1import{r as e,bG as t,bO as i,dK as n,cy as s,dL as a,dM as r,bq as o,b4 as l,c3 as c,c4 as d,b3 as u,dN as p,cu as h,dO as A,cG as _,R as T,dP as g,dQ as E,dR as m,dS as I,dT as C,dk as R,dU as P,dV as S,dW as y,bw as f,bs as L,bM as N,c_ as O,dX as j,dY as D,cB as x,dZ as v,d_ as b,d$ as w,e0 as k,e1 as M,e2 as U,e3 as F,e4 as G}from"./MZk2sk3Q.js";import{W as B,B as z,P as V}from"./BM-92CBZ.js";import{D as q}from"./t2hC0EP0.js";import{D as K}from"./Z5VP5c1c.js";import{D as H}from"./UVfp44lh.js";import{F as J,e as W,a as $,q as Y,d as Q,h as Z,T as X,B as ee,A as te,Z as ie,f as ne,C as se,v as ae,z as re,E as oe,s as le,p as ce,b as de,_ as ue,c as pe,$ as he,O as Ae,o as _e}from"./r_90E_HP.js";import{E as Te}from"./BLz_EGKY.js";import{P as ge}from"./BoE8QyMS.js";import{F as Ee}from"./D6oVoAjQ.js";import{c as me,g as Ie,T as Ce,C as Re,i as Pe,a as Se,b as ye,p as fe,d as Le,M as Ne,e as Oe,f as je,h as De,G as xe,j as ve,k as be}from"./9VhZKnCR.js";import{U as we,i as ke}from"./8DkdnniB.js";import{A as Me,w as Ue,c as Fe}from"./BOUBkpjR.js";import{C as Ge}from"./Dur37L9A.js";import{F as Be}from"./CXOMndHZ.js";import{R as ze}from"./fUp3Wv8x.js";import{b as Ve,n as qe,r as Ke,A as He}from"./p6-b-ns9.js";import{C as Je}from"./BwkLPAw1.js";import{A as We}from"./Becx9I8r.js";import{b as $e,r as Ye}from"./B1otG8n1.js";import{D as Qe}from"./HVQRPxhf.js";import{F as Ze}from"./D5_PwlkE.js";import"./wz-rn5kw.js";import"./Bwpy_8dK.js";import"./DCpTMEt3.js";import"./9_mgoJfO.js";import"./BIDQScwC.js";import"./BZ8oOFgu.js";const Xe=["client_credentials","urn:ietf:params:oauth:grant-type:token-exchange"],et="enable_device_registration_dcr",tt="enable_mcp",it=e=>!!e?.[et],nt=e=>!!e?.[tt],st=e=>nt(e)||it(e),at=e=>e&&e.includes("//devhub.")?"https://devapi.lrinternal.com/identity/v2/manage":e&&e.includes("//staginghub.")?"https://stagingapi.lrinternal.com/identity/v2/manage":"https://api.loginradius.com/identity/v2/manage",rt=e=>!!e&&"object"==typeof e&&!Array.isArray(e),ot=(e,t)=>{const i=Array.isArray(e)?[...e]:{...e||{}};return Object.keys(t||{}).forEach(n=>{const s=t[n],a=e?.[n];Array.isArray(s)?i[n]=s:rt(s)&&rt(a)?i[n]=ot(a,s):i[n]=s}),i},lt=["authorization_code","urn:ietf:params:oauth:grant-type:device_code","password","implicit"],ct=e=>"public"===e?"none":"client_secret_post",dt=e=>"public"===e?.ClientType||"confidential"===e?.ClientType?e.ClientType:"none"===e?.TokenAuthMethod?"public":"confidential",ut=e=>{const t={...e||{}},i=t?.PushedAuthorizationRequest||{},n=t?.RichAuthorizationRequest||{},s=(e=>{const t=(Array.isArray(e)?e:[]).map(e=>String(e||"").trim().toLowerCase()).filter(Boolean);return t.filter((e,i)=>t.indexOf(e)===i)})(n?.AllowedTypes);return t.PushedAuthorizationRequest={IsEnabled:!!i?.IsEnabled||!!i?.IsRequired,IsRequired:!!i?.IsRequired},t.RichAuthorizationRequest={IsEnabled:!!n?.IsEnabled,AllowedTypes:s},t},{Text:pt}=W,ht=[{value:"openid",label:"OpenID (id_token)"},{value:"email",label:"Email address"},{value:"phone",label:"Phone"},{value:"profile",label:"Profile"},{value:"address",label:"Address"}],At=[{value:"client_secret_basic",label:"Client secret basic"},{value:"client_secret_post",label:"Client secret post"},{value:"client_secret_auto",label:"Client secret auto"},{value:"none",label:"None (public / no secret sent)"}],_t=[{value:"Base20",label:"Base20"},{value:"Digits",label:"Digits"},{value:"Alpha",label:"Alpha"},{value:"Alphanumeric",label:"Alphanumeric"}],Tt=e.forwardRef(({app:A,i18n:_,saving:T,onSave:g,initialRevealedSecret:E,canDeleteApp:m,onDeleteApp:I},C)=>{const[R]=J.useForm(),[P,S]=e.useState(!1),y=e.useRef(null),[f,L]=e.useState(!1),[N,O]=e.useState(void 0),[j,D]=e.useState(!1),[x,v]=e.useState(!1),[b,w]=e.useState(void 0),[k,M]=e.useState(!1),[U,F]=e.useState(void 0),G=t(e=>e.auth.appFeatures),z=t(e=>e.workflow.allWorkflows),V=t(e=>e.auth.appPermission),q=!!V?.API_EditThirdPartyCredentials,K=i();e.useEffect(()=>{z.Data||z.isLoading||z.isError||!G.isSuccess||!G.identity_orchestration||K(n())},[z.isLoading,G.isSuccess,G.identity_orchestration]);const H=e.useMemo(()=>function(e){return{AppName:e?.AppName||"",Description:e?.Description||"",ClientType:dt(e),DefaultWorkflow:e?.DefaultWorkflow||"",TokenAuthMethod:e?.TokenAuthMethod||"client_secret_post",GrantTypes:Array.isArray(e?.GrantTypes)?e.GrantTypes:[],AllowedScopes:Array.isArray(e?.AllowedScopes)?e.AllowedScopes:[],DeviceCodeConfig:{...e?.DeviceCodeConfig||{}},EnforcePKCE:e?.EnforcePKCE??!1,RegistrationCIMD:e?.Registration?.CIMD?.IsEnabled??!1,RegistrationDCR:e?.Registration?.DCR?.IsEnabled??!1}}(A),[A?.AppName,A?.Description,A?.ClientType,A?.DefaultWorkflow,A?.TokenAuthMethod,JSON.stringify(A?.GrantTypes||[]),JSON.stringify(A?.AllowedScopes||[]),JSON.stringify(A?.DeviceCodeConfig||{}),A?.EnforcePKCE,A?.Registration?.CIMD?.IsEnabled,A?.Registration?.DCR?.IsEnabled]),[ae,re]=e.useState(H.GrantTypes||[]),oe=J.useWatch("AllowedScopes",R)||[],le=J.useWatch("ClientType",R)||"confidential",ce=J.useWatch("TokenAuthMethod",R)||"client_secret_post",de=e.useMemo(()=>me(ae),[JSON.stringify(ae)]),ue=ae.includes("urn:ietf:params:oauth:grant-type:device_code"),pe=ae.includes("authorization_code"),he=(J.useWatch("EnforcePKCE",R)??H.EnforcePKCE)||!1,Ae=(J.useWatch("RegistrationCIMD",R)??H.RegistrationCIMD)||!1,_e=(J.useWatch("RegistrationDCR",R)??H.RegistrationDCR)||!1,Te=Ae||_e,Ee=ae.some(e=>["authorization_code","urn:ietf:params:oauth:grant-type:device_code","password","implicit","urn:ietf:params:oauth:grant-type:token-exchange"].includes(e)),Ne=1===de.length&&"tokenExchange"===de[0],Oe=String(A?.ClientId||""),je=!!G?.EnableMachineToMachineAuthentication,De=e=>Se(e)&&!je?_.MSG_FEATURE_NOT_AVAILABLE:ce===Ce&&ye(e)&&!de.includes(e)?_.APP_GRANT_UNAVAILABLE_WITH_NONE_AUTH:null,xe=Ie(de),ve=nt(G),be=it(G),Ve=st(G),qe="public"===le,Ke="none"!==ce;e.useEffect(()=>{y.current=He(H),R.resetFields(),re(H.GrantTypes||[]),S(!1),O(E)},[R,H,E]),e.useEffect(()=>{w(void 0),F(A?.Registration?.DCR?.InitialAccessTokenRotatedAt||void 0)},[A?.AppName]),e.useEffect(()=>{b||F(A?.Registration?.DCR?.InitialAccessTokenRotatedAt||void 0)},[A?.Registration?.DCR?.InitialAccessTokenRotatedAt,b]);const He=e=>({AppName:e.AppName,Description:e.Description||"",ClientType:e.ClientType||"confidential",DefaultWorkflow:e.DefaultWorkflow||"",TokenAuthMethod:e.TokenAuthMethod,GrantTypes:e.GrantTypes||[],AllowedScopes:e.AllowedScopes||[],DeviceCodeConfig:e.DeviceCodeConfig||{}
1,EnforcePKCE:e.EnforcePKCE??!1,...Ve?{Registration:{DCR:{IsEnabled:!!e.RegistrationDCR},...ve?{CIMD:{IsEnabled:!!e.RegistrationCIMD}}:{}}}:{}}),Je=()=>{const e=He(R.getFieldsValue(!0));S(!ke(e,y.current))},We=()=>R.validateFields().then(()=>!!(R.getFieldValue("GrantTypes")||[]).length&&(g(He(R.getFieldsValue(!0))),!0)).catch(()=>!1),$e=()=>{R.resetFields(),re(H.GrantTypes||[]),S(!1)},Ye=e=>{if(!e)return"";const t=new Date(e);return Number.isNaN(t.getTime())?"":t.toLocaleString()},Qe=!!U;e.useImperativeHandle(C,()=>({isDirty:()=>P,hasErrors:()=>R.getFieldsError().some(({errors:e})=>e.length>0)||0===(R.getFieldValue("GrantTypes")||[]).length,save:We,reset:$e}),[P,H]);const Ze=[{type:"string",name:"AppName",label:_.NAME,placeholder:"Enter application name",disabled:!0,rules:[{validator:(e,t)=>t&&t.trim()?t&&t.trim().length>60?Promise.reject(s(_,"App name").max_length.replace("%s","60")):t&&a(t)?Promise.reject(s(_,"App name").alpha_numeric_underscore_dash):t&&t.includes(" ")?Promise.reject(s(_,"App name").no_spaces):Promise.resolve():Promise.reject(s(_,"App name").required)}]}],Xe=[{type:"textarea",name:"Description",label:"Description",isOptional:!0,placeholder:"What this app is for. Visible to your team only, not end users.",rows:2,maxLength:255,rules:[{validator:(e,t)=>t&&t.length>255?Promise.reject(s(_,"Description").max_length.replace("%s","255")):Promise.resolve()}]}],et=[{type:"dropdown",name:"ClientType",label:"Client type",placeholder:"Select client type",values:[{text:"Confidential",value:"confidential"},{text:"Public",value:"public"}],extra:o.jsx(pt,{type:"secondary",children:qe?"For browser and mobile apps. Keep the secret on the server side only. Switching type just updates this guidance, not your saved settings or secrets.":"For apps with a trusted backend. Secret-based auth is the recommended default. Switching type just updates this guidance, not your saved settings or secrets."})}],tt=[{type:"dropdown",name:"DefaultWorkflow",label:_.DEFAULT_WORKFLOW_TITLE,placeholder:"Select a workflow",tooltipText:_.DEFAULT_WORKFLOW_TITLE_TOOLTIP,allowClear:!0,values:Array.isArray(z?.Data)?z.Data.map(e=>({text:e.Name,value:e.Name})):[]}],at=[{type:"multidropdown",name:"AllowedScopes",label:"Allowed scopes",placeholder:"Select scopes",values:ht.map(e=>({value:e.value,text:e.label}))}],rt=[{type:"dropdown",name:"TokenAuthMethod",label:_.FEDERATED_SSO_OPENID_FORM_TOKEN_METHOD,placeholder:"Select auth method",values:At.map(e=>({text:e.label,value:e.value,disabled:e.value===Ce&&xe}))}],ot=[{type:"string",name:["DeviceCodeConfig","VerificationUrl"],label:"Verification URL",extra:o.jsx(pt,{type:"secondary",children:"Enter the verification URL for users to manually enter their user code into their user agent."}),placeholder:"Enter URL",rules:[{validator:(e,t)=>t&&t.trim()?r(t)?Promise.resolve():Promise.reject(s(_,"Verification URL").valid_url):Promise.reject(s(_,"Verification URL").required)}]},{type:"string",name:["DeviceCodeConfig","AfterVerificationUrl"],label:"After verification URL",extra:o.jsx(pt,{type:"secondary",children:"Enter the redirection URL for users after successful authentication."}),placeholder:"Enter URL",rules:[{validator:(e,t)=>t&&t.trim()?r(t)?Promise.resolve():Promise.reject(s(_,"After verification URL").valid_url):Promise.reject(s(_,"After verification URL").required)}]},{type:"inputNumber",name:["DeviceCodeConfig","DeviceCodeExpire"],label:"Device code expire",extra:o.jsx(pt,{type:"secondary",children:"Enter the lifetime of the device code in seconds."}),min:0,precision:0,rules:[{validator:(e,t)=>null==t||""===t?Promise.resolve():Number.isInteger(Number(t))?Number(t)<0?Promise.reject(s(_,"Device code expire").integer):Promise.resolve():Promise.reject(s(_,"Device code expire").integer)}]},{type:"inputNumber",name:["DeviceCodeConfig","PollingInterval"],label:"Polling interval",extra:o.jsx(pt,{type:"secondary",children:"Enter the time in seconds. This is the minimum time the client should wait between polling requests to the token endpoint"}),min:0,precision:0,rules:[{validator:(e,t)=>null==t||""===t?Promise.resolve():Number.isInteger(Number(t))?Number(t)<0?Promise.reject(s(_,"Polling interval").integer):Promise.resolve():Promise.reject(s(_,"Polling interval").integer)}]},{type:"dropdown",name:["DeviceCodeConfig","UserCodeCharacterSet"],label:"User code
