetails(o.mfa_token,r,i,o.mfa_requirements);else if(o instanceof ui)throw new ui(o.error,o.error_description);throw o}}}const pi=new p;class fi{constructor(e){let t,n;if(this.userCache=(new ie).enclosedCache,this.activeLockKeys=new Set,this.defaultOptions={authorizationParams:{scope:"openid profile email"},useRefreshTokensFallback:!1,useFormData:!0},this._releaseLockOnPageHide=async()=>{const e=Array.from(this.activeLockKeys);for(const t of e)await pi.releaseLock(t);this.activeLockKeys.clear(),window.removeEventListener("pagehide",this._releaseLockOnPageHide)},this.options=Object.assign(Object.assign(Object.assign({},this.defaultOptions),e),{authorizationParams:Object.assign(Object.assign({},this.defaultOptions.authorizationParams),e.authorizationParams)}),"undefined"!=typeof window&&(()=>{if(!I())throw new Error("For security reasons, `window.crypto` is required to run `auth0-spa-js`.");if(void 0===I().subtle)throw new Error("\n      auth0-spa-js must run on a secure origin. See https://github.com/auth0/auth0-spa-js/blob/main/FAQ.md#why-do-i-get-auth0-spa-js-must-run-on-a-secure-origin for more information.\n    ")})(),e.cache&&e.cacheLocation,e.cache)n=e.cache;else{if(t=e.cacheLocation||"memory",!Ae(t))throw new Error('Invalid cache location "'.concat(t,'"'));n=Ae(t)()}var o,r;this.httpTimeoutMs=e.httpTimeoutInSeconds?1e3*e.httpTimeoutInSeconds:1e4,this.cookieStorage=!1===e.legacySameSiteCookie?me:ye,this.orgHintCookieName=(o=this.options.clientId,"auth0.".concat(o,".organization_hint")),this.isAuthenticatedCookieName=(r=this.options.clientId,"auth0.".concat(r,".is.authenticated")),this.sessionCheckExpiryDays=e.sessionCheckExpiryDays||1;const i=e.useCookiesForTransactions?this.cookieStorage:we;var a;this.scope=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),r=2;r<n;r++)o[r-2]=arguments[r];if("object"!=typeof e)return{default:te(t,e,...o)};let i={default:te(t,...o)};return Object.keys(e).forEach(n=>{const r=e[n];i[n]=te(t,r,...o)}),i}(this.options.authorizationParams.scope,"openid",this.options.useRefreshTokens?"offline_access":""),this.transactionManager=new se(i,this.options.clientId,this.options.cookieDomain),this.nowProvider=this.options.nowProvider||y,this.cacheManager=new ae(n,n.allKeys?void 0:new Ee(n,this.options.clientId),this.nowProvider),this.dpop=this.options.useDpop?new xe(this.options.clientId):void 0,this.domainUrl=(a=this.options.domain,/^https?:\/\//.test(a)?a:"https://".concat(a)),this.tokenIssuer=((e,t)=>e?e.startsWith("https://")?e:"https://".concat(e,"/"):"".concat(t,"/"))(this.options.issuer,this.domainUrl);const s="".concat(this.domainUrl,"/me/"),c=this.createFetcher(Object.assign(Object.assign({},this.options.useDpop&&{dpopNonceId:"__auth0_my_account_api__"}),{getAccessToken:()=>this.getTokenSilently({authorizationParams:{scope:"create:me:connected_accounts",audience:s},detailedResponse:!0})}));this.myAccountApi=new De(c,s),this.authJsClient=new $r({domain:this.options.domain,clientId:this.options.clientId}),this.mfa=new hi(this.authJsClient.mfa,this),"undefined"!=typeof window&&window.Worker&&this.options.useRefreshTokens&&"memory"===t&&(this.options.workerUrl?this.worker=new Worker(this.options.workerUrl):this.worker=new _e)}getConfiguration(){return Object.freeze({domain:this.options.domain,clientId:this.options.clientId})}_url(e){const t=this.options.auth0Client||m,n=j(t,!0),o=encodeURIComponent(btoa(JSON.stringify(n)));return"".concat(this.domainUrl).concat(e,"&auth0Client=").concat(o)}_authorizeUrl(e){return this._url("/authorize?".concat(D(e)))}async _verifyIdToken(e,t,n){const o=await this.nowProvider();return(e=>{if(!e.id_token)throw new Error("ID token is required but missing");const t=(e=>{const t=e.split("."),[n,o,r]=t;if(3!==t.length||!n||!o||!r)throw new Error("ID token could not be decoded");const i=JSON.parse(L(o)),a={__raw:e},s={};
