PageSourceSearch

https://m.fredit.co.kr/_ustra/b70d6e4.js

js fredit.co.kr collected 2026-09-24 09:27:12 UTC 81,750 bytes, 2 lines download raw bytes

1/*! For license information please see LICENSES */
2(window.webpackJsonp=window.webpackJsonp||[]).push([[520],{1392:function(e,t){t.read=function(e,t,r,n,o){var c,d,l=8*o-n-1,h=(1<<l)-1,f=h>>1,y=-7,i=r?o-1:0,w=r?-1:1,s=e[t+i];for(i+=w,c=s&(1<<-y)-1,s>>=-y,y+=l;y>0;c=256*c+e[t+i],i+=w,y-=8);for(d=c&(1<<-y)-1,c>>=-y,y+=n;y>0;d=256*d+e[t+i],i+=w,y-=8);if(0===c)c=1-f;else{if(c===h)return d?NaN:1/0*(s?-1:1);d+=Math.pow(2,n),c-=f}return(s?-1:1)*d*Math.pow(2,c-n)},t.write=function(e,t,r,n,o,c){var d,l,h,f=8*c-o-1,y=(1<<f)-1,w=y>>1,rt=23===o?Math.pow(2,-24)-Math.pow(2,-77):0,i=n?0:c-1,m=n?1:-1,s=t<0||0===t&&1/t<0?1:0;for(t=Math.abs(t),isNaN(t)||t===1/0?(l=isNaN(t)?1:0,d=y):(d=Math.floor(Math.log(t)/Math.LN2),t*(h=Math.pow(2,-d))<1&&(d--,h*=2),(t+=d+w>=1?rt/h:rt*Math.pow(2,1-w))*h>=2&&(d++,h/=2),d+w>=y?(l=0,d=y):d+w>=1?(l=(t*h-1)*Math.pow(2,o),d+=w):(l=t*Math.pow(2,w-1)*Math.pow(2,o),d=0));o>=8;e[r+i]=255&l,i+=m,l/=256,o-=8);for(d=d<<o|l,f+=o;f>0;e[r+i]=255&d,i+=m,d/=256,f-=8);e[r+i-m]|=128*s}},1394:function(e,t,r){"use strict";r.r(t),r.d(t,"version",(function(){return c})),r.d(t,"VERSION",(function(){return d})),r.d(t,"atob",(function(){return j})),r.d(t,"atobPolyfill",(function(){return M})),r.d(t,"btoa",(function(){return P})),r.d(t,"btoaPolyfill",(function(){return _})),r.d(t,"fromBase64",(function(){return G})),r.d(t,"toBase64",(function(){return R})),r.d(t,"utob",(function(){return T})),r.d(t,"encode",(function(){return R})),r.d(t,"encodeURI",(function(){return O})),r.d(t,"encodeURL",(function(){return O})),r.d(t,"btou",(function(){return I})),r.d(t,"decode",(function(){return G})),r.d(t,"isValid",(function(){return F})),r.d(t,"fromUint8Array",(function(){return k})),r.d(t,"toUint8Array",(function(){return B})),r.d(t,"extendString",(function(){return V})),r.d(t,"extendUint8Array",(function(){return X})),r.d(t,"extendBuiltins",(function(){return Y})),r.d(t,"Base64",(function(){return Z}));var n,o=r(296),c=(r(2),r(27),r(824),r(159),r(119),r(120),r(121),r(122),r(123),r(124),r(125),r(126),r(127),r(128),r(129),r(130),r(131),r(132),r(133),r(134),r(135),r(136),r(137),r(138),r(139),r(140),r(141),r(49),r(39),r(25),r(35),r(41),r(53),"3.6.0"),d=c,l="function"==typeof atob,h="function"==typeof btoa,f="function"==typeof Buffer,y="function"==typeof TextDecoder?new TextDecoder:void 0,w="function"==typeof TextEncoder?new TextEncoder:void 0,m=Object(o.a)("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/="),E=(n={},m.forEach((function(e,i){return n[e]=i})),n),A=/^(?:[A-Za-z\d+\/]{4})*?(?:[A-Za-z\d+\/]{2}(?:==)?|[A-Za-z\d+\/]{3}=?)?$/,S=String.fromCharCode.bind(String),v="function"==typeof Uint8Array.from?Uint8Array.from.bind(Uint8Array):function(e){var t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:function(e){return e};return new Uint8Array(Array.prototype.slice.call(e,0).map(t))},H=function(e){return e.replace(/[+\/]/g,(function(e){return"+"==e?"-":"_"})).replace(/=+$/m,"")},C=function(s){return s.replace(/[^A-Za-z0-9\+\/]/g,"")},_=function(e){for(var t,r,n,o,c="",d=e.length%3,i=0;i<e.length;){if((r=e.charCodeAt(i++))>255||(n=e.charCodeAt(i++))>255||(o=e.charCodeAt(i++))>255)throw new TypeError("invalid character found");c+=m[(t=r<<16|n<<8|o)>>18&63]+m[t>>12&63]+m[t>>6&63]+m[63&t]}return d?c.slice(0,d-3)+"===".substring(d):c},P=h?function(e){return btoa(e)}:f?function(e){return Buffer.from(e,"binary").toString("base64")}:_,K=f?function(e){return Buffer.from(e).toString("base64")}:function(e){for(var t=[],i=0,r=e.length;i<r;i+=4096)t.push(S.apply(null,e.subarray(i,i+4096)));return P(t.join(""))},k=function(e){var t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return t?H(K(e)):K(e)},W=function(e){if(e.length<2)return(t=e.charCodeAt(0))<128?e:t<2048?S(192|t>>>6)+S(128|63&t):S(224|t>>>12&15)+S(128|t>>>6&63)+S(128|63&t);var t=65536+1024*(e.charCodeAt(0)-55296)+(e.charCodeAt(1)-56320);return S(240|t>>>18&7)+S(128|t>>>12&63)+S(128|t>>>6&63)+S(128|63&t)},J=/[\uD800-\uDBFF][\uDC00-\uDFFFF]|[^\x00-\x7F]/g,T=function(u){return u.replace(J,W)},U=f?function(s){return Buffer.from(s,"utf8").toString("base64")}:w?function(s){return K(w.encode(s))}:function(s){return P(T(s))},R=function(e){var t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return t?H(U(e)):U(e)},O=function(e){return R(e,!0)},x=/[\xC0-\xDF][\x80-\xBF]|[\xE0-\xEF][\x80-\xBF]{2}|[\xF0-\xF7][\x80-\xBF]{3}/g,D=function(e){switch(e.length){case 4:var t=((7&e.charCodeAt(0))<<18|(63&e.charCodeAt(1))<<12|(63&e.charCodeAt(2))<<6|63&e.charCodeAt(3))-65536;return S(55296+(t>>>10))+S(56320+(1023&t));case 3:return S((15&e.charCodeAt(0))<<12|(63&e.charCodeAt(1))<<6|63&e.charCodeAt(2));default:return S((31&e.charCodeAt(0))<<6|63&e.charCodeAt(1))}},I=function(b){return b.replace(x,D)}
2,M=function(e){if(e=e.replace(/\s+/g,""),!A.test(e))throw new TypeError("malformed base64.");e+="==".slice(2-(3&e.length));for(var t,r,n,o="",i=0;i<e.length;)t=E[e.charAt(i++)]<<18|E[e.charAt(i++)]<<12|(r=E[e.charAt(i++)])<<6|(n=E[e.charAt(i++)]),o+=64===r?S(t>>16&255):64===n?S(t>>16&255,t>>8&255):S(t>>16&255,t>>8&255,255&t);return o},j=l?function(e){return atob(C(e))}:f?function(e){return Buffer.from(e,"base64").toString("binary")}:M,N=f?function(a){return v(Buffer.from(a,"base64"))}:function(a){return v(j(a),(function(e){return e.charCodeAt(0)}))},B=function(a){return N(L(a))},$=f?function(a){return Buffer.from(a,"base64").toString("utf8")}:y?function(a){return y.decode(N(a))}:function(a){return I(j(a))},L=function(a){return C(a.replace(/[-_]/g,(function(e){return"-"==e?"+":"/"})))},G=function(e){return $(L(e))},F=function(e){if("string"!=typeof e)return!1;var s=e.replace(/\s+/g,"").replace(/=+$/,"");return!/[^\s0-9a-zA-Z\+/]/.test(s)||!