1character set",extra:o.jsx(pt,{type:"secondary",children:"Select the character set for the user code."}),placeholder:"Select character set",values:_t.map(e=>({text:e.label,value:e.value}))},{type:"string",name:["DeviceCodeConfig","UserCodeMask"],label:"User code mask",extra:o.jsx(pt,{type:"secondary",children:"Enter the user code pattern. For example, ***-*** generates ASD-QWE user code."})}],lt=oe.some(e=>"openid"!==e)&&!oe.includes("openid"),ct=[...ve?[{type:"switch",name:"RegistrationCIMD",label:"CIMD (Client ID Metadata Document)",description:_.APPLICATIONS_CIMD_HELP,disabled:!q}]:[],{type:"switch",name:"RegistrationDCR",label:"Dynamic Client Registration (DCR)",description:be?_.APPLICATIONS_DCR_DEVICE_HELP:_.APPLICATIONS_DCR_HELP,disabled:!q}];return o.jsxs(J,{form:R,layout:"vertical",requiredMark:!1,onValuesChange:Je,initialValues:H,children:[o.jsxs($,{direction:"vertical",size:16,style:{width:"100%"},children:[o.jsx(Be,{title:_.APP_GROUP_CREDENTIALS_TITLE,description:_.APP_GROUP_CREDENTIALS_DESCRIPTION,rightContent:o.jsxs($,{direction:"vertical",size:0,style:{width:"100%"},children:[o.jsx(Y,{schema:Ze}),o.jsx(Y,{schema:Xe}),o.jsx(Y,{schema:et}),o.jsxs(Q,{vertical:!0,gap:4,style:{marginBottom:16},children:[o.jsx(pt,{className:"font-medium",children:"Client ID"}),o.jsx(Z,{disabled:!0,value:Oe,suffix:o.jsx(Ge,{copyableContent:Oe,i18n:_,disabled:!1,permissions:["API_ViewThirdPartyCredentials"],noBorder:!0})}),_.APPLICATIONS_CLIENT_ID_HELP?o.jsx("div",{className:"form-item-extra",children:o.jsx(pt,{type:"secondary",children:_.APPLICATIONS_CLIENT_ID_HELP})}):null]}),o.jsxs(Q,{vertical:!0,gap:8,style:{marginBottom:24},children:[o.jsx(pt,{className:"font-medium",children:"Client secret"}),o.jsx(Z,{disabled:!0,type:N?"text":"password",value:N||"********",suffix:N?o.jsx(Ge,{copyableContent:N,i18n:_,disabled:!1,permissions:["API_ViewThirdPartyCredentials"],noBorder:!0}):o.jsx(ge,{permissions:["API_EditThirdPartyCredentials"],children:o.jsx(X,{title:_.RESET_SECRET_TOOLTIP,children:o.jsx(ee,{id:"btn_api_secret_show",type:"link",size:"small","aria-label":_.RESET_CLIENT_SECRET_TITLE,disabled:T,onClick:()=>D(!0),loading:f,icon:o.jsx(ze,{})})})})}),N?o.jsx(te,{type:"info",showIcon:!0,styles:Me,style:{marginTop:4},title:_.CLIENT_SECRET_SHOWN_ONCE}):null,qe?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,style:{marginTop:4},title:Ue(_.APPLICATIONS_PUBLIC_SECRET_WARNING)}):null]}),o.jsxs(Q,{vertical:!0,gap:12,style:{marginBottom:24},children:[o.jsx(Y,{schema:rt,dropLastMargin:!0}),qe&&Ke?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue("This method sends the client secret, so use it only from a server-side component. Public clients should use `none` instead.")}):null,qe||Ke?null:o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue("Confidential clients should authenticate with their secret. `none` means it's never verified. Consider `client_secret_post` or `client_secret_basic` instead.")})]}),G.identity_orchestration?o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx(Y,{schema:tt,dropLastMargin:!0}),Ee?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue("No workflow will run. This app has no grant that signs a user in, so the selected workflow won't execute until one is added.")})]}):null]})}),o.jsx(Be,{title:_.APP_GROUP_GRANT_TYPE_TITLE,description:_.APP_GROUP_GRANT_TYPE_DESCRIPTION,rightContent:o.jsxs($,{direction:"vertical",size:24,style:{width:"100%"},children:[o.jsxs($,{direction:"vertical",size:12,style:{width:"100%"},children:[0===ae.length?o.jsx(te,{type:"error",showIcon:!0,styles:Me,title:"Select at least one grant type."}):null,o.jsx(l,{gutter:[8,8],align:"stretch",children:Re.map(e=>{const t=De(e.id),i=null!==t,n=o.jsx(ie,{title:e.title,description:o.jsxs(o.Fragment,{children:[e.legacy?o.jsx("div",{style:{marginBottom:4},children:o.jsx(ne,{variant:"outlined",color:"warning",children:"Not recommended"})}):null,e.description,o.jsx("div",{children:o.jsx(ne,{bordered:!1,color:"blue",style:{fontFamily:"monospace",fontSize:11,whiteSpace:"normal",marginTop:6,color:c},children:e.grants.join(" ")})}),"keepSession"===e.id&&de.includes("keepSession")&&Pe(de)?o.jsx("div",{style:{marginTop:6},children:o.jsxs(pt,{style:{fontSize:12,color:d},children:["Needs the ",o.jsx("code",{children:"authorization_code"}),", ",o.jsx("code",{children:"device_code"}),", or ",o.jsx("code",{children:"password"})," grant to take effect."]})}):null]}),checked:de.includes(e.id),highlightWhenChecked:!0,disabled:i,onChange:t=>((e,t)=>
1{if((e=>null!==De(e))(e))return;const i=t?Array.from(new Set([...de,e])):de.filter(t=>t!==e),n="keepSession"===e?i:fe(i),s=Le(n);re(s),R.setFieldValue("GrantTypes",s),Je()})(e.id,t.target.checked)});return o.jsx(u,{span:12,children:t?o.jsx(X,{title:t,placement:"top",children:o.jsx("span",{style:{display:"block",width:"100%",height:"100%"},children:n})}):n},e.id)})}),Ne?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue("Token exchange needs a token source. Add a grant type that mints tokens (browser, device code, password, or machine-to-machine).")}):null]}),o.jsxs($,{direction:"vertical",size:12,style:{width:"100%"},children:[o.jsx(Y,{schema:[{type:"switch",name:"EnforcePKCE",label:"Enforce PKCE",description:"Requires a code verifier on every authorization code exchange, blocking interception attacks"}],dropLastMargin:!0}),he&&!pe?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue("PKCE is enabled but the `authorization_code` grant isn't, so it has nothing to protect. Enable the grant or turn PKCE off.")}):null]})]})}),o.jsx(Be,{title:"Scopes",description:Fe("Controls what the app can learn about the signed-in user. Add `openid` to issue an ID token (OpenID Connect). Without it, the app runs in plain OAuth 2.0 mode."),rightContent:o.jsxs($,{direction:"vertical",size:12,style:{width:"100%"},children:[o.jsx(Y,{schema:at,dropLastMargin:!0}),lt?o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue("Without `openid`, this app stays in OAuth 2.0 mode, with claims returned in the access token instead of an ID token.")}):null]})}),ue?o.jsx(Be,{title:_.APP_GROUP_DEVICE_TITLE,description:_.APP_GROUP_DEVICE_DESCRIPTION,rightContent:o.jsx(Y,{schema:ot})}):null,Ve?o.jsx(Be,{title:be?_.APPLICATIONS_DEVICE_REG_TITLE:"MCP client registration",description:be?_.APPLICATIONS_DEVICE_REG_DESC:"Controls how external clients may register against this application. Changes here also appear on the MCP Clients tab.",rightContent:o.jsxs($,{direction:"vertical",size:12,style:{width:"100%"},children:[o.jsx(Y,{schema:ct,dropLastMargin:!0}),ve&&Te?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue(_.CONSENT_SDK_VERSION_WARNING)}):null,be&&_e?o.jsxs(Q,{vertical:!0,gap:8,style:{marginTop:8},children:[o.jsx(pt,{className:"font-medium",children:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_LABEL}),o.jsx(Z,{disabled:!0,type:b?"text":"password",value:b||"********",suffix:b?o.jsx(Ge,{copyableContent:b,i18n:_,disabled:!1,permissions:["API_ViewThirdPartyCredentials"],noBorder:!0}):o.jsx(ge,{permissions:["API_EditThirdPartyCredentials"],children:o.jsx(X,{title:Qe?_.APPLICATIONS_DCR_REGISTRATION_TOKEN_ROTATE:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_GENERATE,children:o.jsx(ee,{type:"link",size:"small","aria-label":Qe?_.APPLICATIONS_DCR_REGISTRATION_TOKEN_ROTATE:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_GENERATE,disabled:T||P,onClick:()=>M(!0),loading:x,icon:o.jsx(ze,{})})})})}),o.jsx("div",{className:"form-item-extra",children:o.jsx(pt,{type:"secondary",children:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_HELP})}),Qe&&Ye(U)?o.jsxs(pt,{type:"secondary",children:[_.APPLICATIONS_DCR_REGISTRATION_TOKEN_LAST_ROTATED,": ",Ye(U)]}):null,b?o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_SHOWN_ONCE}):null,Qe||b?null:o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_MISSING})]}):null]})}):null,m&&I?o.jsx(se,{styles:{body:{padding:24}},style:{borderColor:"#ffccc7",background:"#fff2f0"},children:o.jsxs(Q,{justify:"space-between",align:"center",gap:24,children:[o.jsxs("div",{children:[o.jsx(W.Title,{level:5,style:{margin:0,paddingBottom:8},children:"Danger Zone"}),o.jsx(pt,{type:"secondary",children:"Deleting this application is a critical action that cannot be undone. It permanently removes all associated data and configuration, and any integration using its client ID or secret will stop working."})]}),o.jsx(ee,{danger:!0,type:"primary",onClick:I,style:{flexShrink:0},children:_.APPLICATIONS_DELETE_APPLICATION})]})}):null,o.jsx(J.Item,{shouldUpdate:!0,noStyle:!0,children:()=>{const e=R.getFieldsError().some(({errors:e})=>e.length>0)||0===ae.length;return o.jsx(we,{isDirty:P,onSave:We,onReset:$e,saveLoading:T,saveDisabled:e,permissions:["API_EditThirdPartyCredentials"]})}})]}),o.jsx(B,{open:j,onClose:()=>D(!1),onConfirm:async()=>{L(!0);try{const e=await p("/platform-configuration/sso/oauth/reset",{v:String(Date.now())},{AppName:H.AppName});if(e?.ErrorCode)throw new Error(e.Description||e.Message||"Request could not be processed.");const t=e?.ClientSecret||e?.Secret||e?.Data?.ClientSecret||e?.Data?.Secret||e?.Data?.ClientSecretKey||"";if(!t)return h("success",_.CLIENT_SECRET_SUCCESSFULLY_RESET),void D(!1);O(String(t)),h("success",_.CLIENT_SECRET_SUCCESSFULLY_RESET),D(!1)}catch(e){h("error",e?.message||"Request could not be processed.")}finally{L(!1)}},title:_.RESET_CLIENT_SECRET_TITLE,message:_.RESET_CLIENT_SECRET_MESSAGE,alertMessage:_.RESET_CLIENT_SECRET_ALERT,alertType:"warning",showCaution:!0,checkboxMessage:_.RESET_CLIENT_SECRET_CONFIRMATION,ButtonText:_.RESET_CLIENT_SECRET_BUTTON,dangerButton:!0,loading:f}),o.jsx(B,{open:k,onClose:()=>M(!1),onConfirm:async()=>