1return Object.keys(i).forEach(e=>{a[e]=i[e],ue.includes(e)||(s[e]=i[e])}),{encoded:{header:n,payload:o,signature:r},header:JSON.parse(L(n)),claims:a,user:s}})(e.id_token);if(!t.claims.iss)throw new Error("Issuer (iss) claim must be a string present in the ID token");if(t.claims.iss!==e.iss)throw new Error('Issuer (iss) claim mismatch in the ID token; expected "'.concat(e.iss,'", found "').concat(t.claims.iss,'"'));if(!t.user.sub)throw new Error("Subject (sub) claim must be a string present in the ID token");if("RS256"!==t.header.alg)throw new Error('Signature algorithm of "'.concat(t.header.alg,'" is not supported. Expected the ID token to be signed with "RS256".'));if(!t.claims.aud||"string"!=typeof t.claims.aud&&!Array.isArray(t.claims.aud))throw new Error("Audience (aud) claim must be a string or array of strings present in the ID token");if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e.aud))throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but was not one of "').concat(t.claims.aud.join(", "),'"'));if(t.claims.aud.length>1){if(!t.claims.azp)throw new Error("Authorized Party (azp) claim must be a string present in the ID token when Audience (aud) claim has multiple values");if(t.claims.azp!==e.aud)throw new Error('Authorized Party (azp) claim mismatch in the ID token; expected "'.concat(e.aud,'", found "').concat(t.claims.azp,'"'))}}else if(t.claims.aud!==e.aud)throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but found "').concat(t.claims.aud,'"'));if(e.nonce){if(!t.claims.nonce)throw new Error("Nonce (nonce) claim must be a string present in the ID token");if(t.claims.nonce!==e.nonce)throw new Error('Nonce (nonce) claim mismatch in the ID token; expected "'.concat(e.nonce,'", found "').concat(t.claims.nonce,'"'))}if(e.max_age&&!ce(t.claims.auth_time))throw new Error("Authentication Time (auth_time) claim must be a number present in the ID token when Max Age (max_age) is specified");if(null==t.claims.exp||!ce(t.claims.exp))throw new Error("Expiration Time (exp) claim must be a number present in the ID token");if(!ce(t.claims.iat))throw new Error("Issued At (iat) claim must be a number present in the ID token");const n=e.leeway||60,o=new Date(e.now||Date.now()),r=new Date(0);if(r.setUTCSeconds(t.claims.exp+n),o>r)throw new Error("Expiration Time (exp) claim error in the ID token; current time (".concat(o,") is after expiration time (").concat(r,")"));if(null!=t.claims.nbf&&ce(t.claims.nbf)){const e=new Date(0);if(e.setUTCSeconds(t.claims.nbf-n),o<e)throw new Error("Not Before time (nbf) claim in the ID token indicates that this token can't be used just yet. Current time (".concat(o,") is before ").concat(e))}if(null!=t.claims.auth_time&&ce(t.claims.auth_time)){const r=new Date(0);if(r.setUTCSeconds(parseInt(t.claims.auth_time)+e.max_age+n),o>r)throw new Error("Authentication Time (auth_time) claim in the ID token indicates that too much time has passed since the last end-user authentication. Current time (".concat(o,") is after last auth at ").concat(r))}if(e.organization){const n=e.organization.trim();if(n.startsWith("org_")){const e=n;if(!t.claims.org_id)throw new Error("Organization ID (org_id) claim must be a string present in the ID token");if(e!==t.claims.org_id)throw new Error('Organization ID (org_id) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_id,'"'))}else{const e=n.toLowerCase();if(!t.claims.org_name)throw new Error("Organization Name (org_name) claim must be a string present in the ID token");if(e!==t.claims.org_name)throw new Error('Organization Name (org_name) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_name,'"'))}}return t})({iss:this.tokenIssuer,aud:this.options.clientId,id_token:e,nonce:t,organization:n,leeway:this.options.leeway,max_age:(r=this.options.authorizationParams.max_age,"string"!