PageSourceSearch

https://www.onepeloton.com/_next/static/chunks/526778d9-9ec5998f02…?dpl=dpl_BsvNBCqwx4HtZUy9sXU2x9f98NTi

js onepeloton.com collected 2026-09-24 09:07:36 UTC 165,251 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[44164],{86495:function(e,t,n){let r,o,i,a,s,c,l,u,h;function d(e,t){var n={};for(var r in e)Object.prototype.hasOwnProperty.call(e,r)&&0>t.indexOf(r)&&(n[r]=e[r]);if(null!=e&&"function"==typeof Object.getOwnPropertySymbols){var o=0;for(r=Object.getOwnPropertySymbols(e);o<r.length;o++)0>t.indexOf(r[o])&&Object.prototype.propertyIsEnumerable.call(e,r[o])&&(n[r[o]]=e[r[o]])}return n}n.d(t,{OS:function(){return ii}}),"function"==typeof SuppressedError&&SuppressedError;let p={timeoutInSeconds:60},f="memory",m={name:"auth0-spa-js",version:"2.19.2"},y=()=>Date.now(),w="default";class g extends Error{constructor(e,t){super(t),this.error=e,this.error_description=t,Object.setPrototypeOf(this,g.prototype)}static fromPayload(e){let{error:t,error_description:n}=e;return new g(t,n)}}class v extends g{constructor(e,t,n){let r=arguments.length>3&&void 0!==arguments[3]?arguments[3]:null;super(e,t),this.state=n,this.appState=r,Object.setPrototypeOf(this,v.prototype)}}class b extends g{constructor(e,t,n,r){let o=arguments.length>4&&void 0!==arguments[4]?arguments[4]:null;super(e,t),this.connection=n,this.state=r,this.appState=o,Object.setPrototypeOf(this,b.prototype)}}class _ extends g{constructor(){super("timeout","Timeout"),Object.setPrototypeOf(this,_.prototype)}}class k extends _{constructor(e){super(),this.popup=e,Object.setPrototypeOf(this,k.prototype)}}class S extends g{constructor(e){super("cancelled","Popup closed"),this.popup=e,Object.setPrototypeOf(this,S.prototype)}}class T extends g{constructor(){super("popup_open","Unable to open a popup for loginWithPopup - window.open returned `null`"),Object.setPrototypeOf(this,T.prototype)}}class E extends g{constructor(e,t,n,r){super(e,t),this.mfa_token=n,this.mfa_requirements=r,Object.setPrototypeOf(this,E.prototype)}}class P extends g{constructor(e,t){super("missing_refresh_token","Missing Refresh Token (audience: '".concat(x(e,["default"]),"', scope: '").concat(x(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,P.prototype)}}class A extends g{constructor(e,t){super("missing_scopes","Missing requested scopes after refresh (audience: '".concat(x(e,["default"]),"', missing scope: '").concat(x(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,A.prototype)}}class R extends g{constructor(e){super("use_dpop_nonce","Server rejected DPoP proof: wrong nonce"),this.newDpopNonce=e,Object.setPrototypeOf(this,R.prototype)}}function x(e){return e&&!(arguments.length>1&&void 0!==arguments[1]?arguments[1]:[]).includes(e)?e:""}let I=()=>window.crypto,O=()=>{let e="";for(;e.length<43;)for(let t of I().getRandomValues(new Uint8Array(43-e.length)))e.length<43&&t<198&&(e+="0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-_~."[t%66]);return e},C=e=>btoa(e),j=[{key:"name",type:["string"]},{key:"version",type:["string","number"]},{key:"env",type:["object"]}],W=function(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return Object.keys(e).reduce((n,r)=>{if(t&&"env"===r)return n;let o=j.find(e=>e.key===r);return o&&o.type.includes(typeof e[r])&&(n[r]=e[r]),n},{})},K=e=>{let t;var{clientId:n}=e;return new URLSearchParams(Object.keys(t=Object.assign({client_id:n},d(e,["clientId"]))).filter(e=>void 0!==t[e]).reduce((e,n)=>Object.assign(Object.assign({},e),{[n]:t[n]}),{})).toString()},U=async e=>{let t=I().subtle.digest({name:"SHA-256"},(new TextEncoder).encode(e));return await t},D=e=>decodeURIComponent(atob(e.replace(/_/g,"/").replace(/-/g,"+")).split("").map(e=>"%"+("00"+e.charCodeAt(0).toString(16)).slice(-2)).join("")),N=e=>{let t=new Uint8Array(e);return(e=>{let t={"+":"-","/":"_","=":""};return e.replace(/[+/=]/g,e=>t[e])})(window.btoa(String.fromCharCode(...Array.from(t))))};var L="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:void 0!==n.g?n.g:"undefined"!=typeof self?self:{},z={},H={};Object.defineProperty(H,"__esModule",{value:!0});var J=function(){function e(){var e=this;this.locked=new Map,this.addToLocked=function(t,n){var r=e.locked.get(t);void 0===r?void 0===n?e.locked.set(t,[]):e.locked.set(t,[n]):void 0!==n&&(r.unshift(n),e.locked.set(t,r))},this.isLocked=function(t){return e.locked.has(t)},this.lock=function(t){return new Promise(function(n,r){e.isLocked(t)?e.addToLocked(t,n):(e.addToLocked(t),n())})},this.unlock=function(t){var n=e.locked.get(t);if(void 0!==n&&0!==n.length){var r=n.pop();e.locked.set(t,n),void 0!==r&&setTimeout(r,0)}else e.locked.delete(t)}}return e.getInstance=function(){return void 0===e.instance&&(e.instance=new e),e.instance},e}();H.default=function(){return J.getInstance()};
1var M=L&&L.__awaiter||function(e,t,n,r){return new(n||(n=Promise))(function(o,i){function a(e){try{c(r.next(e))}catch(e){i(e)}}function s(e){try{c(r.throw(e))}catch(e){i(e)}}function c(e){e.done?o(e.value):new n(function(t){t(e.value)}).then(a,s)}c((r=r.apply(e,t||[])).next())})},Z=L&&L.__generator||function(e,t){var n,r,o,i,a={label:0,sent:function(){if(1&o[0])throw o[1];return o[1]},trys:[],ops:[]};return i={next:s(0),throw:s(1),return:s(2)},"function"==typeof Symbol&&(i[Symbol.iterator]=function(){return this}),i;function s(i){return function(s){return function(i){if(n)throw TypeError("Generator is already executing.");for(;a;)try{if(n=1,r&&(o=2&i[0]?r.return:i[0]?r.throw||((o=r.return)&&o.call(r),0):r.next)&&!(o=o.call(r,i[1])).done)return o;switch(r=0,o&&(i=[2&i[0],o.value]),i[0]){case 0:case 1:o=i;break;case 4:return a.label++,{value:i[1],done:!1};case 5:a.label++,r=i[1],i=[0];continue;case 7:i=a.ops.pop(),a.trys.pop();continue;default:if(!(o=(o=a.trys).length>0&&o[o.length-1])&&(6===i[0]||2===i[0])){a=0;continue}if(3===i[0]&&(!o||i[1]>o[0]&&i[1]<o[3])){a.label=i[1];break}if(6===i[0]&&a.label<o[1]){a.label=o[1],o=i;break}if(o&&a.label<o[2]){a.label=o[2],a.ops.push(i);break}o[2]&&a.ops.pop(),a.trys.pop();continue}i=t.call(e,a)}catch(e){i=[6,e],r=0}finally{n=o=0}if(5&i[0])throw i[1];return{value:i[0]?i[1]:void 0,done:!0}}([i,s])}}};Object.defineProperty(z,"__esModule",{value:!0});var V="browser-tabs-lock-key",X={key:function(e){return M(L,void 0,void 0,function(){return Z(this,function(e){throw Error("Unsupported")})})},getItem:function(e){return M(L,void 0,void 0,function(){return Z(this,function(e){throw Error("Unsupported")})})},clear:function(){return M(L,void 0,void 0,function(){return Z(this,function(e){return[2,window.localStorage.clear()]})})},removeItem:function(e){return M(L,void 0,void 0,function(){return Z(this,function(e){throw Error("Unsupported")})})},setItem:function(e,t){return M(L,void 0,void 0,function(){return Z(this,function(e){throw Error("Unsupported")})})},keySync:function(e){return window.localStorage.key(e)},getItemSync:function(e){return window.localStorage.getItem(e)},clearSync:function(){return window.localStorage.clear()},removeItemSync:function(e){return window.localStorage.removeItem(e)},setItemSync:function(e,t){return window.localStorage.setItem(e,t)}};function F(e){return new Promise(function(t){return setTimeout(t,e)})}function G(e){for(var t="",n=0;n<e;n++)t+="0123456789ABCDEFGHIJKLMNOPQRSTUVWXTZabcdefghiklmnopqrstuvwxyz"[Math.floor(61*Math.random())];return t}var Y=function(){function e(t){this.acquiredIatSet=new Set,this.storageHandler=void 0,this.id=Date.now().toString()+G(15),this.acquireLock=this.acquireLock.bind(this),this.releaseLock=this.releaseLock.bind(this),this.releaseLock__private__=this.releaseLock__private__.bind(this),this.waitForSomethingToChange=this.waitForSomethingToChange.bind(this),this.refreshLockWhileAcquired=this.refreshLockWhileAcquired.bind(this),this.storageHandler=t,void 0===e.waiters&&(e.waiters=[])}return e.prototype.acquireLock=function(t,n){return void 0===n&&(n=5e3),M(this,void 0,void 0,function(){var r,o,i,a,s,c,l;return Z(this,function(u){switch(u.label){case 0:r=Date.now()+G(4),o=Date.now()+n,i=V+"-"+t,a=void 0===this.storageHandler?X:this.storageHandler,u.label=1;case 1:return Date.now()<o?[4,F(30)]:[3,8];case 2:return u.sent(),null!==a.getItemSync(i)?[3,5]:(s=this.id+"-"+t+"-"+r,[4,F(Math.floor(25*Math.random()))]);case 3:return u.sent(),a.setItemSync(i,JSON.stringify({id:this.id,iat:r,timeoutKey:s,timeAcquired:Date.now(),timeRefreshed:Date.now()})),[4,F(30)];case 4:return u.sent(),null!==(c=a.getItemSync(i))&&(l=JSON.parse(c)).id===this.id&&l.iat===r?(this.acquiredIatSet.add(r),this.refreshLockWhileAcquired(i,r),[2,!0]):[3,7];case 5:return e.lockCorrector(void 0===this.storageHandler?X:this.storageHandler),[4,this.waitForSomethingToChange(o)];case 6:u.sent(),u.label=7;case 7:return r=Date.now()+G(4),[3,1];case 8:return[2,!1]}})})},e.prototype.refreshLockWhileAcquired=function(e,t){return M(this,void 0,void 0,function(){var n=this;return Z(this,function(r){return setTimeout(function(){return M(n,void 0,void 0,function(){var n,r,o;return Z(this,function(i){switch(i.label){case 0:return[4,H.default().lock(t)];case 1:return i.sent(),this.acquiredIatSet.has(t)?null===(r=(n=void 0===this.storageHandler?X:this.storageHandler).getItemSync(e))?H.default().unlock(t):((o=JSON.parse(r)).timeRefreshed=Date.now(),n.setItemSync(e,JSON.stringify(o)),H.default().unlock(t),this.refreshLockWhileAcquired(e,t)):H.default().unlock(t),[2]}})})},1e3),[2]})})},e.prototype.waitForSomethingToChange=function(t){return M(this,void 0,void 0,function(){return Z(this,function(n){switch(n.label){case 0:return[4,new Promise(function(n){var r=!1,o=Date.now(),i=!1;function a(){if(i||(window.removeEventListener("storage",a),e.removeFromWaiting(a),clearTimeout(s),i=!0),!r){r=!0;var t=50-(Date.now()-o);t>0?setTimeout(n,t):n(null)}}window.addEventListener("storage",a),e.addToWaiting(a);var s=setTimeout(a,Math.max(0,t-Date.now()))})];case 1:return n.sent(),[2]}})})},e.addToWaiting=function(t){this.removeFromWaiting(t),void 0!==e.waiters&&e.waiters.push(t)},e.removeFromWaiting=function(t){void 0!==e.waiters&&(e.waiters=e.waiters.filter(function(e){return e!==t}))},e.notifyWaiters=function(){void 0!==e.waiters&&e.waiters.slice().forEac
1h(function(e){return e()})},e.prototype.releaseLock=function(e){return M(this,void 0,void 0,function(){return Z(this,function(t){switch(t.label){case 0:return[4,this.releaseLock__private__(e)];case 1:return[2,t.sent()]}})})},e.prototype.releaseLock__private__=function(t){return M(this,void 0,void 0,function(){var n,r,o,i;return Z(this,function(a){switch(a.label){case 0:return n=void 0===this.storageHandler?X:this.storageHandler,r=V+"-"+t,null===(o=n.getItemSync(r))?[2]:(i=JSON.parse(o)).id!==this.id?[3,2]:[4,H.default().lock(i.iat)];case 1:a.sent(),this.acquiredIatSet.delete(i.iat),n.removeItemSync(r),H.default().unlock(i.iat),e.notifyWaiters(),a.label=2;case 2:return[2]}})})},e.lockCorrector=function(t){for(var n=Date.now()-5e3,r=[],o=0;;){var i=t.keySync(o);if(null===i)break;r.push(i),o++}for(var a=!1,s=0;s<r.length;s++){var c=r[s];if(c.includes(V)){var l=t.getItemSync(c);if(null!==l){var u=JSON.parse(l);(void 0===u.timeRefreshed&&u.timeAcquired<n||void 0!==u.timeRefreshed&&u.timeRefreshed<n)&&(t.removeItemSync(c),a=!0)}}}a&&e.notifyWaiters()},e.waiters=void 0,e}(),B=z.default=Y;class q{async runWithLock(e,t,n){let r=new AbortController,o=setTimeout(()=>r.abort(),t);try{return await navigator.locks.request(e,{mode:"exclusive",signal:r.signal},async e=>{if(clearTimeout(o),!e)throw Error("Lock not available");return await n()})}catch(e){if(clearTimeout(o),"AbortError"===(null==e?void 0:e.name))throw new _;throw e}}}class Q{constructor(){this.activeLocks=new Set,this.lock=new B,this.pagehideHandler=()=>{this.activeLocks.forEach(e=>this.lock.releaseLock(e)),this.activeLocks.clear()}}async runWithLock(e,t,n){let r=!1;for(let n=0;n<10&&!r;n++)r=await this.lock.acquireLock(e,t);if(!r)throw new _;this.activeLocks.add(e),1===this.activeLocks.size&&"undefined"!=typeof window&&window.addEventListener("pagehide",this.pagehideHandler);try{return await n()}finally{this.activeLocks.delete(e),await this.lock.releaseLock(e),0===this.activeLocks.size&&"undefined"!=typeof window&&window.removeEventListener("pagehide",this.pagehideHandler)}}}let $=null,ee=new TextEncoder,et=new TextDecoder;function en(e){return"string"==typeof e?ee.encode(e):et.decode(e)}function er(e){if("number"!=typeof e.modulusLength||e.modulusLength<2048)throw new ea(`${e.name} modulusLength must be at least 2048 bits`)}async function eo(e,t,n){var o,i,a;if(!1===n.usages.includes("sign"))throw TypeError('private CryptoKey instances used for signing assertions must include "sign" in their "usages"');let s=`${(o=en(JSON.stringify(e)),r(o))}.${(i=en(JSON.stringify(t)),r(i))}`;return`${s}.${a=await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:"SHA-256"};case"RSA-PSS":return er(e.algorithm),{name:e.algorithm.name,saltLength:32};case"RSASSA-PKCS1-v1_5":return er(e.algorithm),{name:e.algorithm.name};case"Ed25519":return{name:e.algorithm.name}}throw new ei}(n),n,en(s)),r(a)}`}Uint8Array.prototype.toBase64?r=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0})):r=e=>{e instanceof ArrayBuffer&&(e=new Uint8Array(e));let t=[];for(let n=0;n<e.byteLength;n+=32768)t.push(String.fromCharCode.apply(null,e.subarray(n,n+32768)));return btoa(t.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")};class ei extends Error{constructor(e){var t;super(null!=e?e:"operation not supported"),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}
1class ea extends Error{constructor(e){var t;super(e),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}function es(e){return e instanceof CryptoKey}function ec(e){return es(e)&&"public"===e.type}async function el(e,t,n,o,i,a){var s;let c=null==e?void 0:e.privateKey,l=null==e?void 0:e.publicKey;if(!es(c)||"private"!==c.type)throw TypeError('"keypair.privateKey" must be a private CryptoKey');if(!ec(l))throw TypeError('"keypair.publicKey" must be a public CryptoKey');if(!0!==l.extractable)throw TypeError('"keypair.publicKey.extractable" must be true');if("string"!=typeof t)throw TypeError('"htu" must be a string');if("string"!=typeof n)throw TypeError('"htm" must be a string');if(void 0!==o&&"string"!=typeof o)throw TypeError('"nonce" must be a string or undefined');if(void 0!==i&&"string"!=typeof i)throw TypeError('"accessToken" must be a string or undefined');if(void 0!==a&&("object"!=typeof a||null===a||Array.isArray(a)))throw TypeError('"additional" must be an object');return eo({alg:function(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){if("SHA-256"===e.algorithm.hash.name)return"PS256";throw new ei("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"RSASSA-PKCS1-v1_5":return function(e){if("SHA-256"===e.algorithm.hash.name)return"RS256";throw new ei("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"ECDSA":return function(e){if("P-256"===e.algorithm.namedCurve)return"ES256";throw new ei("unsupported EcKeyAlgorithm namedCurve")}(e);case"Ed25519":return"Ed25519";default:throw new ei("unsupported CryptoKey algorithm name")}}(c),typ:"dpop+jwt",jwk:await eu(l)},Object.assign(Object.assign({},a),{iat:Math.floor(Date.now()/1e3),jti:crypto.randomUUID(),htm:n,nonce:o,htu:t,ath:i?(s=await crypto.subtle.digest("SHA-256",en(i)),r(s)):void 0}),c)}async function eu(e){let{kty:t,e:n,n:r,x:o,y:i,crv:a}=await crypto.subtle.exportKey("jwk",e);return{kty:t,crv:a,e:n,n:r,x:o,y:i}}let eh="dpop-nonce",ed=["authorization_code","refresh_token","urn:ietf:params:oauth:grant-type:token-exchange","http://auth0.com/oauth/grant-type/mfa-oob","http://auth0.com/oauth/grant-type/mfa-otp","http://auth0.com/oauth/grant-type/mfa-rec
1overy-code"],ep=(e,t)=>new Promise(function(n,r){let o=new MessageChannel;o.port1.onmessage=function(e){e.data.error?r(Error(e.data.error)):n(e.data),o.port1.close()},t.postMessage(e,[o.port2])}),ef=(e,t,n)=>{let r;let o=new AbortController;return t.signal=o.signal,Promise.race([fetch(e,t),new Promise((e,t)=>{r=setTimeout(()=>{o.abort(),t(Error("Timeout when executing 'fetch'"))},n)})]).finally(()=>{clearTimeout(r)})},em=async function(e,t,n,r,o,i){let a=arguments.length>6&&void 0!==arguments[6]?arguments[6]:1e4;return o?(async(e,t,n,r,o,i,a,s)=>ep({type:"refresh",auth:{audience:t,scope:n},timeout:o,fetchUrl:e,fetchOptions:r,useFormData:a,useMrrt:s},i))(e,t,n,r,a,o,i,arguments.length>7?arguments[7]:void 0):(async(e,t,n)=>{let r=await ef(e,t,n);return{ok:r.ok,json:await r.json(),headers:[...r.headers].reduce((e,t)=>{let[n,r]=t;return e[n]=r,e},{})}})(e,r,a)};async function ey(e,t,n,r,o,i,a,s,c,l){let u;if(c){let t=await c.generateProof({url:e,method:o.method||"GET",nonce:await c.getNonce()});o.headers=Object.assign(Object.assign({},o.headers),{dpop:t})}let h,p=null;for(let c=0;c<3;c++)try{h=await em(e,n,r,o,i,a,t,s),p=null;break}catch(e){p=e}if(p)throw p;let f=h.json,{error:m,error_description:y}=f,w=d(f,["error","error_description"]),{headers:v,ok:b}=h;if(c&&(u=v[eh])&&await c.setNonce(u),!b){let h=y||"HTTP error. Unable to fetch ".concat(e);if("mfa_required"===m)throw new E(m,h,w.mfa_token,w.mfa_requirements);if("missing_refresh_token"===m)throw new P(n,r);if("use_dpop_nonce"===m){if(!c||!u||l)throw new R(u);return ey(e,t,n,r,o,i,a,s,c,!0)}throw new g(m||"request_error",h)}return w}async function ew(e,t){var n,{baseUrl:r,timeout:o,audience:i,scope:a,auth0Client:s,useFormData:c,useMrrt:l,dpop:u}=e,h=d(e,["baseUrl","timeout","audience","scope","auth0Client","useFormData","useMrrt","dpop"]);let p="urn:ietf:params:oauth:grant-type:token-exchange"===h.grant_type,f="refresh_token"===h.grant_type&&l,y=Object.assign(Object.assign(Object.assign(Object.assign({},h),p&&i&&{audience:i}),p&&a&&{scope:a}),f&&{audience:i,scope:a}),g=c?K(y):JSON.stringify(y),v=(n=h.grant_type,ed.includes(n));return await ey("".concat(r,"/oauth/token"),o,i||w,a,{method:"POST",body:g,headers:{"Content-Type":c?"application/x-www-form-urlencoded":"application/json","Auth0-Client":btoa(JSON.stringify(W(s||m)))}},t,c,l,v?u:void 0)}let eg=function(){for(var e=arguments.length,t=Array(e),n=0;n<e;n++)t[n]=arguments[n];return Array.from(new Set(t.filter(Boolean).join(" ").trim().split(/\s+/))).join(" ")},ev=(e,t,n)=>{let r;return n&&(r=e[n]),r||(r=e[w]),eg(r,t)},eb="@@auth0spajs@@",e_="@@user@@";class ek{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:eb,n=arguments.length>2?arguments[2]:void 0;this.prefix=t,this.suffix=n,this.clientId=e.clientId,this.scope=e.scope,this.audience=e.audience}toKey(){return[this.prefix,this.clientId,this.audience,this.scope,this.suffix].filter(Boolean).join("::")}static fromKey(e){let[t,n,r,o]=e.split("::");return new ek({clientId:n,scope:o,audience:r},t)}static fromCacheEntry(e){let{scope:t,audience:n,client_id:r}=e;return new ek({scope:t,audience:n,clientId:r})}}class eS{set(e,t){localStorage.setItem(e,JSON.stringify(t))}get(e){let t=window.localStorage.getItem(e);if(t)try{return JSON.parse(t)}catch(e){return}}remove(e){localStorage.removeItem(e)}allKeys(){return Object.keys(window.localStorage).filter(e=>e.startsWith(eb))}}class eT{constructor(){let e;this.enclosedCache=(e={},{set(t,n){e[t]=n},get(t){let n=e[t];if(n)return n},remove(t){delete e[t]},allKeys:()=>Object.keys(e)})}}class eE{constructor(e,t,n){this.cache=e,this.keyManifest=t,this.nowProvider=n||y}async setIdToken(e,t,n){var r;let o=this.getIdTokenCacheKey(e);await this.cache.set(o,{id_token:t,decodedToken:n}),await (null===(r=this.keyManifest)||void 0===r?void 0:r.add(o))}async getIdToken(e){let t=await this.cache.get(this.getIdTokenCacheKey(e.clientId));if(!t&&e.scope&&e.audience){let t=await this.get(e);if(!t||!t.id_token||!t.decodedToken)return;return{id_token:t.id_token,decodedToken:t.decodedToken}}if(t)return{id_token:t.id_token,decodedToken:t.decodedToken}}async get(e){var t;let n=arguments.length>1&&void 0!==arguments[1]?arguments[1]:0,r=arguments.length>2&&void 0!==arguments[2]&&arguments[2],o=arguments.length>3?arguments[3]:void 0,i=await this.cache.get(e.toKey()),a=e;if(!i){let t=await this.getCacheKeys();if(!t)return;let n=this.matchExistingCacheKey(e,t);if(n&&(i=await this.cache.get(n),a=ek.fromKey(n)),!i&&r&&"cache-only"!==o)return this.getEntryWithRefreshToken(e,t)}if(!i)return;let s=await this.nowProvider();return i.expiresAt-n<Math.floor(s/1e3)?i.body.refresh_token?this.modifiedCachedEntry(i,a):(await this.cache.remove(a.toKey()),void await (null===(t=this.keyManifest)||void 0===t?void 0:t.remove(a.toKey()))):i.body}async modifiedCachedEntry(e,t){let n={refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope},r={body:n,expiresAt:e.expiresAt};return await this.cache.set(t.toKey(),r),{refresh_token:n.refresh_token,audience:n.audience,scope:n.scope}}async set(e){var t;let n=new ek({clientId:e.client_id,scope:e.scope,audience:e.audience}),r=await this.wrapCacheEntry(e);await this.cache.set(n.toKey(),r),await (null===(t=this.keyManifest)||void 0===t?void 0:t.add(n.toKey()))}async remove(e,t,n){let r=new ek({clientId:e,scope:n,audience:t});await this.cache.remove(r.toKey())}async stripRefreshToken(e){var t;let n=await this.getCacheKeys();if(n)for(let r of n){let n=await this.cache.get(r);(null===(t=null==n?void 0:n.body)||void 0===t?void 0:t.refresh_token)===e&&(delete n.body.refresh_token,await this.cache.set(r,n))}}async clear(e){var t;let n=await this.getCacheKeys();n&&(await n.filter(t=>!e||t.includes(e)).reduce(async(e,t)=>{await e,await this.cache.remove(t)},Promise.resolve()),await (null===(t=this.keyManifest)||void 0===t?void 0:t.clear()))}async wrapCacheEntry(e){return{body:e,expiresAt:Math.floor(await this.nowProvider()/1e3)+e.expires_in}}async getCacheKeys(){var e;return this.keyManifest?null===(e=await this.keyManifest.get())||void 0===e?void 0:e.keys:this.cache.allKe