1{if(!P&&!T&&_e){v(!0);try{const e=await p("/platform-configuration/sso/oauth/dcr-registration-token",{v:String(Date.now())},{AppName:H.AppName});if(e?.ErrorCode)throw new Error(e.Description||e.Message||"Request could not be processed.");const t=e?.RegistrationToken||e?.Data?.RegistrationToken||"",i=e?.RotatedAt||e?.Data?.RotatedAt||(new Date).toISOString();if(!t)return h("success",_.APPLICATIONS_DCR_REGISTRATION_TOKEN_SUCCESS),void M(!1);w(String(t)),F(String(i)),h("success",_.APPLICATIONS_DCR_REGISTRATION_TOKEN_SUCCESS),M(!1)}catch(e){h("error",e?.message||"Request could not be processed.")}finally{v(!1)}}},title:Qe?_.APPLICATIONS_DCR_ROTATE_TITLE:_.APPLICATIONS_DCR_GENERATE_TITLE,message:Qe?_.APPLICATIONS_DCR_ROTATE_MESSAGE:_.APPLICATIONS_DCR_GENERATE_MESSAGE,alertMessage:Qe?_.APPLICATIONS_DCR_ROTATE_ALERT:void 0,alertType:"warning",showCaution:!0,checkboxMessage:Qe?_.APPLICATIONS_DCR_ROTATE_CONFIRMATION:_.APPLICATIONS_DCR_GENERATE_CONFIRMATION,ButtonText:Qe?_.APPLICATIONS_DCR_REGISTRATION_TOKEN_ROTATE:_.APPLICATIONS_DCR_REGISTRATION_TOKEN_GENERATE,dangerButton:Qe,loading:x})]})});Tt.displayName="GeneralTab";const gt=(e=[])=>e.map(e=>String(e||"").trim().toLowerCase()).filter(Boolean).filter((e,t,i)=>i.indexOf(e)===t),Et=(e,t)=>"STANDARD FIELDS"===t?(e||[]).filter(e=>!String(e).includes("cf_")).map(e=>({text:String(e),value:String(e)})):(e||[]).filter(e=>String(e).includes("cf_")).map(e=>({text:String(e).replace(/^cf_/,""),value:String(e)})),mt=e.forwardRef(({app:i,i18n:n,mappingFields:a,saving:l,onSave:c},d)=>{const[u]=J.useForm(),[p,h]=e.useState(!1),_=e.useRef(null),T=t(e=>e.auth.appFeatures),{EnableMappingTemplate:g=!1}=t(e=>e.auth.appBasicInfo),E=e.useRef(null),m=e.useRef(null),I=e.useMemo(()=>function(e){return{JwtTokenConfig:{Algorithm:e?.JwtTokenConfig?.Algorithm||"RS256",TokenTTL:e?.JwtTokenConfig?.TokenTTL??3600,IdTokenTTL:e?.JwtTokenConfig?.IdTokenTTL??3600},RefreshTokenTTL:e?.RefreshTokenTTL??86400,TokenAuthMethod:e?.TokenAuthMethod||"client_secret_post",ForceReAuthentication:e?.ForceReAuthentication??!1,SignedUserInfo:e?.SignedUserInfo??!1,PushedAuthorizationRequest:{IsEnabled:e?.PushedAuthorizationRequest?.IsEnabled??!1,IsRequired:e?.PushedAuthorizationRequest?.IsRequired??!1},RichAuthorizationRequest:{IsEnabled:e?.RichAuthorizationRequest?.IsEnabled??!1,AllowedTypes:gt(e?.RichAuthorizationRequest?.AllowedTypes||[]).length?gt(e?.RichAuthorizationRequest?.AllowedTypes||[]):[""]},IdTokenMappingTemplate:e?.IdTokenMappingTemplate,AccessTokenMappingTemplate:e?.AccessTokenMappingTemplate,IdTokenAudiences:e?.IdTokenAudiences?.length?e.IdTokenAudiences:[""],Mapping:e?.Mapping&&Object.entries(e.Mapping).length?Object.entries(e.Mapping).map(([e,t])=>({key:e,value:t||""})):[{key:"",value:"ID"}],Metadata:e?.Metadata&&Object.keys(e.Metadata).length?Object.keys(e.Metadata).map(t=>({key:t,value:e.Metadata[t]})):[{key:"",value:""}],RefreshTokenRotation:{ReuseInterval:e?.RefreshTokenRotation?.ReuseInterval||0},SubjectType:e?.SubjectType||"public",SectorIdentifierURI:e?.SectorIdentifierURI||""}}(i),[i?.AppName,i?.TokenAuthMethod,i?.RefreshTokenTTL,i?.ForceReAuthentication,i?.SignedUserInfo,i?.SubjectType,i?.SectorIdentifierURI,JSON.stringify(i?.RefreshTokenRotation||{}),JSON.stringify(i?.PushedAuthorizationRequest||{}),JSON.stringify(i?.RichAuthorizationRequest||{}),JSON.stringify(i?.JwtTokenConfig||{}),String(i?.IdTokenMappingTemplate||""),String(i?.AccessTokenMappingTemplate||""),JSON.stringify(i?.IdTokenAudiences||[]),JSON.stringify(i?.Mapping||{}),JSON.stringify(i?.Metadata||{})]),{standardFields:C,customFields:R}=e.useMemo(()=>(e=>{const t=(e||[]).filter(e=>!String(e).includes("cf_")),i=(e||[]).filter(e=>String(e).includes("cf_"));return{standardFields:t.map(e=>({label:String(e),value:String(e)})),customFields:i.map(e=>({label:String(e).replace(/^cf_/,""),value:String(e)}))}})(a),[a]),P=!!T?.enable_oauth_pushed_authz_request,S=!!T?.enable_oauth_rich_authz_request,y=P||S,f=J.useWatch(["PushedAuthorizationRequest","IsEnabled"],u)??!1,L=J.useWatch(["RichAuthorizationRequest","IsEnabled"],u)??!1,N=J.useWatch(["RichAuthorizationRequest","AllowedTypes"],u)||[],O="pairwise"===J.useWatch("SubjectType",u),j=Array.isArray(i?.GrantTypes)?i.GrantTypes:[],D=(Array.isArray(i?.AllowedScopes)?i.AllowedScopes:[]).includes("openid"),x=j.includes("authorization_code")||j.includes("urn:ietf:params:oauth:grant-type:device_code")||j.includes("password")||j.includes("implicit")||j.includes("urn:ietf:params:oauth:grant-type:token-exchange");e.useEffect(()=>{_.current=(e=>{const t={JwtTokenConfig:{Algorithm:e?.JwtTokenConfig?.Algorithm||I?.JwtTokenConfig?.Algorithm||"RS256",TokenTTL:e?.JwtTokenConfig?.TokenTTL,IdTokenTTL:e?.JwtTokenConfig?.IdTokenTTL},RefreshTokenTTL:e.RefreshTokenTTL,TokenAuthMethod:e.TokenAuthMethod,ForceReAuthentication:e.ForceReAuthentication,SignedUserInfo:e.SignedUserInfo,PushedAuthorizationRequest:{IsEnabled:e?.PushedAuthorizationRequest?.IsEnabled??I?.PushedAuthorizationRequest?.IsEnabled??!1,IsRequired:!!e?.PushedAuthorizationRequest?.IsEnabled&&(e?.PushedAuthorizationRequest?.IsRequired??I?.PushedAuthorizationRequest?.IsRequired??!1)},RichAuthorizationRequest:{IsEnabled:e?.RichAuthorizationRequest?.IsEnabled??I?.RichAuthorizationRequest?.IsEnabled??!1,AllowedTypes:gt(e?.RichAuthorizationRequest?.AllowedTypes||I?.RichAuthorizationRequest?.AllowedTypes||[])},RefreshTokenRotation:{ReuseInterval:e?.RefreshTokenRotation?.ReuseInterval||0},SubjectType:e?.SubjectType||"public",SectorIdentifierURI:e?.SectorIdentifierURI||""};
1if(t.IdTokenAudiences=(e.IdTokenAudiences||[]).filter(Boolean),g)t.IdTokenMappingTemplate=e.IdTokenMappingTemplate,t.AccessTokenMappingTemplate=e.AccessTokenMappingTemplate;else{t.Mapping=(e.Mapping||[]).reduce((e,t)=>(t?.key&&(e[t.key]=t.value),e),{});const i={};(e.Metadata||[]).forEach(e=>{e?.key&&(i[e.key]=e.value)}),t.Metadata=i}return t})(I),u.resetFields(),h(!1)},[u,I]);const v=()=>{const e=u.getFieldsValue(!0),t={JwtTokenConfig:{Algorithm:e?.JwtTokenConfig?.Algorithm||I?.JwtTokenConfig?.Algorithm||"RS256",TokenTTL:e?.JwtTokenConfig?.TokenTTL,IdTokenTTL:e?.JwtTokenConfig?.IdTokenTTL},RefreshTokenTTL:e.RefreshTokenTTL,TokenAuthMethod:e.TokenAuthMethod,ForceReAuthentication:e.ForceReAuthentication,SignedUserInfo:e.SignedUserInfo,PushedAuthorizationRequest:{IsEnabled:e?.PushedAuthorizationRequest?.IsEnabled??I?.PushedAuthorizationRequest?.IsEnabled??!1,IsRequired:!!e?.PushedAuthorizationRequest?.IsEnabled&&(e?.PushedAuthorizationRequest?.IsRequired??I?.PushedAuthorizationRequest?.IsRequired??!1)},RichAuthorizationRequest:{IsEnabled:e?.RichAuthorizationRequest?.IsEnabled??I?.RichAuthorizationRequest?.IsEnabled??!1,AllowedTypes:gt(e?.RichAuthorizationRequest?.AllowedTypes||I?.RichAuthorizationRequest?.AllowedTypes||[])},RefreshTokenRotation:{ReuseInterval:e?.RefreshTokenRotation?.ReuseInterval||0},SubjectType:e?.SubjectType||"public",SectorIdentifierURI:e?.SectorIdentifierURI||""};if(t.IdTokenAudiences=(e.IdTokenAudiences||[]).filter(Boolean),g)t.IdTokenMappingTemplate=e.IdTokenMappingTemplate,t.AccessTokenMappingTemplate=e.AccessTokenMappingTemplate;else{t.Mapping=(e.Mapping||[]).reduce((e,t)=>(t?.key&&(e[t.key]=t.value),e),{});const i={};(e.Metadata||[]).forEach(e=>{e?.key&&(i[e.key]=e.value)}),t.Metadata=i}return t},b=()=>u.validateFields().then(()=>(c(v()),!0)).catch(()=>!1),w=()=>{u.resetFields(),h(!1)};return e.useImperativeHandle(d,()=>({isDirty:()=>p,hasErrors:()=>u.getFieldsError().some(({errors:e})=>e.length>0),save:b,reset:w}),[p,I]),o.jsx(J,{form:u,layout:"vertical",requiredMark:!1,onValuesChange:()=>{h(!ke(v(),_.current))},initialValues:I,children:o.jsxs($,{direction:"vertical",size:16,style:{width:"100%"},children:[o.jsx(Be,{title:n.APP_GROUP_TOKEN_TITLE,description:n.APP_GROUP_TOKEN_DESCRIPTION,rightContent:o.jsxs($,{direction:"vertical",size:24,style:{width:"100%"},children:[o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx("div",{children:o.jsx(Y,{dropLastMargin:!0,schema:[{type:"inputNumber",name:["JwtTokenConfig","TokenTTL"],label:"Access token lifetime",suffix:"Secs",min:0,rules:[{validator:(e,t)=>null==t||""===t?Promise.reject(s(n,"Access token lifetime").required):t<0?Promise.reject(s(n,"Access token lifetime").is_natural):A(t)?Promise.reject(s(n,"Access token lifetime").integer):Promise.resolve()}]},{type:"inputNumber",name:"RefreshTokenTTL",label:"Refresh token lifetime",suffix:"Secs",min:0,dependencies:[["JwtTokenConfig","TokenTTL"]],rules:[{validator:(e,t)=>{if(null==t||""===t)return Promise.reject(s(n,"Refresh token lifetime").required);if(t<0)return Promise.reject(s(n,"Refresh token lifetime").is_natural);if(A(t))return Promise.reject(s(n,"Refresh token lifetime").integer);const i=u.getFieldValue(["JwtTokenConfig","TokenTTL"]);return"number"==typeof i&&t<=i?Promise.reject(s(n,"Refresh token lifetime").greater_than.replace("%s","the access token lifetime")):Promise.resolve()}}]},{type:"inputNumber",name:["JwtTokenConfig","IdTokenTTL"],label:"ID token lifetime",suffix:"Secs",min:0,rules:[{validator:(e,t)=>null==t||""===t?Promise.reject(s(n,"ID token lifetime").required):t<0?Promise.reject(s(n,"ID token lifetime").is_natural):A(t)?Promise.reject(s(n,"ID token lifetime").integer):Promise.resolve()}]}]})}),D&&!x?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue("No ID token will be issued. OpenID is configured but no grant signs a user in. Add a user grant, or remove the `openid` scope.")}):D?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue("No ID token is currently issued. This app is in OAuth 2.0 mode. Add the `openid` scope (General â Scopes) to issue one.")})]}),o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx("div",{children:o.jsx(Y,{dropLastMargin:!0,schema:[{type:"switch",name:"ForceReAuthentication",label:"Force reauthentication",description:n.APPLICATIONS_FORCE_REAUTH_HELP},{type:"switch",name:"SignedUserInfo",label:"Signed user info",description:n.APPLICATIONS_SIGNED_USERINFO_HELP}]})}),x?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue("Force reauthentication and Signed user info apply only to user sign-in grants (authorization code, device code, or password).")})]})]})}),o.jsx(Be,{title:n.APP_GROUP_SUBJECT_TYPE_TITLE,description:Fe(n.APP_GROUP_SUBJECT_TYPE_DESCRIPTION),rightContent:o.jsxs($,{direction:"vertical",size:12,style:{width:"100%"},children:[o.jsx(Y,{schema:[{type:"radiogroup",name:"SubjectType",label:n.APP_SUBJECT_TYPE_LABEL,disabled:!1,tooltipText:n.APP_SUBJECT_TYPE_TOOLTIP,values:[{text:n.APP_SUBJECT_TYPE_PUBLIC_LABEL,value:"public"},{text:n.APP_SUBJECT_TYPE_PAIRWISE_LABEL,value:"pairwise"}]}]}),O?o.jsxs(o.Fragment,{children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"string",name:"SectorIdentifierURI",label:n.APP_SECTOR_IDENTIFIER_URI_LABEL,placeholder:"https://example.com/redirect_uris.json",tooltipText:n.APP_SECTOR_IDENTIFIER_URI_TOOLTIP,isOptional:!0,rules:[{validator:(e,t)=>