/[^\s0-9a-zA-Z\-_]/.test(s)},z=function(e){return{value:e,enumerable:!1,writable:!0,configurable:!0}},V=function(){var e=function(e,body){return Object.defineProperty(String.prototype,e,z(body))};e("fromBase64",(function(){return G(this)})),e("toBase64",(function(e){return R(this,e)})),e("toBase64URI",(function(){return R(this,!0)})),e("toBase64URL",(function(){return R(this,!0)})),e("toUint8Array",(function(){return B(this)}))},X=function(){var e=function(e,body){return Object.defineProperty(Uint8Array.prototype,e,z(body))};e("toBase64",(function(e){return k(this,e)})),e("toBase64URI",(function(){return k(this,!0)})),e("toBase64URL",(function(){return k(this,!0)}))},Y=function(){V(),X()},Z={version:c,VERSION:d,atob:j,atobPolyfill:M,btoa:P,btoaPolyfill:_,fromBase64:G,toBase64:R,encode:R,encodeURI:O,encodeURL:O,utob:T,btou:I,decode:G,isValid:F,fromUint8Array:k,toUint8Array:B,extendString:V,extendUint8Array:X,extendBuiltins:Y}},176:function(e,t,r){(function(e,n){var o;(function(){var c=r(2092),d={function:!0,object:!0},l=d[typeof t]&&t&&!t.nodeType&&t,h=d[typeof window]&&window||this,f=l&&d[typeof e]&&e&&!e.nodeType&&"object"==typeof n&&n;function y(e,t){e||(e=h.Object()),t||(t=h.Object());var r=e.Number||h.Number,n=e.String||h.String,o=e.Object||h.Object,c=e.Date||h.Date,l=e.SyntaxError||h.SyntaxError,f=e.TypeError||h.TypeError,w=e.Math||h.Math,m=e.JSON||h.JSON;"object"==typeof m&&m&&(t.stringify=m.stringify,t.parse=m.parse);var E,A=o.prototype,S=A.toString,v=A.hasOwnProperty;function H(e,t){try{e()}catch(e){t&&t()}}var C=new c(-0xc782b5b800cec);function _(e){if(null!=_[e])return _[e];var o;if("bug-string-char-index"==e)o="a"!="a"[0];else if("json"==e)o=_("json-stringify")&&_("date-serialization")&&_("json-parse");else if("date-serialization"==e){if(o=_("json-stringify")&&C){var d=t.stringify;H((function(){o='"-271821-04-20T00:00:00.000Z"'==d(new c(-864e13))&&'"+275760-09-13T00:00:00.000Z"'==d(new c(864e13))&&'"-000001-01-01T00:00:00.000Z"'==d(new c(-621987552e5))&&'"1969-12-31T23:59:59.999Z"'==d(new c(-1))}))}}else{var l,h='{"a":[1,true,false,null,"\\u0000\\b\\n\\f\\r\\t"]}';if("json-stringify"==e){var f="function"==typeof(d=t.stringify);f&&((l=function(){return 1}).toJSON=l,H((function(){f="0"===d(0)&&"0"===d(new r)&&'""'==d(new n)&&d(S)===E&&d(E)===E&&d()===E&&"1"===d(l)&&"[1]"==d([l])&&"[null]"==d([E])&&"null"==d(null)&&"[null,null,null]"==d([E,S,null])&&d({a:[l,!0,!1,null,"\0\b\n\f\r\t"]})==h&&"1"===d(null,l)&&"[\n 1,\n 2\n]"==d([1,2],null,1)}),(function(){f=!1}))),o=f}if("json-parse"==e){var y,w=t.parse;"function"==typeof w&&H((function(){0!==w("0")||w(!1)||(l=w(h),(y=5==l.a.length&&1===l.a[0])&&(H((function(){y=!w('"\t"')})),y&&H((function(){y=1!==w("01")})),y&&H((function(){y=1!==w("1.")}))))}),(function(){y=!1})),o=y}}return _[e]=!!o}if(H((function(){C=-109252==C.getUTCFullYear()&&0===C.getUTCMonth()&&1===C.getUTCDate()&&10==C.getUTCHours()&&37==C.getUTCMinutes()&&6==C.getUTCSeconds()&&708==C.getUTCMilliseconds()})),_["bug-string-char-index"]=_["date-serialization"]=_.json=_["json-stringify"]=_["json-parse"]=null,!_("json")){var P="[object Function]",K="[object Number]",k="[object String]",W="[object Array]",J=_("bug-string-char-index"),T=function(object,e){var t,r,n,o=0;for(n in(t=function(){this.valueOf=0}).prototype.valueOf=0,r=new t)v.call(r,n)&&o++;return t=r=null,o?T=function(object,e){var t,r,n=S.call(object)==P;for(t in object)n&&"prototype"==t||!v.call(object,t)||(r="constructor"===t)||e(t);(r||v.call(object,t="constructor"))&&e(t)}
2:(r=["valueOf","toString","toLocaleString","propertyIsEnumerable","isPrototypeOf","hasOwnProperty","constructor"],T=function(object,e){var t,n,o=S.call(object)==P,c=!o&&"function"!=typeof object.constructor&&d[typeof object.hasOwnProperty]&&object.hasOwnProperty||v;for(t in object)o&&"prototype"==t||!c.call(object,t)||e(t);for(n=r.length;t=r[--n];)c.call(object,t)&&e(t)}),T(object,e)};if(!_("json-stringify")&&!_("date-serialization")){var U={92:"\\\\",34:'\\"',8:"\\b",12:"\\f",10:"\\n",13:"\\r",9:"\\t"},R=function(e,t){return("000000"+(t||0)).slice(-e)},O=function(e){var t,r,n,o,time,c,d,l,h;if(C)t=function(e){r=e.getUTCFullYear(),n=e.getUTCMonth(),o=e.getUTCDate(),c=e.getUTCHours(),d=e.getUTCMinutes(),l=e.getUTCSeconds(),h=e.getUTCMilliseconds()};else{var f=w.floor,y=[0,31,59,90,120,151,181,212,243,273,304,334],m=function(e,t){return y[t]+365*(e-1970)+f((e-1969+(t=+(t>1)))/4)-f((e-1901+t)/100)+f((e-1601+t)/400)};t=function(e){for(o=f(e/864e5),r=f(o/365.2425)+1970-1;m(r+1,0)<=o;r++);for(n=f((o-m(r,0))/30.42);m(r,n+1)<=o;n++);o=1+o-m(r,n),c=f((time=(e%864e5+864e5)%864e5)/36e5)%24,d=f(time/6e4)%60,l=f(time/1e3)%60,h=time%1e3}}return O=function(e){return e>-1/0&&e<1/0?(t(e),e=(r<=0||r>=1e4?(r<0?"-":"+")+R(6,r<0?-r:r):R(4,r))+"-"+R(2,n+1)+"-"+R(2,o)+"T"+R(2,c)+":"+R(2,d)+":"+R(2,l)+"."+R(3,h)+"Z",r=n=o=c=d=l=h=null):e=null,e},O(e)};if(_("json-stringify")&&!_("date-serialization")){function x(e){return O(this)}var D=t.stringify;t.stringify=function(source,filter,e){var t=c.prototype.toJSON;c.prototype.toJSON=x;var r=D(source,filter,e);return c.prototype.toJSON=t,r}}else{var I=function(e){var t=e.charCodeAt(0),r=U[t];return r||"\\u00"+R(2,t.toString(16))},M=/[\x00-\x1f\x22\x5c]/g,j=function(e){return M.lastIndex=0,'"'+(M.test(e)?e.replace(M,I):e)+'"'},N=function(e,object,t,r,n,o,d){var l,h,y,w,element,m,A,v,C;if(H((function(){l=object[e]})),"object"==typeof l&&l&&(l.getUTCFullYear&&"[object Date]"==S.call(l)&&l.toJSON===c.prototype.toJSON?l=O(l):"function"==typeof l.toJSON&&(l=l.toJSON(e))),t&&(l=t.call(object,e,l)),l==E)return l===E?l:"null";switch("object"==(h=typeof l)&&(y=S.call(l)),y||h){case"boolean":case"[object Boolean]":return""+l;case"number":case K:return l>-1/0&&l<1/0?""+l:"null";case"string":case k:return j(""+l)}if("object"==typeof l){for(A=d.length;A--;)if(d[A]===l)throw f();if(d.push(l),w=[],v=o,o+=n,y==W){for(m=0,A=l.length;m<A;m++)element=N(m,l,t,r,n,o,d),w.push(element===E?"null":element);C=w.length?n?"[\n"+o+w.join(",\n"+o)+"\n"+v+"]":"["+w.join(",")+"]":"[]"}else T(r||l,(function(e){var element=N(e,l,t,r,n,o,d);element!==E&&w.push(j(e)+":"+(n?" ":"")+element)})),C=w.length?n?"{\n"+o+w.join(",\n"+o)+"\n"+v+"}":"{"+w.join(",")+"}":"{}";return d.pop(),C}};t.stringify=function(source,filter,e){var t,r,n,o;if(d[typeof filter]&&filter)if((o=S.call(filter))==P)r=filter;else if(o==W){n={};for(var c,l=0,h=filter.length;l<h;)c=filter[l++],"[object String]"!=(o=S.call(c))&&"[object Number]"!=o||(n[c]=1)}if(e)if((o=S.call(e))==K){if((e-=e%1)>0)for(e>10&&(e=10),t="";t.length<e;)t+=" "}else o==k&&(t=e.length<=10?e:e.slice(0,10));return N("",((c={})[""]=source,c),r,n,t,"",[])}}}if(!_("json-parse")){var B,$,L=n.fromCharCode,G={92:"\\",34:'"',47:"/",98:"\b",116:"\t",110:"\n",102:"\f",114:"\r"},F=function(){throw B=$=null,l()},z=function(){for(var e,t,r,n,o,source=$,c=source.length;B<c;)switch(o=source.charCodeAt(B)){case 9:case 10:case 13:case 32:B++;break;case 123:case 125:case 91:case 93:case 58:case 44:return e=J?source.charAt(B):source[B],B++,e;case 34:for(e="@",B++;B<c;)if((o=source.charCodeAt(B))<32)F();else if(92==o)switch(o=source.charCodeAt(++B)){case 92:case 34:case 47:case 98:case 116:case 110:case 102:case 114:e+=G[o],B++;break;case 117:for(t=++B,r=B+4;B<r;B++)(o=source.charCodeAt(B))>=48&&o<=57||o>=97&&o<=102||o>=65&&o<=70||F();e+=L("0x"+source.slice(t,B));break;default:F()}else{if(34==o)break;for(o=source.charCodeAt(B),t=B;o>=32&&92!