1ys?this.cache.allKeys():void 0}getIdTokenCacheKey(e){return new ek({clientId:e},eb,e_).toKey()}matchExistingCacheKey(e,t){return t.filter(t=>{var n;let r=ek.fromKey(t),o=new Set(r.scope&&r.scope.split(" ")),i=(null===(n=e.scope)||void 0===n?void 0:n.split(" "))||[],a=r.scope&&i.reduce((e,t)=>e&&o.has(t),!0);return r.prefix===eb&&r.clientId===e.clientId&&r.audience===e.audience&&a})[0]}async getEntryWithRefreshToken(e,t){var n;for(let r of t){let t=ek.fromKey(r);if(t.prefix===eb&&t.clientId===e.clientId){let e=await this.cache.get(r);if(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)return{refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope}}}}async getRefreshTokensByAudience(e,t){var n;let r=await this.getCacheKeys();if(!r)return[];let o=new Set;for(let i of r){let r=ek.fromKey(i);if(r.prefix===eb&&r.clientId===t&&r.audience===e){let e=await this.cache.get(i);(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)&&o.add(e.body.refresh_token)}}return Array.from(o)}async updateEntry(e,t){var n;let r=await this.getCacheKeys();if(r)for(let o of r){let r=await this.cache.get(o);(null===(n=null==r?void 0:r.body)||void 0===n?void 0:n.refresh_token)===e&&(r.body.refresh_token=t,await this.cache.set(o,r))}}}class eP{constructor(e,t,n){this.storage=e,this.clientId=t,this.cookieDomain=n,this.storageKey="".concat("a0.spajs.txs",".").concat(this.clientId)}create(e){this.storage.save(this.storageKey,e,{daysUntilExpire:1,cookieDomain:this.cookieDomain})}get(){return this.storage.get(this.storageKey)}remove(){this.storage.remove(this.storageKey,{cookieDomain:this.cookieDomain})}}let eA=e=>"number"==typeof e,eR=["iss","aud","exp","nbf","iat","jti","azp","nonce","auth_time","at_hash","c_hash","acr","amr","sub_jwk","cnf","sip_from_tag","sip_date","sip_callid","sip_cseq_num","sip_via_branch","orig","dest","mky","events","toe","txn","rph","sid","vot","vtm"],ex=e=>{if(!e.id_token)throw Error("ID token is required but missing");let t=(e=>{let t=e.split("."),[n,r,o]=t;if(3!==t.length||!n||!r||!o)throw Error("ID token could not be decoded");let i=JSON.parse(D(r)),a={__raw:e},s={};
1return Object.keys(i).forEach(e=>{a[e]=i[e],eR.includes(e)||(s[e]=i[e])}),{encoded:{header:n,payload:r,signature:o},header:JSON.parse(D(n)),claims:a,user:s}})(e.id_token);if(!t.claims.iss)throw Error("Issuer (iss) claim must be a string present in the ID token");if(t.claims.iss!==e.iss)throw Error('Issuer (iss) claim mismatch in the ID token; expected "'.concat(e.iss,'", found "').concat(t.claims.iss,'"'));if(!t.user.sub)throw Error("Subject (sub) claim must be a string present in the ID token");if("RS256"!==t.header.alg)throw Error('Signature algorithm of "'.concat(t.header.alg,'" is not supported. Expected the ID token to be signed with "RS256".'));if(!t.claims.aud||"string"!=typeof t.claims.aud&&!Array.isArray(t.claims.aud))throw Error("Audience (aud) claim must be a string or array of strings present in the ID token");if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e.aud))throw Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but was not one of "').concat(t.claims.aud.join(", "),'"'));if(t.claims.aud.length>1){if(!t.claims.azp)throw Error("Authorized Party (azp) claim must be a string present in the ID token when Audience (aud) claim has multiple values");if(t.claims.azp!==e.aud)throw Error('Authorized Party (azp) claim mismatch in the ID token; expected "'.concat(e.aud,'", found "').concat(t.claims.azp,'"'))}}else if(t.claims.aud!==e.aud)throw Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but found "').concat(t.claims.aud,'"'));if(e.nonce){if(!t.claims.nonce)throw Error("Nonce (nonce) claim must be a string present in the ID token");if(t.claims.nonce!==e.nonce)throw Error('Nonce (nonce) claim mismatch in the ID token; expected "'.concat(e.nonce,'", found "').concat(t.claims.nonce,'"'))}if(e.max_age&&!eA(t.claims.auth_time))throw Error("Authentication Time (auth_time) claim must be a number present in the ID token when Max Age (max_age) is specified");if(null==t.claims.exp||!eA(t.claims.exp))throw Error("Expiration Time (exp) claim must be a number present in the ID token");if(!eA(t.claims.iat))throw Error("Issued At (iat) claim must be a number present in the ID token");let n=e.leeway||60,r=new Date(e.now||Date.now()),o=new Date(0);if(o.setUTCSeconds(t.claims.exp+n),r>o)throw Error("Expiration Time (exp) claim error in the ID token; current time (".concat(r,") is after expiration time (").concat(o,")"));if(null!=t.claims.nbf&&eA(t.claims.nbf)){let e=new Date(0);if(e.setUTCSeconds(t.claims.nbf-n),r<e)throw Error("Not Before time (nbf) claim in the ID token indicates that this token can't be used just yet. Current time (".concat(r,") is before ").concat(e))}if(null!=t.claims.auth_time&&eA(t.claims.auth_time)){let o=new Date(0);if(o.setUTCSeconds(parseInt(t.claims.auth_time)+e.max_age+n),r>o)throw Error("Authentication Time (auth_time) claim in the ID token indicates that too much time has passed since the last end-user authentication. Current time (".concat(r,") is after last auth at ").concat(o))}if(e.organization){let n=e.organization.trim();if(n.startsWith("org_")){if(!t.claims.org_id)throw Error("Organization ID (org_id) claim must be a string present in the ID token");if(n!==t.claims.org_id)throw Error('Organization ID (org_id) claim mismatch in the ID token; expected "'.concat(n,'", found "').concat(t.claims.org_id,'"'))}else{let e=n.toLowerCase();if(!t.claims.org_name)throw Error("Organization Name (org_name) claim must be a string present in the ID token");if(e!==t.claims.org_name)throw Error('Organization Name (org_name) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_name,'"'))}}return t};var eI=L&&L.__assign||function(){return(eI=Object.assign||function(e){for(var t,n=1,r=arguments.length;n<r;n++)for(var o in t=arguments[n])Object.prototype.hasOwnProperty.call(t,o)&&(e[o]=t[o]);return e}).apply(this,arguments)};function eO(e,t){if(!t)return"";var n="; "+e;return!0===t?n:n+"="+t}function eC(e,t,n){var r;document.cookie=(r=eI({path:"/"},n),encodeURIComponent(e).replace(/%(23|24|26|2B|5E|60|7C)/g,decode
1URIComponent).replace(/\(/g,"%28").replace(/\)/g,"%29")+"="+encodeURIComponent(t).replace(/%(23|24|26|2B|3A|3C|3E|3D|2F|3F|40|5B|5D|5E|60|7B|7D|7C)/g,decodeURIComponent)+function(e){if("number"==typeof e.expires){var t=new Date;t.setMilliseconds(t.getMilliseconds()+864e5*e.expires),e.expires=t}return eO("Expires",e.expires?e.expires.toUTCString():"")+eO("Domain",e.domain)+eO("Path",e.path)+eO("Secure",e.secure)+eO("SameSite",e.sameSite)}(r))}var ej=function(e,t){eC(e,"",eI(eI({},t),{expires:-1}))};let eW={get(e){let t=function(e){for(var t={},n=e?e.split("; "):[],r=/(%[\dA-F]{2})+/gi,o=0;o<n.length;o++){var i=n[o].split("="),a=i.slice(1).join("=");'"'===a.charAt(0)&&(a=a.slice(1,-1));try{t[i[0].replace(r,decodeURIComponent)]=a.replace(r,decodeURIComponent)}catch(e){}}return t}(document.cookie)[e];if(void 0!==t)return JSON.parse(t)},save(e,t,n){let r={};"https:"===window.location.protocol&&(r={secure:!0,sameSite:"none"}),(null==n?void 0:n.daysUntilExpire)&&(r.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(r.domain=n.cookieDomain),eC(e,JSON.stringify(t),r)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),ej(e,n)}},eK="_legacy_",eU={get:e=>eW.get(e)||eW.get("".concat(eK).concat(e)),save(e,t,n){let r={};"https:"===window.location.protocol&&(r={secure:!0}),(null==n?void 0:n.daysUntilExpire)&&(r.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(r.domain=n.cookieDomain),eC("".concat(eK).concat(e),JSON.stringify(t),r),eW.save(e,t,n)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),ej(e,n),eW.remove(e,t),eW.remove("".concat(eK).concat(e),t)}},eD={get(e){if("undefined"==typeof sessionStorage)return;let t=sessionStorage.getItem(e);return null!=t?JSON.parse(t):void 0},save(e,t){sessionStorage.setItem(e,JSON.stringify(t))},remove(e){sessionStorage.removeItem(e)}};(eN=eL||(eL={})).Code="code",eN.ConnectCode="connect_code";var eN,eL,ez,eH,eJ=(ez="Lyogcm9sbHVwLXBsdWdpbi13ZWItd29ya2VyLWxvYWRlciAqLwohZnVuY3Rpb24oKXsidXNlIHN0cmljdCI7Y2xhc3MgZSBleHRlbmRzIEVycm9ye2NvbnN0cnVjdG9yKHQscil7c3VwZXIociksdGhpcy5lcnJvcj10LHRoaXMuZXJyb3JfZGVzY3JpcHRpb249cixPYmplY3Quc2V0UHJvdG90eXBlT2YodGhpcyxlLnByb3RvdHlwZSl9c3RhdGljIGZyb21QYXlsb2FkKHQpe2xldHtlcnJvcjpyLGVycm9yX2Rlc2NyaXB0aW9uOm99PXQ7cmV0dXJuIG5ldyBlKHIsbyl9fWNsYXNzIHQgZXh0ZW5kcyBle2NvbnN0cnVjdG9yKGUsbyl7c3VwZXIoIm1pc3NpbmdfcmVmcmVzaF90b2tlbiIsIk1pc3NpbmcgUmVmcmVzaCBUb2tlbiAoYXVkaWVuY2U6ICciLmNvbmNhdChyKGUsWyJkZWZhdWx0Il0pLCInLCBzY29wZTogJyIpLmNvbmNhdChyKG8pLCInKSIpKSx0aGlzLmF1ZGllbmNlPWUsdGhpcy5zY29wZT1vLE9iamVjdC5zZXRQcm90b3R5cGVPZih0aGlzLHQucHJvdG90eXBlKX19ZnVuY3Rpb24gcihlKXtyZXR1cm4gZSYmIShhcmd1bWVudHMubGVuZ3RoPjEmJnZvaWQgMCE9PWFyZ3VtZW50c1sxXT9hcmd1bWVudHNbMV06W10pLmluY2x1ZGVzKGUpP2U6IiJ9ImZ1bmN0aW9uIj09dHlwZW9mIFN1cHByZXNzZWRFcnJvciYmU3VwcHJlc3NlZEVycm9yO2NvbnN0IG89ZT0+e3ZhcntjbGllbnRJZDp0fT1lLHI9ZnVuY3Rpb24oZSx0KXt2YXIgcj17fTtmb3IodmFyIG8gaW4gZSlPYmplY3QucHJvdG90eXBlLmhhc093blByb3BlcnR5LmNhbGwoZSxvKSYmdC5pbmRleE9mKG8pPDAmJihyW29dPWVbb10pO2lmKG51bGwhPWUmJiJmdW5jdGlvbiI9PXR5cGVvZiBPYmplY3QuZ2V0T3duUHJvcGVydHlTeW1ib2xzKXt2YXIgcz0wO2ZvcihvPU9iamVjdC5nZXRPd25Qcm9wZXJ0eVN5bWJvbHMoZSk7czxvLmxlbmd0aDtzKyspdC5pbmRleE9mKG9bc10pPDAmJk9iamVjdC5wcm90b3R5cGUucHJvcGVydHlJc0VudW1lcmFibGUuY2FsbChlLG9bc10pJiYocltvW3NdXT1lW29bc11dKX1yZXR1cm4gcn0oZSxbImNsaWVudElkIl0pO3JldHVybiBuZXcgVVJMU2VhcmNoUGFyYW1zKChlPT5PYmplY3Qua2V5cyhlKS5maWx0ZXIodD0+dm9pZCAwIT09ZVt0XSkucmVkdWNlKCh0LHIpPT5PYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30sdCkse1tyXTplW3JdfSkse30pKShPYmplY3QuYXNzaWduKHtjbGllbnRfaWQ6dH0scikpKS50b1N0cmluZygpfTtsZXQgcz17fSxuPW51bGw7Y29uc3QgaT0oZSx0KT0+IiIuY29uY2F0KGUsInwiKS5jb25jYXQodCksYT0oZSx0KT0+dC5zdGFydHNXaXRoKCIiLmNvbmNhdChlLCJ8IikpLGM9ZT0+e09iamVjdC5lbnRyaWVzKHMpLmZvckVhY2godD0+e2xldFtyLG9dPXQ7bz09PWUmJmRlbGV0ZSBzW3JdfSl9LGw9ZT0+e2NvbnN0IHQ9bmV3IFVSTFNlYXJjaFBhcmFtcyhlKSxyPXt9O3JldHVybiB0LmZvckVhY2goKGUsdCk9PntyW3RdPWV9KSxyfSxmPWFzeW5jIGU9PntsZXQgcixuLHtkYXRhOnt0aW1lb3V0OmMsYXV0aDpmLGZldGNoVXJsOnUsZmV0Y2hPcHRpb25zOmgsdXNlRm9ybURhdGE6ZCx1c2VNcnJ0OnB9LHBvcnRzOltnXX09ZSx5PXt9O2NvbnN0e2F1ZGllbmNlOmIsc2NvcGU6T309Znx8e307dHJ5e2NvbnN0IGU9ZD9sKGguYm9keSk6SlNPTi5wYXJzZShoLmJvZHkpO2lmKCFlLnJlZnJlc2hfdG9rZW4mJiJyZWZyZXNoX3Rva2VuIj09PWUuZ3JhbnRfdHlwZSl7aWYobj0oKGUsdCk9PnNbaShlLHQpXSkoYixPKSwhbiYmcCl7Y29uc3QgZT1zLmxhdGVzdF9yZWZyZXNoX3Rva2VuLHQ9KChlLHQpPT4hIU9iamVjdC5rZXlzKHMpLmZpbmQocj0+e2lmKCJsYXRlc3RfcmVmcmVzaF90b2tlbiIhPT1yKXtjb25zdCBvPWEodCxyKSxzPXIuc3BsaXQoInwiKVsxXS5zcGxpdCgiICIpLG49ZS5zcGxpdCgiICIpLmV2ZXJ5KGU9PnMuaW5jbHVkZXMoZSkpO3JldHVybiBvJiZufX0pKShPLGIpO2UmJiF0JiYobj1lKX1pZighbil0aHJvdyBuZXcgdChiLE8pO2guYm9keT1kP28oT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LGUpLHtyZWZyZXNoX3Rva2VuOm59KSk6SlNPTi5zdHJpbmdpZnkoT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LGUpLHtyZWZyZXNoX3Rva2VuOm59KSl9bGV0IGYsdzsiZnVuY3Rpb24iPT10eXBlb2YgQWJvcnRDb250cm9sbGVyJiYoZj1uZXcgQWJvcnRDb250cm9sbGVyLGguc2lnbmFsPWYuc2lnbmFsKTt0cnl7dz1hd2FpdCBQcm9taXNlLnJhY2UoWyhtPWMsbmV3IFByb21pc2UoZT0+c2V0VGltZW91dChlLG0pKSksZmV0Y2godSxPYmplY3QuYXNzaWduKHt9LGgpKV0pfWNhdGNoKGUpe3JldHVybiB2b2lkIGcucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZX0pfWlmKCF3
1KXJldHVybiBmJiZmLmFib3J0KCksdm9pZCBnLnBvc3RNZXNzYWdlKHtlcnJvcjoiVGltZW91dCB3aGVuIGV4ZWN1dGluZyAnZmV0Y2gnIn0pO189dy5oZWFkZXJzLHk9Wy4uLl9dLnJlZHVjZSgoZSx0KT0+e2xldFtyLG9dPXQ7cmV0dXJuIGVbcl09byxlfSx7fSkscj1hd2FpdCB3Lmpzb24oKSxyLnJlZnJlc2hfdG9rZW4/KHAmJihzLmxhdGVzdF9yZWZyZXNoX3Rva2VuPXIucmVmcmVzaF90b2tlbixrPW4saj1yLnJlZnJlc2hfdG9rZW4sT2JqZWN0LmVudHJpZXMocykuZm9yRWFjaChlPT57bGV0W3Qscl09ZTtyPT09ayYmKHNbdF09ail9KSksKChlLHQscik9PntzW2kodCxyKV09ZX0pKHIucmVmcmVzaF90b2tlbixiLE8pLGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4pOigoZSx0KT0+e2RlbGV0ZSBzW2koZSx0KV19KShiLE8pLGcucG9zdE1lc3NhZ2Uoe29rOncub2ssanNvbjpyLGhlYWRlcnM6eX0pfWNhdGNoKGUpe2cucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOmUuZXJyb3IsZXJyb3JfZGVzY3JpcHRpb246ZS5tZXNzYWdlfSxoZWFkZXJzOnl9KX12YXIgayxqLF8sbX0sdT1hc3luYyBlPT57bGV0e2RhdGE6e3RpbWVvdXQ6dCxhdXRoOnIsZmV0Y2hVcmw6bixmZXRjaE9wdGlvbnM6aSx1c2VGb3JtRGF0YTpmfSxwb3J0czpbdV19PWU7Y29uc3R7YXVkaWVuY2U6aH09cnx8e307dHJ5e2NvbnN0IGU9KGU9Pntjb25zdCB0PW5ldyBTZXQ7cmV0dXJuIE9iamVjdC5lbnRyaWVzKHMpLmZvckVhY2gocj0+e2xldFtvLHNdPXI7YShlLG8pJiZ0LmFkZChzKX0pLEFycmF5LmZyb20odCl9KShoKTtpZigwPT09ZS5sZW5ndGgpcmV0dXJuIHZvaWQgdS5wb3N0TWVzc2FnZSh7b2s6ITB9KTtjb25zdCByPWY/bChpLmJvZHkpOkpTT04ucGFyc2UoaS5ib2R5KTtmb3IoY29uc3QgcyBvZiBlKXtjb25zdCBlPWY/byhPYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30scikse3Rva2VuOnN9KSk6SlNPTi5zdHJpbmdpZnkoT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHIpLHt0b2tlbjpzfSkpO2xldCBhLGwsaCxkOyJmdW5jdGlvbiI9PXR5cGVvZiBBYm9ydENvbnRyb2xsZXImJihhPW5ldyBBYm9ydENvbnRyb2xsZXIsbD1hLnNpZ25hbCk7dHJ5e2Q9YXdhaXQgUHJvbWlzZS5yYWNlKFtuZXcgUHJvbWlzZS
1hlPT57aD1zZXRUaW1lb3V0KGUsdCl9KSxmZXRjaChuLE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxpKSx7Ym9keTplLHNpZ25hbDpsfSkpXSkuZmluYWxseSgoKT0+Y2xlYXJUaW1lb3V0KGgpKX1jYXRjaChlKXtyZXR1cm4gdm9pZCB1LnBvc3RNZXNzYWdlKHtlcnJvcjplLm1lc3NhZ2V9KX1pZighZClyZXR1cm4gYSYmYS5hYm9ydCgpLHZvaWQgdS5wb3N0TWVzc2FnZSh7ZXJyb3I6IlRpbWVvdXQgd2hlbiBleGVjdXRpbmcgJ2ZldGNoJyJ9KTtpZighZC5vayl7bGV0IGU7dHJ5e2NvbnN0e2Vycm9yX2Rlc2NyaXB0aW9uOnR9PUpTT04ucGFyc2UoYXdhaXQgZC50ZXh0KCkpO2U9dH1jYXRjaChlKXt9cmV0dXJuIHZvaWQgdS5wb3N0TWVzc2FnZSh7ZXJyb3I6ZXx8IkhUVFAgZXJyb3IgIi5jb25jYXQoZC5zdGF0dXMpfSl9YyhzKX11LnBvc3RNZXNzYWdlKHtvazohMH0pfWNhdGNoKGUpe3UucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZXx8IlVua25vd24gZXJyb3IgZHVyaW5nIHRva2VuIHJldm9jYXRpb24ifSl9fSxoPShlLHQpPT57aWYoIW4pcmV0dXJuITE7dHJ5e2NvbnN0IHI9bmV3IFVSTChuKS5vcmlnaW4sbz1uZXcgVVJMKGUuZmV0Y2hVcmwpO3JldHVybiBvLm9yaWdpbj09PXImJm8ucGF0aG5hbWU9PT10fWNhdGNoKGUpe3JldHVybiExfX07YWRkRXZlbnRMaXN0ZW5lcigibWVzc2FnZSIsZT0+e2NvbnN0e2RhdGE6dCxwb3J0czpyfT1lLFtvXT1yO2lmKCEoInR5cGUiaW4gdCl8fCJpbml0IiE9PXQudHlwZSlyZXR1cm4idHlwZSJpbiB0JiYiY2xlYXIiPT09dC50eXBlPyhzPXt9LHZvaWQobnVsbD09b3x8by5wb3N0TWVzc2FnZSh7b2s6ITB9KSkpOiJ0eXBlImluIHQmJiJyZXZva2UiPT09dC50eXBlP2godCwiL29hdXRoL3Jldm9rZSIpP3ZvaWQgdShlKTp2b2lkKG51bGw9PW98fG8ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOiJpbnZhbGlkX2ZldGNoX3VybCIsZXJyb3JfZGVzY3JpcHRpb246IlVuYXV0aG9yaXplZCBmZXRjaCBVUkwifSxoZWFkZXJzOnt9fSkpOnZvaWQoImZldGNoVXJsImluIHQmJmgodCwiL29hdXRoL3Rva2VuIik/ZihlKTpudWxsPT1vfHxvLnBvc3RNZXNzYWdlKHtvazohMSxqc29uOntlcnJvcjoiaW52YWxpZF9mZXRjaF91cmwiLGVycm9yX2Rlc2NyaXB0aW9uOiJVbmF1dGhvcml6ZWQgZmV0Y2ggVVJMIn0saGVhZGVyczp7fX0pKTtpZihudWxsPT09bil0cnl7bmV3IFVSTCh0LmFsbG93ZWRCYXNlVXJsKSxuPXQuYWxsb3dlZEJhc2VVcmx9Y2F0Y2goZSl7cmV0dXJufX0pfSgpOwoK",function(e){var t,n,r;return new Worker(eH=eH||(n=(t=function(e,t){var n=atob(e);if(t){for(var r=new Uint8Array(n.length),o=0,i=n.length;o<i;++o)r[o]=n.charCodeAt(o);return String.fromCharCode.apply(null,new Uint16Array(r.buffer))}return n}(ez,!1)).indexOf("\n",10)+1,r=new Blob([t.substring(n)+""],{type:"application/javascript"}),URL.createObjectURL(r)),e)});let eM={};class eZ{constructor(e,t){this.cache=e,this.clientId=t,this.manifestKey=this.createManifestKeyFrom(this.clientId)}async add(e){var t;let n=new Set((null===(t=await this.cache.get(this.manifestKey))||void 0===t?void 0:t.keys)||[]);n.add(e),await this.cache.set(this.manifestKey,{keys:[...n]})}async remove(e){let t=await this.cache.get(this.manifestKey);if(t){let n=new Set(t.keys);return n.delete(e),n.size>0?await this.cache.set(this.manifestKey,{keys:[...n]}):await this.cache.remove(this.manifestKey)}}get(){return this.cache.get(this.manifestKey)}clear(){return this.cache.remove(this.manifestKey)}createManifestKeyFrom(e){return"".concat(eb,"::").concat(e)}}let eV="auth0.is.authenticated",eX={memory:()=>(new eT).enclosedCache,localstorage:()=>new eS},eF=e=>eX[e],eG=e=>{let{openUrl:t,onRedirect:n}=e;return Object.assign(Object.assign({},d(e,["openUrl","onRedirect"])),{openUrl:!1===t||t?t:n})},eY=(e,t)=>{let n=(null==t?void 0:t.split(" "))||[];return((null==e?void 0:e.split(" "))||[]).every(e=>n.includes(e))},eB={NONCE:"nonce",KEYPAIR:"keypair"};class eq{constructor(e){this.clientId=e}getVersion(){return 1}createDbHandle(){let e=window.indexedDB.open("auth0-spa-js",this.getVersion());return new Promise((t,n)=>{e.onupgradeneeded=()=>Object.values(eB).forEach(t=>e.result.createObjectStore(t)),e.onerror=()=>n(e.error),e.onsuccess=()=>t(e.result)})}async getDbHandle(){return this.dbHandle||(this.dbHandle=await this.createDbHandle()),this.dbHandle}async executeDbRequest(e,t,n){let r=n((await this.getDbHandle()).transaction(e,t).objectStore(e));return new Promise((e,t)=>{r.onsuccess=()=>e(r.result),r.onerror=()=>t(r.error)})}buildKey(e){return"".concat(this.clientId,"::").concat(e?"_".concat(e):"auth0")}setNonce(e,t){return this.save(eB.NONCE,this.buildKey(t),e)}setKeyPair(e){return this.save(eB.KEYPAIR,this.buildKey(),e)}async save(e,t,n){await this.executeDbRequest(e,"readwrite",e=>e.put(n,t))}findNonce(e){return this.find(eB.NONCE,this.buildKey(e))}findKeyPair(){return this.find(eB.KEYPAIR,this.buildKey())}find(e,t){return this.executeDbRequest(e,"readonly",e=>e.get(t))}async deleteBy(e,t){let n=await this.executeDbRequest(e,"readonly",e=>e.getAllKeys());null==n||n.filter(t).map(t=>this.executeDbRequest(e,"readwrite",e=>e.delete(t)))}deleteByClientId(e,t){return this.deleteBy(e,e=>"string"==typeof e&&e.startsWith("".concat(t,"::")))}clearNonces(){return this.deleteByClientId(eB.NONCE,this.clientId)}clearKeyPairs(){return this.deleteByClientId(eB.KEYPAIR,this.clientId)}}class eQ{constructor(e){this.storage=new eq(e)}getNonce(e){return this.storage.findNonce(e)}setNonce(e,t){return this.storage.setNonce(e,t)}async getOrGenerateKeyPair(){let e=await this.storage.findKeyPair();