1t&&t.trim()?t.trim().length>255?Promise.reject(s(n,n.APP_SECTOR_IDENTIFIER_URI_LABEL).max_length.replace("%s","255")):r(t.trim())?/^https:\/\//i.test(t.trim())?Promise.resolve():Promise.reject(n.APP_SECTOR_IDENTIFIER_URI_HTTPS_ERROR):Promise.reject(s(n,n.APP_SECTOR_IDENTIFIER_URI_LABEL).valid_url):Promise.resolve()}]}]}),o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue(n.APP_SUBJECT_TYPE_PAIRWISE_SUB_WARNING)})]}):null]})}),o.jsx(Be,{title:n.APP_GROUP_REFRESH_TOKEN_ROTATION_TITLE,description:n.APP_GROUP_REFRESH_TOKEN_ROTATION_DESCRIPTION,rightContent:o.jsx($,{direction:"vertical",size:12,style:{width:"100%"},children:o.jsx(Y,{schema:[{type:"inputNumber",name:["RefreshTokenRotation","ReuseInterval"],label:"Reuse grace period",suffix:"Secs",tooltipText:n.APP_REFRESH_TOKEN_ROTATION_REUSE_TOOLTIP,min:0,rules:[{validator:(e,t)=>null==t||""===t||t<0?Promise.reject(s(n,"Reuse grace period").is_natural):A(t)?Promise.reject(s(n,"Reuse grace period").integer):t>60?Promise.reject(s(n,"Reuse grace period").less_than_or_equal_to.replace("%s",String(60))):Promise.resolve()}]}]})})}),y?o.jsx(Be,{title:n.APP_GROUP_AUTHORIZATION_REQUESTS_TITLE,description:n.APP_GROUP_AUTHORIZATION_REQUESTS_DESCRIPTION,rightContent:o.jsxs($,{direction:"vertical",size:24,style:{width:"100%"},children:[x?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue("PAR and RAR act on `/authorize`. They take effect once a browser or device sign-in grant is enabled. Your configuration is preserved.")}),P?o.jsxs(Q,{vertical:!0,gap:24,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"switch",name:["PushedAuthorizationRequest","IsEnabled"],label:n.APPLICATIONS_PAR_TITLE,description:n.APPLICATIONS_PAR_ENABLED_HELP}]}),f?o.jsx(Y,{dropLastMargin:!0,schema:[{type:"switch",name:["PushedAuthorizationRequest","IsRequired"],label:n.APPLICATIONS_PAR_REQUIRED_LABEL,description:n.APPLICATIONS_PAR_REQUIRED_HELP}]}):null]}):null,S?o.jsxs(Q,{vertical:!0,gap:24,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"switch",name:["RichAuthorizationRequest","IsEnabled"],label:n.APPLICATIONS_RAR_TITLE,description:n.APPLICATIONS_RAR_ENABLED_HELP}]}),L?o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"inputlist",name:["RichAuthorizationRequest","AllowedTypes"],label:n.APPLICATIONS_RAR_ALLOWED_TYPES_LABEL,placeholder:n.APPLICATIONS_RAR_ALLOWED_TYPES_LABEL,addButtonText:"Add Type",isOptional:!0}]}),0===gt(N).length?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue(n.APPLICATIONS_RAR_EMPTY_TYPES_WARNING)}):null]}):null]}):null]})}):null,g?o.jsx(Be,{title:n.APP_GROUP_OIDC_AUDIENCES_TITLE,description:Fe(n.APP_GROUP_OIDC_AUDIENCES_DESCRIPTION),formSchema:[{type:"inputlist",label:"Audiences",name:"IdTokenAudiences",tooltipText:n.FEDERATED_SSO_OPENID_FORM_AUDIENCES_TOOLTIP,placeholder:"Enter audience",isOptional:!0,addButtonText:"Add"}]}):null,g?null:o.jsx(Be,{title:n.APP_GROUP_DATA_MAPPING_TITLE,description:n.APP_GROUP_DATA_MAPPING_DESCRIPTION,formSchema:[{type:"inputlist",label:"Audiences",name:"IdTokenAudiences",tooltipText:n.FEDERATED_SSO_OPENID_FORM_AUDIENCES_TOOLTIP,placeholder:"Enter audience",isOptional:!0,addButtonText:"Add",style:{marginBottom:32}},{type:"customfields",label:"Data mapping",isOptional:!0,name:"Mapping",description:n.FEDERATED_SSO_OPENID_FORM_DATA_MAPPING,tooltipText:n.FEDERATED_SSO_OPENID_FORM_DATA_MAPPING_TOOLTIP,defaultAddValues:{key:"",value:"ID"},customFields:[{type:"string",name:"key",label:"Key",placeholder:"Name"},{type:"customdropdown",name:"value",label:"Value",values:[{label:o.jsx("span",{children:"Standard fields"}),title:"standard-fields",options:Et(a,"STANDARD FIELDS")},{label:o.jsx("span",{children:"Custom fields"}),title:"custom-fields",options:Et(a,"CUSTOM FIELDS")}]}]},{type:"customfields",label:"Metadata",name:"Metadata",isOptional:!0,description:n.FEDERATED_SSO_OPENID_FORM_META_DATA,tooltipText:n.FEDERATED_SSO_OPENID_FORM_META_DATA_TOOLTIP,defaultAddValues:{key:"",value:""},addButtonText:"Add",customFields:[{type:"string",name:"key",label:"Key",placeholder:"Enter key"},{type:"string",name:"value",label:"Value",placeholder:"Enter value"}]}]}
1),g?o.jsx(Ne,{fieldName:"AccessTokenMappingTemplate",editorRef:m,i18n:n,title:n.MAPPING_ACCESS_TOKEN_TEMPLATE_TITLE,description:n.MAPPING_ACCESS_TOKEN_TEMPLATE_DESCRIPTION,jsonEditorTitle:n.MAPPING_JSON_EDITOR_TITLE,standardFields:C,customFields:R,invalidJSONMessage:n.INVALID_JSON,hideInfo:!0}):null,g?o.jsxs($,{direction:"vertical",size:12,style:{width:"100%"},children:[D&&!x?o.jsx(te,{type:"warning",showIcon:!0,styles:Me,title:Ue("ID token template won't be applied. OpenID is configured but no grant signs a user in.")}):D?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue("ID token template is inactive. Add the `openid` scope (General â Scopes) to apply it.")}),o.jsx(Ne,{fieldName:"IdTokenMappingTemplate",editorRef:E,i18n:n,title:n.MAPPING_ID_TOKEN_TEMPLATE_TITLE,description:n.MAPPING_ID_TOKEN_TEMPLATE_DESCRIPTION,jsonEditorTitle:n.MAPPING_JSON_EDITOR_TITLE,standardFields:C,customFields:R,invalidJSONMessage:n.INVALID_JSON,hideInfo:!0})]}):null,o.jsx(J.Item,{shouldUpdate:!0,noStyle:!0,children:()=>o.jsx(we,{isDirty:p,onSave:b,onReset:w,saveLoading:l,saveDisabled:u.getFieldsError().some(({errors:e})=>e.length>0),permissions:["API_EditThirdPartyCredentials"]})})]})})});mt.displayName="TokensTab";const It=(e,t)=>
1[{validator:(i,n)=>n&&n.trim()?n.trim().length>255?Promise.reject(s(e,t).max_length.replace("%s","255")):r(n)?Promise.resolve():Promise.reject(s(e,t).valid_url):Promise.resolve()}],Ct=(e,t)=>[{validator:(i,n)=>n&&n.trim()?Promise.resolve():Promise.reject(s(e,t).required)},...It(e,t)],Rt=(e,t)=>[{validator:(i,n)=>{if(!n||!n.trim())return Promise.resolve();if(n.trim().length>255)return Promise.reject(s(e,t).max_length.replace("%s","255"));const a=(e=>{const t=String(e||"").trim();if(!t)return"";if(t.includes("*"))return"Wildcards aren't allowed â register the exact redirect URL (OAuth 2.1 requires exact match).";if(t.includes("#"))return"Redirect URLs can't contain a fragment (#).";let i;try{i=new URL(t)}catch{return""}const n=i.protocol.replace(/:$/,"").toLowerCase(),s=i.hostname.toLowerCase();return"http"===n&&"localhost"!==s&&"127.0.0.1"!==s&&"[::1]"!==s?"Use HTTPS â plain HTTP is only allowed for localhost during development.":""})(n);return a?Promise.reject(new Error(a)):r(n)?Promise.resolve():Promise.reject(s(e,t).valid_url)}}],{Text:Pt}=W,St=e=>(Array.isArray(e)?e:[]).map(e=>String(e||"").trim()).filter(Boolean),yt=e.forwardRef(({app:n,i18n:a,saving:r,onSave:l},c)=>{const[d]=J.useForm(),[u,p]=e.useState(!1),h=e.useRef(null),A=i(),T=t(e=>e.auth.authConfig.hubDomain),g=t(e=>e.auth.appFeatures),E=t(e=>e.customDomainMapping),m=e.useMemo(()=>function(e){const t=Array.isArray(e?.LoginRedirectUri)?e.LoginRedirectUri:[],i=Array.isArray(e?.LogoutRedirectUri)?e.LogoutRedirectUri:[],n=Array.isArray(e?.AllowedCorsOrigin)?e.AllowedCorsOrigin:[],s=Array.isArray(e?.BackChannelLogout?.LogoutURIs)?e.BackChannelLogout.LogoutURIs:[];return{LoginRedirectUri:t.length?t:[""],LogoutRedirectUri:i.length?i:[""],EnableCorsOrigin:e?.EnableCorsOrigin??!1,AllowedCorsOrigin:n.length?n:[""],BackChannelLogout:{IsEnabled:e?.BackChannelLogout?.IsEnabled??!1,LogoutURIs:s.length?s:[""],LogoutTokenTTL:e?.BackChannelLogout?.LogoutTokenTTL??0}}}(n),[n?.AppName,JSON.stringify(n?.LoginRedirectUri||[]),JSON.stringify(n?.LogoutRedirectUri||[]),String(n?.EnableCorsOrigin??!1),JSON.stringify(n?.AllowedCorsOrigin||[]),JSON.stringify(n?.BackChannelLogout||{})]),I=J.useWatch("EnableCorsOrigin",d),C=J.useWatch(["BackChannelLogout","IsEnabled"],d);e.useEffect(()=>{E?.isSuccess||E?.isError||A(_())},[E?.isSuccess,E?.isError,A]);const R=Array.isArray(n?.GrantTypes)?n.GrantTypes:[],P=Array.isArray(n?.AllowedScopes)?n.AllowedScopes:[],S=R.includes("authorization_code"),y=R.includes("urn:ietf:params:oauth:grant-type:device_code"),f=R.includes("password"),L=R.includes("implicit"),N=R.includes("urn:ietf:params:oauth:grant-type:token-exchange"),O=P.includes("openid"),j="public"===dt(n),D=S||y||f||L||N,x=!O,v=!x&&!!g?.enable_oauth_pushed_authz_request&&!!n?.PushedAuthorizationRequest?.IsEnabled,b=e.useMemo(()=>{const e=localStorage.siteName||localStorage.getItem("siteName")||"",t=String(n?.AppName||"").trim(),i=(Array.isArray(E?.Data)?E.Data:[]).filter(e=>e?.IsDone&&e?.Domain),s=i.length>0?String(i[0].Domain||"").trim():"",a=e&&T?`https://${e}.${T.replace("//","")}`:"",r=(s?`https://${s}`:a).replace(/\/$/,"");if(!r||!t)return{issuer:"",authorization:"",deviceAuthorization:"",pushedAuthorizationRequest:"",token:"",userInfo:"",discovery:"",authServerMetadata:"",jwks:""};const o=x?"oauth":"oidc",l=`${r}/service/${o}/${t}`,c=`${r}/api/${o}/${t}`;return{issuer:l,authorization:`${l}/authorize`,deviceAuthorization:`${l}/device/authorize`,pushedAuthorizationRequest:`${c}/par`,token:`${c}/token`,userInfo:`${l}/userinfo`,discovery:`${l}/.well-known/openid-configuration`,authServerMetadata:`${l}/.well-known/oauth-authorization-server`,jwks:`${l}/jwks`}},[n?.AppName,T,E?.Data,x]),w=e.useMemo(()=>{const e=[{id:"issuer",label:a.APP_ENDPOINT_ISSUER_URL_LABEL,value:b.issuer,oidcOnly:!0},{id:"authorization",label:a.APP_ENDPOINT_AUTHORIZATION_URL_LABEL,value:b.authorization,oidcOnly:!1},{id:"device",label:a.APP_ENDPOINT_DEVICE_AUTHORIZATION_URL_LABEL,value:b.deviceAuthorization,oidcOnly:!1},{id:"par",label:a.APP_GROUP_OIDC_PAR_ENDPOINT_LABEL,value:b.pushedAuthorizationRequest,oidcOnly:!0,hide:!v},{id:"token",label:a.APP_ENDPOINT_TOKEN_URL_LABEL,value:b.token,oidcOnly:!1},{id:"userInfo",label:a.APP_ENDPOINT_USER_INFO_URL_LABEL,value:b.userInfo,oidcOnly:!1},{id:"discovery",label:a.APP_ENDPOINT_OPENID_DISCOVERY_LABEL,value:b.discovery,oidcOnly:!0},{id:"metadata",label:a.APP_ENDPOINT_OAUTH_METADATA_LABEL,value:b.authServerMetadata,oidcOnly:!1},{id:"jwks",label:a.APP_ENDPOINT_JWKS_URL_LABEL,value:b.jwks,oidcOnly:!0}];return x?e.filter(e=>!e.oidcOnly):e.filter(e=>!e.hide)},[a,x,b,v]);e.useEffect(()=>{h.current={LoginRedirectUri:St(m.LoginRedirectUri),LogoutRedirectUri:St(m.LogoutRedirectUri),EnableCorsOrigin:!!m.EnableCorsOrigin,AllowedCorsOrigin:St(m.AllowedCorsOrigin),BackChannelLogout:{IsEnabled:!!m?.BackChannelLogout?.IsEnabled,LogoutURIs:St(m?.BackChannelLogout?.LogoutURIs),LogoutTokenTTL:m?.BackChannelLogout?.LogoutTokenTTL??