=o&&34!=o;)o=source.charCodeAt(++B);e+=source.slice(t,B)}if(34==source.charCodeAt(B))return B++,e;F();default:if(t=B,45==o&&(n=!0,o=source.charCodeAt(++B)),o>=48&&o<=57){for(48==o&&((o=source.charCodeAt(B+1))>=48&&o<=57)&&F(),n=!1;B<c&&((o=source.charCodeAt(B))>=48&&o<=57);B++);if(46==source.charCodeAt(B)){for(r=++B;r<c&&!((o=source.charCodeAt(r))<48||o>57);r++);r==B&&F(),B=r}if(101==(o=source.charCodeAt(B))||69==o){for(43!=(o=source.charCodeAt(++B))&&45!=o||B++,r=B;r<c&&!((o=source.charCodeAt(r))<48||o>57);r++);r==B&&F(),B=r}return+source.slice(t,B)}n&&F();var d=source.slice(B,B+4);if("true"==d)return B+=4,!0;if("fals"==d&&101==source.charCodeAt(B+4))return B+=5,!1;if("null"==d)return B+=4,null;F()}return"$"},V=function(e){var t,r;if("$"==e&&F(),"string"==typeof e){if("@"==(J?e.charAt(0):e[0]))return e.slice(1);if("["==e){for(t=[];"]"!=(e=z());)r?","==e?"]"==(e=z())&&F():F():r=!0,","==e&&F(),t.push(V(e));return t}if("{"==e){for(t={};"}"!=(e=z());)r?","==e?"}"==(e=z())&&F():F():r=!0,","!=e&&"string"==typeof e&&"@"==(J?e.charAt(0):e[0])&&":"==z()||F(),t[e.slice(1)]=V(z());return t}F()}return e},X=function(source,e,t){var element=Y(source,e,t);element===E?delete source[e]:source[e]=element},Y=function(source,e,t){var r,n=source[e];if("object"==typeof n&&n)if(S.call(n)==W)for(r=n.length;r--;)X(S,T,n);else T(n,(function(e){X(n,e,t)}));return t.call(source,e,n)};t.parse=function(source,e){var t,r;return B=0,$=""+source,t=V(z()),"$"!=z()&&F(),B=$=null,e&&S.call(e)==P?Y(((r={})[""]=t,r),"",e):t}}}return t.runInContext=y,t}if(!f||f.global!==f&&f.window!==f&&f.self!==f||(h=f),l&&!c)y(h,l);else{var w=h.JSON,m=h.JSON3,E=!1,A=y(h,h.JSON3={noConflict:function(){return E||(E=!0,h.JSON=w,h.JSON3=m,w=m=null),A}});h.JSON={parse:A.parse,stringify:A.stringify}}c&&(void 0===(o=function(){return A}.call(t,r,t,e))||(e.exports=o))}).call(this)}).call(this,r(163)(e),r(30))},2047:function(e,t){e.exports=function(data,e,t,r){var n=new Blob(void 0!==r?[r,data]:[data],{type:t||"application/octet-stream"});if(void 0!==window.navigator.msSaveBlob)window.navigator.msSaveBlob(n,e);else{var o=window.URL&&window.URL.createObjectURL?window.URL.createObjectURL(n):window.webkitURL.createObjectURL(n),c=document.createElement("a");c.style.display="none",c.href=o,c.setAttribute("download",e),void 0===c.download&&c.setAttribute("target","_blank"),document.body.appendChild(c),c.click(),setTimeout((function(){document.body.removeChild(c),window.URL.revokeObjectURL(o)}),200)}}},2158:function(e,t){e.exports=function(e){if(!e)return!1;var t=r.call(e);return"[object Function]"===t||"function"==typeof e&&"[object RegExp]"!==t||"undefined"!=typeof window&&(e===window.setTimeout||e===window.alert||e===window.confirm||e===window.prompt)};var r=Object.prototype.toString},2177:function(e,t,r){"use strict";r.r(t),r.d(t,"compactDecrypt",(function(){return Le})),r.d(t,"flattenedDecrypt",(function(){return $e})),r.d(t,"generalDecrypt",(function(){return Ge})),r.d(t,"GeneralEncrypt",(function(){return et})),r.d(t,"compactVerify",(function(){return ot})),r.d(t,"flattenedVerify",(function(){return it})),r.d(t,"generalVerify",(function(){return st})),r.d(t,"jwtVerify",(function(){return yt})),r.d(t,"jwtDecrypt",(function(){return wt})),r.d(t,"CompactEncrypt",(function(){return gt})),r.d(t,"FlattenedEncrypt",(function(){return qe})),r.d(t,"CompactSign",(function(){return At})),r.d(t,"FlattenedSign",(function(){return Et})),r.d(t,"GeneralSign",(function(){return vt})),r.d(t,"SignJWT",(function(){return Ht})),r.d(t,"EncryptJWT",(function(){return Ct})),r.d(t,"calculateJwkThumbprint",(function(){return Pt})),r.d(t,"calculateJwkThumbprintUri",(function(){return Kt})),r.d(t,"EmbeddedJWK",(function(){return kt})),r.d(t,"createLocalJWKSet",(function(){return Ut})),r.d(t,"createRemoteJWKSet",(function(){return xt})),r.d(t,"UnsecuredJWT",(function(){return Dt})),r.d(t,"exportPKCS8",(function(){return Ve})),r.d(t,"exportSPKI",(function(){return ze})),r.d(t,"exportJWK",(function(){return Xe})),r.d(t,"importSPKI",(function(){return Re})),r.d(t,"importPKCS8",(function(){return xe})),r.d(t,"importX509",(function(){return Oe})),r.d(t,"importJWK",(function(){return De})),r.d(t,"decodeProtectedHeader",(function(){return jt})),r.d(t,"decodeJwt",(function(){return Nt})),r.d(t,"errors",(function(){return n})),r.d(t,"generateKeyPair",(function(){return $t})),r.d(t,"generateSecret",(function(){return Lt})),r.d(t,"base64url",(function(){return o}
2));var n={};r.r(n),r.d(n,"JOSEError",(function(){return P})),r.d(n,"JWTClaimValidationFailed",(function(){return K})),r.d(n,"JWTExpired",(function(){return k})),r.d(n,"JOSEAlgNotAllowed",(function(){return W})),r.d(n,"JOSENotSupported",(function(){return J})),r.d(n,"JWEDecryptionFailed",(function(){return T})),r.d(n,"JWEInvalid",(function(){return U})),r.d(n,"JWSInvalid",(function(){return R})),r.d(n,"JWTInvalid",(function(){return O})),r.d(n,"JWKInvalid",(function(){return x})),r.d(n,"JWKSInvalid",(function(){return D})),r.d(n,"JWKSNoMatchingKey",(function(){return I})),r.d(n,"JWKSMultipleMatchingKeys",(function(){return M})),r.d(n,"JWKSTimeout",(function(){return j})),r.d(n,"JWSSignatureVerificationFailed",(function(){return N}));var o={};r.r(o),r.d(o,"encode",(function(){return It})),r.d(o,"decode",(function(){return Mt}));var c=crypto;const d=e=>e instanceof CryptoKey;var l=async(e,data)=>{const t=`SHA-${e.slice(-3)}`;return new Uint8Array(await c.subtle.digest(t,data))};const h=new TextEncoder,f=new TextDecoder,y=2**32;function w(...e){const t=e.reduce(((e,{length:t})=>e+t),0),r=new Uint8Array(t);let i=0;return e.forEach((e=>{r.set(e,i),i+=e.length})),r}function m(e,t,r){if(t<0||t>=y)throw new RangeError(`value must be >= 0 and <= 4294967295. Received ${t}`);e.set([t>>>24,t>>>16,t>>>8,255&t],r)}function E(e){const t=Math.floor(e/y),r=e%y,n=new Uint8Array(8);return m(n,t,0),m(n,r,4),n}function A(e){const t=new Uint8Array(4);return m(t,e),t}function S(input){return w(A(input.length),input)}const v=input=>{let e=input;"string"==typeof e&&(e=h.encode(e));const t=[];for(let i=0;i<e.length;i+=32768)t.push(String.fromCharCode.apply(null,e.subarray(i,i+32768)));return btoa(t.join(""))},H=input=>v(input).