1return e||(e=await async function(e,t){var n;let r;if("string"!=typeof e||0===e.length)throw TypeError('"alg" must be a non-empty string');switch(e){case"PS256":r={name:"RSA-PSS",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"RS256":r={name:"RSASSA-PKCS1-v1_5",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"ES256":r={name:"ECDSA",namedCurve:"P-256"};break;case"Ed25519":r={name:"Ed25519"};break;default:throw new ei}return crypto.subtle.generateKey(r,null!==(n=null==t?void 0:t.extractable)&&void 0!==n&&n,["sign","verify"])}("ES256",{extractable:!1}),await this.storage.setKeyPair(e)),e}async generateProof(e){return function(e){let{keyPair:t,url:n,method:r,nonce:o,accessToken:i}=e;return el(t,function(e){let t=new URL(e);return t.search="",t.hash="",t.href}(n),r,o,i)}(Object.assign({keyPair:await this.getOrGenerateKeyPair()},e))}async calculateThumbprint(){return async function(e){var t;let n;if(!ec(e))throw TypeError('"publicKey" must be a public CryptoKey');if(!0!==e.extractable)throw TypeError('"publicKey.extractable" must be true');let o=await eu(e);switch(o.kty){case"EC":n={crv:o.crv,kty:o.kty,x:o.x,y:o.y};break;case"OKP":n={crv:o.crv,kty:o.kty,x:o.x};break;case"RSA":n={e:o.e,kty:o.kty,n:o.n};break;default:throw new ei("unsupported JWK kty")}return t=await crypto.subtle.digest({name:"SHA-256"},en(JSON.stringify(n))),r(t)}((await this.getOrGenerateKeyPair()).publicKey)}async clear(){await Promise.all([this.storage.clearNonces(),this.storage.clearKeyPairs()])}}(rz=rH||(rH={})).Bearer="Bearer",rz.DPoP="DPoP";class e${constructor(e,t){this.hooks=t,this.config=Object.assign(Object.assign({},e),{fetch:e.fetch||("undefined"==typeof window?fetch:window.fetch.bind(window))})}isAbsoluteUrl(e){return/^(https?:)?\/\//i.test(e)}buildUrl(e,t){if(t){if(this.isAbsoluteUrl(t))return t;if(e)return"".concat(e.replace(/\/?\/$/,""),"/").concat(t.replace(/^\/+/,""))}throw TypeError("`url` must be absolute or `baseUrl` non-empty.")}getAccessToken(e){return this.config.getAccessToken?this.config.getAccessToken(e):this.hooks.getAccessToken(e)}extractUrl(e){return"string"==typeof e?e:e instanceof URL?e.href:e.url}buildBaseRequest(e,t){if(!this.config.baseUrl)return new Request(e,t);let n=this.buildUrl(this.config.baseUrl,this.extractUrl(e)),r=e instanceof Request?new Request(n,e):n;return new Request(r,t)}setAuthorizationHeader(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:rH.Bearer;e.headers.set("authorization","".concat(n," ").concat(t))}async setDpopProofHeader(e,t){if(!this.config.dpopNonceId)return;let n=await this.hooks.getDpopNonce(),r=await this.hooks.generateDpopProof({accessToken:t,method:e.method,nonce:n,url:e.url});e.headers.set("dpop",r)}async prepareRequest(e,t){let n,r;let o=await this.getAccessToken(t);"string"==typeof o?(n=this.config.dpopNonceId?rH.DPoP:rH.Bearer,r=
1o):(n=o.token_type,r=o.access_token),this.setAuthorizationHeader(e,r,n),n===rH.DPoP&&await this.setDpopProofHeader(e,r)}getHeader(e,t){return Array.isArray(e)?new Headers(e).get(t)||"":"function"==typeof e.get?e.get(t)||"":e[t]||""}hasUseDpopNonceError(e){if(401!==e.status)return!1;let t=this.getHeader(e.headers,"www-authenticate");return t.includes("invalid_dpop_nonce")||t.includes("use_dpop_nonce")}async handleResponse(e,t){let n=this.getHeader(e.headers,eh);if(n&&await this.hooks.setDpopNonce(n),!this.hasUseDpopNonceError(e))return e;if(!n||!t.onUseDpopNonceError)throw new R(n);return t.onUseDpopNonceError()}async internalFetchWithAuth(e,t,n,r){let o=this.buildBaseRequest(e,t);await this.prepareRequest(o,r);let i=await this.config.fetch(o);return this.handleResponse(i,n)}fetchWithAuth(e,t,n){let r={onUseDpopNonceError:()=>this.internalFetchWithAuth(e,t,Object.assign(Object.assign({},r),{onUseDpopNonceError:void 0}),n)};return this.internalFetchWithAuth(e,t,r,n)}}class e0{constructor(e,t){this.myAccountFetcher=e,this.apiBase=t}async connectAccount(e){let t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/connect"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)});return this._handleResponse(t)}async completeAccount(e){let t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/complete"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)});return this._handleResponse(t)}async _handleResponse(e){let t;try{t=await e.text(),t=JSON.parse(t)}catch(n){throw new e2({type:"invalid_json",status:e.status,title:"Invalid JSON response",detail:t||String(n)})}if(e.ok)return t;throw new e2(t)}}class e2 extends Error{constructor(e){let{type:t,status:n,title:r,detail:o,validation_errors:i}=e;super(o),this.name="MyAccountApiError",this.type=t,this.status=n,this.title=r,this.detail=o,this.validation_errors=i,Object.setPrototypeOf(this,e2.prototype)}}let e1={otp:{authenticatorTypes:["otp"]},sms:{authenticatorTypes:["oob"],oobChannels:["sms"]},email:{authenticatorTypes:["oob"],oobChannels:["email"]},push:{authenticatorTypes:["oob"],oobChannels:["auth0"]},voice:{authenticatorTypes:["oob"],oobChannels:["voice"]}};function e5(e,t){this.v=e,this.k=t}function e3(e,t,n){if("function"==typeof e?e===t:e.has(t))return arguments.length<3?t:n;throw TypeError("Private element is not present on this object")}function e9(e,t){if(t.has(e))throw TypeError("Cannot initialize the same private elements twice on an object")}function e6(e,t){return e.get(e3(e,t))}function e4(e,t,n){e9(e,t),t.set(e,n)}function e8(e,t,n){return e.set(e3(e,t),n),n}function e7(e,t,n){var r;return(t="symbol"==typeof(r=function(e,t){if("object"!=typeof e||!e)return e;var n=e[Symbol.toPrimitive];if(void 0!==n){var r=n.call(e,t||"default");if("object"!=typeof r)return r;throw TypeError("@@toPrimitive must return a primitive value.")}return("string"===t?String:Number)(e)}(t,"string"))?r:r+"")in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function te(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);t&&(r=r.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,r)}return n}function tt(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?te(Object(n),!0).forEach(function(t){e7(e,t,n[t])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):te(Object(n)).forEach(function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))})}return e}function tn(e,t){if(null==e)return{};var n,r,o=function(e,t){if(null==e)return{};var n={};for(var r in e)if(({}).hasOwnProperty.call(e,r)){if(-1!==t.indexOf(r))continue;n[r]=e[r]}return n}(e,t);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);for(r=0;r<i.length;r++)n=i[r],-1===t.indexOf(n)&&({}).propertyIsEnumerable.call(e,n)&&(o[n]=e[n])}return o}function tr(e){var t,n;function r(t,n){try{var i=e[t](n),a=i.value,s=a instanceof e5;Promise.resolve(s?a.v:a).then(function(n){if(s){var c="return"===t&&a.k?t:"next";if(!a.k||n.done)return r(c,n);n=e[c](n).value}o(!!i.done,n)},function(e){r("throw",e)})}catch(e){o(2,e)}}function o(e,o){2===e?t.reject(o):t.resolve({value:o,done:e}),(t=t.next)?r(t.key,t.arg):n=null}this._invoke=function(e,o){return new Promise(function(i,a){var s={key:e,arg:o,resolve:i,reject:a,next:null};n?n=n.next=s:(t=n=s,r(e,o))})}
1,"function"!=typeof e.return&&(this.return=void 0)}function to(e,t){if(null==e)return!1;try{return e instanceof t||Object.getPrototypeOf(e)[Symbol.toStringTag]===t.prototype[Symbol.toStringTag]}catch(e){return!1}}tr.prototype["function"==typeof Symbol&&Symbol.asyncIterator||"@@asyncIterator"]=function(){return this},tr.prototype.next=function(e){return this._invoke("next",e)},tr.prototype.throw=function(e){return this._invoke("throw",e)},tr.prototype.return=function(e){return this._invoke("return",e)},"undefined"!=typeof navigator&&null!==(rJ=navigator.userAgent)&&void 0!==rJ&&null!==(rM=rJ.startsWith)&&void 0!==rM&&rM.call(rJ,"Mozilla/5.0 ")||(o="".concat("oauth4webapi","/").concat("v3.8.5"));let ti="ERR_INVALID_ARG_VALUE",ta="ERR_INVALID_ARG_TYPE";function ts(e,t,n){let r=TypeError(e,{cause:n});return Object.assign(r,{code:t}),r}let tc=Symbol(),tl=Symbol(),tu=Symbol(),th=Symbol(),td=Symbol(),tp=Symbol(),tf=new TextEncoder,tm=new TextDecoder;function ty(e){return"string"==typeof e?tf.encode(e):tm.decode(e)}function tw(e){return"string"==typeof e?a(e):i(e)}Uint8Array.prototype.toBase64?i=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0})):i=e=>{e instanceof ArrayBuffer&&(e=new Uint8Array(e));let t=[];for(let n=0;n<e.byteLength;n+=32768)t.push(String.fromCharCode.apply(null,e.subarray(n,n+32768)));return btoa(t.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")},a=Uint8Array.fromBase64?e=>{try{return Uint8Array.fromBase64(e,{alphabet:"base64url"})}catch(e){throw ts("The input to be decoded is not correctly encoded.",ti,e)}}:e=>{try{let t=atob(e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"")),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}catch(e){throw ts("The input to be decoded is not correctly encoded.",ti,e)}};class tg extends Error{constructor(e,t){var n;super(e,t),e7(this,"code",void 0),this.name=this.constructor.name,this.code=no,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class tv extends Error{constructor(e,t){var n;super(e,t),e7(this,"code",void 0),this.name=this.constructor.name,null!=t&&t.code&&(this.code=null==t?void 0:t.code),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function tb(e,t,n){return new tv(e,{code:t,cause:n})}function t_(e){return null!==e&&"object"==typeof e&&!Array.isArray(e)}function tk(e){to(e,Headers)&&(e=Object.fromEntries(e.entries()));let t=new Headers(null!=e?e:{});if(o&&!t.has("user-agent")&&t.set("user-agent",o),t.has("authorization"))throw ts('"options.headers" must not include the "authorization" header name',ti);return t}function tS(e,t){if(void 0!==t){if("function"==typeof t&&(t=t(e.href)),!(t instanceof AbortSignal))throw ts('"options.signal" must return or be an instance of AbortSignal',ta);return t}}function tT(e){return e.includes("//")?e.replace("//","/"):e}async function tE(e,t){return async function(e,t,n,r){if(!(e instanceof URL))throw ts('"'.concat(t,'" must be an instance of URL'),ta);tD(e,!0!==(null==r?void 0:r[tc]));let o=n(new URL(e.href)),i=tk(null==r?void 0:r.headers);return i.set("accept","application/json"),((null==r?void 0:r[th])||fetch)(o.href,{body:void 0,headers:Object.fromEntries(i.entries()),method:"GET",redirect:"manual",signal:tS(o,null==r?void 0:r.signal)}
1)}(e,"issuerIdentifier",e=>{switch(null==t?void 0:t.algorithm){case void 0:case"oidc":var n;n=".well-known/openid-configuration",e.pathname=tT("".concat(e.pathname,"/").concat(n));break;case"oauth2":!function(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];"/"===e.pathname?e.pathname=t:e.pathname=tT("".concat(t,"/").concat(n?e.pathname:e.pathname.replace(/(\/)$/,"")))}(e,".well-known/oauth-authorization-server");break;default:throw ts('"options.algorithm" must be "oidc" (default), or "oauth2"',ti)}return e},t)}function tP(e,t,n,r,o){try{if("number"!=typeof e||!Number.isFinite(e))throw ts("".concat(n," must be a number"),ta,o);if(e>0)return;if(t){if(0!==e)throw ts("".concat(n," must be a non-negative number"),ti,o);return}throw ts("".concat(n," must be a positive number"),ti,o)}catch(e){if(r)throw tb(e.message,r,o);throw e}}function tA(e,t,n,r){try{if("string"!=typeof e)throw ts("".concat(t," must be a string"),ta,r);if(0===e.length)throw ts("".concat(t," must not be empty"),ti,r)}catch(e){if(n)throw tb(e.message,n,r);throw e}}function tR(e){!function(e,t){if(tB(e)!==t)throw function(e){let t='"response" content-type must be ';for(var n=arguments.length,r=Array(n>1?n-1:0),o=1;o<n;o++)r[o-1]=arguments[o];if(r.length>2){let e=r.pop();t+="".concat(r.join(", "),", or ").concat(e)}else 2===r.length?t+="".concat(r[0]," or ").concat(r[1]):t+=r[0];return tb(t,nc,e)}(e,t)}(e,"application/json")}function tx(){return tw(crypto.getRandomValues(new Uint8Array(32)))}function tI(e){let t=null==e?void 0:e[tl];return"number"==typeof t&&Number.isFinite(t)?t:0}function tO(e){let t=null==e?void 0:e[tu];return"number"==typeof t&&Number.isFinite(t)&&-1!==Math.sign(t)?t:30}function tC(){return Math.floor(Date.now()/1e3)}function tj(e){if("object"!=typeof e||null===e)throw ts('"as" must be an object',ta);tA(e.issuer,'"as.issuer"')}function tW(e){if("object"!=typeof e||null===e)throw ts('"client" must be an object',ta);tA(e.client_id,'"client.client_id"')}function tK(e){return tA(e,'"clientSecret"'),(t,n,r,o)=>{r.set("client_id",n.client_id),r.set("client_secret",e)}}let tU=URL.parse?(e,t)=>URL.parse(e,t):(e,t)=>{try{return new URL(e,t)}catch(e){return null}};function tD(e,t){if(t&&"https:"!==e.protocol)throw tb("only requests to HTTPS are allowed",nu,e);if("https:"!==e.protocol&&"http:"!==e.protocol)throw tb("only HTTP and HTTPS requests are allowed",nh,e)}function tN(e,t,n,r){let o;if("string"!=typeof e||!(o=tU(e)))throw tb("authorization server metadata does not contain a valid ".concat(n?'"as.mtls_endpoint_aliases.'.concat(t,'"'):'"as.'.concat(t,'"')),void 0===e?nm:ny,{attribute:n?"mtls_endpoint_aliases.".concat(t):t});return tD(o,r),o}function tL(e,t,n,r){return n&&e.mtls_endpoint_aliases&&t in e.mtls_endpoint_aliases?tN(e.mtls_endpoint_aliases[t],t,n,r):tN(e[t],t,n,r)}class tz extends Error{constructor(e,t){var n;super(e,t),e7(this,"cause",void 0),e7(this,"code",void 0),e7(this,"error",void 0),e7(this,"status",void 0),e7(this,"error_description",void 0),e7(this,"response",void 0),this.name=this.constructor.name,this.code=nr,this.cause=t.cause,this.error=t.cause.error,this.status=t.response.status,this.error_description=t.cause.error_description,Object.defineProperty(this,"response",{enumerable:!1,value:t.response}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}
1class tH extends Error{constructor(e,t){var n,r;super(e,t),e7(this,"cause",void 0),e7(this,"code",void 0),e7(this,"error",void 0),e7(this,"error_description",void 0),this.name=this.constructor.name,this.code=ni,this.cause=t.cause,this.error=t.cause.get("error"),this.error_description=null!==(n=t.cause.get("error_description"))&&void 0!==n?n:void 0,null===(r=Error.captureStackTrace)||void 0===r||r.call(Error,this,this.constructor)}}class tJ extends Error{constructor(e,t){var n;super(e,t),e7(this,"cause",void 0),e7(this,"code",void 0),e7(this,"response",void 0),e7(this,"status",void 0),this.name=this.constructor.name,this.code=nn,this.cause=t.cause,this.status=t.response.status,this.response=t.response,Object.defineProperty(this,"response",{enumerable:!1}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}let tM="[a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+",tZ=RegExp("^[,\\s]*("+tM+")"),tV=RegExp("^[,\\s]*("+tM+')\\s*=\\s*"((?:[^"\\\\]|\\\\[\\s\\S])*)"[,\\s]*(.*)'),tX=RegExp("^[,\\s]*("+tM+")\\s*=\\s*("+tM+")[,\\s]*(.*)"),tF=RegExp("^([a-zA-Z0-9\\-\\._\\~\\+\\/]+={0,2})(?:$|[,\\s])(.*)");async function tG(e,t,n){if(e.status!==t){var r;let t;if(function(e){let t;if(t=function(e){if(!to(e,Response))throw ts('"response" must be an instance of Response',ta);let t=e.headers.get("www-authenticate");if(null===t)return;let n=[],r=t;for(;r;){var o;let e;let t=r.match(tZ),i=null===(o=t)||void 0===o?void 0:o[1].toLowerCase();if(!i)return;let a=r.substring(t[0].length);if(a&&!a.match(/^[\s,]/))return;let s=a.match(/^\s+(.*)$/),c=!!s;r=s?s[1]:void 0;let l={};if(c)for(;r;){let n,o;if(t=r.match(tV)){if([,n,o,r]=t,o.includes("\\"))try{o=JSON.parse('"'.concat(o,'"'))}catch(e){}l[n.toLowerCase()]=o}else{if(!(t=r.match(tX))){if(t=r.match(tF)){if(Object.keys(l).length)break;[,e,r]=t;break}return}[,n,o,r]=t,l[n.toLowerCase()]=o}}else r=a||void 0;let u={scheme:i,parameters:l};e&&(u.token68=e),n.push(u)}return n.length?n:void 0}(e))throw new tJ("server responded with a challenge in the WWW-Authenticate HTTP Header",{cause:t,response:e})}(e),t=await async function(e){if(e.status>399&&e.status<500){nw(e),tR(e);try{let t=await e.clone().json();if(t_(t)&&"string"==typeof t.error&&t.error.length)return t}catch(e){}}}(e))throw await (null===(r=e.body)||void 0===r?void 0:r.cancel()),new tz("server responded with an error in the response body",{cause:t,response:e});throw tb('"response" is not a conform '.concat(n," response (unexpected HTTP status code)"),nl,e)}}function tY(e){if(!t9.has(e))throw ts('"options.DPoP" is not a valid DPoPHandle',ti)}function tB(e){var t;return null===(t=e.headers.get("content-type"))||void 0===t?void 0:t.split(";")[0]}async function tq(e,t,n,r,o,i,a){return await n(e,t,o,i),i.set("content-type","application/x-www-form-urlencoded;charset=UTF-8"),((null==a?void 0:a[th])||fetch)(r.href,{body:o,headers:Object.fromEntries(i.entries()),method:"POST",redirect:"manual",signal:tS(r,null==a?void 0:a.signal)})}async function tQ(e,t,n,r,o,i){var a;let s=tL(e,"token_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[tc]));o.set("grant_type",r);let c=tk(null==i?void 0:i.headers);c.set("accept","application/json"),void 0!==(null==i?void 0:i.DPoP)&&(tY(i.DPoP),await i.DPoP.addProof(s,c,"POST"));let l=await tq(e,t,n,s,o,c,i);return null==i||null===(a=i.DPoP)||void 0===a||a.cacheNonce(l,s),l}let t$=new WeakMap,t0=new WeakMap;function t2(e){if(!e.id_token)return;let t=t$.get(e);if(!t)throw ts('"ref" was already garbage collected or did not resolve from the proper sources',ti);return t}async function t1(e,t,n,r,o,i){if(tj(e),tW(t),!to(n,Response))throw ts('"response" must be an instance of Response',ta);await tG(n,200,"Token Endpoint"),nw(n);let a=await nT(n);if(tA(a.access_token,'"response" body "access_token" property',ns,{body:a}),tA(a.token_type,'"response" body "token_type" property',ns,{body:a}),a.token_type=a.token_type.toLowerCase(),void 0!==a.expires_in){let e="number"!=typeof a.expires_in?parseFloat(a.expires_in):a.expires_in;tP(e,!0,'"response" body "expires_in" property',ns,{body:a}),a.expires_in=e}if(void 0!==a.refresh_token&&tA(a.refresh_token,'"response" body "refresh_token" property',ns,{body:a}),void 0!==a.scope&&"string"!=typeof a.scope)throw tb('"response" body "scope" property must be a string',ns,{body:a});if(void 0!==a.id_token){tA(a.id_token,'"response" body "id_token" property',ns,{body:a});let i=["aud","exp","iat","iss","sub"];!0===t.require_auth_time&&i.push("auth_time"),void 0!==t.default_max_age&&(tP(t.default_max_age,!0,'"client.default_max_age"'),i.push("auth_time")),null!=r&&r.length&&i.push(...r);let{claims:s,jwt:c}=await (async function(e,t,n,r,o){let i,a,{0:s,1:c,length:l}=e.split(".");if(5===l){if(void 0===o)throw new tg("JWE decryption is not configured",{cause:e});e=await o(e),{0:s,1:c,length:l}=e.split(".")}if(3!==l)throw tb("Invalid JWT",ns,e);try{i=JSON.parse(ty(tw(s)))}catch(e){throw tb("failed to parse JWT Header body as base64url encoded JSON",na,e)}if(!t_(i))throw tb("JWT Header must be a top level object",ns,e);if(t(i),void 0!==i.crit)throw new tg('no JWT "crit" header parameter extensions are supported',{cause:{header:i}});try{a=JSON.parse(ty(tw(c)))}catch(e){throw tb("failed to parse JWT Payload body as base64url encoded JSON",na,e)}if(!t_(a))throw tb("JWT Payload must be a top level object",ns,e);let u=tC()+n;if(void 0!==a.exp){if("number"!=typeof a.exp)throw tb('unexpected JWT "exp" (expiration time) claim type',ns,{claims:a});if(a.exp<=u-r)throw tb('unexpected JWT "exp" (expiration time) claim value, expiration is past current timestamp',nd,{claims:a,now:u,tolerance:r,claim:"exp"})}if(void 0!==a.iat&&"number"!=typeof a.iat)throw tb('unexpected JWT "iat" (issued at) claim type',ns,{claims:a});if(void 0!==a.iss&&"string"!=typeof a.iss)throw tb('unexpected JWT "iss" (issuer) claim type',ns,{claims:a});if(void 0!==a.nbf){if("number"!=typeof a.nbf)throw tb('unexpected JWT "nbf" (not before) claim type',ns,{claims:a});if(a.nbf>u+r)throw tb('unexpected JWT "nbf" (not before) claim value',nd,{claims:a,now:u,tolerance:r,claim:"nbf"})}if(void 0!==a.aud&&"string"!=typeof a.aud&&!Array.isArray(a.aud))throw tb('unexpected JWT "aud" (audience) claim type',ns,{claims:a});return{header:i,claims:a,jwt:e}})(a.id_token,nb.bind(void 0,t.id_token_signed_response_alg,e.id_token_signing_alg_values_supported,"RS256"),tI(t),tO(t),o).then(t8.bind(void 0,i)).then(t3.bind(void 0,e)).then(t5.bind(void 0,t.client_id));if(Array.isArray(s.aud)&&1!==s.aud.length){if(void 0===s.azp)throw tb('ID Token "aud" (audience) claim includes additional untrusted audiences',np,{claims:s,claim:"aud"});if(s.azp!==t.client_id)throw tb('unexpected ID Token "azp" (authorized party) claim value',np,{expected:t.client_id,claims:s,claim:"azp"})}void 0!==s.auth_time&&tP(s.auth_time,!0,'ID Token "auth_time" (authentication time)',ns,{claims:s}),t0.set(n,c),t$.set(a,s)}if(void 0!==(null==i?void 0:i[a.token_type]))i[a.token_type](n,a);else if("dpop"!==a.token_type&&"bearer"!==a.token_type)throw new tg("unsupported `token_type` value",{cause:{body:a}});return a}function t5(e,t){if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e))throw tb('unexpected JWT "aud" (audience) claim value',np,{expected:e,claims:t.claims,claim:"aud"})}else if(t.claims.aud!==e)throw tb('unexpected JWT "aud" (audience) claim value',np,{expected:e,claims:t.claims,claim:"aud"});return t}function t3(e,t){var n,r;let o=null!==(n=null===(r=e[nP])||void 0===r?void 0:r.call(e,t))&&void 0!==n?n:e.issuer;if(t.claims.iss!==o)throw tb('unexpected JWT "iss" (issuer) claim value',np,{expected:o,claims:t.claims,claim:"iss"});return t}let t9=new WeakSet,t6=Symbol(),t4={aud:"audience",c_hash:"code hash",client_id:"client id",exp:"expiration time",iat:"issued at",iss:"issuer",jti:"jwt id",nonce:"nonce",s_hash:"state hash",sub:"subject",ath:"access token hash",htm:"http method",htu:"http uri",cnf:"confirmation",auth_time:"authentication time"};function t8(e,t){for(let n of e)if(void 0===t.claims[n])throw tb('JWT "'.concat(n,'" (').concat(t4[n],") claim missing"),ns,{claims:t.claims});return t}let t7=Symbol(),ne=Symbol();async function nt(e,t,n,r){return"string"==typeof(null==r?void 0:r.expectedNonce)||"number"==typeof(null==r?void 0:r.maxAge)||null!=r&&r.requireIdToken?async function(e,t,n,r,o,i,a){let s=[];switch(r){case void 0:r=t7;break;case t7:break;default:tA(r,'"expectedNonce" argument'),s.push("nonce")}switch(null!=o||(o=t.default_max_age),o){case void 0:o=ne;break;case ne:break;default:tP(o,!0,'"maxAge" argument'),s.push("auth_time")}let c=await t1(e,t,n,s,i,a);tA(c.id_token,'"response" body "id_token" property',ns,{body:c});let l=t2(c);if(o!==ne){let e=tC()+tI(t),n=tO(t);if(l.auth_time+o<e-n)throw tb("too much time has elapsed since the last End-User authentication",nd,{claims:l,now:e,tolerance:n,claim:"auth_time"})}if(r===t7){if(void 0!==l.nonce)throw tb('unexpected ID Token "nonce" claim value',np,{expected:void 0,claims:l,claim:"nonce"})}else if(l.nonce!==r)throw tb('unexpected ID Token "nonce" claim value',np,{expected:r,claims:l,claim:"nonce"});return c}(e,t,n,r.expectedNonce,r.maxAge,r[tp],r.recognizedTokenTypes):async function(e,t,n,r,o){let i=await t1(e,t,n,void 0,r,o),a=t2(i);if(a){if(void 0!==t.default_max_age){tP(t.default_max_age,!0,'"client.default_max_age"');let e=tC()+tI(t),n=tO(t);if(a.auth_time+t.default_max_age<e-n)throw tb("too much time has elapsed since the last End-User authentication",nd,{claims:a,now:e,tolerance:n,claim:"auth_time"})}if(void 0!==a.nonce)throw tb('unexpected ID Token "nonce" claim value',np,{expected:void 0,claims:a,claim:"nonce"})}return i}(e,t,n,null==r?void 0:r[tp],null==r?void 0:r.recognizedTokenTypes)}let nn="OAUTH_WWW_AUTHENTICATE_CHALLENGE",nr="OAUTH_RESPONSE_BODY_ERROR",no="OAUTH_UNSUPPORTED_OPERATION",ni="OAUTH_AUTHORIZATION_RESPONSE_E