10}},d.resetFields(),p(!1)},[d,m]);const k=()=>d.validateFields().then(()=>(l((()=>{const e=d.getFieldsValue(!0);return{LoginRedirectUri:St(e.LoginRedirectUri),LogoutRedirectUri:St(e.LogoutRedirectUri),EnableCorsOrigin:e.EnableCorsOrigin,AllowedCorsOrigin:St(e.AllowedCorsOrigin),BackChannelLogout:{...e.BackChannelLogout||{IsEnabled:!1,LogoutURIs:[],LogoutTokenTTL:0},LogoutURIs:St(e?.BackChannelLogout?.LogoutURIs)}}})()),!0)).catch(()=>!1),M=()=>{d.resetFields(),p(!1)};return e.useImperativeHandle(c,()=>({isDirty:()=>u,hasErrors:()=>d.getFieldsError().some(({errors:e})=>e.length>0),save:k,reset:M}),[u,m]),o.jsx(J,{form:d,layout:"vertical",requiredMark:!1,onValuesChange:()=>{const e=d.getFieldsValue(!0),t={LoginRedirectUri:St(e.LoginRedirectUri),LogoutRedirectUri:St(e.LogoutRedirectUri),EnableCorsOrigin:!!e.EnableCorsOrigin,AllowedCorsOrigin:St(e.AllowedCorsOrigin),BackChannelLogout:{IsEnabled:!!e?.BackChannelLogout?.IsEnabled,LogoutURIs:St(e?.BackChannelLogout?.LogoutURIs),LogoutTokenTTL:e?.BackChannelLogout?.LogoutTokenTTL??0}};p(!ke(t,h.current))},initialValues:m,children:o.jsxs($,{direction:"vertical",size:16,style:{width:"100%"},children:[o.jsx(Be,{title:x?a.APP_GROUP_OAUTH_ENDPOINTS_TITLE:a.APP_GROUP_OIDC_ENDPOINTS_TITLE,description:x?a.APP_GROUP_OAUTH_ENDPOINTS_DESCRIPTION:a.APP_GROUP_OIDC_ENDPOINTS_DESCRIPTION,rightContent:o.jsx($,{direction:"vertical",size:24,style:{width:"100%"},children:w.map(e=>{const t="authorization"!==(i=e.id)||S?"device"!==i||y?"userInfo"!==i||D&&O?"":a.APP_ENDPOINT_NOTE_USER_INFO:a.APP_ENDPOINT_NOTE_DEVICE:a.APP_ENDPOINT_NOTE_AUTHORIZATION;var i;return o.jsxs(Q,{vertical:!0,gap:4,children:[o.jsx(Pt,{className:"font-medium",children:e.label}),o.jsx(Z,{value:e.value,disabled:!0,suffix:o.jsx(Ge,{copyableContent:e.value||"",i18n:a,disabled:!e.value,permissions:[],noBorder:!0})}),t?o.jsx(Pt,{type:"secondary",style:{fontSize:13},children:t}):null]},e.id)})})}),o.jsx(Be,{title:a.APP_GROUP_REDIRECT_URL_TITLE,description:Fe(a.APP_GROUP_REDIRECT_URL_DESCRIPTION),rightContent:o.jsxs($,{direction:"vertical",size:24,style:{width:"100%"},children:[o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"inputlist",name:"LoginRedirectUri",label:a.APP_LOGIN_REDIRECT_URLS_LABEL,placeholder:a.APP_URL_PLACEHOLDER,isOptional:!0,addButtonText:a.ADD,rules:Rt(a,"Login redirect URL")}]}),S?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue(a.APP_LOGIN_REDIRECT_INACTIVE_NOTE)})]}),o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"inputlist",name:"LogoutRedirectUri",label:a.APP_LOGOUT_REDIRECT_URLS_LABEL,placeholder:a.APP_URL_PLACEHOLDER,isOptional:!0,addButtonText:a.ADD,rules:Rt(a,"Logout redirect URL")}]}),S&&O?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue(a.APP_LOGOUT_REDIRECT_INACTIVE_NOTE)})]})]})}),o.jsx(Be,{title:a.APP_GROUP_CROSS_ORIGIN_TITLE,description:a.APP_GROUP_CROSS_ORIGIN_DESCRIPTION,rightContent:o.jsxs(Q,{vertical:!0,gap:24,children:[o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"switch",name:"EnableCorsOrigin",label:a.APP_CORS_ORIGIN_LABEL,description:a.APPLICATIONS_CORS_TOGGLE_DESC}]}),j&&S?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue(a.APP_CORS_INACTIVE_NOTE)})]}),I?o.jsx(Y,{dropLastMargin:!0,schema:[{type:"inputlist",name:"AllowedCorsOrigin",label:a.APP_ALLOWED_CORS_ORIGIN_LABEL,placeholder:a.APP_ORIGIN_PLACEHOLDER,isOptional:!0,addButtonText:a.ADD,rules:It(a,"Allowed CORS origin"),style:{marginBottom:24}}]}):null]})}),o.jsx(Be,{title:a.APP_GROUP_BACK_CHANNEL_LOGOUT_TITLE,description:a.APP_GROUP_BACK_CHANNEL_LOGOUT_DESCRIPTION,rightContent:o.jsxs(Q,{vertical:!0,gap:24,children:[o.jsxs(Q,{vertical:!0,gap:12,children:[o.jsx(Y,{dropLastMargin:!0,schema:[{type:"switch",name:["BackChannelLogout","IsEnabled"],label:a.APP_BACK_CHANNEL_LOGOUT_LABEL,description:a.APPLICATIONS_BACKCHANNEL_TOGGLE_DESC}]}),D&&O?null:o.jsx(te,{type:"info",showIcon:!0,styles:Me,title:Ue(a.APP_BACK_CHANNEL_INACTIVE_NOTE)})]}),C?o.jsx(Y,{dropLastMargin:!0,schema:[{type:"inputlist",name:["BackChannelLogout","LogoutURIs"],label:a.APP_BACK_CHANNEL_LOGOUT_URLS_LABEL,placeholder:a.APP_URL_PLACEHOLDER,addButtonText:a.ADD,rules:Ct(a,"Back-channel logout URL"),style:{marginBottom:24}},{type:"inputNumber",name:["BackChannelLogout","LogoutTokenTTL"],label:a.APP_BACK_CHANNEL_LOGOUT_TOKEN_TTL_LABEL,isOptional:!0,min:0,precision:0,rules:[{validator:(e,t)=>
1null==t||""===t?Promise.resolve():Number.isInteger(Number(t))?Number(t)<0?Promise.reject(s(a,"Logout token TTL").integer):Number(t)>600?Promise.reject(s(a,"Logout token TTL").less_than_or_equal_to.replace("%s","600")):Promise.resolve():Promise.reject(s(a,"Logout token TTL").integer)}]}]}):null]})}),o.jsx(J.Item,{shouldUpdate:!0,noStyle:!0,children:()=>o.jsx(we,{isDirty:u,onSave:k,onReset:M,saveLoading:r,saveDisabled:d.getFieldsError().some(({errors:e})=>e.length>0),permissions:["API_EditThirdPartyCredentials"]})})]})})});yt.displayName="EndpointsTab";const ft=e.forwardRef(({app:t,i18n:i,saving:n,hubDomain:s,apiConfigs:a,onSave:r},l)=>{const[c]=J.useForm(),[d,u]=e.useState(!1),p=e.useRef(null),h=e.useMemo(()=>at(s),[s]),A=e.useMemo(()=>(e=>at(e).replace("/identity",""))(s),[s]),_=e.useMemo(()=>Array.isArray(t?.GrantTypes)?t.GrantTypes:[],[JSON.stringify(t?.GrantTypes||[])]),T=e.useMemo(()=>_.includes("client_credentials"),[_]),g=e.useMemo(()=>_.some(e=>"client_credentials"!==e),[_]),E=e.useMemo(()=>{let e=Ve(t?.AudienceScopes);return T||(e=e.filter(e=>qe(e?.Audience||"")!==qe(A))),g&&!e.some(e=>qe(e?.Audience||"")===qe(h))&&(e.push({Audience:h,AllowedScopes:[]}),e.sort((e,t)=>String(e.Audience).localeCompare(String(t.Audience)))),e.length?e:[{Audience:null,AllowedScopes:[]}]},[JSON.stringify(t?.AudienceScopes||{}),T,g,h,A]);e.useEffect(()=>{p.current={AudienceScopes:Ke(E)},c.resetFields(),u(!1)},[c,JSON.stringify(E)]);const m=()=>c.validateFields().then(()=>(r({AudienceScopes:Ke(c.getFieldValue("AudienceScopes"))}),!0)).catch(()=>!1),I=()=>{c.resetFields(),u(!1)};return e.useImperativeHandle(l,()=>({isDirty:()=>d,hasErrors:()=>c.getFieldsError().some(({errors:e})=>e.length>0),save:m,reset:I}),[d,JSON.stringify(E)]),o.jsx(J,{form:c,layout:"vertical",requiredMark:!1,onValuesChange:()=>{const e={AudienceScopes:Ke(c.getFieldValue("AudienceScopes"))};u(!ke(e,p.current))},initialValues:{AudienceScopes:E},children:o.jsxs($,{direction:"vertical",size:20,style:{width:"100%"},children:[o.jsx(Be,{title:i.APP_GROUP_API_ACCESS_TITLE,description:i.APP_GROUP_API_ACCESS_DESCRIPTION,rightContent:o.jsx($,{direction:"vertical",size:16,style:{width:"100%"},children:o.jsx(He,{form:c,optional:!0,fieldName:"AudienceScopes",apiConfigs:a,initialRows:E,manageApi:h,hideManageApis:!T,lockedAudience:g?h:void 0})})}),o.jsx(J.Item,{shouldUpdate:!0,noStyle:!0,children:()=>o.jsx(we,{isDirty:d,onSave:m,onReset:I,saveLoading:n,saveDisabled:c.getFieldsError().some(({errors:e})=>e.length>0),permissions:["API_EditThirdPartyCredentials"]})})]})})});ft.displayName="ApisTab";const{Text:Lt,Title:Nt}=W,Ot=({value:e})=>{const t=String(e||"");return o.jsx(X,{title:t?"Copy":"",children:o.jsx(ee,{type:"default",size:"small",className:"oauth-client-drawer__copyBtn",icon:o.jsx(ae,{}),onClick:()=>(e=>{const t=String(e||"").trim();t&&(navigator.clipboard.writeText(t),h("success","Copied to clipboard"))})(t),disabled:!t,"aria-label":"Copy"})})},jt=({label:e,value:t,action:i})=>o.jsxs("div",{className:"oauth-client-drawer__row",children:[o.jsx("div",{className:"oauth-client-drawer__rowLabel",children:e}),o.jsx("div",{className:"oauth-client-drawer__rowValue",children:t}),o.jsx("div",{className:"oauth-client-drawer__rowAction",children:i||null})]}),Dt=({open:n,serverId:s,dcrEnabled:a,cimdEnabled:r,deviceMode:l=!1,onClose:c})=>{const d=i(),{selectedClient:u,clientUsers:p,clientUsersLoading:h,revokingUser:A}=t(e=>e.oauthClients),_=t(e=>e.organizations.permissions),P=t(e=>e.appState.i18n.languages),[S,y]=T.useState(null),f=e.useMemo(()=>{return e=u,e?.ClientId||e?.ClientID||e?.client_id||null;var e},[u]),L=e.useMemo(()=>$e(_.Data),[_.Data]),N=e.useMemo(()=>{const e=new Set;return(p||[]).forEach(t=>{Ye(t,L).unresolvedIds.forEach(t=>e.add(t))}),e},[p,L]),O=String(u?.RegistrationType||"").toLowerCase(),j=!!O&&O.includes("dcr")&&!a,D=!!O&&O.includes("cimd")&&!r;e.useEffect(()=>{n&&s&&f&&d(g({serverId:s,clientId:f}))},[n,s,f,d]);const x=T.useRef(null);e.useEffect(()=>{n&&f&&N.size&&(_.isLoading||x.current!==f&&(x.current=f,d(E())))},[n,f,N,_.isLoading,d]),e.useEffect(()=>{n||(x.current=null)},[n]);const v=T.useRef(A);e.useEffect(()=>{v.current&&!A&&y(null),v.current=A},[A]);const b=[{title:"UID",dataIndex:"Uid",key:"Uid",render:e=>o.jsx(Lt,{className:"oauth-client-drawer__mono",children:String(e||"-")})},{title:"Scopes",key:"Scopes",render:(e,t)=>{const{names:i,unresolvedIds:n}=Ye(t,L);return i.length||n.length?o.jsxs($,{size:[6,6],wrap:!0,children:[i.map(e=>o.jsx(ne,{className:"oauth-client-drawer__scopeTag",children:e},e)),n.map(e=>o.jsx(Je,{value:e,className:"consent-unknown-scope",tooltipTitle:`Unknown permission â it may have been deleted. Click to copy ${e}`,children:R(e)},e))]}):o.jsx(Lt,{type:"secondary",children:"-"})}},{title:"Actions",key:"Actions",width:120,render:(e,t)=>o.jsx(ge,{permissions:["API_AdminConfiguration"],children:o.jsx(ee,{danger:!0,size:"small",loading:A&&S===t.Uid,onClick:()=>{y(t.Uid)},children:P.MCP_SERVERS_USERS_REVOKE_ACCESS})})}];return o.jsxs(o.Fragment,{children:[o.jsxs(Qe,{open:n,onClose:()=>{d(C(null)),c()},width:860,className:"oauth-client-drawer",styles:{body:{padding:24}},title:o.jsxs("div",{className:"oauth-client-drawer__headerMain",children:[o.jsx(Nt,{level:3,className:"oauth-client-drawer__title",children:u?.ClientName||(l?P.APPLICATIONS_DEVICES_DRAWER_FALLBACK:P.MCP_SERVERS_CLIENTS_CLIENT)}),o.jsx("div",{className:"oauth-client-drawer__clientId",children:o.jsx(Je,{value:f||""})})]}),destroyOnClose:!0,children:[(j||D)&&o.jsx(te,{type:"warning",showIcon:!0,style:{marginBottom:16},message:"Registration Method Disabled",description:l?P.APPLICATIONS_DEVICES_METHOD_DISABLED:"This MCP client's registration method is disabled in MCP registration settings. Existing clients continue to work, but new registrations may be blocked."}),o.jsxs($,{direction:"vertical",size:20,style:{width:"100%"},children:[o.jsx(se,{styles:{header:{background:m}},className:"oauth-client-drawer__card",title:l?P.APPLICATIONS_DEVICES_DRAWER_DETAILS:P.MCP_SERVERS_CLIENTS_DETAILS_TITLE,children:o.jsxs("div",{className:"oauth-client-drawer__rows",children:[o.jsx(jt,{label:"Name",value:o.jsx(Lt,{children:u?.ClientName||"-"})}),o.jsx(jt,{label:"ID",value:o.jsx(Lt,{className:"oauth-client-drawer__mono",children:f||"-"}),action:o.jsx(Ot,{value:f||""})}),o.jsx(jt,{label:"Registration method",value:(e=>{const t=String(e||"").trim();if(!t)return o.jsx(Lt,{type:"secondary",children:"-"});const i=t.split("|").map(e=>