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_"),C=e=>{const t=atob(e),r=new Uint8Array(t.length);for(let i=0;i<t.length;i++)r[i]=t.charCodeAt(i);return r},_=input=>{let e=input;e instanceof Uint8Array&&(e=f.decode(e)),e=e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"");try{return C(e)}catch(e){throw new TypeError("The input to be decoded is not correctly encoded.")}};class P extends Error{constructor(e){var t;super(e),this.code="ERR_JOSE_GENERIC",this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}static get code(){return"ERR_JOSE_GENERIC"}}class K extends P{constructor(e,t="unspecified",r="unspecified"){super(e),this.code="ERR_JWT_CLAIM_VALIDATION_FAILED",this.claim=t,this.reason=r}static get code(){return"ERR_JWT_CLAIM_VALIDATION_FAILED"}}class k extends P{constructor(e,t="unspecified",r="unspecified"){super(e),this.code="ERR_JWT_EXPIRED",this.claim=t,this.reason=r}static get code(){return"ERR_JWT_EXPIRED"}}class W extends P{constructor(){super(...arguments),this.code="ERR_JOSE_ALG_NOT_ALLOWED"}static get code(){return"ERR_JOSE_ALG_NOT_ALLOWED"}}class J extends P{constructor(){super(...arguments),this.code="ERR_JOSE_NOT_SUPPORTED"}static get code(){return"ERR_JOSE_NOT_SUPPORTED"}}class T extends P{constructor(){super(...arguments),this.code="ERR_JWE_DECRYPTION_FAILED",this.message="decryption operation failed"}static get code(){return"ERR_JWE_DECRYPTION_FAILED"}}class U extends P{constructor(){super(...arguments),this.code="ERR_JWE_INVALID"}static get code(){return"ERR_JWE_INVALID"}}class R extends P{constructor(){super(...arguments),this.code="ERR_JWS_INVALID"}static get code(){return"ERR_JWS_INVALID"}}class O extends P{constructor(){super(...arguments),this.code="ERR_JWT_INVALID"}static get code(){return"ERR_JWT_INVALID"}}class x extends P{constructor(){super(...arguments),this.code="ERR_JWK_INVALID"}static get code(){return"ERR_JWK_INVALID"}}class D extends P{constructor(){super(...arguments),this.code="ERR_JWKS_INVALID"}static get code(){return"ERR_JWKS_INVALID"}}class I extends P{constructor(){super(...arguments),this.code="ERR_JWKS_NO_MATCHING_KEY",this.message="no applicable key found in the JSON Web Key Set"}static get code(){return"ERR_JWKS_NO_MATCHING_KEY"}}class M extends P{constructor(){super(...arguments),this.code="ERR_JWKS_MULTIPLE_MATCHING_KEYS",this.message="multiple matching keys found in the JSON Web Key Set"}static get code(){return"ERR_JWKS_MULTIPLE_MATCHING_KEYS"}}class j extends P{constructor(){super(...arguments),this.code="ERR_JWKS_TIMEOUT",this.message="request timed out"}static get code(){return"ERR_JWKS_TIMEOUT"}}class N extends P{constructor(){super(...arguments),this.code="ERR_JWS_SIGNATURE_VERIFICATION_FAILED",this.message="signature verification failed"}static get code(){return"ERR_JWS_SIGNATURE_VERIFICATION_FAILED"}}var B=c.getRandomValues.bind(c);
2function $(e){switch(e){case"A128GCM":case"A128GCMKW":case"A192GCM":case"A192GCMKW":case"A256GCM":case"A256GCMKW":return 96;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return 128;default:throw new J(`Unsupported JWE Algorithm: ${e}`)}}var L=e=>B(new Uint8Array($(e)>>3));var G=(e,t)=>{if(t.length<<3!==$(e))throw new U("Invalid Initialization Vector length")};var F=(e,t)=>{const r=e.byteLength<<3;if(r!==t)throw new U(`Invalid Content Encryption Key length. Expected ${t} bits, got ${r} bits`)};var z=(a,b)=>{if(!(a instanceof Uint8Array))throw new TypeError("First argument must be a buffer");if(!(b instanceof Uint8Array))throw new TypeError("Second argument must be a buffer");if(a.length!==b.length)throw new TypeError("Input buffers must have the same length");const e=a.length;let t=0,i=-1;for(;++i<e;)t|=a[i]^b[i];return 0===t};function V(){return"undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime}function X(e,t="algorithm.name"){return new TypeError(`CryptoKey does not support this operation, its ${t} must be ${e}`)}function Y(e,t){return e.name===t}function Z(e){return parseInt(e.name.slice(4),10)}function Q(e,t){if(t.length&&!t.some((t=>e.usages.includes(t)))){let e="CryptoKey does not support this operation, its usages must include ";if(t.length>2){const r=t.pop();e+=`one of ${t.join(", ")}, or ${r}.`}else 2===t.length?e+=`one of ${t[0]} or ${t[1]}.`:e+=`${t[0]}.`;throw new TypeError(e)}}function ee(e,t,...r){switch(t){case"HS256":case"HS384":case"HS512":{if(!Y(e.algorithm,"HMAC"))throw X("HMAC");const r=parseInt(t.slice(2),10);if(Z(e.algorithm.hash)!==r)throw X(`SHA-${r}`,"algorithm.hash");break}case"RS256":case"RS384":case"RS512":{if(!Y(e.algorithm,"RSASSA-PKCS1-v1_5"))throw X("RSASSA-PKCS1-v1_5");const r=parseInt(t.slice(2),10);if(Z(e.algorithm.hash)!==r)throw X(`SHA-${r}`,"algorithm.hash");break}
2case"PS256":case"PS384":case"PS512":{if(!Y(e.algorithm,"RSA-PSS"))throw X("RSA-PSS");const r=parseInt(t.slice(2),10);if(Z(e.algorithm.hash)!==r)throw X(`SHA-${r}`,"algorithm.hash");break}case V()&&"EdDSA":if(!Y(e.algorithm,"NODE-ED25519"))throw X("NODE-ED25519");break;case"EdDSA":if("Ed25519"!==e.algorithm.name&&"Ed448"!==e.algorithm.name)throw X("Ed25519 or Ed448");break;case"ES256":case"ES384":case"ES512":{if(!Y(e.algorithm,"ECDSA"))throw X("ECDSA");const r=function(e){switch(e){case"ES256":return"P-256";case"ES384":return"P-384";case"ES512":return"P-521";default:throw new Error("unreachable")}}(t);if(e.algorithm.namedCurve!==r)throw X(r,"algorithm.namedCurve");break}default:throw new TypeError("CryptoKey does not support this operation")}Q(e,r)}function te(e,t,...r){switch(t){case"A128GCM":case"A192GCM":case"A256GCM":{if(!Y(e.algorithm,"AES-GCM"))throw X("AES-GCM");const r=parseInt(t.slice(1,4),10);if(e.algorithm.length!==r)throw X(r,"algorithm.length");break}case"A128KW":case"A192KW":case"A256KW":{if(!Y(e.algorithm,"AES-KW"))throw X("AES-KW");const r=parseInt(t.slice(1,4),10);if(e.algorithm.length!==r)throw X(r,"algorithm.length");break}case"ECDH":switch(e.algorithm.name){case"ECDH":case"X25519":case"X448":break;default:throw X("ECDH, X25519, or X448")}break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":if(!Y(e.algorithm,"PBKDF2"))throw X("PBKDF2");break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":{if(!Y(e.algorithm,"RSA-OAEP"))throw X("RSA-OAEP");const r=parseInt(t.slice(9),10)||1;if(Z(e.algorithm.hash)!==r)throw X(`SHA-${r}`,"algorithm.hash");break}default:throw new TypeError("CryptoKey does not support this operation")}Q(e,r)}function re(e,t,...r){if(r.length>2){const t=r.pop();e+=`one of type ${r.join(", ")}, or ${t}.`}else 2===r.length?e+=`one of type ${r[0]} or ${r[1]}.