1RROR",na="OAUTH_PARSE_ERROR",ns="OAUTH_INVALID_RESPONSE",nc="OAUTH_RESPONSE_IS_NOT_JSON",nl="OAUTH_RESPONSE_IS_NOT_CONFORM",nu="OAUTH_HTTP_REQUEST_FORBIDDEN",nh="OAUTH_REQUEST_PROTOCOL_FORBIDDEN",nd="OAUTH_JWT_TIMESTAMP_CHECK_FAILED",np="OAUTH_JWT_CLAIM_COMPARISON_FAILED",nf="OAUTH_JSON_ATTRIBUTE_COMPARISON_FAILED",nm="OAUTH_MISSING_SERVER_METADATA",ny="OAUTH_INVALID_SERVER_METADATA";function nw(e){if(e.bodyUsed)throw ts('"response" body has been used already',ti)}function ng(e){let{algorithm:t}=e;if("number"!=typeof t.modulusLength||t.modulusLength<2048)throw new tg("unsupported ".concat(t.name," modulusLength"),{cause:e})}async function nv(e){if("POST"!==e.method)throw ts("form_post responses are expected to use the POST method",ti,{cause:e});if("application/x-www-form-urlencoded"!==tB(e))throw ts("form_post responses are expected to use the application/x-www-form-urlencoded content-type",ti,{cause:e});return async function(e){if(e.bodyUsed)throw ts("form_post Request instances must contain a readable body",ti,{cause:e});return e.text()}(e)}function nb(e,t,n,r){if(void 0===e){if(Array.isArray(t)){if(!t.includes(r.alg))throw tb('unexpected JWT "alg" header parameter',ns,{header:r,expected:t,reason:"authorization server metadata"})}else{if(void 0===n)throw tb('missing client or server configuration to verify used JWT "alg" header parameter',void 0,{client:e,issuer:t,fallback:n});if("string"==typeof n?r.alg!==n:"function"==typeof n?!n(r.alg):!n.includes(r.alg))throw tb('unexpected JWT "alg" header parameter',ns,{header:r,expected:n,reason:"default value"})}}else if("string"==typeof e?r.alg!==e:!e.includes(r.alg))throw tb('unexpected JWT "alg" header parameter',ns,{header:r,expected:e,reason:"client configuration"})}function n_(e,t){let{0:n,length:r}=e.getAll(t);if(r>1)throw tb('"'.concat(t,'" parameter must be provided only once'),ns);return n}let nk=Symbol(),nS=Symbol();async function nT(e){let t,n=arguments.length>1&&void 0!==arguments[1]?arguments[1]:tR;try{t=await e.json()}catch(t){throw n(e),tb('failed to parse "response" body as JSON',na,t)}if(!t_(t))throw tb('"response" body must be a top level object',ns,{body:t});return t}let nE=Symbol(),nP=Symbol(),nA=new TextEncoder,nR=new TextDecoder;function nx(e){let t=new Uint8Array(e.length);for(let n=0;n<e.length;n++){let r=e.charCodeAt(n);if(r>127)throw TypeError("non-ASCII string encountered in encode()");t[n]=r}return t}function nI(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);let t=atob(e),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}function nO(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64("string"==typeof e?e:nR.decode(e),{alphabet:"base64url"});let t=e;t instanceof Uint8Array&&(t=nR.decode(t)),t=t.replace(/-/g,"+").replace(/_/g,"/");try{return nI(t)}catch(e){throw TypeError("The input to be decoded is not correctly encoded.")}}let nC=function(e){return TypeError("CryptoKey does not support this operation, its ".concat(arguments.length>1&&void 0!==arguments[1]?arguments[1]:"algorithm.name"," must be ").concat(e))},nj=(e,t)=>e.name===t;function nW(e,t){if(parseInt(e.hash.name.slice(4),10)!==t)throw nC("SHA-".concat(t),"algorithm.hash")}function nK(e,t){for(var n,r=arguments.length,o=Array(r>2?r-2:0),i=2;i<r;i++)o[i-2]=arguments[i];if((o=o.filter(Boolean)).length>2){let t=o.pop();e+="one of type ".concat(o.join(", "),", or ").concat(t,".")}else 2===o.length?e+="one of type ".concat(o[0]," or ").concat(o[1],"."):e+="of type ".concat(o[0],".");return null==t?e+=" Received ".concat(t):"function"==typeof t&&t.name?e+=" Received function ".concat(t.name):"object"==typeof t&&null!=t&&null!==(n=t.constructor)&&void 0!==n&&n.name&&(e+=" Received an instance of ".concat(t.constructor.name)),e}let nU=function(e,t){for(var n=arguments.length,r=Array(n>2?n-2:0),o=2;o<n;o++)r[o-2]=arguments[o];return nK("Key for the ".concat(e," algorithm must be "),t,...r)};class nD extends Error{constructor(e,t){var n;super(e,t),e7(this,"code","ERR_JOSE_GENERIC"),this.name=this.constructor.name,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}
1e7(nD,"code","ERR_JOSE_GENERIC");class nN extends nD{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",r=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:r,payload:t}}),e7(this,"code","ERR_JWT_CLAIM_VALIDATION_FAILED"),e7(this,"claim",void 0),e7(this,"reason",void 0),e7(this,"payload",void 0),this.claim=n,this.reason=r,this.payload=t}}e7(nN,"code","ERR_JWT_CLAIM_VALIDATION_FAILED");class nL extends nD{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",r=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:r,payload:t}}),e7(this,"code","ERR_JWT_EXPIRED"),e7(this,"claim",void 0),e7(this,"reason",void 0),e7(this,"payload",void 0),this.claim=n,this.reason=r,this.payload=t}}e7(nL,"code","ERR_JWT_EXPIRED");class nz extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JOSE_ALG_NOT_ALLOWED")}}e7(nz,"code","ERR_JOSE_ALG_NOT_ALLOWED");class nH extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JOSE_NOT_SUPPORTED")}}e7(nH,"code","ERR_JOSE_NOT_SUPPORTED"),e7(class extends nD{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"decryption operation failed",arguments.length>1?arguments[1]:void 0),e7(this,"code","ERR_JWE_DECRYPTION_FAILED")}},"code","ERR_JWE_DECRYPTION_FAILED"),e7(class extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JWE_INVALID")}},"code","ERR_JWE_INVALID");class nJ extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JWS_INVALID")}}e7(nJ,"code","ERR_JWS_INVALID");class nM extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JWT_INVALID")}}e7(nM,"code","ERR_JWT_INVALID"),e7(class extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JWK_INVALID")}},"code","ERR_JWK_INVALID");class nZ extends nD{constructor(){super(...arguments),e7(this,"code","ERR_JWKS_INVALID")}}e7(nZ,"code","ERR_JWKS_INVALID");class nV extends nD{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"no applicable key found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),e7(this,"code","ERR_JWKS_NO_MATCHING_KEY")}}e7(nV,"code","ERR_JWKS_NO_MATCHING_KEY");class nX extends nD{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"multiple matching keys found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),e7(this,Symbol.asyncIterator,void 0),e7(this,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS")}}e7(nX,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS");class nF extends nD{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"request timed out",arguments.length>1?arguments[1]:void 0),e7(this,"code","ERR_JWKS_TIMEOUT")}}e7(nF,"code","ERR_JWKS_TIMEOUT");class nG extends nD{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"signature verification failed",arguments.length>1?arguments[1]:void 0),e7(this,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED")}}e7(nG,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED");let nY=e=>{if("CryptoKey"===(null==e?void 0:e[Symbol.toStringTag]))return!0;try{return e instanceof CryptoKey}catch(e){return!1}},nB=e=>"KeyObject"===(null==e?void 0:e[Symbol.toStringTag]),nq=e=>nY(e)||nB(e);function nQ(e,t,n){try{return nO(e)}catch(e){throw new n("Failed to base64url decode the ".concat(t))}}function n$(e){if("object"!=typeof e||null===e||"[object Object]"!==Object.prototype.toString.call(e))return!1;if(null===Object.getPrototypeOf(e))return!0;let t=e;for(;null!==Object.getPrototypeOf(t);)t=Object.getPrototypeOf(t);return Object.getPrototypeOf(e)===t}let n0=e=>n$(e)&&"string"==typeof e.kty;async function n2(e,t,n){if(t instanceof Uint8Array){if(!e.startsWith("HS"))throw TypeError(function(e){for(var t=arguments.length,n=Array(t>1?t-1:0),r=1;r<t;r++)n[r-1]=arguments[r];return nK("Key must be ",e,...n)}(t,"CryptoKey","KeyObject","JSON Web Key"));return crypto.subtle.importKey("raw",t,{hash:"SHA-".concat(e.slice(-3)),name:"HMAC"},!1,[n])}
1return function(e,t,n){switch(t){case"HS256":case"HS384":case"HS512":if(!nj(e.algorithm,"HMAC"))throw nC("HMAC");nW(e.algorithm,parseInt(t.slice(2),10));break;case"RS256":case"RS384":case"RS512":if(!nj(e.algorithm,"RSASSA-PKCS1-v1_5"))throw nC("RSASSA-PKCS1-v1_5");nW(e.algorithm,parseInt(t.slice(2),10));break;case"PS256":case"PS384":case"PS512":if(!nj(e.algorithm,"RSA-PSS"))throw nC("RSA-PSS");nW(e.algorithm,parseInt(t.slice(2),10));break;case"Ed25519":case"EdDSA":if(!nj(e.algorithm,"Ed25519"))throw nC("Ed25519");break;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":if(!nj(e.algorithm,t))throw nC(t);break;case"ES256":case"ES384":case"ES512":{if(!nj(e.algorithm,"ECDSA"))throw nC("ECDSA");let n=function(e){switch(e){case"ES256":return"P-256";case"ES384":return"P-384";case"ES512":return"P-521";default:throw Error("unreachable")}}(t);if(e.algorithm.namedCurve!==n)throw nC(n,"algorithm.namedCurve");break}default:throw TypeError("CryptoKey does not support this operation")}!function(e,t){if(t&&!e.usages.includes(t))throw TypeError("CryptoKey does not support this operation, its usages must include ".concat(t,"."))}(e,n)}(t,e,n),t}async function n1(e,t,n,r){let o=await n2(e,t,"verify");!function(e,t){if(e.startsWith("RS")||e.startsWith("PS")){let{modulusLength:n}=t.algorithm;if("number"!=typeof n||n<2048)throw TypeError("".concat(e," requires key modulusLength to be 2048 bits or larger"))}}(e,o);let i=function(e,t){let n="SHA-".concat(e.slice(-3));switch(e){case"HS256":case"HS384":case"HS512":return{hash:n,name:"HMAC"};case"PS256":case"PS384":case"PS512":return{hash:n,name:"RSA-PSS",saltLength:parseInt(e.slice(-3),10)>>3};case"RS256":case"RS384":case"RS512":return{hash:n,name:"RSASSA-PKCS1-v1_5"};case"ES256":case"ES384":case"ES512":return{hash:n,name:"ECDSA",namedCurve:t.namedCurve};
1case"Ed25519":case"EdDSA":return{name:"Ed25519"};case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return{name:e};default:throw new nH("alg ".concat(e," is not supported either by JOSE or your javascript runtime"))}}(e,o.algorithm);try{return await crypto.subtle.verify(i,o,n,r)}catch(e){return!1}}let n5='Invalid or unsupported JWK "alg" (Algorithm) Parameter value';async function n3(e){var t,n;if(!e.alg)throw TypeError('"alg" argument is required when "jwk.alg" is not present');let{algorithm:r,keyUsages:o}=function(e){let t,n;switch(e.kty){case"AKP":switch(e.alg){case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":t={name:e.alg},n=e.priv?["sign"]:["verify"];break;default:throw new nH(n5)}break;case"RSA":switch(e.alg){case"PS256":case"PS384":case"PS512":t={name:"RSA-PSS",hash:"SHA-".concat(e.alg.slice(-3))},n=e.d?["sign"]:["verify"];break;case"RS256":case"RS384":case"RS512":t={name:"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(e.alg.slice(-3))},n=e.d?["sign"]:["verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":t={name:"RSA-OAEP",hash:"SHA-".concat(parseInt(e.alg.slice(-3),10)||1)},n=e.d?["decrypt","unwrapKey"]:["encrypt","wrapKey"];break;default:throw new nH(n5)}break;case"EC":switch(e.alg){case"ES256":case"ES384":case"ES512":t={name:"ECDSA",namedCurve:({ES256:"P-256",ES384:"P-384",ES512:"P-521"})[e.alg]},n=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:"ECDH",namedCurve:e.crv},n=e.d?["deriveBits"]:[];break;default:throw new nH(n5)}break;
1case"OKP":switch(e.alg){case"Ed25519":case"EdDSA":t={name:"Ed25519"},n=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:e.crv},n=e.d?["deriveBits"]:[];break;default:throw new nH(n5)}break;default:throw new nH('Invalid or unsupported JWK "kty" (Key Type) Parameter value')}return{algorithm:t,keyUsages:n}}(e),i=tt({},e);return"AKP"!==i.kty&&delete i.alg,delete i.use,crypto.subtle.importKey("jwk",i,r,null!==(t=e.ext)&&void 0!==t?t:!e.d&&!e.priv,null!==(n=e.key_ops)&&void 0!==n?n:o)}let n9="given KeyObject instance cannot be used for this algorithm",n6=async function(e,t,n){let r=arguments.length>3&&void 0!==arguments[3]&&arguments[3];s||(s=new WeakMap);let o=s.get(e);if(null!=o&&o[n])return o[n];let i=await n3(tt(tt({},t),{},{alg:n}));return r&&Object.freeze(e),o?o[n]=i:s.set(e,{[n]:i}),i};async function n4(e,t){if(e instanceof Uint8Array||nY(e))return e;if(nB(e)){if("secret"===e.type)return e.export();if("toCryptoKey"in e&&"function"==typeof e.toCryptoKey)try{return((e,t)=>{let n;s||(s=new WeakMap);let r=s.get(e);if(null!=r&&r[t])return r[t];let o="public"===e.type,i=!!o;if("x25519"===e.asymmetricKeyType){switch(t){case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":break;default:throw TypeError(n9)}n=e.toCryptoKey(e.asymmetricKeyType,i,o?[]:["deriveBits"])}if("ed25519"===e.asymmetricKeyType){if("EdDSA"!==t&&"Ed25519"!==t)throw TypeError(n9);n=e.toCryptoKey(e.asymmetricKeyType,i,[o?"verify":"sign"])}switch(e.asymmetricKeyType){case"ml-dsa-44":case"ml-dsa-65":case"ml-dsa-87":if(t!==e.asymmetricKeyType.toUpperCase())throw TypeError(n9);n=e.toCryptoKey(e.asymmetricKeyType,i,[o?"verify":"sign"])}if("rsa"===e.asymmetricKeyType){let r;switch(t){case"RSA-OAEP":r="SHA-1";break;case"RS256":case"PS256":case"RSA-OAEP-256":r="SHA-256";break;case"RS384":case"PS384":case"RSA-OAEP-384":r="SHA-384";break;case"RS512":case"PS512":case"RSA-OAEP-512":r="SHA-512";break;default:throw TypeError(n9)}if(t.startsWith("RSA-OAEP"))return e.toCryptoKey({name:"RSA-OAEP",hash:r},i,o?["encrypt"]:["decrypt"]);n=e.toCryptoKey({name:t.startsWith("PS")?"RSA-PSS":"RSASSA-PKCS1-v1_5",hash:r},i,[o?"verify":"sign"])}if("ec"===e.asymmetricKeyType){var a;let r=new Map([["prime256v1","P-256"],["secp384r1","P-384"],["secp521r1","P-521"]]).get(null===(a=e.asymmetricKeyDetails)||void 0===a?void 0:a.namedCurve);if(!r)throw TypeError(n9);let s={ES256:"P-256",ES384:"P-384",ES512:"P-521"};s[t]&&r===s[t]&&(n=e.toCryptoKey({name:"ECDSA",namedCurve:r},i,[o?"verify":"sign"])),t.startsWith("ECDH-ES")&&(n=e.toCryptoKey({name:"ECDH",namedCurve:r},i,o?[]:["deriveBits"]))}if(!n)throw TypeError(n9);return r?r[t]=n:s.set(e,{[t]:n}),n})(e,t)}catch(e){if(e instanceof TypeError)throw e}let n=e.export({format:"jwk"});return n6(e,n,t)}if(n0(e))return e.k?nO(e.k):n6(e,e,t,!0);throw Error("unreachable")}let n8=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let n=0;n<e.byteLength;n++)if(e[n]!==t[n])return!1;return!0},n7=e=>{let t=e.data[e.pos++];if(128&t){let n=127&t,r=0;for(let t=0;t<n;t++)r=r<<8|e.data[e.pos++];return r}return t}
1,re=(e,t,n)=>{if(e.data[e.pos++]!==t)throw Error(n)},rt=(e,t)=>{let n=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,n},rn=e=>{let t=(e=>{re(e,6,"Expected algorithm OID");let t=n7(e);return rt(e,t)})(e);if(n8(t,[43,101,110]))return"X25519";if(!n8(t,[42,134,72,206,61,2,1]))throw Error("Unsupported key algorithm");re(e,6,"Expected curve OID");let n=n7(e),r=rt(e,n);for(let{name:e,oid:t}of[{name:"P-256",oid:[42,134,72,206,61,3,1,7]},{name:"P-384",oid:[43,129,4,0,34]},{name:"P-521",oid:[43,129,4,0,35]}])if(n8(r,t))return e;throw Error("Unsupported named curve")},rr=async(e,t,n,r)=>{var o;let i,a;let s="spki"===e,c=()=>s?["verify"]:["sign"];switch(n){case"PS256":case"PS384":case"PS512":i={name:"RSA-PSS",hash:"SHA-".concat(n.slice(-3))},a=c();break;case"RS256":case"RS384":case"RS512":i={name:"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(n.slice(-3))},a=c();break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":i={name:"RSA-OAEP",hash:"SHA-".concat(parseInt(n.slice(-3),10)||1)},a=s?["encrypt","wrapKey"]:["decrypt","unwrapKey"];break;case"ES256":case"ES384":case"ES512":i={name:"ECDSA",namedCurve:({ES256:"P-256",ES384:"P-384",ES512:"P-521"})[n]},a=c();break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":try{let e=r.getNamedCurve(t);i="X25519"===e?{name:"X25519"}:{name:"ECDH",namedCurve:e}}catch(e){throw new nH("Invalid or unsupported key format")}a=s?[]:["deriveBits"];break;
1case"Ed25519":case"EdDSA":i={name:"Ed25519"},a=c();break;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":i={name:n},a=c();break;default:throw new nH('Invalid or unsupported "alg" (Algorithm) value')}return crypto.subtle.importKey(e,t,i,null!==(o=null==r?void 0:r.extractable)&&void 0!==o?o:!!s,a)},ro=(e,t,n)=>{var r;let o;let i=(o=/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g,nI(e.replace(o,""))),a=n;return null!=t&&null!==(r=t.startsWith)&&void 0!==r&&r.call(t,"ECDH-ES")&&(a||(a={}),a.getNamedCurve=e=>{let t={data:e,pos:0};return function(e){re(e,48,"Invalid PKCS#8 structure"),n7(e),re(e,2,"Expected version field");let t=n7(e);e.pos+=t,re(e,48,"Expected algorithm identifier"),n7(e),e.pos}(t),rn(t)}),rr("pkcs8",i,t,a)},ri=e=>null==e?void 0:e[Symbol.toStringTag],ra=(e,t,n)=>{if(void 0!==t.use){let e;switch(n){case"sign":case"verify":e="sig";break;case"encrypt":case"decrypt":e="enc"}if(t.use!==e)throw TypeError('Invalid key for this operation, its "use" must be "'.concat(e,'" when present'))}if(void 0!==t.alg&&t.alg!==e)throw TypeError('Invalid key for this operation, its "alg" must be "'.concat(e,'" when present'));if(Array.isArray(t.key_ops)){var r,o;let i;switch(!0){case"sign"===n||"verify"===n:case"dir"===e:case e.includes("CBC-HS"):i=n;break;case e.startsWith("PBES2"):i="deriveBits";break;case/^A\d{3}(?:GCM)?(?:KW)?$/.test(e):i=!e.includes("GCM")&&e.endsWith("KW")?"encrypt"===n?"wrapKey":"unwrapKey":n;break;case"encrypt"===n&&e.startsWith("RSA"):i="wrapKey";break;case"decrypt"===n:i=e.startsWith("RSA")?"unwrapKey":"deriveBits"}if(i&&!1===(null===(r=t.key_ops)||void 0===r||null===(o=r.includes)||void 0===o?void 0:o.call(r,i)))throw TypeError('Invalid key for this operation, its "key_ops" must include "'.concat(i,'" when present'))}return!0};"undefined"!=typeof navigator&&null!==(rZ=navigator.userAgent)&&void 0!==rZ&&null!==(rV=rZ.startsWith)&&void 0!==rV&&rV.call(rZ,"Mozilla/5.0 ")||(c={"user-agent":"".concat("openid-client","/").concat("v6.8.3")});let rs=e=>l.get(e);function rc(e){return void 0!==e?tK(e):(u||(u=new WeakMap),(e,t,n,r)=>{let o;return(o=u.get(t))||(function(e,t){if("string"!=typeof e)throw rh("".concat(t," must be a string"),ru);if(0===e.length)throw rh("".concat(t," must not be empty"),rl)}(t.client_secret,'"metadata.client_secret"'),o=tK(t.client_secret),u.set(t,o)),o(e,t,n,r)})}let rl="ERR_INVALID_ARG_VALUE",ru="ERR_INVALID_ARG_TYPE";function rh(e,t,n){let r=TypeError(e,{cause:n});return Object.assign(r,{code:t}),r}class rd extends Error{constructor(e,t){var n;super(e,t),e7(this,"code",void 0),this.name=this.constructor.name,this.code=null==t?void 0:t.code,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function rp(e,t,n){return new rd(e,{cause:t,code:n})}function rf(e){if(e instanceof TypeError||e instanceof rd||e instanceof tz||e instanceof tH||e instanceof tJ)throw e;if(e instanceof tv)switch(e.code){case nu:throw rp("only requests to HTTPS are allowed",e,e.code);case nh:throw rp("only requests to HTTP or HTTPS are allowed",e,e.code);case nl:throw rp("unexpected HTTP response status code",e.cause,e.code);case nc:throw rp("unexpected response content-type",e.cause,e.code);case na:throw rp("parsing error occured",e,e.code);case ns:throw rp("invalid response encountered",e,e.code);case np:throw rp("unexpected JWT claim value encountered",e,e.code);case nf:throw rp("unexpected JSON attribute value encountered",e,e.code);case nd:throw rp("JWT timestamp claim value failed validation",e,e.code);default:throw rp(e.message,e,e.code)}if(e instanceof tg)throw rp("unsupported operation",e,e.code);if(e instanceof DOMException)switch(e.name){case"OperationError":throw rp("runtime operation error",e,no);case"NotSupportedError":throw rp("runtime unsupported operation",e,no);case"TimeoutError":throw rp("operation timed out",e,"OAUTH_TIMEOUT");case"AbortError":throw rp("operation aborted",e,"OAUTH_ABORT")}throw new rd("something went wrong",{cause:e})}async function rm(e,t,n,r,o){let i=new rw(await async function(e,t){var n,r,o;if(!(e instanceof URL))throw rh('"server" must be an instance of URL',ru);let i=!e.href.includes("/.well-known/"),a=null!==(n=null==t?void 0:t.t