1e.trim()).filter(Boolean);return i.length<=1?o.jsx(Lt,{children:t}):o.jsx($,{size:10,wrap:!0,children:i.map((e,t)=>o.jsxs(T.Fragment,{children:[o.jsx(Lt,{children:e}),t<i.length-1?o.jsx(Lt,{type:"secondary",children:"|"}):null]},`${e}-${t}`))})})(u?.RegistrationType)})]})}),(()=>{const e=u?.Metadata||{},t=e.Custom||e.custom||{},i=Object.entries(t).filter(([e,t])=>e&&null!=t&&String(t).length),n=e.SoftwareId||e.software_id,s=e.LogoUri||e.logo_uri,a=e.TosUri||e.tos_uri,r=e.PolicyUri||e.policy_uri;return n||s||a||r||i.length||u?.ClientUri?o.jsx(se,{styles:{header:{background:m}},className:"oauth-client-drawer__card",title:"Metadata",children:o.jsxs("div",{className:"oauth-client-drawer__rows",children:[n?o.jsx(jt,{label:"Software ID",value:o.jsx(Lt,{className:"oauth-client-drawer__mono",children:n}),action:o.jsx(Ot,{value:String(n)})}):null,u?.ClientUri?o.jsx(jt,{label:"Client URI",value:o.jsx(Lt,{children:u.ClientUri}),action:o.jsx(Ot,{value:u.ClientUri})}):null,s?o.jsx(jt,{label:"Logo URI",value:o.jsx(Lt,{children:s}),action:o.jsx(Ot,{value:String(s)})}):null,a?o.jsx(jt,{label:"Terms URI",value:o.jsx(Lt,{children:a}),action:o.jsx(Ot,{value:String(a)})}):null,r?o.jsx(jt,{label:"Policy URI",value:o.jsx(Lt,{children:r}),action:o.jsx(Ot,{value:String(r)})}):null,i.map(([e,t])=>o.jsx(jt,{label:e,value:o.jsx(Lt,{className:"oauth-client-drawer__mono",children:String(t)}),action:o.jsx(Ot,{value:String(t)})},e))]})}):null})(),o.jsx(se,{styles:{header:{background:m}},className:"oauth-client-drawer__card",title:"Redirect URLs",children:o.jsx("div",{className:"oauth-client-drawer__rows",children:(u?.RedirectURIs||[]).length?(u?.RedirectURIs||[]).map((e,t)=>o.jsxs("div",{className:"oauth-client-drawer__valueRow",children:[o.jsx(Lt,{children:e}),o.jsx(Ot,{value:e})]},`${e}-${t}`)):o.jsx("div",{className:"oauth-client-drawer__empty",children:o.jsx(Lt,{type:"secondary",children:"-"})})})}),o.jsx(se,{styles:{header:{background:m}},className:"oauth-client-drawer__card",title:P.MCP_SERVERS_TAB_CONSENTED_USERS,children:o.jsx(Ze,{className:"oauth-client-drawer__table",columns:b,dataSource:(p||[]).map(e=>({...e,key:`${e.Uid}-${e.ClientId}`})),loading:h,locale:{emptyText:l?P.APPLICATIONS_DEVICES_CONSENTED_USERS_EMPTY:"No users have consented to this client."},pagination:{pageSize:5,position:["bottomCenter"],showSizeChanger:!1,hideOnSinglePage:!0}})})]})]}),o.jsx(B,{open:!!S||!!A,title:P.MCP_SERVERS_REVOKE_USER_TITLE,message:P.MCP_SERVERS_REVOKE_USER_CONFIRM,ButtonText:P.MCP_SERVERS_USERS_REVOKE_ACCESS,dangerButton:!0,onConfirm:()=>{S&&f&&s&&d(I({serverId:s,clientId:f,uid:S}))},onClose:()=>y(null),loading:A})]})},{Text:xt}=W,vt=["DCR","CIMD"],bt=e=>String(e||"").split("|").map(e=>e.trim().toUpperCase()).filter(e=>vt.includes(e)),wt=e.forwardRef(({app:n,serverId:s,deviceMode:a=!1},r)=>{const c=i(),{clients:d,clientsLoading:p,selectedClient:h,deletingClient:A}=t(e=>e.oauthClients),_=t(e=>e.auth.appPermission),T=t(e=>e.appState.i18n.languages),g=!!_?.API_AdminConfiguration,E=n?.Registration?.DCR?.IsEnabled??!1,m=n?.Registration?.CIMD?.IsEnabled??!1;e.useEffect(()=>{s&&c(P(s))},[s]);const[I,R]=e.useState(""),[y,f]=e.useState([]),[L,N]=e.useState(null),O=e.useMemo(()=>vt.map(e=>({value:e,label:e})),[]),j=e.useMemo(()=>(d||[]).filter(e=>{const t=I.trim().toLowerCase(),i=!t||String(e?.ClientName||"").toLowerCase().includes(t)||String(e?.ClientId||"").toLowerCase().includes(t),n=bt(e?.RegistrationType),s=!y.length||y.some(e=>n.includes(e));return i&&s}),[d,I,y]),D=[{title:a?T.APPLICATIONS_DEVICES_COLUMN_NAME:T.MCP_SERVERS_CLIENTS_CLIENT_NAME,dataIndex:"ClientName",key:"ClientName",render:e=>o.jsx(xt,{children:e})},{title:"Client ID",dataIndex:"ClientId",key:"ClientId",render:e=>o.jsx(Je,{value:e})},...a?[{title:"Software ID",key:"SoftwareId",render:(e,t)=>{const i=t?.Metadata?.SoftwareId||t?.Metadata?.software_id||"";return i?o.jsx(Je,{value:i}):o.jsx(xt,{type:"secondary",children:"-"})}}]:[],{title:"Method",dataIndex:"RegistrationType",key:"RegistrationType",render:e=>{const t=bt(e);return t.length?o.jsx($,{size:4,wrap:!0,children:t.map(e=>{const t="DCR"===e&&!E||"CIMD"===e&&!m;return o.jsx(ne,{variant:"outlined",color:t?"warning":"default",children:e},e)})}):o.jsx(ne,{variant:"outlined",children:"-"})}},{title:"Actions",key:"Actions",width:80,render:(e,t)=>o.jsx(We,{items:[{key:"view",label:"View Details",onClick:()=>c(C(t))},...g?[{key:"delete",danger:!0,label:"Delete",onClick:e=>{e.domEvent.stopPropagation(),N(t)}}]:[]]})}];return e.useImperativeHandle(r,()=>({isDirty:()=>!1,save:()=>Promise.resolve(!0),reset:()=>{}}),[]),o.jsxs($,{direction:"vertical",size:20,style:{width:"100%"},children:[o.jsxs(l,{gutter:16,align:"middle",children:[o.jsx(u,{flex:"auto",children:o.jsx(Z,{className:"apps-search",placeholder:a?T.APPLICATIONS_DEVICES_SEARCH_PLACEHOLDER:T.MCP_SERVERS_CLIENTS_SEARCH_PLACEHOLDER,value:I,onChange:e=>R(e.target.value),allowClear:!0})}),o.jsx(u,{children:o.jsx(re,{suffixIcon:o.jsx(oe,{size:16,style:{display:"block"}}),mode:"multiple",placeholder:"Method",value:y,onChange:f,options:O,style:{minWidth:200},allowClear:!0})})]}),p||0!==j.length?o.jsx(q,{caption:a?T.APPLICATIONS_DEVICES_CAPTION:T.MCP_SERVERS_TAB_CLIENTS,columns:D,dataSource:j.map(e=>({...e,key:e.ClientId})),loading:p,rowClassName:()=>"apps-clickable-row",pagination:{pageSize:10,position:["bottomCenter"],showSizeChanger:!1,hideOnSinglePage:!0},onRow:e=>({onClick:()=>c(C(e))})}):o.jsx(Te,{title:a?T.APPLICATIONS_DEVICES_EMPTY_TITLE:T.MCP_SERVERS_CLIENTS_EMPTY_TITLE,subTitle:a?T.APPLICATIONS_DEVICES_EMPTY_SUBTITLE:T.MCP_SERVERS_CLIENTS_EMPTY_DESCRIPTION,iconName:"table-empty",iconSize:64,hasButton:!1}),o.jsx(Dt,{open:!!h,serverId:s,dcrEnabled:E,cimdEnabled:m,deviceMode:a,onClose:()=>c(C(null))}),o.jsx(H,{open:!!L,title:a?T.APPLICATIONS_DEVICES_DELETE_TITLE:T.MCP_SERVERS_CLIENTS_CLIENT,heading:a?T.APPLICATIONS_DEVICES_DELETE_HEADING:T.MCP_SERVERS_CLIENTS_DELETE_HEADING,message:a?T.APPLICATIONS_DEVICES_DELETE_MESSAGE.replace("%s",L?.ClientName||"this device"):`All users associated with ${L?.ClientName||"this client"} will lose their consent.`,showCaution:!0,confirmText:a?T.APPLICATIONS_DEVICES_DELETE_CONFIRM:"DELETE CLIENT",confirmButtonLabel:a?T.APPLICATIONS_DEVICES_DELETE_BUTTON:T.MCP_SERVERS_CLIENTS_DELETE_CLIENT,loading:A,onClose:()=>N(null),onConfirm:()=>{L?.ClientId&&(c(S({serverId:s,clientId:L.ClientId,successMessage:a?T.APPLICATIONS_DEVICES_DELETE_SUCCESS:T.MCP_SERVERS_CLIENTS_DELETE_SUCCESS})),N(null))}})]})});wt.displayName="ClientsTab";const kt=e.forwardRef(({app:t,i18n:i,providerList:n,getSsoConnectionsData:s,enablePasswordlessLogin:a,enableEmailAndPhoneLogin:r,saving:l,onSave:c},d)=>{const u=e.useMemo(()=>Oe({appConnections:t?.Connections,ssoData:s?.Data,providers:n?.Data}),[t?.AppName,JSON.stringify(t?.Connections||{}),JSON.stringify(s?.Data||{}),JSON.stringify(n?.Data||[])]),[p,h]=e.useState(u),A=e.useMemo(()=>JSON.stringify({appName:t?.AppName,connections:t?.Connections||{}}),[t?.AppName,JSON.stringify(t?.Connections||{})]),_=e.useRef(null);e.useEffect(()=>{_.current!==A&&(_.current=A,h(u))},[A,u]);const T=e.useMemo(()=>!ke(p,u),[p,u]),g=()=>{c({Connections:De(p)})},E=()=>{h(u)};return e.useImperativeHandle(d,()=>({isDirty:()=>T,hasErrors:()=>!1,save:g,reset:E}),[T,u,p]),o.jsx(je,{title:i.CONNECTIONS_EDITOR_TITLE,description:i.CONNECTIONS_EDITOR_APP_DESCRIPTION,value:p,onChange:h,enablePasswordlessLogin:a,enableEmailAndPhoneLogin:r,children:o.jsx(we,{isDirty:T,onSave:g,onReset:E,saveLoading:l,permissions:["API_EditThirdPartyCredentials"]})})});kt.displayName="ConnectionsTab";const Mt=({capabilities:t})=>{const i=e.useMemo(()=>function(e){const t=[],i=new Set(Le(e));return 0===e.length&&t.push({type:"warning",message:"Pick at least one grant type.",description:"Without any grant type the app cannot mint tokens."}),1===e.length&&"tokenExchange"===e[0]&&t.push({type:"warning",message:"Token exchange needs a token source.",description:"Add a grant type that mints tokens (browser sign-in, device code, password, or machine-to-machine) for token exchange to act on."}),(i.has(xe)||i.has(ve))&&t.push({type:"warning",message:"Not recommended grants enabled",description:"The password and implicit grants were removed by OAuth 2.1. Prefer authorization code with PKCE where possible."}),t}(t),[t]);return o.jsx(o.Fragment,{children:i.map((e,t)=>o.jsx(te,{type:e.type,showIcon:!0,message:e.message,description:e.description,style:{marginTop:8}},t))})},{Text:Ut}=W,Ft={public:["browserLogin","keepSession"],confidential:["machineToMachine"]}