`:e+=`of type ${r[0]}.`;return null==t?e+=` Received ${t}`:"function"==typeof t&&t.name?e+=` Received function ${t.name}`:"object"==typeof t&&null!=t&&t.constructor&&t.constructor.name&&(e+=` Received an instance of ${t.constructor.name}`),e}var ne=(e,...t)=>re("Key must be ",e,...t);function ae(e,t,...r){return re(`Key for the ${e} algorithm must be `,t,...r)}var ie=e=>d(e);const oe=["CryptoKey"];var se=async(e,t,r,n,o,l)=>{if(!(d(t)||t instanceof Uint8Array))throw new TypeError(ne(t,...oe,"Uint8Array"));switch(G(e,n),e){case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return t instanceof Uint8Array&&F(t,parseInt(e.slice(-3),10)),async function(e,t,r,n,o,d){if(!(t instanceof Uint8Array))throw new TypeError(ne(t,"Uint8Array"));const l=parseInt(e.slice(1,4),10),h=await c.subtle.importKey("raw",t.subarray(l>>3),"AES-CBC",!1,["decrypt"]),f=await c.subtle.importKey("raw",t.subarray(0,l>>3),{hash:"SHA-"+(l<<1),name:"HMAC"},!1,["sign"]),y=w(d,n,r,E(d.length<<3)),m=new Uint8Array((await c.subtle.sign("HMAC",f,y)).slice(0,l>>3));let A,S;try{A=z(o,m)}catch(e){}if(!A)throw new T;try{S=new Uint8Array(await c.subtle.decrypt({iv:n,name:"AES-CBC"},h,r))}catch(e){}if(!S)throw new T;return S}(e,t,r,n,o,l);case"A128GCM":case"A192GCM":case"A256GCM":return t instanceof Uint8Array&&F(t,parseInt(e.slice(1,4),10)),async function(e,t,r,n,o,d){let l;t instanceof Uint8Array?l=await c.subtle.importKey("raw",t,"AES-GCM",!1,["decrypt"]):(te(t,e,"decrypt"),l=t);try{return new Uint8Array(await c.subtle.decrypt({additionalData:d,iv:n,name:"AES-GCM",tagLength:128},l,w(r,o)))}catch(e){throw new T}}(e,t,r,n,o,l);default:throw new J("Unsupported JWE Content Encryption Algorithm")}};const ce=async()=>{throw new J('JWE "zip" (Compression Algorithm) Header Parameter is not supported by your javascript runtime. You need to use the `inflateRaw` decrypt option to provide Inflate Raw implementation.')},de=async()=>{throw new J('JWE "zip" (Compression Algorithm) Header Parameter is not supported by your javascript runtime. You need to use the `deflateRaw` encrypt option to provide Deflate Raw implementation.')};var ue=(...e)=>{const t=e.filter(Boolean);if(0===t.length||1===t.length)return!0;let r;for(const header of t){const e=Object.keys(header);if(r&&0!==r.size)for(const t of e){if(r.has(t))return!1;r.add(t)}else r=new Set(e)}return!0};function pe(input){if("object"!=typeof(e=input)||null===e||"[object Object]"!==Object.prototype.toString.call(input))return!1;var e;if(null===Object.getPrototypeOf(input))return!0;let t=input;for(;null!==Object.getPrototypeOf(t);)t=Object.getPrototypeOf(t);return Object.getPrototypeOf(input)===t}
2var le=[{hash:"SHA-256",name:"HMAC"},!0,["sign"]];function he(e,t){if(e.algorithm.length!==parseInt(t.slice(1,4),10))throw new TypeError(`Invalid key size for alg: ${t}`)}function fe(e,t,r){if(d(e))return te(e,t,r),e;if(e instanceof Uint8Array)return c.subtle.importKey("raw",e,"AES-KW",!0,[r]);throw new TypeError(ne(e,...oe,"Uint8Array"))}const ye=async(e,t,r)=>{const n=await fe(t,e,"wrapKey");he(n,e);const o=await c.subtle.importKey("raw",r,...le);return new Uint8Array(await c.subtle.wrapKey("raw",o,n,"AES-KW"))},we=async(e,t,r)=>{const n=await fe(t,e,"unwrapKey");he(n,e);const o=await c.subtle.unwrapKey("raw",r,n,"AES-KW",...le);return new Uint8Array(await c.subtle.exportKey("raw",o))};async function ge(e,t,r,n,o=new Uint8Array(0),f=new Uint8Array(0)){if(!d(e))throw new TypeError(ne(e,...oe));if(te(e,"ECDH"),!d(t))throw new TypeError(ne(t,...oe));te(t,"ECDH","deriveBits");const y=w(S(h.encode(r)),S(o),S(f),A(n));let m;m="X25519"===e.algorithm.name?256:"X448"===e.algorithm.name?448:Math.ceil(parseInt(e.algorithm.namedCurve.substr(-3),10)/8)<<3;return async function(e,t,r){const n=Math.ceil((t>>3)/32),o=new Uint8Array(32*n);for(let t=0;t<n;t++){const n=new Uint8Array(4+e.length+r.length);n.set(A(t+1)),n.set(e,4),n.set(r,4+e.length),o.set(await l("sha256",n),32*t)}return o.slice(0,t>>3)}(new Uint8Array(await c.subtle.deriveBits({name:e.algorithm.name,public:e},t,m)),n,y)}function me(e){if(!d(e))throw new TypeError(ne(e,...oe));return["P-256","P-384","P-521"].includes(e.algorithm.namedCurve)||"X25519"===e.algorithm.name||"X448"===e.algorithm.name}async function Ee(e,t,r,n){!function(e){if(!(e instanceof Uint8Array)||e.length<8)throw new U("PBES2 Salt Input must be 8 or more octets")}(e);const o=function(e,t){return w(h.encode(e),new Uint8Array([0]),t)}(t,e),l=parseInt(t.slice(13,16),10),f={hash:`SHA-${t.slice(8,11)}`,iterations:r,name:"PBKDF2",salt:o},y={length:l,name:"AES-KW"},m=await function(e,t){if(e instanceof Uint8Array)return c.subtle.importKey("raw",e,"PBKDF2",!1,["deriveBits"]);if(d(e))return te(e,t,"deriveBits","deriveKey"),e;throw new TypeError(ne(e,...oe,"Uint8Array"))}(n,t);if(m.usages.includes("deriveBits"))return new Uint8Array(await c.subtle.deriveBits(f,m,l));if(m.usages.includes("deriveKey"))return c.subtle.deriveKey(f,m,y,!1,["wrapKey","unwrapKey"]);throw new TypeError('PBKDF2 key "usages" must include "deriveBits" or "deriveKey"')}function Ae(e){switch(e){case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":return"RSA-OAEP";default:throw new J(`alg ${e} is not supported either by JOSE or your javascript runtime`)}}var Se=(e,t)=>{if(e.startsWith("RS")||e.startsWith("PS")){const{modulusLength:r}=t.algorithm;if("number"!=typeof r||r<2048)throw new TypeError(`${e} requires key modulusLength to be 2048 bits or larger`)}};function ve(e){switch(e){case"A128GCM":return 128;case"A192GCM":return 192;case"A256GCM":case"A128CBC-HS256":return 256;case"A192CBC-HS384":return 384;case"A256CBC-HS512":return 512;default:throw new J(`Unsupported JWE Algorithm: ${e}`)}}var be=e=>B(new Uint8Array(ve(e)>>3)),He=(e,t)=>`-----BEGIN ${t}-----\n${(e.match(/.{1,64}/g)||[]).join("\n")}\n-----END ${t}-----`;const Ce=async(e,t,r)=>{if(!d(r))throw new TypeError(ne(r,...oe));if(!r.extractable)throw new TypeError("CryptoKey is not extractable");if(r.type!==e)throw new TypeError(`key is not a ${e} key`);return He(v(new Uint8Array(await c.subtle.exportKey(t,r))),`${e.toUpperCase()} KEY`)},_e=(e,t,r=0)=>{0===r&&(t.unshift(t.length),t.unshift(6));let i=e.indexOf(t[0],r);if(-1===i)return!1;const sub=e.subarray(i,i+t.length);return sub.length===t.length&&(sub.every(((e,r)=>e===t[r]))||_e(e,t,i+1))},Pe=e=>{switch(!0){case _e(e,[42,134,72,206,61,3,1,7]):return"P-256";case _e(e,[43,129,4,0,34]):return"P-384";case _e(e,[43,129,4,0,35]):return"P-521";case _e(e,[43,101,110]):return"X25519";case _e(e,[43,101,111]):return"X448";case _e(e,[43,101,112]):return"Ed25519";case _e(e,[43,101,113]):return"Ed448";default:throw new J("Invalid or unsupported EC Key Curve or OKP Key Sub Type")}},Ke=async(e,t,r,n,o)=>{var d;let l,h;const f=new Uint8Array(atob(r.replace(e,"")).split("").map((e=>e.charCodeAt(0)))),y="spki"===t;switch(n){case"PS256":case"PS384":case"PS512":l={name:"RSA-PSS",hash:`SHA-${n.slice(-3)}`},h=y?