1imeout)&&void 0!==n?n:30,s=AbortSignal.timeout(1e3*a),l=await (i?tE(e,{algorithm:null==t?void 0:t.algorithm,[th]:null==t?void 0:t[th],[tc]:null==t||null===(r=t.execute)||void 0===r?void 0:r.includes(rS),signal:s,headers:new Headers(c)}):((null==t?void 0:t[th])||fetch)((tD(e,null==t||null===(o=t.execute)||void 0===o||!o.includes(rS)),e.href),{headers:Object.fromEntries(new Headers(tt({accept:"application/json"},c)).entries()),body:void 0,method:"GET",redirect:"manual",signal:s})).then(e=>(async function(e,t){if(!(e instanceof URL)&&e!==nE)throw ts('"expectedIssuerIdentifier" must be an instance of URL',ta);if(!to(t,Response))throw ts('"response" must be an instance of Response',ta);if(200!==t.status)throw tb('"response" is not a conform Authorization Server Metadata response (unexpected HTTP status code)',nl,t);nw(t);let n=await nT(t);if(tA(n.issuer,'"response" body "issuer" property',ns,{body:n}),e!==nE&&new URL(n.issuer).href!==e.href)throw tb('"response" body "issuer" property does not match the expected value',nf,{expected:e.href,body:n,attribute:"issuer"});return n})(nE,e)).catch(rf);return!i||new URL(l.issuer).href===e.href||("https://login.microsoftonline.com"!==e.origin||null!=t&&t.algorithm&&"oidc"!==t.algorithm||(l[ry]=!0,0))&&(!e.hostname.endsWith(".b2clogin.com")||null!=t&&t.algorithm&&"oidc"!==t.algorithm)&&(()=>{throw new rd("discovered metadata issuer does not match the expected issuer",{code:nf,cause:{expected:e.href,body:l,attribute:"issuer"}})})(),l}(e,o),t,n,r),a=rs(i);if(null!=o&&o[th]&&(a.fetch=o[th]),null!=o&&o.timeout&&(a.timeout=o.timeout),null!=o&&o.execute)for(let e of o.execute)e(i);return i}new TextDecoder;let ry=Symbol();class rw{constructor(e,t,n,r){var o,i,a,s,c;let u;if("string"!=typeof t||!t.length)throw rh('"clientId" must be a non-empty string',ru);if("string"==typeof n&&(n={client_secret:n}),void 0!==(null===(o=n)||void 0===o?void 0:o.client_id)&&t!==n.client_id)throw rh('"clientId" and "metadata.client_id" must be the same',rl);let h=tt(tt({},structuredClone(n)),{},{client_id:t});h[tl]=null!==(i=null===(a=n)||void 0===a?void 0:a[tl])&&void 0!==i?i:0,h[tu]=null!==(s=null===(c=n)||void 0===c?void 0:c[tu])&&void 0!==s?s:30,u=r||("string"==typeof h.client_secret&&h.client_secret.length?rc(h.client_secret):(e,t,n,r)=>{n.set("client_id",t.client_id)});let d=Object.freeze(h),p=structuredClone(e);ry in e&&(p[nP]=t=>{let{claims:{tid:n}}=t;return e.issuer.replace("{tenantid}",n)});let f=Object.freeze(p);l||(l=new WeakMap),l.set(this,{__proto__:null,as:f,c:d,auth:u,tlsOnly:!0,jwksCache:{}})}serverMetadata(){let e=structuredClone(rs(this).as);return Object.defineProperties(e,{supportsPKCE:{__proto__:null,value(){var t;let n=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"S256";return!0===(null===(t=e.code_challenge_methods_supported)||void 0===t?void 0:t.includes(n))}}}),e}clientMetadata(){return structuredClone(rs(this).c)}get timeout(){return rs(this).timeout}set timeout(e){rs(this).timeout=e}get[th](){return rs(this).fetch}set[th](e){rs(this).fetch=e}}function rg(e){Object.defineProperties(e,function(e){let t;if(void 0!==e.expires_in){let n=new Date;n.setSeconds(n.getSeconds()+e.expires_in),t=n.getTime()}
1return{expiresIn:{__proto__:null,value(){if(t){let e=Date.now();return t>e?Math.floor((t-e)/1e3):0}}},claims:{__proto__:null,value(){try{return t2(this)}catch(e){return}}}}}(e))}async function rv(e,t,n){var r;let o;let i=arguments.length>3&&void 0!==arguments[3]&&arguments[3],a=null===(r=e.headers.get("retry-after"))||void 0===r?void 0:r.trim();if(void 0!==a){if(/^\d+$/.test(a))o=parseInt(a,10);else{let e=new Date(a);if(Number.isFinite(e.getTime())){let t=new Date,n=e.getTime()-t.getTime();n>0&&(o=Math.ceil(n/1e3))}}if(i&&!Number.isFinite(o))throw new tv("invalid Retry-After header value",{cause:e});o>t&&await rb(o-t,n)}}function rb(e,t){return new Promise((n,r)=>{let o=e=>{try{t.throwIfAborted()}catch(e){return void r(e)}if(e<=0)return void n();let i=Math.min(e,5);setTimeout(()=>o(e-i),1e3*i)};o(e)})}async function r_(e,t){rx(e);let{as:n,c:r,auth:o,fetch:i,tlsOnly:a,timeout:s}=rs(e);return(async function(e,t,n,r,o){tj(e),tW(t);let i=tL(e,"backchannel_authentication_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==o?void 0:o[tc])),a=new URLSearchParams(r);a.set("client_id",t.client_id);let s=tk(null==o?void 0:o.headers);return s.set("accept","application/json"),tq(e,t,n,i,a,s,o)})(n,r,o,t,{[th]:i,[tc]:!a,headers:new Headers(c),signal:rI(s)}).then(e=>(async function(e,t,n){if(tj(e),tW(t),!to(n,Response))throw ts('"response" must be an instance of Response',ta);await tG(n,200,"Backchannel Authentication Endpoint"),nw(n);let r=await nT(n);tA(r.auth_req_id,'"response" body "auth_req_id" property',ns,{body:r});let o="number"!=typeof r.expires_in?parseFloat(r.expires_in):r.expires_in;return tP(o,!0,'"response" body "expires_in" property',ns,{body:r}),r.expires_in=o,void 0!==r.interval&&tP(r.interval,!1,'"response" body "interval" property',ns,{body:r}),r})(n,r,e)).catch(rf)}async function rk(e,t,n,r){var o,i,a;let s;rx(e),n=new URLSearchParams(n);let l=null!==(o=t.interval)&&void 0!==o?o:5,u=null!==(i=null==r?void 0:r.signal)&&void 0!==i?i:AbortSignal.timeout(1e3*t.expires_in);try{await rb(l,u)}catch(e){rf(e)}let{as:h,c:d,auth:p,fetch:f,tlsOnly:m,nonRepudiation:y,timeout:w,decrypt:g}=rs(e),v=(o,i)=>rk(e,tt(tt({},t),{},{interval:o}),n,tt(tt({},r),{},{signal:u,flag:i})),b=await (async function(e,t,n,r,o){tj(e),tW(t),tA(r,'"authReqId"');let i=new URLSearchParams(null==o?void 0:o.additionalParameters);return i.set("auth_req_id",r),tQ(e,t,n,"urn:openid:params:grant-type:ciba",i,o)})(h,d,p,t.auth_req_id,{[th]:f,[tc]:!m,additionalParameters:n,DPoP:null==r?void 0:r.DPoP,headers:new Headers(c),signal:u.aborted?u:rI(w)}).catch(rf);if(503===b.status&&b.headers.has("retry-after"))return await rv(b,l,u,!0),await (null===(a=b.body)||void 0===a?void 0:a.cancel()),v(l);let _=async function(e,t,n,r){return t1(e,t,n,void 0,null==r?void 0:r[tp],null==r?void 0:r.recognizedTokenTypes)}(h,d,b,{[tp]:g});try{s=await _}catch(e){if(rO(e,r))return v(l,rC);if(e instanceof tz)switch(e.error){case"slow_down":l+=5;case"authorization_pending":return await rv(e.response,l,u),v(l)}rf(e)}return s.id_token&&await (null==y?void 0:y(b)),rg(s),s}function rS(e){rs(e).tlsOnly=!1}async function rT(e,t,n,r,o){let i,a,s;if(rx(e),!((null==o?void 0:o.flag)===rC||t instanceof URL||function(e,t){try{return Object.getPrototypeOf(e)[Symbol.toStringTag]===t}catch(e){return!1}}(t,"Request")))throw rh('"currentUrl" must be an instance of URL, or Request',ru);let{as:l,c:u,auth:h,fetch:d,tlsOnly:p,jarm:f,hybrid:m,nonRepudiation:y,timeout:w,decrypt:g,implicit:v}=rs(e);if((null==o?void 0:o.flag)===rC)i=o.authResponse,a=o.redirectUri;else{var b;if(!(t instanceof URL)){let e=t;switch(t=new URL(t.url),e.method){case"GET":break;case"POST":let n=new URLSearchParams(await nv(e));if(m)t.hash=n.toString();else for(let[e,r]of n.entries())t.searchParams.append(e,r);break;default:throw rh("unexpected Request HTTP method",rl)}}switch((b=new URL(b=t)).search="",b.hash="",a=b.href,!0){case!!f:i=await f(t,null==n?void 0:n.expectedState);break;case!!m:i=await m(t,null==n?void 0:n.expectedNonce,null==n?void 0:n.expectedState,null==n?void 0:n.maxAge);break;case!!v:throw TypeError("authorizationCodeGrant() cannot be used by response_type=id_token clients");default:try{i=function(e,t,n,r){var o;if(tj(e),tW(t),n instanceof URL&&(n=n.searchParams),!(n instanceof URLSearchParams))throw ts('"parameters" must be an instance of URLSearchParams, or URL',ta);if(n_(n,"response"))throw tb('"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()',ns,{parameters:n});let i=n_(n,"iss"),a=n_(n,"state");if(!i&&e.authorization_response_iss_parameter_supported)throw tb('response parameter "iss" (issuer) missing',ns,{parameters:n});if(i&&i!==e.issuer)throw tb('unexpected "iss" (issuer) response parameter value',ns,{expected:e.issuer,parameters:n});switch(r){case void 0:case nS:if(void 0!==a)throw tb('unexpected "state" response parameter encountered',ns,{expected:void 0,parameters:n});break;case nk:break;default:if(tA(r,'"expectedState" argument'),a!==r)throw tb(void 0===a?'response parameter "state" missing':'unexpected "state" response parameter value',ns,{expected:r,parameters:n})}if(n_(n,"error"))throw new tH("authorization response from the server is an error",{cause:n});let s=n_(n,"id_token"),c=n_(n,"token");
1if(void 0!==s||void 0!==c)throw new tg("implicit and hybrid flows are not supported");return o=new URLSearchParams(n),t9.add(o),o}(l,u,t.searchParams,null==n?void 0:n.expectedState)}catch(e){rf(e)}}}let _=await (async function(e,t,n,r,o,i,a){if(tj(e),tW(t),!t9.has(r))throw ts('"callbackParameters" must be an instance of URLSearchParams obtained from "validateAuthResponse()", or "validateJwtAuthResponse()',ti);tA(o,'"redirectUri"');let s=n_(r,"code");if(!s)throw tb('no authorization code in "callbackParameters"',ns);let c=new URLSearchParams(null==a?void 0:a.additionalParameters);return c.set("redirect_uri",o),c.set("code",s),i!==t6&&(tA(i,'"codeVerifier"'),c.set("code_verifier",i)),tQ(e,t,n,"authorization_code",c,a)})(l,u,h,i,a,(null==n?void 0:n.pkceCodeVerifier)||t6,{additionalParameters:r,[th]:d,[tc]:!p,DPoP:null==o?void 0:o.DPoP,headers:new Headers(c),signal:rI(w)}).catch(rf);"string"!=typeof(null==n?void 0:n.expectedNonce)&&"number"!=typeof(null==n?void 0:n.maxAge)||(n.idTokenExpected=!0);let k=nt(l,u,_,{expectedNonce:null==n?void 0:n.expectedNonce,maxAge:null==n?void 0:n.maxAge,requireIdToken:null==n?void 0:n.idTokenExpected,[tp]:g});try{s=await k}catch(t){if(rO(t,o))return rT(e,void 0,n,r,tt(tt({},o),{},{flag:rC,authResponse:i,redirectUri:a}));rf(t)}return s.id_token&&await (null==y?void 0:y(_)),rg(s),s}async function rE(e,t,n,r){let o;rx(e),n=new URLSearchParams(n);let{as:i,c:a,auth:s,fetch:l,tlsOnly:u,nonRepudiation:h,timeout:d,decrypt:p}=rs(e),f=await (async function(e,t,n,r,o){tj(e),tW(t),tA(r,'"refreshToken"');let i=new URLSearchParams(null==o?void 0:o.additionalParameters);return i.set("refresh_token",r),tQ(e,t,n,"refresh_token",i,o)})(i,a,s,t,{[th]:l,[tc]:!u,additionalParameters:n,DPoP:null==r?void 0:r.DPoP,headers:new Headers(c),signal:rI(d)}).catch(rf),m=async function(e,t,n,r){return t1(e,t,n,void 0,null==r?void 0:r[tp],null==r?void 0:r.recognizedTokenTypes)}(i,a,f,{[tp]:p});try{o=await m}catch(o){if(rO(o,r))return rE(e,t,n,tt(tt({},r),{},{flag:rC}));rf(o)}return o.id_token&&await (null==h?void 0:h(f)),rg(o),o}async function rP(e,t,n){let r;rx(e),t=new URLSearchParams(t);let{as:o,c:i,auth:a,fetch:s,tlsOnly:l,timeout:u}=rs(e),h=await (async function(e,t,n,r,o){return tj(e),tW(t),tQ(e,t,n,"client_credentials",new URLSearchParams(r),o)})(o,i,a,t,{[th]:s,[tc]:!l,DPoP:null==n?void 0:n.DPoP,headers:new Headers(c),signal:rI(u)}).catch(rf),d=async function(e,t,n,r){return t1(e,t,n,void 0,void 0,void 0)}(o,i,h);try{r=await d}catch(r){if(rO(r,n))return rP(e,t,tt(tt({},n),{},{flag:rC}));rf(r)}return rg(r),r}function rA(e,t){rx(e);let{as:n,c:r,tlsOnly:o,hybrid:i,jarm:a,implicit:s}=rs(e),c=tL(n,"authorization_endpoint",!1,o);if((t=new URLSearchParams(t)).has("client_id")||t.set("client_id",r.client_id),!t.has("request_uri")&&!t.has("request")){if(t.has("response_type")||t.set("response_type",i?"code id_token":s?"id_token":"code"),s&&!t.has("nonce"))throw rh("response_type=id_token clients must provide a nonce parameter in their authorization request parameters",rl);a&&t.set("response_mode","jwt")}for(let[e,n]of t.entries())c.searchParams.append(e,n);return c}async function rR(e,t,n){let r;rx(e);let o=rA(e,t),{as:i,c:a,auth:s,fetch:l,tlsOnly:u,timeout:h}=rs(e),d=await (async function(e,t,n,r,o){var i;tj(e),tW(t);let a=tL(e,"pushed_authorization_request_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==o?void 0:o[tc])),s=new URLSearchParams(r);s.set("client_id",t.client_id);let c=tk(null==o?void 0:o.headers);c.set("accept","application/json"),void 0!==(null==o?void 0:o.DPoP)&&(tY(o.DPoP),await o.DPoP.addProof(a,c,"POST"));let l=await tq(e,t,n,a,s,c,o);return null==o||null===(i=o.DPoP)||void 0===i||i.cacheNonce(l,a),l})(i,a,s,o.searchParams,{[th]:l,[tc]:!u,DPoP:null==n?void 0:n.DPoP,headers:new Headers(c),signal:rI(h)}).catch(rf),p=async function(e,t,n){if(tj(e),tW(t),!to(n,Response))throw ts('"response" must be an instance of Response',ta);await tG(n,201,"Pushed Authorization Request Endpoint"),nw(n);let r=await nT(n);tA(r.request_uri,'"response" body "request_uri" property',ns,{body:r});let o="number"!=typeof r.expires_in?parseFloat(r.expires_in):r.expires_in;return tP(o,!0,'"response" body "expires_in" property',ns,{body:r}),r.expires_in=o,r}(i,a,d);try{r=await p}catch(r){if(rO(r,n))return rR(e,t,tt(tt({},n),{},{flag:rC}));rf(r)}return rA(e,{request_uri:r.request_uri})}function rx(e){if(!(e instanceof rw))throw rh('"config" must be an instance of Configuration',ru);if(Object.getPrototypeOf(e)!==rw.prototype)throw rh("subclassing Configuration is not allowed",rl)}function rI(e){return e?AbortSignal.timeout(1e3*e):void 0}function rO(e,t){return!(null==t||!t.DPoP||t.flag===rC)&&function(e){if(e instanceof tJ){let{0:t,length:n}=e.cause;return 1===n&&"dpop"===t.scheme&&"use_dpop_nonce"===t.parameters.error}return e instanceof tz&&"use_dpop_nonce"===e.error}(e)}Object.freeze(rw.prototype);let rC=Symbol();async function rj(e,t,n,r){rx(e);let{as:o,c:i,auth:a,fetch:s,tlsOnly:l,timeout:u,decrypt:h}=rs(e),d=await (async function(e,t,n,r,o,i){return tj(e),tW(t),tA(r,'"grantType"'),tQ(e,t,n,r,new URLSearchParams(o),i)})(o,i,a,t,new URLSearchParams(n),{[th]:s,[tc]:!l,DPoP:null==r?void 0:r.DPoP,headers:new Headers(c),signal:rI(u)}).then(e=>{let n;return"urn:ietf:params:oauth:grant-type:token-exchange"===t&&(n={n_a:()=>{}}),async function(e,t,n,r){return t1(e,t,n,void 0,null==r?void 0:r[tp],null==r?void 0:r.recognizedTokenTypes)}(o,i,e,{[tp]:h,recognizedTokenTypes:n})}).catch(rf);return rg(d),d}async function rW(e,t,n){if(!n$(e))throw new nJ("Flattened JWS must be an object");
1if(void 0===e.protected&&void 0===e.header)throw new nJ('Flattened JWS must have either of the "protected" or "header" members');if(void 0!==e.protected&&"string"!=typeof e.protected)throw new nJ("JWS Protected Header incorrect type");if(void 0===e.payload)throw new nJ("JWS Payload missing");if("string"!=typeof e.signature)throw new nJ("JWS Signature missing or incorrect type");if(void 0!==e.header&&!n$(e.header))throw new nJ("JWS Unprotected Header incorrect type");let r={};if(e.protected)try{let t=nO(e.protected);r=JSON.parse(nR.decode(t))}catch(e){throw new nJ("JWS Protected Header is invalid")}if(!function(){let e;for(var t=arguments.length,n=Array(t),r=0;r<t;r++)n[r]=arguments[r];let o=n.filter(Boolean);if(0===o.length||1===o.length)return!0;for(let t of o){let n=Object.keys(t);if(e&&0!==e.size)for(let t of n){if(e.has(t))return!1;e.add(t)}else e=new Set(n)}return!0}(r,e.header))throw new nJ("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");let o=tt(tt({},r),e.header),i=function(e,t,n,r,o){let i;if(void 0!==o.crit&&void 0===(null==r?void 0:r.crit))throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!r||void 0===r.crit)return new Set;if(!Array.isArray(r.crit)||0===r.crit.length||r.crit.some(e=>"string"!=typeof e||0===e.length))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');for(let a of(i=void 0!==n?new Map([...Object.entries(n),...t.entries()]):t,r.crit)){if(!i.has(a))throw new nH('Extension Header Parameter "'.concat(a,'" is not recognized'));if(void 0===o[a])throw new e('Extension Header Parameter "'.concat(a,'" is missing'));if(i.get(a)&&void 0===r[a])throw new e('Extension Header Parameter "'.concat(a,'" MUST be integrity protected'))}return new Set(r.crit)}(nJ,new Map([["b64",!0]]),null==n?void 0:n.crit,r,o),a=!0;if(i.has("b64")&&"boolean"!=typeof(a=r.b64))throw new nJ('The "b64" (base64url-encode payload) Header Parameter must be a boolean');let{alg:s}=o;if("string"!=typeof s||!s)throw new nJ('JWS "alg" (Algorithm) Header Parameter missing or invalid');let c=n&&function(e,t){if(void 0!==t&&(!Array.isArray(t)||t.some(e=>"string"!=typeof e)))throw TypeError('"'.concat(e,'" option must be an array of strings'));if(t)return new Set(t)}("algorithms",n.algorithms);if(c&&!c.has(s))throw new nz('"alg" (Algorithm) Header Parameter value not allowed');if(a){if("string"!=typeof e.payload)throw new nJ("JWS Payload must be a string")}else if("string"!=typeof e.payload&&!(e.payload instanceof Uint8Array))throw new nJ("JWS Payload must be a string or an Uint8Array instance");let l=!1;"function"==typeof t&&(t=await t(r,e),l=!0),function(e,t,n){switch(e.substring(0,2)){case"A1":case"A2":case"di":case"HS":case"PB":((e,t,n)=>{if(!(t instanceof Uint8Array)){if(n0(t)){if("oct"===t.kty&&"string"==typeof t.k&&ra(e,t,n))return;throw TypeError('JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present')}if(!nq(t))throw TypeError(nU(e,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"));if("secret"!==t.type)throw TypeError("".concat(ri(t),' instances for symmetric algorithms must be of type "secret"'))}})(e,t,n);break;default:((e,t,n)=>{if(n0(t))switch(n){case"decrypt":case"sign":if("oct"!==t.kty&&("AKP"===t.kty&&"string"==typeof t.priv||"string"==typeof t.d)&&ra(e,t,n))return;throw TypeError("JSON Web Key for this operation must be a private JWK");case"encrypt":case"verify":if("oct"!==t.kty&&void 0===t.d&&void 0===t.priv&&ra(e,t,n))return;throw TypeError("JSON Web Key for this operation must be a public JWK")}if(!nq(t))throw TypeError(nU(e,t,"CryptoKey","KeyObject","JSON Web Key"));if("secret"===t.type)throw TypeError("".concat(ri(t),' instances for asymmetric algorithms must not be of type "secret"'));if("public"===t.type)switch(n){case"sign":throw TypeError("".concat(ri(t),' instances for asymmetric algorithm signing must be of type "private"'));case"decrypt":throw TypeError("".concat(ri(t),' instances for asymmetric algorithm decryption must be of type "private"'))}if("private"===t.type)switch(n){case"verify":throw TypeError("".concat(ri(t),' instances for asymmetric algorithm verifying must be of type "public"'));case"encrypt":throw TypeError("".concat(ri(t),' instances for asymmetric algorithm encryption must be of type "public"'))}})(e,t,n)}}(s,t,"verify");let u=function(){for(var e=arguments.length,t=Array(e),n=0;n<e;n++)t[n]=arguments[n];let r=new Uint8Array(t.reduce((e,t)=>