=typeof r?r:parseInt(r,10)||void 0),now:o});var r}_processOrgHint(e){e?this.cookieStorage.save(this.orgHintCookieName,e,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}):this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain})}async _prepareAuthorizeUrl(e,t,n){var o;const r=x(O()),i=x(O()),a=O(),s=await K(a),c=U(s),u=await(null===(o=this.dpop)||void 0===o?void 0:o.calculateThumbprint()),l=(h=this.options,p=this.scope,f=e,m=r,y=i,w=c,g=e.redirect_uri||this.options.authorizationParams.redirect_uri||n,v=null==t?void 0:t.response_mode,b=u,Object.assign(Object.assign(Object.assign({client_id:h.clientId},h.authorizationParams),f),{scope:ne(p,f.scope,f.audience),response_type:"code",response_mode:v||"query",state:m,nonce:y,redirect_uri:g||h.authorizationParams.redirect_uri,code_challenge:w,code_challenge_method:"S256",dpop_jkt:b})),d=this._authorizeUrl(l);var h,p,f,m,y,w,g,v,b;return{nonce:i,code_verifier:a,scope:l.scope,audience:l.audience||"default",redirect_uri:l.redirect_uri,state:r,url:d}}async loginWithPopup(e,t){var n;if(e=e||{},!(t=t||{}).popup&&(t.popup=(()=>{const e=window.screenX+(window.innerWidth-400)/2,t=window.screenY+(window.innerHeight-600)/2;return window.open("","auth0:authorize:popup","left=".concat(e,",top=").concat(t,",width=").concat(400,",height=").concat(600,",resizable,scrollbars=yes,status=1"))})(),!t.popup))throw new S;const o=await this._prepareAuthorizeUrl(e.authorizationParams||{},{response_mode:"web_message"},window.location.origin);t.popup.location.href=o.url;const r=await(i=Object.assign(Object.assign({},t),{timeoutInSeconds:t.timeoutInSeconds||this.options.authorizeTimeoutInSeconds||60}),new Promise((e,t)=>
1{let n;const o=setInterval(()=>{i.popup&&i.popup.closed&&(clearInterval(o),clearTimeout(r),window.removeEventListener("message",n,!1),t(new k(i.popup)))},1e3),r=setTimeout(()=>{clearInterval(o),t(new _(i.popup)),window.removeEventListener("message",n,!1)},1e3*(i.timeoutInSeconds||60));n=function(a){if(a.data&&"authorization_response"===a.data.type){if(clearTimeout(r),clearInterval(o),window.removeEventListener("message",n,!1),!1!==i.closePopup&&i.popup.close(),a.data.response.error)return t(w.fromPayload(a.data.response));e(a.data.response)}},window.addEventListener("message",n)}));var i;if(o.state!==r.state)throw new w("state_mismatch","Invalid state");const a=(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization;await this._requestToken({audience:o.audience,scope:o.scope,code_verifier:o.code_verifier,grant_type:"authorization_code",code:r.code,redirect_uri:o.redirect_uri},{nonceIn:o.nonce,organization:a})}async getUser(){var e;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.user}async getIdTokenClaims(){var e;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.claims}async loginWithRedirect(){var t;const n=Pe(arguments.length>0&&void 0!==arguments[0]?arguments[0]:{}),{openUrl:o,fragment:r,appState:i}=n,a=e(n,["openUrl","fragment","appState"]),s=(null===(t=a.authorizationParams)||void 0===t?void 0:t.organization)||this.options.authorizationParams.organization,c=await this._prepareAuthorizeUrl(a.authorizationParams||{}),{url:u}=c,l=e(c,["url"]);this.transactionManager.create(Object.assign(Object.assign(Object.assign({},l),{appState:i,response_type:ge.Code}),s&&{organization:s}));const d=r?"".concat(u,"#").concat(r):u;o?await o(d):window.location.assign(d)}async handleRedirectCallback(){const e=(arguments.length>0&&void 0!==arguments[0]?arguments[0]:window.location.href).split("?").slice(1);if(0===e.length)throw new Error("There are no query params available for parsing.");const t=this.transactionManager.get();if(!t)throw new w("missing_transaction","Invalid state");this.transactionManager.remove();const n=(e=>{e.indexOf("#")>-1&&(e=e.substring(0,e.indexOf("#")));const t=new URLSearchParams(e);return{state:t.get("state"),code:t.get("code")||void 0,connect_code:t.get("connect_code")||void 0,error:t.get("error")||void 0,error_description:t.get("error_description")||void 0}})(e.join(""));return t.response_type===ge.ConnectCode?this._handleConnectAccountRedirectCallback(n,t):this._handleLoginRedirectCallback(n,t)}async _handleLoginRedirectCallback(e,t){const{code:n,state:o,error:r,error_description:i}=e;if(r)throw new g(r,i||r,o,t.appState);if(!t.code_verifier||t.state&&t.state!