["verify"]:["sign"];break;case"RS256":case"RS384":case"RS512":l={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${n.slice(-3)}`},h=y?["verify"]:["sign"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":l={name:"RSA-OAEP",hash:`SHA-${parseInt(n.slice(-3),10)||1}`},h=y?["encrypt","wrapKey"]:["decrypt","unwrapKey"];break;case"ES256":l={name:"ECDSA",namedCurve:"P-256"},h=y?["verify"]:["sign"];break;case"ES384":l={name:"ECDSA",namedCurve:"P-384"},h=y?["verify"]:["sign"];break;case"ES512":l={name:"ECDSA",namedCurve:"P-521"},h=y?["verify"]:["sign"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{const e=Pe(f);l=e.startsWith("P-")?{name:"ECDH",namedCurve:e}:{name:e},h=y?[]:["deriveBits"];break}
2case V()&&"EdDSA":{const e=Pe(f).toUpperCase();l={name:`NODE-${e}`,namedCurve:`NODE-${e}`},h=y?["verify"]:["sign"];break}case"EdDSA":l={name:Pe(f)},h=y?["verify"]:["sign"];break;default:throw new J('Invalid or unsupported "alg" (Algorithm) value')}return c.subtle.importKey(t,f,l,null!==(d=null==o?void 0:o.extractable)&&void 0!==d&&d,h)},ke=(e,t,r)=>Ke(/(?:-----(?:BEGIN|END) PUBLIC KEY-----|\s)/g,"spki",e,t,r);var We=async e=>{var t,r;const{algorithm:n,keyUsages:o}=function(e){let t,r;switch(e.kty){case"oct":switch(e.alg){case"HS256":case"HS384":case"HS512":t={name:"HMAC",hash:`SHA-${e.alg.slice(-3)}`},r=["sign","verify"];break;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":throw new J(`${e.alg} keys cannot be imported as CryptoKey instances`);case"A128GCM":case"A192GCM":case"A256GCM":case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":t={name:"AES-GCM"},r=["encrypt","decrypt"];break;case"A128KW":case"A192KW":case"A256KW":t={name:"AES-KW"},r=["wrapKey","unwrapKey"];break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":t={name:"PBKDF2"},r=["deriveBits"];break;default:throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"RSA":switch(e.alg){case"PS256":case"PS384":case"PS512":t={name:"RSA-PSS",hash:`SHA-${e.alg.slice(-3)}`},r=e.d?["sign"]:["verify"];break;case"RS256":case"RS384":case"RS512":t={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${e.alg.slice(-3)}`},r=e.d?["sign"]:["verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":t={name:"RSA-OAEP",hash:`SHA-${parseInt(e.alg.slice(-3),10)||1}`},r=e.d?["decrypt","unwrapKey"]:["encrypt","wrapKey"];break;default:throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"EC":switch(e.alg){case"ES256":t={name:"ECDSA",namedCurve:"P-256"},r=e.d?["sign"]:["verify"];break;case"ES384":t={name:"ECDSA",namedCurve:"P-384"},r=e.d?["sign"]:["verify"];break;case"ES512":t={name:"ECDSA",namedCurve:"P-521"},r=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:"ECDH",namedCurve:e.crv},r=e.d?["deriveBits"]:[];break;default:throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case V()&&"OKP":if("EdDSA"!==e.alg)throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');if("Ed25519"!==e.crv)throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');t={name:"NODE-ED25519",namedCurve:"NODE-ED25519"},r=e.d?["sign"]:["verify"];break;case"OKP":switch(e.alg){case"EdDSA":t={name:e.crv},r=e.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":t={name:e.crv},r=e.d?["deriveBits"]:[];break;default:throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;default:throw new J('Invalid or unsupported JWK "kty" (Key Type) Parameter value')}return{algorithm:t,keyUsages:r}}(e),d=[n,null!==(t=e.ext)&&void 0!==t&&t,null!==(r=e.key_ops)&&void 0!==r?r:o];if("PBKDF2"===n.name)return c.subtle.importKey("raw",_(e.k),...d);const l={...e};return delete l.alg,delete l.use,c.subtle.importKey("jwk",l,...d)};function Je(e){let t=[],r=0;for(;r<e.length;){let n=Te(e.subarray(r));t.push(n),r+=n.byteLength}return t}function Te(e){let t=0,r=31&e[0];if(t++,31===r){for(r=0;e[t]>=128;)r=128*r+e[t]-128,t++;r=128*r+e[t]-128,t++}let n=0;if(e[t]<128)n=e[t],t++;else{if(128===n){for(n=0;0!==e[t+n]||0!==e[t+n+1];){if(n>e.byteLength)throw new TypeError("invalid indefinite form length");n++}const r=t+n+2;return{byteLength:r,contents:e.subarray(t,t+n),raw:e.subarray(0,r)}}{let r=127&e[t];t++,n=0;for(let i=0;i<r;i++)n=256*n+e[t],t++}}const o=t+n;return{byteLength:o,contents:e.subarray(t,o),raw:e.subarray(0,o)}}function Ue(e){const t=e.replace(/(?:-----(?:BEGIN|END) CERTIFICATE-----|\s)/g,""),r=C(t);return He(function(e){const t=Je(Je(Te(e).contents)[0].contents);return v(t[160===t[0].raw[0]?6:5].raw)}(r),"PUBLIC KEY")}async function Re(e,t,r){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PUBLIC KEY-----"))throw new TypeError('"spki" must be SPKI formatted string');return ke(e,t,r)}async function Oe(e,t,r){if("string"!=typeof e||0!==e.indexOf("-----BEGIN CERTIFICATE-----"))throw new TypeError('"x509" must be X.509 formatted string');let n;try{n=Ue(e)}catch(e){throw new TypeError("failed to parse the X.509 certificate",{cause:e})}return ke(n,t,r)}async function xe(e,t,r){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw new TypeError('"pkcs8" must be PKCS#8 formatted string');return((e,t,r)=>
2Ke(/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g,"pkcs8",e,t,r))(e,t,r)}async function De(e,t,r){var n;if(!pe(e))throw new TypeError("JWK must be an object");if(t||(t=e.alg),"string"!=typeof t||!t)throw new TypeError('"alg" argument is required when "jwk.alg" is not present');switch(e.kty){case"oct":if("string"!=typeof e.k||!e.k)throw new TypeError('missing "k" (Key Value) Parameter value');return null!=r||(r=!0!==e.ext),r?We({...e,alg:t,ext:null!==(n=e.ext)&&void 0!==n&&n}):_(e.k);case"RSA":if(void 0!==e.oth)throw new J('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');case"EC":case"OKP":return We({...e,alg:t});default:throw new J('Unsupported "kty" (Key Type) Parameter value')}}var Ie=(e,t,r)=>{e.startsWith("HS")||"dir"===e||e.startsWith("PBES2")||/^A\d{3}(?:GCM)?KW$/.test(e)?((e,t)=>{if(!(t instanceof Uint8Array)){if(!ie(t))throw new TypeError(ae(e,t,...oe,"Uint8Array"));if("secret"!