1{let{length:n}=t;return e+n},0)),o=0;for(let e of t)r.set(e,o),o+=e.length;return r}(void 0!==e.protected?nx(e.protected):new Uint8Array,nx("."),"string"==typeof e.payload?a?nx(e.payload):nA.encode(e.payload):e.payload),h=nQ(e.signature,"signature",nJ),d=await n4(t,s);if(!await n1(s,d,h,u))throw new nG;let p={payload:a?nQ(e.payload,"payload",nJ):"string"==typeof e.payload?nA.encode(e.payload):e.payload};return void 0!==e.protected&&(p.protectedHeader=r),void 0!==e.header&&(p.unprotectedHeader=e.header),l?tt(tt({},p),{},{key:d}):p}let rK=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i;function rU(e){let t;let n=rK.exec(e);if(!n||n[4]&&n[1])throw TypeError("Invalid time period format");let r=parseFloat(n[2]);switch(n[3].toLowerCase()){case"sec":case"secs":case"second":case"seconds":case"s":t=Math.round(r);break;case"minute":case"minutes":case"min":case"mins":case"m":t=Math.round(60*r);break;case"hour":case"hours":case"hr":case"hrs":case"h":t=Math.round(3600*r);break;case"day":case"days":case"d":t=Math.round(86400*r);break;case"week":case"weeks":case"w":t=Math.round(604800*r);break;default:t=Math.round(31557600*r)}return"-"===n[1]||"ago"===n[4]?-t:t}let rD=e=>e.includes("/")?e.toLowerCase():"application/".concat(e.toLowerCase());async function rN(e,t,n){var r;let o=await async function(e,t,n){if(e instanceof Uint8Array&&(e=nR.decode(e)),"string"!=typeof e)throw new nJ("Compact JWS must be a string or Uint8Array");let{0:r,1:o,2:i,length:a}=e.split(".");if(3!==a)throw new nJ("Invalid Compact JWS");let s=await rW({payload:o,protected:r,signature:i},t,n),c={payload:s.payload,protectedHeader:s.protectedHeader};return"function"==typeof t?tt(tt({},c),{},{key:s.key}):c}(e,t,n);if(null!==(r=o.protectedHeader.crit)&&void 0!==r&&r.includes("b64")&&!1===o.protectedHeader.b64)throw new nM("JWTs MUST NOT use unencoded payload");let i={payload:function(e,t){var n,r;let o,i,a=arguments.length>2&&void 0!==arguments[2]?arguments[2]:{};try{i=JSON.parse(nR.decode(t))}catch(e){}if(!n$(i))throw new nM("JWT Claims Set must be a top-level JSON object");let{typ:s}=a;if(s&&("string"!=typeof e.typ||rD(e.typ)!==rD(s)))throw new nN('unexpected "typ" JWT header value',i,"typ","check_failed");let{requiredClaims:c=[],issuer:l,subject:u,audience:h,maxTokenAge:d}=a,p=[...c];for(let e of(void 0!==d&&p.push("iat"),void 0!==h&&p.push("aud"),void 0!==u&&p.push("sub"),void 0!==l&&p.push("iss"),new Set(p.reverse())))if(!(e in i))throw new nN('missing required "'.concat(e,'" claim'),i,e,"missing");if(l&&!(Array.isArray(l)?l:[l]).includes(i.iss))throw new nN('unexpected "iss" claim value',i,"iss","check_failed");if(u&&i.sub!==u)throw new nN('unexpected "sub" claim value',i,"sub","check_failed");
1if(h&&(n=i.aud,r="string"==typeof h?[h]:h,!("string"==typeof n?r.includes(n):Array.isArray(n)&&r.some(Set.prototype.has.bind(new Set(n))))))throw new nN('unexpected "aud" claim value',i,"aud","check_failed");switch(typeof a.clockTolerance){case"string":o=rU(a.clockTolerance);break;case"number":o=a.clockTolerance;break;case"undefined":o=0;break;default:throw TypeError("Invalid clockTolerance option type")}let{currentDate:f}=a,m=Math.floor((f||new Date).getTime()/1e3);if((void 0!==i.iat||d)&&"number"!=typeof i.iat)throw new nN('"iat" claim must be a number',i,"iat","invalid");if(void 0!==i.nbf){if("number"!=typeof i.nbf)throw new nN('"nbf" claim must be a number',i,"nbf","invalid");if(i.nbf>m+o)throw new nN('"nbf" claim timestamp check failed',i,"nbf","check_failed")}if(void 0!==i.exp){if("number"!=typeof i.exp)throw new nN('"exp" claim must be a number',i,"exp","invalid");if(i.exp<=m-o)throw new nL('"exp" claim timestamp check failed',i,"exp","check_failed")}if(d){let e=m-i.iat;if(e-o>("number"==typeof d?d:rU(d)))throw new nL('"iat" claim timestamp check failed (too far in the past)',i,"iat","check_failed");if(e<0-o)throw new nN('"iat" claim timestamp check failed (it should be in the past)',i,"iat","check_failed")}return i}(o.protectedHeader,o.payload,n),protectedHeader:o.protectedHeader};return"function"==typeof t?tt(tt({},i),{},{key:o.key}):i}function rL(e){return n$(e)}var rz,rH,rJ,rM,rZ,rV,rX,rF,rG=new WeakMap,rY=new WeakMap;class rB{constructor(e){if(e4(this,rG,void 0),e4(this,rY,new WeakMap),!(e&&"object"==typeof e&&Array.isArray(e.keys)&&e.keys.every(rL)))throw new nZ("JSON Web Key Set malformed");e8(rG,this,structuredClone(e))}jwks(){return e6(rG,this)}async getKey(e,t){let{alg:n,kid:r}=tt(tt({},e),null==t?void 0:t.header),o=function(e){switch("string"==typeof e&&e.slice(0,2)){case"RS":case"PS":return"RSA";case"ES":return"EC";case"Ed":return"OKP";case"ML":return"AKP";default:throw new nH('Unsupported "alg" value for a JSON Web Key Set')}}(n),i=e6(rG,this).keys.filter(e=>{let t=o===e.kty;if(t&&"string"==typeof r&&(t=r===e.kid),t&&("string"==typeof e.alg||"AKP"===o)&&(t=n===e.alg),t&&"string"==typeof e.use&&(t="sig"===e.use),t&&Array.isArray(e.key_ops)&&(t=e.key_ops.includes("verify")),t)switch(n){case"ES256":t="P-256"===e.crv;break;case"ES384":t="P-384"===e.crv;break;case"ES512":t="P-521"===e.crv;break;
1case"Ed25519":case"EdDSA":t="Ed25519"===e.crv}return t}),{0:a,length:s}=i;if(0===s)throw new nV;if(1!==s){var c;let e=new nX,t=e6(rY,this);throw e[Symbol.asyncIterator]=(c=function*(){for(let r of i)try{var e;yield yield(e=rq(t,r,n),new e5(e,0))}catch(e){}},function(){return new tr(c.apply(this,arguments))}),e}return rq(e6(rY,this),a,n)}}async function rq(e,t,n){let r=e.get(t)||e.set(t,{}).get(t);if(void 0===r[n]){let e=await async function(e,t,n){let r;if(!n$(e))throw TypeError("JWK must be an object");switch(null!=t||(t=e.alg),null!=r||(r=e.ext),e.kty){case"oct":if("string"!=typeof e.k||!e.k)throw TypeError('missing "k" (Key Value) Parameter value');return nO(e.k);case"RSA":if("oth"in e&&void 0!==e.oth)throw new nH('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');return n3(tt(tt({},e),{},{alg:t,ext:r}));case"AKP":if("string"!=typeof e.alg||!e.alg)throw TypeError('missing "alg" (Algorithm) Parameter value');if(void 0!==t&&t!==e.alg)throw TypeError("JWK alg and alg option value mismatch");return n3(tt(tt({},e),{},{ext:r}));case"EC":case"OKP":return n3(tt(tt({},e),{},{alg:t,ext:r}));default:throw new nH('Unsupported "kty" (Key Type) Parameter value')}}(tt(tt({},t),{},{ext:!0}),n);if(e instanceof Uint8Array||"public"!==e.type)throw new nZ("JSON Web Key Set members must be public keys");r[n]=e}return r[n]}function rQ(e){let t=new rB(e),n=async(e,n)=>t.getKey(e,n);return Object.defineProperties(n,{jwks:{value:()=>structuredClone(t.jwks()),enumerable:!1,configurable:!1,writable:!1}}),n}"undefined"!=typeof navigator&&null!==(rX=navigator.userAgent)&&void 0!==rX&&null!==(rF=rX.startsWith)&&void 0!==rF&&rF.call(rX,"Mozilla/5.0 ")||(h="".concat("jose","/").concat("v6.2.2"));let r$=Symbol(),r0=Symbol();var r2=new WeakMap,r1=new WeakMap,r5=new WeakMap,r3=new WeakMap,r9=new WeakMap,r6=new WeakMap,r4=new WeakMap,r8=new WeakMap,r7=new WeakMap,oe=new WeakMap;class ot{constructor(e,t){var n,r;if(e4(this,r2,void 0),e4(this,r1,void 0),e4(this,r5,void 0),e4(this,r3,void 0),e4(this,r9,void 0),e4(this,r6,void 0),e4(this,r4,void 0),e4(this,r8,void 0),e4(this,r7,void 0),e4(this,oe,void 0),!(e instanceof URL))throw TypeError("url must be an instance of URL");e8(r2,this,new URL(e.href)),e8(r1,this,"number"==typeof(null==t?void 0:t.timeoutDuration)?null==t?void 0:t.timeoutDuration:5e3),e8(r5,this,"number"==typeof(null==t?void 0:t.cooldownDuration)?null==t?void 0:t.cooldownDuration:3e4),e8(r3,this,"number"==typeof(null==t?void 0:t.cacheMaxAge)?null==t?void 0:t.cacheMaxAge:6e5),e8(r4,this,new Headers(null==t?void 0:t.headers)),h&&!e6(r4,this).has("User-Agent")&&e6(r4,this).set("User-Agent",h),e6(r4,this).has("accept")||(e6(r4,this).set("accept","application/json"),e6(r4,this).append("accept","application/jwk-set+json")),e8(r8,this,null==t?void 0:t[r$]),void 0!==(null==t?void 0:t[r0])&&(e8(oe,this,null==t?void 0:t[r0]),n=null==t?void 0:t[r0],r=e6(r3,this),"object"==typeof n&&null!==n&&"uat"in n&&"number"==typeof n.uat&&!(Date.now()-n.uat>=r)&&"jwks"in n&&n$(n.jwks)&&Array.isArray(n.jwks.keys)&&Array.prototype.every.call(n.jwks.keys,n$)&&(e8(r9,this,e6(oe,this).uat),e8(r7,this,rQ(e6(oe,this).jwks))))}pendingFetch(){return!!e6(r6,this)}coolingDown(){return"number"==typeof e6(r9,this)&&Date.now()<e6(r9,this)+e6(r5,this)}fresh(){return"number"==typeof e6(r9,this)&&Date.now()<e6(r9,this)+e6(r3,this)}jwks(){var e;return null===(e=e6(r7,this))||void 0===e?void 0:e.jwks()}async getKey(e,t){e6(r7,this)&&this.fresh()||await this.reload();try{return await e6(r7,this).call(this,e,t)}catch(n){if(n instanceof nV&&!1===this.coolingDown())return await this.reload(),e6(r7,this).call(this,e,t);throw n}}async reload(){e6(r6,this)&&("undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime)&&e8(r6,this,void 0),e6(r6,this)||e8(r6,this,(async function(e,t,n){let r=arguments.length>3&&void 0!==arguments[3]?arguments[3]:fetch,o=await r(e,{method:"GET",signal:n,redirect:"manual",headers:t}).catch(e=>{if("TimeoutError"===e.name)throw new nF;throw e});if(200!==o.status)throw new nD("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await o.json()}catch(e){throw new nD("Failed to parse the JSON Web Key Set HTTP response as JSON")}})(e6(r2,this).href,e6(r4,this),AbortSignal.timeout(e6(r1,this)),e6(r8,this)).then(e=>{e8(r7,this,rQ(e)),e6(oe,this)&&(e6(oe,this).uat=Date.now(),e6(oe,this).jwks=e),e8(r9,this,Date.now()),e8(r6,this,void 0)}).catch(e=>{throw e8(r6,this,void 0),e})),await e6(r6,this)}}let on=["mfaToken"],or=["mfaToken"];var oo,oi,oa,os,oc,ol,ou,oh,od,op,of,om,oy,ow,og,ov,ob=class extends 
1Error{constructor(e,t){super(t),e7(this,"code",void 0),this.name="NotSupportedError",this.code=e}},o_=class extends Error{constructor(e,t,n){super(t),e7(this,"cause",void 0),e7(this,"code",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},ok=class extends o_{constructor(e,t){super("token_by_code_error",e,t),this.name="TokenByCodeError"}},oS=class extends o_{constructor(e,t){super("token_by_client_credentials_error",e,t),this.name="TokenByClientCredentialsError"}},oT=class extends o_{constructor(e,t){super("token_by_refresh_token_error",e,t),this.name="TokenByRefreshTokenError"}},oE=class extends o_{constructor(e,t){super("token_by_password_error",e,t),this.name="TokenByPasswordError"}},oP=class extends o_{constructor(e,t){super("token_for_connection_error",e,t),this.name="TokenForConnectionErrorCode"}},oA=class extends o_{constructor(e,t){super("token_exchange_error",e,t),this.name="TokenExchangeError"}},oR=class extends Error{constructor(e){super(e),e7(this,"code","verify_logout_token_error"),this.name="VerifyLogoutTokenError"}},ox=class extends o_{constructor(e){super("backchannel_authentication_error","There was an error when trying to use Client-Initiated Backchannel Authentication.",e),e7(this,"code","backchannel_authentication_error"),this.name="BackchannelAuthenticationError"}},oI=class extends o_{constructor(e){super("build_authorization_url_error","There was an error when trying to build the authorization URL.",e),this.name="BuildAuthorizationUrlError"}},oO=class extends o_{constructor(e){super("build_link_user_url_error","There was an error when trying to build the Link User URL.",e),this.name="BuildLinkUserUrlError"}},oC=class extends o_{constructor(e){super("build_unlink_user_url_error","There was an error when trying to build the Unlink User URL.",e),this.name="BuildUnlinkUserUrlError"}},oj=class extends Error{constructor(){super("The client secret or client assertion signing key must be provided."),e7(this,"code","missing_client_auth_error"),this.name="MissingClientAuthError"}};function oW(e){return Object.entries(e).filter(e=>{let[,t]=e;return void 0!==t}).reduce((e,t)=>tt(tt({},e),{},{[t[0]]:t[1]}),{})}var oK=class extends Error{constructor(e,t,n){super(t),e7(this,"cause",void 0),e7(this,"code",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},oU=class extends oK{constructor(e,t){super("mfa_list_authenticators_error",e,t),this.name="MfaListAuthenticatorsError"}},oD=class extends oK{constructor(e,t){super("mfa_enrollment_error",e,t),this.name="MfaEnrollmentError"}},oN=class extends oK{constructor(e,t){super("mfa_delete_authenticator_error",e,t),this.name="MfaDeleteAuthenticatorError"}},oL=class extends oK{constructor(e,t){super("mfa_challenge_error",e,t),this.name="MfaChallengeError"}};function oz(e){return{id:e.id,authenticatorType:e.authenticator_type,active:e.active,name:e.name,oobChannels:e.oob_channels,type:e.type}}var oH=(oo=new WeakMap,oi=new WeakMap,oa=new WeakMap,class{constructor(e){var t;e4(this,oo,void 0),e4(this,oi,void 0),e4(this,oa,void 0),e8(oo,this,"https://".concat(e.domain)),e8(oi,this,e.clientId),e8(oa,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)})}async listAuthenticators(e){let t="".concat(e6(oo,this),"/mfa/authenticators"),{mfaToken:n}=e,r=await e6(oa,this).call(this,t,{method:"GET",headers:{Authorization:"Bearer ".concat(n),"Content-Type":"application/json"}});if(!r.ok){let e=await r.json();throw new oU(e.error_description||"Failed to list authenticators",e)}return(await r.json()).map(oz)}async enrollAuthenticator(e){let t="".concat(e6(oo,this),"/mfa/associate"),{mfaToken:n}=e,r=tn(e,on),o={authenticator_types:r.authenticatorTypes};"oobChannels"in r&&(o.oob_channels=r.oobChannels),"phoneNumber"in r&&r.phoneNumber&&(o.phone_number=r.phoneNumber),"email"in r&&r.email&&(o.email=r.email);let i=await e6(oa,this).call(this,t,{method:"POST",headers:{Authorization:"Bearer ".concat(n),"Content-Type":"application/json"},body:JSON.stringify(o)});if(!i.ok){let e=await i.json();throw new oD(e.error_description||"Failed to enroll authenticator",e)}return function(e){if("otp"===e.authenticator_type)return{authenticatorType:"otp",secret:e.secret,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes,id:e.id};if("oob"===e.authenticator_type)return{authenticatorType:"oob",oobChannel:e.oob_channel,oobCode:e.oob_code,bindingMethod:e.binding_method,id:e.id,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes};throw Error("Unexpected authenticator type: ".concat(e.authenticator_type))}(await i.json())}async deleteAuthenticator(e){let{authenticatorId:t,mfaToken:n}=e,r="".concat(e6(oo,this),"/mfa/authenticators/").concat(encodeURIComponent(t)),o=await e6(oa,this).call(this,r,{method:"DELETE",headers:{Authorization:"Bearer ".concat(n),"Content-Type":"application/json"}});if(!o.ok){let e=await o.json();throw new oN(e.error_description||"Failed to delete authenticator",e)}}async challengeAuthenticator(e){let t="".concat(e6(oo,this),"/mfa/challenge"),{mfaToken:n}=e,r=tn(e,or),o={mfa_token:n,client_id:e6(oi,this),challenge_type:r.challengeType};r.authenticatorId&&(o.authenticator_id=r.authenticatorId);let i=await e6(oa,this).call(this,t,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(o)});if(!i.ok){let e=await i.json();throw new oL(e.error_description||"Failed to challenge authenticator",e)}return function(e){let t={challengeType:e.challenge_type};return void 0!==e.oob_code&&(t.oobCode=e.oob_code),void 0!==e.binding_method&&(t.bindingMethod=e.binding_method),t}(await i.json())}}),oJ=class e{constructor(e,t,n,r,o,i,a){e7(this,"accessToken",void 0),e7(this,"idToken",void 0),e7(this,"refreshToken",void 0),e7(this,"expiresAt",void 0),e7(this,"scope",void 0),e7(this,"claims",void 0),e7(this,"authorizationDetail
1s",void 0),e7(this,"tokenType",void 0),e7(this,"issuedTokenType",void 0),this.accessToken=e,this.idToken=n,this.refreshToken=r,this.expiresAt=t,this.scope=o,this.claims=i,this.authorizationDetails=a}static fromTokenEndpointResponse(t){let n=t.id_token?t.claims():void 0,r=new e(t.access_token,Math.floor(Date.now()/1e3)+Number(t.expires_in),t.id_token,t.refresh_token,t.scope,n,t.authorization_details);return r.tokenType=t.token_type,r.issuedTokenType=t.issued_token_type,r}},oM=(os=new WeakMap,oc=new WeakMap,ol=new WeakMap,class{constructor(e,t){e4(this,os,new Map),e4(this,oc,void 0),e4(this,ol,void 0),e8(ol,this,Math.max(1,Math.floor(e))),e8(oc,this,Math.max(0,Math.floor(t)))}get(e){let t=e6(os,this).get(e);if(t){if(!(Date.now()>=t.expiresAt))return e6(os,this).delete(e),e6(os,this).set(e,t),t.value;e6(os,this).delete(e)}}set(e,t){for(e6(os,this).has(e)&&e6(os,this).delete(e),e6(os,this).set(e,{value:t,expiresAt:Date.now()+e6(oc,this)});e6(os,this).size>e6(ol,this);){let e=e6(os,this).keys().next().value;if(void 0===e)break;e6(os,this).delete(e)}}}),oZ=new Map;function oV(e){return{ttlMs:1e3*("number"==typeof(null==e?void 0:e.ttl)?e.ttl:600),maxEntries:"number"==typeof(null==e?void 0:e.maxEntries)&&e.maxEntries>0?e.maxEntries:100}}var oX=class{static createDiscoveryCache(e){var t,n;let r=(t=e.maxEntries,n=e.ttlMs,"".concat(t,":").concat(n)),o=oZ.get(r);return o||(o=new oM(e.maxEntries,e.ttlMs),oZ.set(r,o)),o}static createJwksCache(){return{}}},oF="openid profile email offline_access",oG=Object.freeze(new Set(["grant_type","client_id","client_secret","client_assertion","client_assertion_type","subject_token","subject_token_type","requested_token_type","actor_token","actor_token_type","audience","aud","resource","resources","resource_indicator","scope","connection","login_hint","organization","assertion"]));function oY(e){if(null==e)throw new oA("subject_token is required");if("string"!=typeof e)throw new oA("subject_token must be a string");if(0===e.trim().length)throw new oA("subject_token cannot be blank or whitespace");if(e!==e.trim())throw new oA("subject_token must not include leading or trailing whitespace");if(/^bearer\s+/i.test(e))throw new oA("subject_token must not include the 'Bearer ' prefix")}function oB(e,t){if(t){for(let[n,r]of Object.entries(t))if(!oG.has(n)){if(Array.isArray(r)){if(r.length>20)throw new oA("Parameter '".concat(n,"' exceeds maximum array size of ").concat(20));r.forEach(t=>{e.append(n,t)})}else e.append(n,r)}}}var oq="urn:ietf:params:oauth:token-type:access_token",oQ=(ou=new WeakMap,oh=new WeakMap,od=new WeakMap,op=new WeakMap,of=new WeakMap,om=new WeakMap,oy=new WeakMap,ow=new WeakMap,og=new WeakMap,ov=new WeakSet,class{constructor(e){var t,n,r,o;if(e9(this,ov),ov.add(this),e4(this,ou,void 0),e4(this,oh,void 0),e4(this,od,void 0),e4(this,op,void 0),e4(this,of,void 0),e4(this,om,void 0),e4(this,oy,void 0),e4(this,ow,void 0),e4(this,og,void 0),e7(this,"mfa",void 0),e8(op,this,e),e.useMtls&&!e.customFetch)throw new ob("mtls_without_custom_fetch_not_supported","Using mTLS without a custom fetch implementation is not supported");e8(of,this,function(e,t){if(!1===t.enabled)return e;let n=btoa(JSON.stringify({name:t.name,version:t.version}));return async(t,r)=>{let o=t instanceof Request?new Headers(t.headers):new Headers;return null!=r&&r.headers&&new Headers(r.headers).forEach((e,t)=>{o.set(t,e)}),o.set("Auth0-Client",n),e(t,tt(tt({},r),{},{headers:o}))}}(null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)},!1===(null==(n=e.telemetry)?void 0:n.enabled)?n:{enabled:!0,name:null!==(r=null==n?void 0:n.name)&&void 0!==r?r:"@auth0/auth0-auth-js",version:null!==(o=null==n?void 0:n.version)&&void 0!==o?o:"1.6.0"}));let i=oV(e.discoveryCache);e8(oy,this,oX.createDiscoveryCache(i)),e8(ow,this,new Map),e8(og,this,oX.createJwksCache()),this.mfa=new oH({domain:e6(op,this).domain,clientId:e6(op,this).clientId,customFetch:e6(of,this)})}async getServerMetadata(){let{serverMetadata:e}=await e3(ov,this,o2).call(this);return e}async buildAuthorizationUrl(e){let{serverMetadata:t}=await e3(ov,this,o2).call(this);if(null!=e&&e.pushedAuthorizationRequests&&!t.pushed_authorization_request_endpoint)throw new ob("par_not_supported_error","The Auth0 tenant does not have pushed authorization requests enabled. Learn how to enable it here: https://auth0.com/docs/get-started/applications/configure-par");try{return await e3(ov,this,o9).call(this,e)}catch(e){throw new oI(e)}}async buildLinkUserUrl(e){try{let t=await e3(ov,this,o9).call(this,{authorizationParams:tt(tt({},e.authorizationParams),{},{requested_connection:e.connection,requested_connection_scope:e.connectionScope,scope:"openid link_account offline_access",id_token_hint:e.idToken})});return{linkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new oO(e)}}async buildUnlinkUserUrl(e){try{let t=await e3(ov,this,o9).call(this,{authorizationParams:tt(tt({},e.authorizationParams),{},{requested_connection:e.connection,scope:"openid unlink_account",id_token_hint:e.idToken})});return{unlinkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new oC(e)}}