==o)throw new w("state_mismatch","Invalid state");const a=t.organization,s=t.nonce,c=t.redirect_uri;return await this._requestToken(Object.assign({audience:t.audience,scope:t.scope,code_verifier:t.code_verifier,grant_type:"authorization_code",code:n},c?{redirect_uri:c}:{}),{nonceIn:s,organization:a}),{appState:t.appState,response_type:ge.Code}}async _handleConnectAccountRedirectCallback(e,t){const{connect_code:n,state:o,error:r,error_description:i}=e;if(r)throw new v(r,i||r,t.connection,o,t.appState);if(!n)throw new w("missing_connect_code","Missing connect code");if(!(t.code_verifier&&t.state&&t.auth_session&&t.redirect_uri&&t.state===o))throw new w("state_mismatch","Invalid state");const a=await this.myAccountApi.completeAccount({auth_session:t.auth_session,connect_code:n,redirect_uri:t.redirect_uri,code_verifier:t.code_verifier});return Object.assign(Object.assign({},a),{appState:t.appState,response_type:ge.ConnectCode})}async checkSession(e){if(!this.cookieStorage.get(this.isAuthenticatedCookieName)){if(!this.cookieStorage.get("auth0.is.authenticated"))return;this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove("auth0.is.authenticated")}try{await this.getTokenSilently(e)}catch(t){}}async getTokenSilently(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var t,n;const o=Object.assign(Object.assign({cacheMode:"on"},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:ne(this.scope,null===(t=e.authorizationParams)||void 0===t?void 0:t.scope,(null===(n=e.authorizationParams)||void 0===n?void 0:n.audience)||this.options.authorizationParams.audience)})}),r=await((e,t)=>{let n=ke[t];return n||(n=e().finally(()=>{delete ke[t],n=null}),ke[t]=n),n})(()=>this._getTokenSilently(o),"".concat(this.options.clientId,"::").concat(o.authorizationParams.audience,"::").concat(o.authorizationParams.scope));return e.detailedResponse?r:null==r?void 0:r.access_token}async _getTokenSilently(t){const{cacheMode:n}=t,o=e(t,["cacheMode"]);if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||"default",clientId:this.options.clientId,cacheMode:n});if(e)return e}if("cache-only"===n)return;const r=(i=this.options.clientId,a=o.authorizationParams.audience||"default","".concat("auth0.lock.getTokenSilently",".").concat(i,".").concat(a));var i,a;if(!(await Se(()=>pi.acquireLock(r,5e3),10)))throw new b;this.activeLockKeys.add(r),1===this.activeLockKeys.size&&window.addEventListener("pagehide",this._releaseLockOnPageHide);try{if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||"default",clientId:this.options.clientId});if(e)return e}const e=this.options.useRefreshTokens?await this._getTokenUsingRefreshToken(o):await this._getTokenFromIFrame(o),{id_token:t,token_type:r,access_token:i,oauthTokenScope:a,expires_in:s}=e;return Object.assign(Object.assign({id_token:t,token_type:r,access_token:i},a?{scope:a}:null),{expires_in:s})}finally{await pi.releaseLock(r),this.activeLockKeys.delete(r),0===this.activeLockKeys.size&&window.removeEventListener("pagehide",this._releaseLockOnPageHide)}}async getTokenWithPopup(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{};var n,o;const r=Object.assign(Object.assign({},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:ne(this.scope,null===(n=e.authorizationParams)||void 0===n?void 0:n.scope,(null===(o=e.authorizationParams)||void 0===o?void 0:o.audience)||this.options.authorizationParams.audience)})});return t=Object.assign(Object.assign({},f),t),await this.loginWithPopup(r,t),(await this.cacheManager.get(new oe({scope:r.authorizationParams.scope,audience:r.authorizationParams.audience||"default",clientId:this.options.clientId}),void 0,this.options.useMrrt)).access_token}async isAuthenticated(){return!!