==t.type)throw new TypeError(`${oe.join(" or ")} instances for symmetric algorithms must be of type "secret"`)}})(e,t):((e,t,r)=>{if(!ie(t))throw new TypeError(ae(e,t,...oe));if("secret"===t.type)throw new TypeError(`${oe.join(" or ")} instances for asymmetric algorithms must not be of type "secret"`);if("sign"===r&&"public"===t.type)throw new TypeError(`${oe.join(" or ")} instances for asymmetric algorithm signing must be of type "private"`);if("decrypt"===r&&"public"===t.type)throw new TypeError(`${oe.join(" or ")} instances for asymmetric algorithm decryption must be of type "private"`);if(t.algorithm&&"verify"===r&&"private"===t.type)throw new TypeError(`${oe.join(" or ")} instances for asymmetric algorithm verifying must be of type "public"`);if(t.algorithm&&"encrypt"===r&&"private"===t.type)throw new TypeError(`${oe.join(" or ")} instances for asymmetric algorithm encryption must be of type "public"`)})(e,t,r)};var Me=async(e,t,r,n,o)=>{if(!(d(r)||r instanceof Uint8Array))throw new TypeError(ne(r,...oe,"Uint8Array"));switch(G(e,n),e){case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return r instanceof Uint8Array&&F(r,parseInt(e.slice(-3),10)),async function(e,t,r,n,o){if(!(r instanceof Uint8Array))throw new TypeError(ne(r,"Uint8Array"));const d=parseInt(e.slice(1,4),10),l=await c.subtle.importKey("raw",r.subarray(d>>3),"AES-CBC",!1,["encrypt"]),h=await c.subtle.importKey("raw",r.subarray(0,d>>3),{hash:"SHA-"+(d<<1),name:"HMAC"},!1,["sign"]),f=new Uint8Array(await c.subtle.encrypt({iv:n,name:"AES-CBC"},l,t)),y=w(o,n,f,E(o.length<<3));return{ciphertext:f,tag:new Uint8Array((await c.subtle.sign("HMAC",h,y)).slice(0,d>>3))}}(e,t,r,n,o);case"A128GCM":case"A192GCM":case"A256GCM":return r instanceof Uint8Array&&F(r,parseInt(e.slice(1,4),10)),async function(e,t,r,n,o){let d;r instanceof Uint8Array?d=await c.subtle.importKey("raw",r,"AES-GCM",!1,["encrypt"]):(te(r,e,"encrypt"),d=r);const l=new Uint8Array(await c.subtle.encrypt({additionalData:o,iv:n,name:"AES-GCM",tagLength:128},d,t)),h=l.slice(-16);return{ciphertext:l.slice(0,-16),tag:h}}(e,t,r,n,o);default:throw new J("Unsupported JWE Content Encryption Algorithm")}};var je=async function(e,t,r,n,o){switch(Ie(e,t,"decrypt"),e){case"dir":if(void 0!==r)throw new U("Encountered unexpected JWE Encrypted Key");return t;case"ECDH-ES":if(void 0!==r)throw new U("Encountered unexpected JWE Encrypted Key");case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{if(!pe(n.epk))throw new U('JOSE Header "epk" (Ephemeral Public Key) missing or invalid');if(!me(t))throw new J("ECDH with the provided key is not allowed or not supported by your javascript runtime");const o=await De(n.epk,e);let c,d;if(void 0!==n.apu){if("string"!=typeof n.apu)throw new U('JOSE Header "apu" (Agreement PartyUInfo) invalid');c=_(n.apu)}if(void 0!==n.apv){if("string"!=typeof n.apv)throw new U('JOSE Header "apv" (Agreement PartyVInfo) invalid');d=_(n.apv)}const l=await ge(o,t,"ECDH-ES"===e?n.enc:e,"ECDH-ES"===e?ve(n.enc):parseInt(e.slice(-5,-2),10),c,d);if("ECDH-ES"===e)return l;if(void 0===r)throw new U("JWE Encrypted Key missing");return we(e.slice(-6),l,r)}case"RSA1_5":case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":if(void 0===r)throw new U("JWE Encrypted Key missing");return(async(e,t,r)=>{if(!d(t))throw new TypeError(ne(t,...oe));if(te(t,e,"decrypt","unwrapKey"),Se(e,t),t.usages.includes("decrypt"))return new Uint8Array(await c.subtle.decrypt(Ae(e),t,r));if(t.usages.includes("unwrapKey")){const n=await c.subtle.unwrapKey("raw",r,t,Ae(e),...le);return new Uint8Array(await c.subtle.exportKey("raw",n))}throw new TypeError('RSA-OAEP key "usages" must include "decrypt" or "unwrapKey" for this operation')})(e,t,r);case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":{if(void 0===r)throw new U("JWE Encrypted Key missing");if("number"!=typeof n.p2c)throw new U('JOSE Header "p2c" (PBES2 Count) missing or invalid');const c=(null==o?void 0:o.maxPBES2Count)||1e4;if(n.p2c>c)throw new U('JOSE Header "p2c" (PBES2 Count) out is of acceptable bounds');if("string"!=typeof n.p2s)throw new U('JOSE Header "p2s" (PBES2 Salt) missing or invalid');return(async(e,t,r,n,o)=>{const c=await Ee(o,e,n,t);return we(e.slice(-6),c,r)})(e,t,r,n.p2c,_(n.p2s))}
2case"A128KW":case"A192KW":case"A256KW":if(void 0===r)throw new U("JWE Encrypted Key missing");return we(e,t,r);case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":if(void 0===r)throw new U("JWE Encrypted Key missing");if("string"!=typeof n.iv)throw new U('JOSE Header "iv" (Initialization Vector) missing or invalid');if("string"!=typeof n.tag)throw new U('JOSE Header "tag" (Authentication Tag) missing or invalid');return async function(e,t,r,n,o){const c=e.slice(0,7);return se(c,t,r,n,o,new Uint8Array(0))}(e,t,r,_(n.iv),_(n.tag));default:throw new J('Invalid or unsupported "alg" (JWE Algorithm) header value')}};var Ne=function(e,t,r,n,o){if(void 0!==o.crit&&void 0===n.crit)throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!n||void 0===n.crit)return new Set;if(!Array.isArray(n.crit)||0===n.crit.length||n.crit.some((input=>"string"!=typeof input||0===input.length)))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');let c;c=void 0!==r?new Map([...Object.entries(r),...t.entries()]):t;for(const t of n.crit){if(!c.has(t))throw new J(`Extension Header Parameter "${t}" is not recognized`);if(void 0===o[t])throw new e(`Extension Header Parameter "${t}" is missing`);if(c.get(t)&&void 0===n[t])throw new e(`Extension Header Parameter "${t}" MUST be integrity protected`)}return new Set(n.crit)};var Be=(option,e)=>{if(void 0!==e&&(!Array.isArray(e)||e.some((s=>"string"!=typeof s))))throw new TypeError(`"${option}" option must be an array of strings`);if(e)return new Set(e)};async function $e(e,t,r){var n;if(!pe(e))throw new U("Flattened JWE must be an object");if(void 0===e.protected&&void 0===e.header&&void 0===e.unprotected)throw new U("JOSE Header missing");if("string"!=typeof e.iv)throw new U("JWE Initialization Vector missing or incorrect type");if("string"!=typeof e.ciphertext)throw new U("JWE Ciphertext missing or incorrect type");if("string"!=typeof e.tag)throw new U("JWE Authentication Tag missing or incorrect type");if(void 0!==e.protected&&"string"!=typeof e.protected)throw new U("JWE Protected Header incorrect type");if(void 0!==e.encrypted_key&&"string"!=typeof e.encrypted_key)throw new U("JWE Encrypted Key incorrect type");if(void 0!==e.aad&&"string"!=typeof e.aad)throw new U("JWE AAD incorrect type");if(void 0!==e.header&&!pe(e.header))throw new U("JWE Shared Unprotected Header incorrect type");if(void 0!