1async backchannelAuthentication(e){let{configuration:t,serverMetadata:n}=await e3(ov,this,o2).call(this),r=oW(tt(tt({},e6(op,this).authorizationParams),null==e?void 0:e.authorizationParams)),o=new URLSearchParams(tt(tt({scope:oF},r),{},{client_id:e6(op,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:n.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&o.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&o.append("authorization_details",JSON.stringify(e.authorizationDetails));try{let e=await r_(t,o),n=await rk(t,e);return oJ.fromTokenEndpointResponse(n)}catch(e){throw new ox(e)}}async initiateBackchannelAuthentication(e){let{configuration:t,serverMetadata:n}=await e3(ov,this,o2).call(this),r=oW(tt(tt({},e6(op,this).authorizationParams),null==e?void 0:e.authorizationParams)),o=new URLSearchParams(tt(tt({scope:oF},r),{},{client_id:e6(op,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:n.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&o.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&o.append("authorization_details",JSON.stringify(e.authorizationDetails));try{let e=await r_(t,o);return{authReqId:e.auth_req_id,expiresIn:e.expires_in,interval:e.interval}}catch(e){throw new ox(e)}}async backchannelAuthenticationGrant(e){let{authReqId:t}=e,{configuration:n}=await e3(ov,this,o2).call(this),r=new URLSearchParams({auth_req_id:t});try{let e=await rj(n,"urn:openid:params:grant-type:ciba",r);return oJ.fromTokenEndpointResponse(e)}catch(e){throw new ox(e)}}async getTokenForConnection(e){var t;if(e.refreshToken&&e.accessToken)throw new oP("Either a refresh or access token should be specified, but not both.");let n=null!==(t=e.accessToken)&&void 0!==t?t:e.refreshToken;if(!n)throw new oP("Either a refresh or access token must be specified.");try{return await this.exchangeToken({connection:e.connection,subjectToken:n,subjectTokenType:e.accessToken?oq:"urn:ietf:params:oauth:token-type:refresh_token",loginHint:e.loginHint})}catch(e){if(e instanceof oA)throw new oP(e.message,e.cause);throw e}}async exchangeToken(e){return"connection"in e?e3(ov,this,o1).call(this,e):e3(ov,this,o5).call(this,e)}async getTokenByCode(e,t){let{configuration:n}=await e3(ov,this,o2).call(this);try{let r=await rT(n,e,{pkceCodeVerifier:t.codeVerifier});return oJ.fromTokenEndpointResponse(r)}catch(e){throw new ok("There was an error while trying to request a token.",e)}}async getTokenByRefreshToken(e){let{configuration:t}=await e3(ov,this,o2).call(this),n=new URLSearchParams;e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope);try{let r=await rE(t,e.refreshToken,n);return oJ.fromTokenEndpointResponse(r)}catch(e){throw new oT("The access token has expired and there was an error while trying to refresh it.",e)}}async getTokenByPassword(e){let{configuration:t}=await e3(ov,this,o2).call(this),n=new URLSearchParams({username:e.username,password:e.password});e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),e.realm&&n.append("realm",e.realm);let r=t;if(e.auth0ForwardedFor){let n=await e3(ov,this,o3).call(this);(r=new rw(t.serverMetadata(),e6(op,this).clientId,e6(op,this).clientSecret,n))[th]=(t,n)=>e6(of,this).call(this,t,tt(tt({},n),{},{headers:tt(tt({},n.headers),{},{"auth0-forwarded-for":e.auth0ForwardedFor})}))}try{let e=await rj(r,"password",n);return oJ.fromTokenEndpointResponse(e)}catch(e){throw new oE("There was an error while trying to request a token.",e)}}async getTokenByClientCredentials(e){let{configuration:t}=await e3(ov,this,o2).call(this);try{let n=new URLSearchParams({audience:e.audience});e.organization&&n.append("organization",e.organization);let r=await rP(t,n);return oJ.fromTokenEndpointResponse(r)}catch(e){throw new oS("There was an error while trying to request a token.",e)}}async buildLogoutUrl(e){let{configuration:t,serverMetadata:n}=await e3(ov,this,o2).call(this);if(!n.end_session_endpoint){let t=new URL("https://".concat(e6(op,this).domain,"/v2/logout"));return t.searchParams.set("returnTo",e.returnTo),t.searchParams.set("client_id",e6(op,this).clientId),t}return function(e,t){rx(e);let{as:n,c:r,tlsOnly:o}=rs(e),i=tL(n,"end_session_endpoint",!1,o);for(let[e,n]of((t=new URLSearchParams(t)).has("client_id")||t.set("client_id",r.client_id),t.entries()))i.searchParams.append(e,n);return i}(t,{post_logout_redirect_uri:e.returnTo})}async verifyLogoutToken(e){let{serverMetadata:t}=await e3(ov,this,o2).call(this),n=oV(e6(op,this).discoveryCache),r=t.jwks_uri;e6(om,this)||e8(om,this,function(e,t){let n=new ot(e,t),r=async(e,t)=>n.getKey(e,t);return Object.defineProperties(r,{coolingDown:{get:()=>n.coolingDown(),enumerable:!0,configurable:!1},fresh:{get:()=>n.fresh(),enumerable:!0,configurable:!1},reload:{value:()=>n.reload(),enumerable:!0,configurable:!1,writable:!1},reloading:{get:()=>n.pendingFetch(),enumerable:!0,configurable:!1},jwks:{value:()=>n.jwks(),enumerable:!0,configurable:!1,writable:!1}}),r}(new URL(r),{cacheMaxAge:n.ttlMs,[r$]:e6(of,this),[r0]:e6(og,this)}));let{payload:o}=await rN(e.logoutToken,e6(om,this),{issuer:t.issuer,audience:e6(op,this).clientId,algorithms:["RS256"],requiredClaims:["iat"]});if(!("sid"in o)&&!("sub"in o))throw new oR('either "sid" or "sub" (or both) claims must be present');if("sid"in o&&"string"!=typeof o.sid)throw new oR('"sid" claim must be a string');
1if("sub"in o&&"string"!=typeof o.sub)throw new oR('"sub" claim must be a string');if("nonce"in o)throw new oR('"nonce" claim is prohibited');if(!("events"in o))throw new oR('"events" claim is missing');if("object"!=typeof o.events||null===o.events)throw new oR('"events" claim must be an object');if(!("http://schemas.openid.net/event/backchannel-logout"in o.events))throw new oR('"http://schemas.openid.net/event/backchannel-logout" member is missing in the "events" claim');if("object"!=typeof o.events["http://schemas.openid.net/event/backchannel-logout"])throw new oR('"http://schemas.openid.net/event/backchannel-logout" member in the "events" claim must be an object');return{sid:o.sid,sub:o.sub}}});function o$(){let e=e6(op,this).domain.toLowerCase();return"".concat(e,"|mtls:").concat(e6(op,this).useMtls?"1":"0")}async function o0(e){let t=await e3(ov,this,o3).call(this),n=new rw(e,e6(op,this).clientId,e6(op,this).clientSecret,t);return n[th]=e6(of,this),n}async function o2(){if(e6(ou,this)&&e6(oh,this))return{configuration:e6(ou,this),serverMetadata:e6(oh,this)};let e=e3(ov,this,o$).call(this),t=e6(oy,this).get(e);if(t)return e8(oh,this,t.serverMetadata),e8(ou,this,await e3(ov,this,o0).call(this,t.serverMetadata)),{configuration:e6(ou,this),serverMetadata:e6(oh,this)};let n=e6(ow,this).get(e);if(n){let e=await n;return e8(oh,this,e.serverMetadata),e8(ou,this,await e3(ov,this,o0).call(this,e.serverMetadata)),{configuration:e6(ou,this),serverMetadata:e6(oh,this)}}let r=(async()=>{let t=await e3(ov,this,o3).call(this),n=await rm(new URL("https://".concat(e6(op,this).domain)),e6(op,this).clientId,{use_mtls_endpoint_aliases:e6(op,this).useMtls},t,{[th]:e6(of,this)}),r=n.serverMetadata();return e6(oy,this).set(e,{serverMetadata:r}),{configuration:n,serverMetadata:r}})(),o=r.then(e=>{let{serverMetadata:t}=e;return{serverMetadata:t}});o.catch(()=>{}),e6(ow,this).set(e,o);try{let{configuration:e,serverMetadata:t}=await r;e8(ou,this,e),e8(oh,this,t),e6(ou,this)[th]=e6(of,this)}finally{e6(ow,this).delete(e)}return{configuration:e6(ou,this),serverMetadata:e6(oh,this)}}async function o1(e){var t,n;let{configuration:r}=await e3(ov,this,o2).call(this);if("audience"in e||"resource"in e)throw new oA("audience and resource parameters are not supported for Token Vault exchanges");oY(e.subjectToken);let o=new URLSearchParams({connection:e.connection,subject_token:e.subjectToken,subject_token_type:null!==(t=e.subjectTokenType)&&void 0!==t?t:oq,requested_token_type:null!==(n=e.requestedTokenType)&&void 0!==n?n:"http://auth0.com/oauth/token-type/federated-connection-access-token"});e.loginHint&&o.append("login_hint",e.loginHint),e.scope&&o.append("scope",e.scope),oB(o,e.extra);try{let e=await rj(r,"urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token",o);return oJ.fromTokenEndpointResponse(e)}catch(t){throw new oA("Failed to exchange token for connection '".concat(e.connection,"'."),t)}}async function o5(e){let{configuration:t}=await e3(ov,this,o2).call(this);oY(e.subjectToken);let n=new URLSearchParams({subject_token_type:e.subjectTokenType,subject_token:e.subjectToken});e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),e.requestedTokenType&&n.append("requested_token_type",e.requestedTokenType),e.organization&&n.append("organization",e.organization),oB(n,e.extra);try{let e=await rj(t,"urn:ietf:params:oauth:grant-type:token-exchange",n);return oJ.fromTokenEndpointResponse(e)}catch(t){throw new oA("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),t)}}async function o3(){return e6(od,this)||e8(od,this,(async()=>{if(!e6(op,this).clientSecret&&!e6(op,this).clientAssertionSigningKey&&!e6(op,this).useMtls)throw new oj;if(e6(op,this).useMtls)return(e,t,n,r)=>{n.set("client_id",t.client_id)};let e=e6(op,this).clientAssertionSigningKey;return!e||e instanceof CryptoKey||(e=await async function(e,t,n){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw TypeError('"pkcs8" must be PKCS#8 formatted string');return ro(e,t,void 0)}(e,e6(op,this).clientAssertionSigningAlg||"RS256")),e?function(e,t){let{key:n,kid:r}=e instanceof CryptoKey?{key:e}:(null==e?void 0:e.key)instanceof CryptoKey?(void 0!==e.kid&&tA(e.kid,'"kid"'),{key:e.key,kid:e.kid}):{};return function(e,t){if(function(e,t){if(!(e instanceof CryptoKey))throw ts("".concat(t," must be a CryptoKey"),ta)}(e,t),"private"!==e.type)throw ts("".concat(t," must be a private CryptoKey"),ti)}(n,'"clientPrivateKey.key"'),async(e,o,i,a)=>{var s;let c={alg:function(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"PS256";case"SHA-384":return"PS384";case"SHA-512":return"PS512";default:throw new tg("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"RSASSA-PKCS1-v1_5":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"RS256";case"SHA-384":return"RS384";case"SHA-512":return"RS512";default:throw new tg("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"ECDSA":return function(e){switch(e.algorithm.namedCurve){case"P-256":return"ES256";case"P-384":return"ES384";case"P-521":return"ES512";default:throw new tg("unsupported EcKeyAlgorithm namedCurve",{cause:e})}}(e);case"Ed25519":case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return e.algorithm.name;case"EdDSA":return"Ed25519";default:throw new tg("unsupported CryptoKey algorithm name",{cause:e})}}(n),kid:r},l=function(e,t){let n=tC()+tI(t);return{jti:tx(),aud:e.issuer,exp:n+60,iat:n,nbf:n,iss:t.client_id,sub:t.client_id}}(e,o);null==t||null===(s=t[td])||void 0===s||s.call(t,c,l),i.set("client_id",o.client_id),i.set("client_assertion_type","urn:ietf:params:oauth:client-assertion-type:jwt-bearer"),i.set("client_assertion",await async function(e,t,n){if(!n.usages.includes("sign"))throw ts('
1CryptoKey instances used for signing assertions must include "sign" in their "usages"',ti);let r="".concat(tw(ty(JSON.stringify(e))),".").concat(tw(ty(JSON.stringify(t)))),o=tw(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:function(e){let{algorithm:t}=e;switch(t.namedCurve){case"P-256":return"SHA-256";case"P-384":return"SHA-384";case"P-521":return"SHA-512";default:throw new tg("unsupported ECDSA namedCurve",{cause:e})}}(e)};case"RSA-PSS":switch(ng(e),e.algorithm.hash.name){case"SHA-256":case"SHA-384":case"SHA-512":return{name:e.algorithm.name,saltLength:parseInt(e.algorithm.hash.name.slice(-3),10)>>3};default:throw new tg("unsupported RSA-PSS hash name",{cause:e})}case"RSASSA-PKCS1-v1_5":return ng(e),e.algorithm.name;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":case"Ed25519":return e.algorithm.name}throw new tg("unsupported CryptoKey algorithm name",{cause:e})}(n),n,ty(r)));return"".concat(r,".").concat(o)}(c,l,n))}}(e,void 0):rc(e6(op,this).clientSecret)})().catch(e=>{throw e8(od,this,void 0),e})),e6(od,this)}async function o9(e){let{configuration:t}=await e3(ov,this,o2).call(this),n=tx(),r=await async function(e){return tA(e,"codeVerifier"),tw(await crypto.subtle.digest("SHA-256",ty(e)))}(n),o=oW(tt(tt({},e6(op,this).authorizationParams),null==e?void 0:e.authorizationParams)),i=new URLSearchParams(tt(tt({scope:oF},o),{},{client_id:e6(op,this).clientId,code_challenge:r,code_challenge_method:"S256"}));return{authorizationUrl:null!=e&&e.pushedAuthorizationRequests?await rR(t,i):await rA(t,i),codeVerifier:n}}class o6 extends g{constructor(e,t){super(e,t),Object.setPrototypeOf(this,o6.prototype)}static fromPayload(e){let{error:t,error_description:n}=e;return new o6(t,n)}}class o4 extends o6{constructor(e,t){super(e,t),Object.setPrototypeOf(this,o4.prototype)}}class o8 extends o6{constructor(e,t){super(e,t),Object.setPrototypeOf(this,o8.prototype)}}class o7 extends o6{constructor(e,t){super(e,t),Object.setPrototypeOf(this,o7.prototype)}}class ie extends o6{constructor(e,t){super(e,t),Object.setPrototypeOf(this,ie.prototype)}}class it extends o6{constructor(e,t){super(e,t),Object.setPrototypeOf(this,it.prototype)}}class ir{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:6e5;this.contexts=new Map,this.ttlMs=e}set(e,t){this.cleanup(),this.contexts.set(e,Object.assign(Object.assign({},t),{createdAt:Date.now()}))}get(e){let t=this.contexts.get(e);if(t){if(!(Date.now()-t.createdAt>this.ttlMs))return t;this.contexts.delete(e)}}remove(e){this.contexts.delete(e)}cleanup(){let e=Date.now();for(let[t,n]of this.contexts)e-n.createdAt>this.ttlMs&&this.contexts.delete(t)}get size(){return this.contexts.size}}class io{constructor(e,t){this.authJsMfaClient=e,this.auth0Client=t,this.contextManager=new ir}setMFAAuthDetails(e,t,n,r){this.contextManager.set(e,{scope:t,audience:n,mfaRequirements:r})}async getAuthenticators(e){var t,n;let r=this.contextManager.get(e);if(!(null===(t=null==r?void 0:r.mfaRequirements)||void 0===t?void 0:t.challenge)||0===r.mfaRequirements.challenge.length)throw new o4("invalid_request","challengeType is required and must contain at least one challenge type, please check mfa_required error payload");let o=r.mfaRequirements.challenge.map(e=>e.type);try{return(await this.authJsMfaClient.listAuthenticators({mfaToken:e})).filter(e=>!!e.type&&o.includes(e.type))}catch(e){if(e instanceof oU)throw new o4(null===(n=e.cause)||void 0===n?void 0:n.error,e.message);throw e}}async enroll(e){var t;let n=function(e){let t=e1[e.factorType];return Object.assign(Object.assign(Object.assign({mfaToken:e.mfaToken,authenticatorTypes:t.authenticatorTypes},t.oobChannels&&{oobChannels:t.oobChannels}),"phoneNumber"in e&&{phoneNumber:e.phoneNumber}),"email"in e&&{email:e.email})}(e);try{return await this.authJsMfaClient.enrollAuthenticator(n)}catch(e){if(e instanceof oD)throw new o8(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async challenge(e){var t;try{let t={challengeType:e.challengeType,mfaToken:e.mfaToken};return e.authenticatorId&&(t.authenticatorId=e.authenticatorId),await this.authJsMfaClient.challengeAuthenticator(t)}catch(e){if(e instanceof oL)throw new o7(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async getEnrollmentFactors(e){let t=this.contextManager.get(e);if(!t||!t.mfaRequirements)throw new it("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");return t.mfaRequirements.enroll&&0!==t.mfaRequirements.enroll.length?t.mfaRequirements.enroll:[]}async verify(e){let t=this.contextManager.get(e.mfaToken);if(!t)throw new ie("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");let n="otp"in e&&e.otp?"http://auth0.com/oauth/grant-type/mfa-otp":"oobCode"in e&&e.oobCode?"http://auth0.com/oauth/grant-type/mfa-oob":"recoveryCode"in e&&e.recoveryCode?"http://auth0.com/oauth/grant-type/mfa-rec
1overy-code":void 0;if(!n)throw new ie("invalid_request","Unable to determine grant type. Provide one of: otp, oobCode, or recoveryCode.");let r=t.scope,o=t.audience;try{let t=await this.auth0Client._requestTokenForMfa({grant_type:n,mfaToken:e.mfaToken,scope:r,audience:o,otp:e.otp,oob_code:e.oobCode,binding_code:e.bindingCode,recovery_code:e.recoveryCode});return this.contextManager.remove(e.mfaToken),t}catch(e){if(e instanceof E)this.setMFAAuthDetails(e.mfa_token,r,o,e.mfa_requirements);else if(e instanceof ie)throw new ie(e.error,e.error_description);throw e}}}class ii{constructor(e){var t,n,r;let o,i,a,s,c;if(this.userCache=(new eT).enclosedCache,this.defaultOptions={authorizationParams:{scope:"openid profile email"},useRefreshTokensFallback:!1,useFormData:!0},this.options=Object.assign(Object.assign(Object.assign({},this.defaultOptions),e),{authorizationParams:Object.assign(Object.assign({},this.defaultOptions.authorizationParams),e.authorizationParams)}),"undefined"!=typeof window&&(()=>{if(!I())throw Error("For security reasons, `window.crypto` is required to run `auth0-spa-js`.");if(void 0===I().subtle)throw Error("\n      auth0-spa-js must run on a secure origin. See https://github.com/auth0/auth0-spa-js/blob/main/FAQ.md#why-do-i-get-auth0-spa-js-must-run-on-a-secure-origin for more information.\n    ")})(),this.lockManager=($||($="undefined"!=typeof navigator&&"function"==typeof(null===(r=navigator.locks)||void 0===r?void 0:r.request)?new q:new Q),$),e.cache&&e.cacheLocation&&console.warn("Both `cache` and `cacheLocation` options have been specified in the Auth0Client configuration; ignoring `cacheLocation` and using `cache`."),e.cache)i=e.cache;else{if(!eF(o=e.cacheLocation||f))throw Error('Invalid cache location "'.concat(o,'"'));i=eF(o)()}this.httpTimeoutMs=e.httpTimeoutInSeconds?1e3*e.httpTimeoutInSeconds:1e4,this.cookieStorage=!1===e.legacySameSiteCookie?eW:eU,this.orgHintCookieName=(t=this.options.clientId,"auth0.".concat(t,".organization_hint")),this.isAuthenticatedCookieName=(a=this.options.clientId,"auth0.".concat(a,".is.authenticated")),this.sessionCheckExpiryDays=e.sessionCheckExpiryDays||1;let l=e.useCookiesForTransactions?this.cookieStorage:eD;this.scope=function(e,t){for(var n=arguments.length,r=Array(n>2?n-2:0),o=2;o<n;o++)r[o-2]=arguments[o];if("object"!=typeof e)return{[w]:eg(t,e,...r)};let i={[w]:eg(t,...r)};return Object.keys(e).forEach(n=>{let o=e[n];i[n]=eg(t,o,...r)}),i}(this.options.authorizationParams.scope,"openid",this.options.useRefreshTokens?"offline_access":""),this.transactionManager=new eP(l,this.options.clientId,this.options.cookieDomain),this.nowProvider=this.options.nowProvider||y,this.cacheManager=new eE(i,i.allKeys?void 0:new eZ(i,this.options.clientId),this.nowProvider),this.dpop=this.options.useDpop?new eQ(this.options.clientId):void 0,this.domainUrl=(n=this.options.domain,/^https?:\/\//.test(n)?n:"https://".concat(n)),this.tokenIssuer=(s=this.options.issuer,c=this.domainUrl,s?s.startsWith("https://")?s:"https://".concat(s,"/"):"".concat(c,"/"));let u="".concat(this.domainUrl,"/me/"),h=this.createFetcher(Object.assign(Object.assign({},this.options.useDpop&&{dpopNonceId:"__auth0_my_account_api__"}),{getAccessToken:()=>this.getTokenSilently({authorizationParams:{scope:"create:me:connected_accounts",audience:u},detailedResponse:!0})}));this.myAccountApi=new e0(h,u),this.authJsClient=new oQ({domain:this.options.domain,clientId:this.options.clientId}),this.mfa=new io(this.authJsClient.mfa,this),"undefined"!=typeof window&&window.Worker&&this.options.useRefreshTokens&&o===f&&(this.options.workerUrl?this.worker=new Worker(this.options.workerUrl):this.worker=new eJ,this.worker.postMessage({type:"init",allowedBaseUrl:this.domainUrl}))}getConfiguration(){return Object.freeze({domain:this.options.domain,clientId:this.options.clientId})}_url(e){let t=encodeURIComponent(btoa(JSON.stringify(W(this.options.auth0Client||m,!0))));return"".concat(this.domainUrl).concat(e,"&auth0Client=").concat(t)}_authorizeUrl(e){return this._url("/authorize?".concat(K(e)))}async _verifyIdToken(e,t,n){var r;let o=await this.nowProvider();return ex({iss:this.tokenIssuer,aud:this.options.clientId,id_token:e,nonce:t,organization:n,leeway:this.options.leeway,max_age:"string"!=typeof(r=this.options.authorizationParams.max_age)?r:parseInt(r,10)||void 0,now:o})}_processOrgHint(e){e?this.cookieStorage.save(this.orgHintCookieName,e,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}):this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain})}_extractSessionTransferToken(e){return new URLSearchParams(window.location.search).get(e)||void 0}_clearSessionTransferTokenFromUrl(e){try{let t=new URL(window.location.href);t.searchParams.has(e)&&(t.searchParams.delete(e),window.history.replaceState({},"",t.toString()))}catch(e){}}_applySessionTransferToken(e){let t=this.options.sessionTransferTokenQueryParamName;if(!t||e.session_transfer_token)return e;let n=this._extractSessionTransferToken(t);return n?(this._clearSessionTransferTokenFromUrl(t),Object.assign(Object.assign({},e),{session_transfer_token:n})):e}async _prepareAuthorizeUrl(e,t,n){var r;let o,i,a,s;let c=C(O()),l=C(O()),u=O(),h=N(await U(u)),d=await (null===(r=this.dpop)||void 0===r?void 0:r.calculateThumbprint()),p=(o=this.options,i=this.scope,a=e.redirect_uri||this.options.authorizationParams.redirect_uri||n,s=null==t?void 0:t.response_mode,Object.assign(Object.assign(Object.assign({client_id:o.clientId}