(await this.getUser())}_buildLogoutUrl(t){null!==t.clientId?t.clientId=t.clientId||this.options.clientId:delete t.clientId;const n=t.logoutParams||{},{federated:o}=n,r=e(n,["federated"]),i=o?"&federated":"";return this._url("/v2/logout?".concat(D(Object.assign({clientId:t.clientId},r))))+i}async logout(){let t=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var n;const o=Pe(t),{openUrl:r}=o,i=e(o,["openUrl"]);null===t.clientId?await this.cacheManager.clear():await this.cacheManager.clear(t.clientId||this.options.clientId),this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(this.isAuthenticatedCookieName,{cookieDomain:this.options.cookieDomain}),this.userCache.remove("@@user@@"),await(null===(n=this.dpop)||void 0===n?void 0:n.clear());const a=this._buildLogoutUrl(i);r?await r(a):!1!==r&&window.location.assign(a)}async _getTokenFromIFrame(e){const t=(n=this.options.clientId,"".concat("auth0.lock.getTokenFromIFrame",".").concat(n));var n;if(!(await Se(()=>pi.acquireLock(t,5e3),10)))throw new b;try{const t=Object.assign(Object.assign({},e.authorizationParams),{prompt:"none"}),n=this.cookieStorage.get(this.orgHintCookieName);n&&!t.organization&&(t.organization=n);const{url:r,state:i,nonce:a,code_verifier:s,redirect_uri:c,scope:u,audience:l}=await this._prepareAuthorizeUrl(t,{response_mode:"web_message"},window.location.origin);if(window.crossOriginIsolated)throw new w("login_required","The application is running in a Cross-Origin Isolated context, silently retrieving a token without refresh token is not possible.");const d=e.timeoutInSeconds||this.options.authorizeTimeoutInSeconds;let h;try{h=new URL(this.domainUrl).origin}catch(o){h=this.domainUrl}const p=await function(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:60;return new Promise((o,r)=>{const i=window.document.createElement("iframe");i.setAttribute("width","0"),i.setAttribute("height","0"),i.style.display="none";const a=()=>{window.document.body.contains(i)&&(window.document.body.removeChild(i),window.removeEventListener("message",s,!1))};let s;const c=setTimeout(()=>{r(new b),a()},1e3*n);s=function(e){if(e.origin!=t)return;if(!e.data||"authorization_response"!==e.data.type)return;const n=e.source;n&&n.close(),e.data.response.error?r(w.fromPayload(e.data.response)):o(e.data.response),clearTimeout(c),window.removeEventListener("message",s,!1),setTimeout(a,2e3)},window.addEventListener("message",s,!1),window.document.body.appendChild(i),i.setAttribute("src",e)})}(r,h,d);if(i!==p.state)throw new w("state_mismatch","Invalid state");const f=await this._requestToken(Object.assign(Object.assign({},e.authorizationParams),{code_verifier:s,code:p.code,grant_type:"authorization_code",redirect_uri:c,timeout:e.authorizationParams.timeout||this.httpTimeoutMs}),{nonceIn:a,organization:t.organization});return Object.assign(Object.assign({},f),{scope:u,oauthTokenScope:f.scope,audience:l})}catch(o){throw"login_required"===o.error&&this.logout({openUrl:!1}),o}finally{await pi.releaseLock(t)}}async _getTokenUsingRefreshToken(e){var t,n;const o=await this.cacheManager.get(new oe({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||"default",clientId:this.options.clientId}),void 0,this.options.useMrrt);if(!(o&&o.refresh_token||this.worker)){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw new T(e.authorizationParams.audience||"default",e.authorizationParams.scope)}const r=e.authorizationParams.redirect_uri||this.options.authorizationParams.redirect_uri||window.location.origin,i="number"==typeof e.timeoutInSeconds?1e3*e.timeoutInSeconds:null,a=((e,t,n,o)=>{var r;