1,Gt=[{value:"public",title:"Public",description:o.jsxs(o.Fragment,{children:["Best for single-page and mobile/native apps. Runs in a browser or on a device, so it defaults to no secret (",o.jsx("code",{children:"none"}),") and relies on PKCE instead."]})},{value:"confidential",title:"Confidential",description:o.jsxs(o.Fragment,{children:["Best for server-side web apps and machine-to-machine services. Has a backend to keep its secret safe, and can call APIs on its own via ",o.jsx("code",{children:"client_credentials"}),"."]})}],Bt=({open:i,loading:n,onCancel:p,onCreate:h})=>{const A=t(e=>e.platformConfiguration.getOIDCandOAuthApps),{i18n:{languages:_}}=t(e=>e.appState),T=t(e=>e.auth.appFeatures),g=!!T?.EnableMachineToMachineAuthentication,E=e=>{const t=Ft[e].filter(e=>g||!Se(e));return t.length?t:["browserLogin"]},[m,I]=e.useState("public"),[C,R]=e.useState(E("public")),P=e.useRef(!1),[S]=J.useForm(),[N]=le(S),O=C.includes("deviceCode"),j=ct(m)===Ce;e.useEffect(()=>{i&&(I("public"),P.current=!1,R(E("public")),S.resetFields())},[i,S]),e.useEffect(()=>{i&&!P.current&&R(E(m))},[g]);const D=e=>{I(e),P.current=!1,R(E(e))},x=e.useMemo(()=>[{type:"string",name:"AppName",label:"Application name",placeholder:"Enter application name",rules:[{validator(e,t){if(!t||!t.trim())return Promise.reject(s(_,"App name").required);if(t&&t.trim().length>60)return Promise.reject(s(_,"App name").max_length.replace("%s","60"));if(t&&a(t))return Promise.reject(s(_,"App name").alpha_numeric_underscore_dash);if(t&&(t.startsWith("-")||t.endsWith("-")||t.startsWith("_")||t.endsWith("_")))return Promise.reject(s(_,"App name").start_with_alphabet_numeric);if(t&&t.includes(" "))return Promise.reject(s(_,"App name").no_spaces);const i=A?.Data||[],n=0!==i.length?y(i,t):"";return n?Promise.reject(new Error(n)):Promise.resolve()}}]},{type:"textarea",name:"Description",label:"Description (optional)",placeholder:"What this app is for; shown to your team, not to end users.",rows:2,maxLength:255,rules:[{validator:(e,t)=>t&&t.length>255?Promise.reject(s(_,"Description").max_length.replace("%s","255")):Promise.resolve()}]}],[A,_]),v=e.useMemo(()=>[{type:"string",name:"VerificationUrl",label:"Verification URL",placeholder:"Enter URL",extra:o.jsx(Ut,{type:"secondary",children:"Enter the verification URL for users to manually enter their user code into their user agent."}),rules:[{validator:(e,t)=>t&&t.trim()?r(t)?Promise.resolve():Promise.reject(s(_,"Verification URL").valid_url):Promise.reject(s(_,"Verification URL").required)}]},{type:"string",name:"AfterVerificationUrl",label:"After verification URL",placeholder:"Enter URL",extra:o.jsx(Ut,{type:"secondary",children:"Enter the redirection URL for users after successful authentication."}),rules:[{validator:(e,t)=>t&&t.trim()?r(t)?Promise.resolve():Promise.reject(s(_,"After verification URL").valid_url):Promise.reject(s(_,"After verification URL").required)}]}],[_]);return o.jsx(ce,{isOpen:i,className:"apps-create-modal",title:"Create application",width:720,loading:n,schema:x,disabled:0===C.length||O&&!N,buttonText:"Create application",cancelText:"Cancel",onCancel:p,onFinish:e=>{const t=S.getFieldsValue();h({appName:e.AppName,description:e.Description,clientType:m,capabilities:C,deviceCodeConfig:O?{VerificationUrl:String(t.VerificationUrl||"").trim(),AfterVerificationUrl:String(t.AfterVerificationUrl||"").trim()}:void 0})},modalContent:o.jsxs("div",{className:"create-app-modal__body",children:[o.jsxs("div",{className:"create-app-modal__section",children:[o.jsxs(Q,{align:"center",gap:6,children:[o.jsx(Ut,{className:"font-medium",children:"Client type"}),o.jsx(X,{title:"Client type describes whether this app can keep its credentials confidential, per the OAuth 2.0 specification. Confidential clients run on a secured backend and can protect a client secret. Public clients run in a browser or on a user's device and cannot, so they authenticate without a secret and rely on PKCE instead.",styles:{root:{maxWidth:360}},children:o.jsx(de,{style:{color:c,cursor:"help"}})})]}),o.jsx(l,{gutter:[12,12],style:{marginTop:8},children:Gt.map(e=>{const t=m===e.value;return o.jsx(u,{span:12,children:o.jsx(se,{onClick:()=>D(e.value),style:{height:"100%",cursor:"pointer",borderColor:t?L:void 0,backgroundColor:t?f:void 0},styles:{body:{padding:16}},children:o.jsxs(Q,{gap:8,align:"flex-start",children:[o.jsx(ue,{checked:t,onChange:()=>D(e.value)}),o.jsxs(Q,{vertical:!0,gap:2,children:[o.jsx(Ut,{strong:!0,children:e.title}),o.jsx(Ut,{type:"secondary",children:e.description})]})]})})},e.value)})})]}),o.jsxs("div",{className:"create-app-modal__section",children:[o.jsxs(Q,{justify:"space-between",align:"center",children:[o.jsxs(Q,{align:"center",gap:6,children:[o.jsx(Ut,{className:"font-medium",children:"Grant types"}),o.jsx(X,{title:"Grant type is a specific method used by an application to obtain an access token. It defines how the client application communicates with the authorization server to prove its identity and secure user consent.",styles:{root:{maxWidth:360}},children:o.jsx(de,{style:{color:c,cursor:"help"}})})]}),o.jsxs(ne,{bordered:!1,color:"blue",children:[C.length," selected"]})]}),o.jsx(l,{gutter:[12,12],style:{marginTop:8},children:Re.map(e=>{const t=(i=e.id,Se(i)&&!g?_.MSG_FEATURE_NOT_AVAILABLE:j&&ye(i)?_.APP_GRANT_REQUIRES_CONFIDENTIAL_CLIENT:null);var i;const n=o.jsx(ie,{title:e.legacy?o.jsxs(o.Fragment,{children:[e.title," ",o.jsx(ne,{bordered:!1,color:"warning",style:{marginInlineStart:4},children:"Not recommended"})]}
1):e.title,description:o.jsxs(o.Fragment,{children:[e.description,o.jsx("div",{children:(s=e.grants,o.jsx(ne,{bordered:!1,color:"blue",style:{fontFamily:"monospace",fontSize:11,whiteSpace:"normal",marginTop:6,color:c},children:s.join(" ")}))}),"keepSession"===e.id&&C.includes("keepSession")&&Pe(C)?o.jsx("div",{style:{marginTop:6},children:o.jsxs(Ut,{style:{fontSize:12,color:d},children:["Needs the ",o.jsx("code",{children:"authorization_code"}),", ",o.jsx("code",{children:"device_code"}),", or ",o.jsx("code",{children:"password"})," grant to take effect."]})}):null]}),checked:C.includes(e.id),disabled:null!==t,highlightWhenChecked:!0,onChange:t=>((e,t)=>{P.current=!0,R(i=>{const n=t?Array.from(new Set([...i,e])):i.filter(t=>t!==e);return"keepSession"===e?n:fe(n)})})(e.id,t.target.checked)});var s;return o.jsx(u,{span:12,children:t?o.jsx(X,{title:t,placement:"top",children:o.jsx("span",{style:{display:"block",width:"100%",height:"100%"},children:n})}):n},e.id)})})]}),O&&o.jsxs("div",{className:"create-app-modal__section",children:[o.jsx(Ut,{className:"font-medium",children:"Device code settings"}),o.jsx(J,{form:S,layout:"vertical",requiredMark:!1,style:{marginTop:8},children:o.jsx(Y,{schema:v,dropLastMargin:!0})})]}),o.jsx(Mt,{capabilities:C})]})})},{Text:zt}=W,Vt="general",qt="tokens",Kt="endpoints",Ht="apis",Jt="clients",Wt="connections",$t=["AudienceScopes","Mapping","Metadata"],Yt=N(e=>({appFeatures:e.auth.appFeatures,appPermission:e.auth.appPermission,i18n:e.appState.i18n.languages,getAuthServerConfigApiData:e.platformConfiguration.getAuthServerConfigApi,hubDomain:e.auth.authConfig.hubDomain,EnablePasswordlessLogin:e.auth.appFeatures.EnablePasswordlessLogin,EnableEmailandPhoneLogin:e.auth.appFeatures.EnableEmailandPhoneLogin,providerList:e.platformConfiguration.getSocialProviderList,getOidcAndOauthAppsData:e.platformConfiguration.getOIDCandOAuthApps,getSsoConnectionsData:e.platformConfiguration.getSSOConnections,getDataMappinsData:e.platformConfiguration.getDataMapping,permissionsData:e.organizations.permissions,saveOIDCAndOAuthAppsData:e.platformConfiguration.saveOIDCandOAuthAppsData,updateOIDCAndOAuthAppsData:e.platformConfiguration.updateOIDCandOAuthAppsData,deleteOIDCAndOAuthAppsData:e.platformConfiguration.deleteOIDCandOAuthAppsData}),e=>({getAuthServerAPIConfig:()=>e(G()),getProviderList:()=>e(F()),getOIDCAndOAuthApps:()=>e(U()),getSsoConnections:()=>e(M()),getDataMappins:()=>e(k()),getPermissions:()=>e(E()),saveOIDCAndOAuthApps:t=>e(x(w(t),{eventName:"apps_created_new_app",errorEventName:"apps_got_app_error",operation:"create",entityType:"oidc_oauth_a