1,o.authorizationParams),e),{scope:ev(i,e.scope,e.audience),response_type:"code",response_mode:s||"query",state:c,nonce:l,redirect_uri:a||o.authorizationParams.redirect_uri,code_challenge:h,code_challenge_method:"S256",dpop_jkt:d})),f=this._authorizeUrl(p);return{nonce:l,code_verifier:u,scope:p.scope,audience:p.audience||w,redirect_uri:p.redirect_uri,state:c,url:f}}async loginWithPopup(e,t){var n;let r,o;if(e=e||{},!(t=t||{}).popup&&(t.popup=(e=>{let t=window.screenX+(window.innerWidth-400)/2,n=window.screenY+(window.innerHeight-600)/2;return window.open(e,"auth0:authorize:popup","left=".concat(t,",top=").concat(n,",width=").concat(400,",height=").concat(600,",resizable,scrollbars=yes,status=1"))})(""),!t.popup))throw new T;let i=this._applySessionTransferToken(e.authorizationParams||{}),a=await this._prepareAuthorizeUrl(i,{response_mode:"web_message"},window.location.origin);t.popup.location.href=a.url;let s=await (r=Object.assign(Object.assign({},t),{timeoutInSeconds:t.timeoutInSeconds||this.options.authorizeTimeoutInSeconds||60}),o=new URL(a.url).origin,new Promise((e,t)=>{let n;let i=setInterval(()=>{r.popup&&r.popup.closed&&(clearInterval(i),clearTimeout(a),window.removeEventListener("message",n,!1),t(new S(r.popup)))},1e3),a=setTimeout(()=>{clearInterval(i),t(new k(r.popup)),window.removeEventListener("message",n,!1)},1e3*(r.timeoutInSeconds||60));n=function(s){if(s.origin===o&&s.data&&"authorization_response"===s.data.type){if(clearTimeout(a),clearInterval(i),window.removeEventListener("message",n,!1),!1!==r.closePopup&&r.popup.close(),s.data.response.error)return t(g.fromPayload(s.data.response));e(s.data.response)}},window.addEventListener("message",n)}));if(a.state!==s.state)throw new g("state_mismatch","Invalid state");let c=(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization;await this._requestToken({audience:a.audience,scope:a.scope,code_verifier:a.code_verifier,grant_type:"authorization_code",code:s.code,redirect_uri:a.redirect_uri},{nonceIn:a.nonce,organization:c})}async getUser(){var e;let t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.user}async getIdTokenClaims(){var e;let t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.claims}async loginWithRedirect(){var e;let t=eG(arguments.length>0&&void 0!==arguments[0]?arguments[0]:{}),{openUrl:n,fragment:r,appState:o}=t,i=d(t,["openUrl","fragment","appState"]),a=(null===(e=i.authorizationParams)||void 0===e?void 0:e.organization)||this.options.authorizationParams.organization,s=this._applySessionTransferToken(i.authorizationParams||{}),c=await this._prepareAuthorizeUrl(s),{url:l}=c,u=d(c,["url"]);this.transactionManager.create(Object.assign(Object.assign(Object.assign({},u),{appState:o,response_type:eL.Code}),a&&{organization:a}));let h=r?"".concat(l,"#").concat(r):l;n?await n(h):window.location.assign(h)}async handleRedirectCallback(){let e=(arguments.length>0&&void 0!==arguments[0]?arguments[0]:window.location.href).split("?").slice(1);if(0===e.length)throw Error("There are no query params available for parsing.");let t=this.transactionManager.get();if(!t)throw new g("missing_transaction","Invalid state");this.transactionManager.remove();let n=(e=>{e.indexOf("#")>-1&&(e=e.substring(0,e.indexOf("#")));let t=new URLSearchParams(e);return{state:t.get("state"),code:t.get("code")||void 0,connect_code:t.get("connect_code")||void 0,error:t.get("error")||void 0,error_description:t.get("error_description")||void 0}})(e.join(""));return t.response_type===eL.ConnectCode?this._handleConnectAccountRedirectCallback(n,t):this._handleLoginRedirectCallback(n,t)}async _handleLoginRedirectCallback(e,t){let{code:n,state:r,error:o,error_description:i}=e;if(o)throw new v(o,i||o,r,t.appState);if(!t.code_verifier||t.state&&t.state!==r)throw new g("state_mismatch","Invalid state");let a=t.organization,s=t.nonce,c=t.redirect_uri;return await this._requestToken(Object.assign({audience:t.audience,scope:t.scope,code_verifier:t.code_verifier,grant_type:"authorization_code",code:n},c?{redirect_uri:c}:{}),{nonceIn:s,organization:a}),{appState:t.appState,response_type:eL.Code}}
1async _handleConnectAccountRedirectCallback(e,t){let{connect_code:n,state:r,error:o,error_description:i}=e;if(o)throw new b(o,i||o,t.connection,r,t.appState);if(!n)throw new g("missing_connect_code","Missing connect code");if(!(t.code_verifier&&t.state&&t.auth_session&&t.redirect_uri&&t.state===r))throw new g("state_mismatch","Invalid state");return Object.assign(Object.assign({},await this.myAccountApi.completeAccount({auth_session:t.auth_session,connect_code:n,redirect_uri:t.redirect_uri,code_verifier:t.code_verifier})),{appState:t.appState,response_type:eL.ConnectCode})}async checkSession(e){if(!this.cookieStorage.get(this.isAuthenticatedCookieName)){if(!this.cookieStorage.get(eV))return;this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(eV)}try{await this.getTokenSilently(e)}catch(e){}}async getTokenSilently(){var e,t,n,r;let o;let i=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},a=Object.assign(Object.assign({cacheMode:"on"},i),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),i.authorizationParams),{scope:ev(this.scope,null===(e=i.authorizationParams)||void 0===e?void 0:e.scope,(null===(t=i.authorizationParams)||void 0===t?void 0:t.audience)||this.options.authorizationParams.audience)})}),s=await (n=()=>this._getTokenSilently(a),(o=eM[r="".concat(this.options.clientId,"::").concat(a.authorizationParams.audience,"::").concat(a.authorizationParams.scope)])||(o=n().finally(()=>{delete eM[r],o=null}),eM[r]=o),o);return i.detailedResponse?s:null==s?void 0:s.access_token}async _getTokenSilently(e){var t,n;let{cacheMode:r}=e,o=d(e,["cacheMode"]);if("off"!==r){let e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||w,clientId:this.options.clientId,cacheMode:r});if(e)return e}if("cache-only"===r)return;let i=(t=this.options.clientId,n=o.authorizationParams.audience||"default","".concat("auth0.lock.getTokenSilently",".").concat(t,".").concat(n));try{return await this.lockManager.runWithLock(i,5e3,async()=>{if("off"!==r){let e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||w,clientId:this.options.clientId});if(e)return e}let{id_token:e,token_type:t,access_token:n,oauthTokenScope:i,expires_in:a}=this.options.useRefreshTokens?await this._getTokenUsingRefreshToken(o):await this._getTokenFromIFrame(o);return Object.assign(Object.assign({id_token:e,token_type:t,access_token:n},i?{scope:i}:null),{expires_in:a})})}catch(e){if(this._isInteractiveError(e)&&"popup"===this.options.interactiveErrorHandler)return await this._handleInteractiveErrorWithPopup(o);throw e}}_isInteractiveError(e){return e instanceof E||e instanceof g&&this._isIframeMfaError(e)}_isIframeMfaError(e){return"login_required"===e.error&&"Multifactor authentication required"===e.error_description}async _handleInteractiveErrorWithPopup(e){try{await this.loginWithPopup({authorizationParams:e.authorizationParams});let t=await this._getEntryFromCache({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||w,clientId:this.options.clientId});if(!t)throw new g("interactive_handler_cache_miss","Token not found in cache after interactive authentication");return t}catch(e){throw e}}async getTokenWithPopup(){var e,t;let n=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},r=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{},o=Object.assign(Object.assign({},n),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),n.authorizationParams),{scope:ev(this.scope,null===(e=n.authorizationParams)||void 0===e?void 0:e.scope,(null===(t=n.authorizationParams)||void 0===t?void 0:t.audience)||this.options.authorizationParams.audience)})});return r=Object.assign(Object.assign({},p),r),await this.loginWithPopup(o,r),(await this.cacheManager.get(new ek({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||w,clientId:this.options.clientId}),void 0,this.options.useMrrt)).access_token}async isAuthenticated(){return!!await this.getUser()}_buildLogoutUrl(e){null!==e.clientId?e.clientId=e.clientId||this.options.clientId:delete e.clientId;let t=e.logoutParams||{},{federated:n}=t,r=d(t,["federated"]);return this._url("/v2/logout?".concat(K(Object.assign({clientId:e.clientId},r))))+(n?"&federated":"")}async revokeRefreshToken(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!this.options.useRefreshTokens)return;let t=e.audience||this.options.authorizationParams.audience||w,n=await this.cacheManager.getRefreshTokensByAudience(t,this.options.clientId);await async function(e,t){let{baseUrl:n,timeout:r,auth0Client:o,useFormData:i,refreshTokens:a,audience:s,client_id:c,onRefreshTokenRevoked:l}=e,u=r||1e4,h="refresh_token",d="".concat(n,"/oauth/revoke"),p={"Content-Type":i?"application/x-www-form-urlencoded":"application/json","Auth0-Client":btoa(JSON.stringify(W(o||m)))};if(t){let e={client_id:c,token_type_hint:h},n=i?K(e):JSON.stringify(e);try{return await ep({type:"revoke",timeout:u,fetchUrl:d,fetchOptions:{method:"POST",body:n,headers:p},useFormData:i,auth:{audience:null!=s?s:w}},t)}catch(e){throw new g("revoke_error",e.message)}}for(let e of a){let t={client_id:c,token_type_hint:h,token:e},n=i?K(t):JSON.stringify(t),r=await ef(d,{method:"POST",body:n,headers:p},u);if(!r.ok){let e,t;try{({error:e,error_description:t}=JSON.parse(await r.text()))}catch(e){}throw new g(e||"revoke_error",t||"HTTP error ".concat(r.status))}await (null==l?void 0:l(e))}}({baseUrl:this.domainUrl,timeout:this.httpTimeoutMs,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,client_id:this.options.clientId,refreshTokens:n,audience:t,onRefreshTokenRevoked:e=>this.cacheManager.stripRefreshToken(e)},this.worker)}async logout(){var e;let t=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},n=eG(t),{openUrl:r}=n,o=d(n,["openUrl"]);if(null===t.clientId?await this.cacheManager.clear():await this.cacheManager.clear(t.clientId||this.options.clientId),this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(this.isAuthenticatedCookieName,{cookieDomain:this.options.cookieDomain}),this.userCache.remove(e_),await (null===(e=this.dpop)||void 0===e?void 0:e.clear()),this.worker)try{await ep({type:"clear"},this.worker)}catch(e){}let i=this._buildLogoutUrl(o);r?await r(i):!1!==r&&window.location.assign(i)}async _getTokenFromIFrame(e){var t;let n=(t=this.options.clientId,"".concat("auth0.lock.getTokenFromIFrame",".").concat(t));try{return await this.lockManager.runWithLock(n,5e3,async()=>{let t;let n=Object.assign(Object.assign({},e.authorizationParams),{prompt:"none"}),r=this.cookieStorage.get(this.orgHintCookieName);r&&!n.organization&&(n.organization=r);let{url:o,state:i,nonce:a,code_verifier:s,redirect_uri:c,scope:l,audience:u}=await this._prepareAuthorizeUrl(n,{response_mode:"web_message"},window.location.origin);if(window.crossOriginIsolated)throw new g("login_required","The application is running in a Cross-Origin Isolated context, silently retrieving a token without refresh token is not possible.");let h=e.timeoutInSeconds||this.options.authorizeTimeoutInSeconds;try{t=new URL(this.domainUrl).origin}catch(e){t=this.domainUrl}let d=await function(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:60;return new Promise((r,o)=>{let i;let a=window.document.createElement("iframe");a.setAttribute("width","0"),a.setAttribute("height","0"),a.style.display="none";let s=()=>{window.document.body.contains(a)&&(window.document.body.removeChild(a),window.removeEventListener("message",i,!1))},c=setTimeout(()=>{o(new _),s()},1e3*n);i=function(e){if(e.origin!=t||!e.data||"authorization_response"!==e.data.type)return;let n=e.source;n&&n.close(),e.data.response.error?o(g.fromPayload(e.data.response)):r(e.data.response),clearTimeout(c),window.removeEventListener("message",i,!1),setTimeout(s,2e3)},window.addEventListener("message",i,!1),window.document.body.appendChild(a),a.setAttribute("src",e)})}(o,t,h);if(i!==d.state)throw new g("state_mismatch","Invalid state");let p=await this._requestToken(Object.assign(Object.assign({},e.authorizationParams),{code_verifier:s,code:d.code,grant_type:"authorization_code",redirect_uri:c,timeout:e.authorizationParams.timeout||this.httpTimeoutMs}),{nonceIn:a,organization:n.organization});return Object.assign(Object.assign({},p),{scope:l,oauthTokenScope:p.scope,audience:u})})}catch(e){throw"login_required"===e.error&&(e instanceof g&&this._isIframeMfaError(e)&&"popup"===this.options.interactiveErrorHandler||this.logout({openUrl:!1})),e}}async _getTokenUsingRefreshToken(e){var t,n,r,o,i,a;let s=await this.cacheManager.get(new ek({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||w,clientId:this.options.clientId}),void 0,this.options.useMrrt);if(!(s&&s.refresh_token||this.worker)){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw new P(e.authorizationParams.audience||w,e.authorizationParams.scope)}let c=e.authorizationParams.redirect_uri||this.options.authorizationParams.redirect_uri||window.location.origin,l="number"==typeof e.timeoutInSeconds?1e3*e.timeoutInSeconds:null,u=((e,t,n,r)=>{var o;
1if(e&&n&&r){if(t.audience!==n)return t.scope;let e=r.split(" "),i=(null===(o=t.scope)||void 0===o?void 0:o.split(" "))||[],a=i.every(t=>e.includes(t));return e.length>=i.length&&a?r:t.scope}return t.scope})(this.options.useMrrt,e.authorizationParams,null==s?void 0:s.audience,null==s?void 0:s.scope);try{let t=await this._requestToken(Object.assign(Object.assign(Object.assign({},e.authorizationParams),{grant_type:"refresh_token",refresh_token:s&&s.refresh_token,redirect_uri:c}),l&&{timeout:l}),{scopesToRequest:u});if(t.refresh_token&&(null==s?void 0:s.refresh_token)&&await this.cacheManager.updateEntry(s.refresh_token,t.refresh_token),this.options.useMrrt&&(r=null==s?void 0:s.audience,o=null==s?void 0:s.scope,i=e.authorizationParams.audience,a=e.authorizationParams.scope,(r!==i||!eY(a,o))&&!eY(u,t.scope))){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);await this.cacheManager.remove(this.options.clientId,e.authorizationParams.audience,e.authorizationParams.scope);let n=((e,t)=>{let n=(null==e?void 0:e.split(" "))||[],r=(null==t?void 0:t.split(" "))||[];return n.filter(e=>-1==r.indexOf(e)).join(",")})(u,t.scope);throw new A(e.authorizationParams.audience||"default",n)}return Object.assign(Object.assign({},t),{scope:e.authorizationParams.scope,oauthTokenScope:t.scope,audience:e.authorizationParams.audience||w})}catch(r){if(r.message){if(r.message.includes("user is blocked"))throw await this.logout({openUrl:!1}),r;if((r.message.includes("Missing Refresh Token")||r.message.includes("invalid refresh token"))&&this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e)}throw r instanceof E&&this.mfa.setMFAAuthDetails(r.mfa_token,null===(t=e.authorizationParams)||void 0===t?void 0:t.scope,null===(n=e.authorizationParams)||void 0===n?void 0:n.audience,r.mfa_requirements),r}}async _saveEntryInCache(e){let{id_token:t,decodedToken:n}=e,r=d(e,["id_token","decodedToken"]);this.userCache.set(e_,{id_token:t,decodedToken:n}),await this.cacheManager.setIdToken(this.options.clientId,e.id_token,e.decodedToken),await this.cacheManager.set(r)}async _getIdTokenFromCache(){let e=this.options.authorizationParams.audience||w,t=this.scope[e],n=await this.cacheManager.getIdToken(new ek({clientId:this.options.clientId,audience:e,scope:t})),r=this.userCache.get(e_);return n&&n.id_token===(null==r?void 0:r.id_token)?r:(this.userCache.set(e_,n),n)}async _getEntryFromCache(e){let{scope:t,audience:n,clientId:r,cacheMode:o}=e,i=await this.cacheManager.get(new ek({scope:t,audience:n,clientId:r}),60,this.options.useMrrt,o);if(i&&i.access_token){let{token_type:e,access_token:t,oauthTokenScope:n,expires_in:r}=i,o=await this._getIdTokenFromCache();return o&&Object.assign(Object.assign({id_token:o.id_token,token_type:e||"Bearer",access_token:t},n?{scope:n}:null),{expires_in:r})}}async _requestToken(e,t){var n,r;let{nonceIn:o,organization:i,scopesToRequest:a}=t||{},s=await ew(Object.assign(Object.assign({baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,useMrrt:this.options.useMrrt,dpop:this.dpop},e),{scope:a||e.scope}),this.worker),c=await this._verifyIdToken(s.id_token,o,i);if("authorization_code"===e.grant_type){let e=await this._getIdTokenFromCache();(null===(r=null===(n=null==e?void 0:e.decodedToken)||void 0===n?void 0:n.claims)||void 0===r?void 0:r.sub)&&e.decodedToken.claims.sub!==c.claims.sub&&(await this.cacheManager.clear(this.options.clientId),this.userCache.remove(e_))}return await this._saveEntryInCache(Object.assign(Object.assign(Object.assign(Object.assign({},s),{decodedToken:c,scope:e.scope,audience:e.audience||w}),s.scope?{oauthTokenScope:s.scope}:null),{client_id:this.options.clientId})),this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this._processOrgHint(i||c.claims.org_id),Object.assign(Object.assign({},s),{decodedToken:c})}async loginWithCustomTokenExchange(e){return this._requestToken(Object.assign(Object.assign({},e),{grant_type:"urn:ietf:params:oauth:grant-type:token-exchange",subject_token:e.subject_token,subject_token_type:e.subject_token_type,scope:ev(this.scope,e.scope,e.audie
1nce||this.options.authorizationParams.audience),audience:e.audience||this.options.authorizationParams.audience,organization:e.organization||this.options.authorizationParams.organization}))}async exchangeToken(e){return this.loginWithCustomTokenExchange(e)}_assertDpop(e){if(!e)throw Error("`useDpop` option must be enabled before using DPoP.")}getDpopNonce(e){return this._assertDpop(this.dpop),this.dpop.getNonce(e)}setDpopNonce(e,t){return this._assertDpop(this.dpop),this.dpop.setNonce(e,t)}generateDpopProof(e){return this._assertDpop(this.dpop),this.dpop.generateProof(e)}createFetcher(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};return new e$(e,{isDpopEnabled:()=>!!this.options.useDpop,getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:null==e?void 0:e.audience},detailedResponse:!0})},getDpopNonce:()=>this.getDpopNonce(e.dpopNonceId),setDpopNonce:t=>this.setDpopNonce(t,e.dpopNonceId),generateDpopProof:e=>this.generateDpopProof(e)})}async connectAccountWithRedirect(e){let{openUrl:t,appState:n,connection:r,scopes:o,authorization_params:i,redirectUri:a=this.options.authorizationParams.redirect_uri||window.location.origin}=e;if(!r)throw Error("connection is required");let s=C(O()),c=O(),l=N(await U(c)),{connect_uri:u,connect_params:h,auth_session:d}=await this.myAccountApi.connectAccount({connection:r,scopes:o,redirect_uri:a,state:s,code_challenge:l,code_challenge_method:"S256",authorization_params:i});this.transactionManager.create({state:s,code_verifier:c,auth_session:d,redirect_uri:a,appState:n,connection:r,response_type:eL.ConnectCode});let p=new URL(u);p.searchParams.set("ticket",h.ticket),t?await t(p.toString()):window.location.assign(p)}async _requestTokenForMfa(e,t){let{mfaToken:n}=e,r=d(e,["mfaToken"]);return this._requestToken(Object.assign(Object.assign({},r),{mfa_token:n}),t)}}}}]);
2//# sourceMappingURL=526778d9-9ec5998f02b70d05.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.