1if(e&&n&&o){if(t.audience!==n)return t.scope;const e=o.split(" "),i=(null===(r=t.scope)||void 0===r?void 0:r.split(" "))||[],a=i.every(t=>e.includes(t));return e.length>=i.length&&a?o:t.scope}return t.scope})(this.options.useMrrt,e.authorizationParams,null==o?void 0:o.audience,null==o?void 0:o.scope);try{const t=await this._requestToken(Object.assign(Object.assign(Object.assign({},e.authorizationParams),{grant_type:"refresh_token",refresh_token:o&&o.refresh_token,redirect_uri:r}),i&&{timeout:i}),{scopesToRequest:a});if(t.refresh_token&&(null==o?void 0:o.refresh_token)&&await this.cacheManager.updateEntry(o.refresh_token,t.refresh_token),this.options.useMrrt&&(s=null==o?void 0:o.audience,c=null==o?void 0:o.scope,u=e.authorizationParams.audience,l=e.authorizationParams.scope,!(s===u&&Re(l,c)||Re(a,t.scope)))){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);await this.cacheManager.remove(this.options.clientId,e.authorizationParams.audience,e.authorizationParams.scope);const n=((e,t)=>{const n=(null==e?void 0:e.split(" "))||[],o=(null==t?void 0:t.split(" "))||[];return n.filter(e=>-1==o.indexOf(e)).join(",")})(a,t.scope);throw new A(e.authorizationParams.audience||"default",n)}return Object.assign(Object.assign({},t),{scope:e.authorizationParams.scope,oauthTokenScope:t.scope,audience:e.authorizationParams.audience||"default"})}catch(d){if(d.message){if(d.message.includes("user is blocked"))throw await this.logout({openUrl:!1}),d;if((d.message.includes("Missing Refresh Token")||d.message.includes("invalid refresh token"))&&this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e)}throw d instanceof E&&this.mfa.setMFAAuthDetails(d.mfa_token,null===(t=e.authorizationParams)||void 0===t?void 0:t.scope,null===(n=e.authorizationParams)||void 0===n?void 0:n.audience,d.mfa_requirements),d}var s,c,u,l}async _saveEntryInCache(t){const{id_token:n,decodedToken:o}=t,r=e(t,["id_token","decodedToken"]);this.userCache.set("@@user@@",{id_token:n,decodedToken:o}),await this.cacheManager.setIdToken(this.options.clientId,t.id_token,t.decodedToken),await this.cacheManager.set(r)}async _getIdTokenFromCache(){const e=this.options.authorizationParams.audience||"default",t=this.scope[e],n=await this.cacheManager.getIdToken(new oe({clientId:this.options.clientId,audience:e,scope:t})),o=this.userCache.get("@@user@@");return n&&n.id_token===(null==o?void 0:o.id_token)?o:(this.userCache.set("@@user@@",n),n)}async _getEntryFromCache(e){let{scope:t,audience:n,clientId:o,cacheMode:r}=e;const i=await this.cacheManager.get(new oe({scope:t,audience:n,clientId:o}),60,this.options.useMrrt,r);if(i&&i.access_token){const{token_type:e,access_token:t,oauthTokenScope:n,expires_in:o}=i,r=await this._getIdTokenFromCache();return r&&Object.assign(Object.assign({id_token:r.id_token,token_type:e||"Bearer",access_token:t},n?{scope:n}:null),{expires_in:o})}}async _requestToken(e,t){var n,o;const{nonceIn:r,organization:i,scopesToRequest:a}=t||{},s=await ee(Object.assign(Object.assign({baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,useMrrt:this.options.useMrrt,dpop:this.dpop},e),{scope:a||e.scope}),this.worker),c=await this._verifyIdToken(s.id_token,r,i);if("authorization_code"===e.grant_type){const e=await this._getIdTokenFromCache();(null===(o=null===(n=null==e?void 0:e.decodedToken)||void 0===n?void 0:n.claims)||void 0===o?void 0:o.sub)&&e.decodedToken.claims.sub!==c.claims.sub&&(await this.cacheManager.clear(this.options.clientId),this.userCache.remove("@@user@@"))}return await this._saveEntryInCache(Object.assign(Object.assign(Object.assign(Object.assign({},s),{decodedToken:c,scope:e.scope,audience:e.audience||"default"}),s.scope?{oauthTokenScope:s.scope}:null),{client_id:this.options.clientId})),this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this._processOrgHint(i||c.claims.org_id),Object.assign(Object.assign({},s),{decodedToken:c})}async loginWithCustomTokenExchange(e){return this._requestToken(Object.assign(Object.assign({},e),{grant_type:"urn:ietf:params:oauth:grant-type:token-exchange",subject_token:e.subject_token,subject_token_type:e.subject_token_type,scope:ne(this.scope,e.scope,e.audie