1pp",properties:{entry_point:"apps_list_modal"}})),updateOIDCAndOAuthApps:(t,i,n="apps_configured_app_successfully",s)=>e(x(b(t,i),{eventName:n,errorEventName:"apps_got_app_error",operation:"apps_enabled_connections"===n?"enable_connections":"update",entityType:"oidc_oauth_app",properties:s})),deleteOIDCAndOAuthApps:(t,i)=>e(x(v(t,i),{eventName:"apps_deleted_app",errorEventName:"apps_got_app_error",operation:"delete",entityType:"oidc_oauth_app",properties:{entry_point:"apps_list_row"}}))}))(t=>{const{i18n:i,hubDomain:n,appFeatures:s,appPermission:a,providerList:r,getAuthServerConfigApiData:l,getOidcAndOauthAppsData:c,getSsoConnectionsData:d,getDataMappinsData:u,permissionsData:p,saveOIDCAndOAuthAppsData:A,updateOIDCAndOAuthAppsData:_,deleteOIDCAndOAuthAppsData:T,getAuthServerAPIConfig:g,getProviderList:E,getOIDCAndOAuthApps:m,getSsoConnections:I,getDataMappins:C,getPermissions:R,saveOIDCAndOAuthApps:P,updateOIDCAndOAuthApps:S,deleteOIDCAndOAuthApps:y}=t,f=pe(),[L,N]=e.useState(!1),[x,v]=e.useState(""),[b,w]=e.useState(Vt),[k,M]=e.useState(""),[U,F]=e.useState(""),{pulse:G}=he(),[B,J]=e.useState(null),W=e.useMemo(()=>at(n),[n]),Y=e.useMemo(()=>W.replace("/identity",""),[W]),X=!!a?.API_EditThirdPartyCredentials,te=!!s?.EnableResourceLevelRBAC,ie=e.useMemo(()=>Array.isArray(c?.Data)?c.Data.map(e=>ut(e)):[],[c]),se=e.useMemo(()=>ie.find(e=>e.AppName===x)||null,[ie,x]),ae=!!c?.isLoading,re=it(s),oe=st(s),le=e.useRef(null),ce=e.useRef(null),de=e.useRef(null),ue=e.useRef(null),me=e.useRef(null),Ie=e.useRef(null),Ce=e.useRef(!1),Re=e.useRef(!1),Pe=e.useRef(!1),Se=e=>{switch(e){case Vt:return le;case qt:return ce;case Kt:return de;case Ht:return ue;case Jt:return me;case Wt:return Ie;default:return le}};e.useEffect(()=>{const e=f.state;e?.openApp&&(v(e.openApp),w(e.openTab||Vt),window.history.replaceState(null,""))},[]),e.useEffect(()=>{l?.isSuccess||l?.error||g(),c?.isSuccess||c?.error||m(),u?.Data||u?.isSuccess||u?.error||C(),d?.isSuccess||d?.error||I(),r?.isSuccess||E(),!te&&!oe||p?.isSuccess||p?.isLoading||R()},[n]),e.useEffect(()=>{if(Ce.current&&!A?.isLoading){if(A?.isSuccess&&A?.Data){Ce.current=!1;const e=A.Data?.Data||A.Data;h("success",i.SETTING_SAVED_SUCCESSFULLY),N(!1),m(),e?.AppName&&(v(e.AppName),w(Vt),e.ClientSecret&&J({appName:e.AppName,secret:e.ClientSecret}))}A?.isError&&A?.error&&(Ce.current=!1,h("error",A.error))}},[A?.isLoading]),e.useEffect(()=>{B&&x!==B.appName&&J(null)},[x,B]),e.useEffect(()=>{if(Re.current&&!_?.isLoading){if(_?.isSuccess){Re.current=!1,h("success",i.SETTING_SAVED_SUCCESSFULLY);const e=_?.Data||_?.payload?.Data;m(),e?.AppName&&e.AppName!==x&&v(e.AppName)}_?.isError&&_?.error&&(Re.current=!1,h("error",_.error))}},[_?.isLoading]),e.useEffect(()=>{Pe.current&&(T?.isLoading||(T?.isSuccess&&(Pe.current=!1,h("success",i.APP_DELETED_SUCCESSFULLY),m(),U&&U===x&&(v(""),w(Vt)),F("")),T?.isError&&T?.error&&(Pe.current=!1,h("error",T.error),F(""))))},[T?.isLoading]);const ye=e.useMemo(()=>{const e=[...ie];return e.sort((e,t)=>{const i=e?.CreatedDate?new Date(e.CreatedDate).getTime():0;return(t?.CreatedDate?new Date(t.CreatedDate).getTime():0)-i}),e},[ie]),fe=e.useMemo(()=>{const e=k.trim().toLowerCase();return e?ye.filter(t=>String(t?.AppName||"").toLowerCase().includes(e)):ye},[ye,k]),Ne=(e,t)=>{if(!se)return;const n=((e,t)=>{const i=ot(e,t);var n;i.Protocol=i.Protocol||"OpenID Connect 1.0",i.ApplicationType=i.ApplicationType||"web",i.Registration={...(n=i.Registration)||{},DCR:{...n?.DCR||{},IsEnabled:n?.DCR?.IsEnabled??!1,InitialAccessTokenRotatedAt:n?.DCR?.InitialAccessTokenRotatedAt||void 0},CIMD:{...n?.CIMD||{},IsEnabled:n?.CIMD?.IsEnabled??!1}};const s=ut(i);$t.forEach(e=>{Object.prototype.hasOwnProperty.call(t,e)&&(s[e]=t[e])}),s.AudienceScopes=s.AudienceScopes&&"object"==typeof s.AudienceScopes?s.AudienceScopes:{};const a=Array.isArray(s.GrantTypes)?s.GrantTypes:[],r=a.includes("client_credentials"),o=a.some(e=>
1"client_credentials"!==e);return!r&&Object.prototype.hasOwnProperty.call(s.AudienceScopes,Y)&&delete s.AudienceScopes[Y],o&&!Object.prototype.hasOwnProperty.call(s.AudienceScopes,W)&&(s.AudienceScopes[W]=[]),s})(se,t);if(e===Vt){const e=Object.prototype.hasOwnProperty.call(se.AudienceScopes||{},Y),t=Object.prototype.hasOwnProperty.call(n.AudienceScopes||{},Y);e&&!t&&h("warning",i.MANAGE_API_REMOVED_CLIENT_CREDS_OFF)}const s=ie.map(e=>e.AppName===se.AppName?n:e),a=e===Wt?"apps_enabled_connections":"apps_configured_app_successfully";Re.current=!0,S(n,s,a,{tab_section:e})},Oe=e=>{const t=Se(b).current;t?.isDirty()?G():w(e)},je=()=>{const e=Se(b).current;e?.isDirty()?G():(v(""),w(Vt))},De=[{title:"Application",dataIndex:"AppName",key:"AppName",render:e=>o.jsx(zt,{children:e})},{title:"Client ID",dataIndex:"ClientId",key:"ClientId",render:e=>o.jsx(Je,{value:e})},{title:"Type",dataIndex:"ClientType",key:"ClientType",render:(e,t)=>o.jsx(zt,{children:"public"===dt(t)?"Public":"Confidential"})},{title:"Auth flows",key:"AuthFlows",render:(e,t)=>{const i=(e=>{const t=Array.isArray(e?.GrantTypes)?e.GrantTypes:[],i=[];return(Array.isArray(e?.AllowedScopes)?e.AllowedScopes:[]).includes("openid")?i.push("OIDC"):t.some(e=>lt.includes(e))&&i.push("OAuth 2.0"),t.some(e=>Xe.includes(e))&&i.push("M2M"),i})(t);if(!i.length)return o.jsx(zt,{type:"secondary",children:"-"});const n={OIDC:D.BLUE,"OAuth 2.0":D.GREEN,M2M:D.GOLD};return o.jsx($,{size:4,wrap:!0,children:i.map(e=>o.jsx(ne,{variant:"outlined",color:n[e],children:e},e))})}},{title:"Created on",dataIndex:"CreatedDate",key:"CreatedDate",render:e=>{if(!e)return null;const t=new Date(e).toLocaleString("en-US",{year:"numeric",month:"short",day:"2-digit",hour:"2-digit",minute:"2-digit",hour12:!0}).replace(",","").replace(/(\w{3}) (\d{2})/,(e,t,i)=>`${t} ${i}`);return o.jsx(zt,{children:t})}},{title:"Actions",key:"Actions",width:80,render:(e,t)=>o.jsx(We,{placement:"bottomRight",items:[{key:"open",label:i.EDIT,onClick:()=>v(t.AppName)},...X?[{key:"delete",danger:!0,label:i.DELETE,onClick:e=>{e.domEvent.stopPropagation(),F(t.AppName)}}]:[]]})}];return o.jsxs("div",{className:"page page-container apps "+(x?"edit":""),children:[o.jsx(ge,{permissions:["API_ViewThirdPartyCredentials"],children:x?(()=>{if(!se)return null;const e=[{key:Vt,label:"General",children:o.jsx(Tt,{ref:le,app:se,i18n:i,saving:_?.isLoading,manageApi:W,manageApiNoIdentity:Y,initialRevealedSecret:B?.appName===x?B.secret:void 0,onSave:e=>Ne(Vt,e),canDeleteApp:X,onDeleteApp:()=>F(se.AppName)})},{key:qt,label:"Tokens",children:o.jsx(mt,{ref:ce,app:se,i18n:i,mappingFields:Array.isArray(u?.Data)?u.Data:[],saving:_?.isLoading,onSave:e=>Ne(qt,e)})},{key:Kt,label:"Endpoints",children:o.jsx(yt,{ref:de,app:se,i18n:i,saving:_?.isLoading,onSave:e=>Ne(Kt,e)})},{key:Ht,label:"APIs",children:o.jsx(ft,{ref:ue,app:se,i18n:i,saving:_?.isLoading,hubDomain:n,apiConfigs:Array.isArray(l?.Data)?l.Data:[],onSave:e=>Ne(Ht,e)})}];return oe&&e.push({key:Jt,label:re?i.APPLICATIONS_TAB_DEVICES:i.MCP_SERVERS_TAB_CLIENTS,children:o.jsx(Ee,{permissions:["API_ViewConfiguration"],features:[tt,et],singleFeature:!0,children:o.jsx(wt,{ref:me,app:se,serverId:String(se.ClientId||""),deviceMode:re})})}),e.push({key:Wt,label:"Connections",children:o.jsx(kt,{ref:Ie,app:se,i18n:i,providerList:r,getSsoConnectionsData:d,enablePasswordlessLogin:!!t.EnablePasswordlessLogin,enableEmailAndPhoneLogin:!!t.EnableEmailandPhoneLogin,saving:_?.isLoading,onSave:e=>Ne(Wt,e)})}),o.jsxs($,{direction:"vertical",size:24,style:{width:"100%"},children:[o.jsx(z,{onClick:je}),o.jsx(Q,{justify:"space-between",align:"flex-start",children:o.jsx("div",{style:{flex:1},children:o.jsx(K,{username:se.AppName,uid:se.ClientId,hasDropdown:!1,additionalContent:[],hideIcon:!0,loading:ae})})}),o.jsx(Ae,{activeKey:b,onChange:Oe,items:e,destroyOnHidden:!0})]})})():o.jsxs($,{direction:"vertical",size:O.table.gap,style:{width:"100%"}
1,children:[o.jsx(V,{router:null,basename:"",title:"Applications",description:i.MANAGE_APPS_DESCRIPTION,pageType:"table",titleLevel:3,hasActionButton:!0,actionButtonNode:o.jsx(ge,{permissions:["API_EditThirdPartyCredentials"],children:o.jsx(ee,{type:"primary",icon:o.jsx(_e,{}),onClick:()=>N(!0),children:i.APPLICATIONS_ADD_APPLICATION})}),docsKey:"Apps"}),o.jsx(Q,{justify:"space-between",align:"center",children:o.jsx(Z,{className:"apps-search",style:{maxWidth:520},placeholder:i.APPLICATIONS_SEARCH_PLACEHOLDER,value:k,onChange:e=>M(e.target.value),allowClear:!0})}),ae||0!==fe.length?o.jsx(q,{className:"apps-table",caption:"Applications",columns:De,dataSource:fe.map(e=>({...e,key:e.AppName})),loading:ae,pagination:{pageSize:j,position:["bottomCenter"],showSizeChanger:!1,hideOnSinglePage:!0},rowClassName:()=>"apps-clickable-row",onRow:e=>({onClick:()=>v(e.AppName)})}):o.jsx(Te,{title:i.APPLICATIONS_EMPTY_TITLE,subTitle:i.APPLICATIONS_EMPTY_SUBTITLE,hasButton:X,buttonTitle:i.APPLICATIONS_ADD_APPLICATION,onClick:()=>N(!0),permissionArray:["API_EditThirdPartyCredentials"],iconName:"table-empty",iconSize:64,hideButtonIcon:!1})]})}),o.jsx(Bt,{open:L,loading:!!A?.isLoading,onCancel:()=>N(!1),onCreate:e=>{const t=(e=>{const{appName:t,clientType:i,capabilities:n,description:s,deviceCodeConfig:a}=e,r=Le(n),o=ct(i),l=n.includes("browserLogin")||n.includes("deviceCode");return ut({AppName:t,Description:s||"",ClientType:i,ApplicationType:"web",Protocol:l?"OpenID Connect 1.0":"OAuth 2.0",TokenAuthMethod:o,JwtTokenConfig:{Algorithm:"RS256",TokenTTL:3600,IdTokenTTL:3600},RefreshTokenTTL:86400,ForceReAuthentication:!1,SignedUserInfo:!1,GrantTypes:r,AllowedScopes:l?["openid","email","phone","profile","address"]:[],...r.includes(be)&&a?{DeviceCodeConfig:a}:{},EnableCorsOrigin:!1,AllowedCorsOrigin:[],LoginRedirectUri:[],LogoutRedirectUri:[],BackChannelLogout:{IsEnabled:!1,LogoutURIs:[],LogoutTokenTTL:0},Registration:{DCR:{IsEnabled:!1},CIMD:{IsEnabled:!1}},PushedAuthorizationRequest:{IsEnabled:!1,IsRequired:!1},RichAuthorizationRequest:{IsEnabled:!1,AllowedTypes:[]},AudienceScopes:{},RefreshTokenRotation:{ReuseInterval:0},SubjectType:"public"})})(e);Ce.current=!0,P(t)}}),o.jsx(H,{open:X&&!!U,title:"Application",heading:i.APPLICATIONS_DELETE_APPLICATION,onConfirm:()=>{const e=ie.filter(e=>e.AppName!==U);Pe.current=!0,y({AppName:U},e)},onClose:()=>F(""),loading:!!T?.isLoading,message:i.APPS_DELETE_DESCRIPTION})]})});export{Je as CopyableTag,Yt as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.