1nce||this.options.authorizationParams.audience),audience:e.audience||this.options.authorizationParams.audience,organization:e.organization||this.options.authorizationParams.organization}))}async exchangeToken(e){return this.loginWithCustomTokenExchange(e)}_assertDpop(e){if(!e)throw new Error("`useDpop` option must be enabled before using DPoP.")}getDpopNonce(e){return this._assertDpop(this.dpop),this.dpop.getNonce(e)}setDpopNonce(e,t){return this._assertDpop(this.dpop),this.dpop.setNonce(e,t)}generateDpopProof(e){return this._assertDpop(this.dpop),this.dpop.generateProof(e)}createFetcher(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};return new je(e,{isDpopEnabled:()=>!!this.options.useDpop,getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:null==e?void 0:e.audience},detailedResponse:!0})},getDpopNonce:()=>this.getDpopNonce(e.dpopNonceId),setDpopNonce:t=>this.setDpopNonce(t,e.dpopNonceId),generateDpopProof:e=>this.generateDpopProof(e)})}async connectAccountWithRedirect(e){const{openUrl:t,appState:n,connection:o,scopes:r,authorization_params:i,redirectUri:a=this.options.authorizationParams.redirect_uri||window.location.origin}=e;if(!o)throw new Error("connection is required");const s=x(O()),c=O(),u=await K(c),l=U(u),{connect_uri:d,connect_params:h,auth_session:p}=await this.myAccountApi.connectAccount({connection:o,scopes:r,redirect_uri:a,state:s,code_challenge:l,code_challenge_method:"S256",authorization_params:i});this.transactionManager.create({state:s,code_verifier:c,auth_session:p,redirect_uri:a,appState:n,connection:o,response_type:ge.ConnectCode});const f=new URL(d);f.searchParams.set("ticket",h.ticket),t?await t(f.toString()):window.location.assign(f)}async _requestTokenForMfa(t,n){const{mfaToken:o}=t,r=e(t,["mfaToken"]);return this._requestToken(Object.assign(Object.assign({},r),{mfa_token:o}),n)}}const mi={domain:"demo-travel-log.eu.auth0.com",clientId:"VkAQCMA8LZZz79mi0BWDm49gwo289Hff",redirectUri:window.location.origin+"/app.html",logoutRedirectUri:window.location.origin+"/index.html",scope:"openid profile email",audience:"https://spiky729.pythonanywhere.com"},yi="[email protected]",wi="HD-SHOP s.r.o.";let gi=null;async function vi(){gi=await async function(){const e=new fi({domain:mi.domain,clientId:mi.clientId,authorizationParams:{redirect_uri:mi.redirectUri,scope:mi.scope,audience:mi.audience},cacheLocation:"localstorage"});return await e.checkSession(),e}()}async function bi(){return!!gi&&await gi.isAuthenticated()}async function _i(){if(!gi)return;const e=await gi.getUser();if(!e)return;const t=await gi.getIdTokenClaims();if(t)for(const n of Object.keys(t))n.startsWith("https://")&&(e[n]=t[n]);return e}async function ki(){gi&&await gi.loginWithRedirect({authorizationParams:{redirect_uri:mi.redirectUri,ui_locales:"sk"}})}function Si(){gi&&gi.logout({logoutParams:{returnTo:mi.logoutRedirectUri}})}async function Ei(){if(!gi)return;const e=window.location.search;e.includes("code=")&&e.includes("state=")&&(await gi.handleRedirectCallback(),window.history.replaceState({},document.title,window.location.pathname))}const Ti=Object.freeze(Object.defineProperty({__proto__:null,getToken:async function(){if(!gi)return null;try{return await gi.getTokenSilently()}catch(ve){return null}},getUser:_i,getUserId:async function(){const e=await _i();return e?e.sub:null},handleCallback:Ei,init:vi,isAuthenticated:bi,login:ki,logout:Si},Symbol.toStringTag,{value:"Module"})),Ai="1.5.0";export{Ai as A,bi as a,Si as b,yi as c,wi as d,Ti as e,_i as g,Ei as h,vi as i,ki as l};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.