==e.unprotected&&!pe(e.unprotected))throw new U("JWE Per-Recipient Unprotected Header incorrect type");let o;if(e.protected)try{const t=_(e.protected);o=JSON.parse(f.decode(t))}catch(e){throw new U("JWE Protected Header is invalid")}if(!ue(o,e.header,e.unprotected))throw new U("JWE Protected, JWE Unprotected Header, and JWE Per-Recipient Unprotected Header Parameter names must be disjoint");const c={...o,...e.header,...e.unprotected};if(Ne(U,new Map,null==r?void 0:r.crit,o,c),void 0!==c.zip){if(!o||!o.zip)throw new U('JWE "zip" (Compression Algorithm) Header MUST be integrity protected');if("DEF"!==c.zip)throw new J('Unsupported JWE "zip" (Compression Algorithm) Header Parameter value')}const{alg:d,enc:l}=c;if("string"!=typeof d||!d)throw new U("missing JWE Algorithm (alg) in JWE Header");if("string"!=typeof l||!l)throw new U("missing JWE Encryption Algorithm (enc) in JWE Header");const y=r&&Be("keyManagementAlgorithms",r.keyManagementAlgorithms),m=r&&Be("contentEncryptionAlgorithms",r.contentEncryptionAlgorithms);if(y&&!y.has(d))throw new W('"alg" (Algorithm) Header Parameter not allowed');if(m&&!m.has(l))throw new W('"enc" (Encryption Algorithm) Header Parameter not allowed');let E;void 0!==e.encrypted_key&&(E=_(e.encrypted_key));let A,S=!1;"function"==typeof t&&(t=await t(o,e),S=!0);try{A=await je(d,t,E,c,r)}catch(e){if(e instanceof TypeError||e instanceof U||e instanceof J)throw e;A=be(l)}const v=_(e.iv),H=_(e.tag),C=h.encode(null!==(n=e.protected)&&void 0!==n?n:"");let P;P=void 0!==e.aad?w(C,h.encode("."),h.encode(e.aad)):C;let K=await se(l,A,_(e.ciphertext),v,H,P);"DEF"===c.zip&&(K=await((null==r?void 0:r.inflateRaw)||ce)(K));const k={plaintext:K};return void 0!==e.protected&&(k.protectedHeader=o),void 0!==e.aad&&(k.additionalAuthenticatedData=_(e.aad)),void 0!==e.unprotected&&(k.sharedUnprotectedHeader=e.unprotected),void 0!==e.header&&(k.unprotectedHeader=e.header),S?{...k,key:t}:k}async function Le(e,t,r){if(e instanceof Uint8Array&&(e=f.decode(e)),"string"!=typeof e)throw new U("Compact JWE must be a string or Uint8Array");const{0:n,1:o,2:c,3:d,4:l,length:h}=e.split(".");
2if(5!==h)throw new U("Invalid Compact JWE");const y=await $e({ciphertext:d,iv:c||void 0,protected:n||void 0,tag:l||void 0,encrypted_key:o||void 0},t,r),w={plaintext:y.plaintext,protectedHeader:y.protectedHeader};return"function"==typeof t?{...w,key:y.key}:w}async function Ge(e,t,r){if(!pe(e))throw new U("General JWE must be an object");if(!Array.isArray(e.recipients)||!e.recipients.every(pe))throw new U("JWE Recipients missing or incorrect type");if(!e.recipients.length)throw new U("JWE Recipients has no members");for(const n of e.recipients)try{return await $e({aad:e.aad,ciphertext:e.ciphertext,encrypted_key:n.encrypted_key,header:n.header,iv:e.iv,protected:e.protected,tag:e.tag,unprotected:e.unprotected},t,r)}catch(e){}throw new T}var Fe=async e=>{if(e instanceof Uint8Array)return{kty:"oct",k:H(e)};if(!d(e))throw new TypeError(ne(e,...oe,"Uint8Array"));if(!e.extractable)throw new TypeError("non-extractable CryptoKey cannot be exported as a JWK");const{ext:t,key_ops:r,alg:n,use:use,...o}=await c.subtle.exportKey("jwk",e);return o};async function ze(e){return(e=>Ce("public","spki",e))(e)}async function Ve(e){return(e=>Ce("private","pkcs8",e))(e)}async function Xe(e){return Fe(e)}var Ye=async function(e,t,r,n,o={}){let l,h,f;switch(Ie(e,r,"encrypt"),e){case"dir":f=r;break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{if(!me(r))throw new J("ECDH with the provided key is not allowed or not supported by your javascript runtime");const{apu:y,apv:w}=o;let{epk:m}=o;m||(m=(await async function(e){if(!d(e))throw new TypeError(ne(e,...oe));return c.subtle.generateKey(e.algorithm,!0,["deriveBits"])}(r)).privateKey);const{x:E,y:A,crv:S,kty:v}=await Xe(m),C=await ge(r,m,"ECDH-ES"===e?t:e,"ECDH-ES"===e?ve(t):parseInt(e.slice(-5,-2),10),y,w);if(h={epk:{x:E,crv:S,kty:v}},"EC"===v&&(h.epk.y=A),y&&(h.apu=H(y)),w&&(h.apv=H(w)),"ECDH-ES"===e){f=C;break}f=n||be(t);const _=e.slice(-6);l=await ye(_,C,f);break}case"RSA1_5":case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":f=n||be(t),l=await(async(e,t,r)=>{if(!d(t))throw new TypeError(ne(t,...oe));if(te(t,e,"encrypt","wrapKey"),Se(e,t),t.usages.includes("encrypt"))return new Uint8Array(await c.subtle.encrypt(Ae(e),t,r));if(t.usages.includes("wrapKey")){const n=await c.subtle.importKey("raw",r,...le);return new Uint8Array(await c.subtle.wrapKey("raw",n,t,Ae(e)))}throw new TypeError('RSA-OAEP key "usages" must include "encrypt" or "wrapKey" for this operation')})(e,r,f);break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":{f=n||be(t);const{p2c:c,p2s:d}=o;({encryptedKey:l,...h}=await(async(e,t,r,n=2048,o=B(new Uint8Array(16)))=>{const c=await Ee(o,e,n,t);return{encryptedKey:await ye(e.slice(-6),c,r),p2c:n,p2s:H(o)}})(e,r,f,c,d));break}case"A128KW":case"A192KW":case"A256KW":f=n||be(t),l=await ye(e,r,f);break;case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":{f=n||be(t);const{iv:c}=o;({encryptedKey:l,...h}=await async function(e,t,r,n){const o=e.slice(0,7);n||(n=L(o));const{ciphertext:c,tag:d}=await Me(o,r,t,n,new Uint8Array(0));return{encryptedKey:c,iv:H(n),tag:H(d)}}(e,r,f,c));break}default:throw new J('Invalid or unsupported "alg" (JWE Algorithm) header value')}return{cek:f,encryptedKey:l,parameters:h}};const Ze=Symbol();class qe{constructor(e){if(!(e instanceof Uint8Array))throw new TypeError("plaintext must be an instance of Uint8Array");this._plaintext=e}setKeyManagementParameters(e){if(this._keyManagementParameters)throw new TypeError("setKeyManagementParameters can only be called once");return this._keyManagementParameters=e,this}setProtectedHeader(e){if(this._protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setSharedUnprotectedHeader(e){if(this._sharedUnprotectedHeader)throw new TypeError("setSharedUnprotectedHeader can only be called once");return this._sharedUnprotectedHeader=e,this}setUnprotectedHeader(e){if(this._unprotectedHeader)throw new TypeError("setUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}setAdditionalAuthenticatedData(e){return this._aad=e,this}setContentEncryptionKey(e){if(this._cek)throw new TypeError("setContentEncryptionKey can only be called once");return this._cek=e,this}setInitializationVector(e){if(this._iv)throw new TypeError("setInitializationVector can only be called once");return this._iv=e,this}async encrypt(e,t){if(!this._protectedHeader&&!this._unprotectedHeader&&!this._sharedUnprotectedHeader)throw new U("either setProtectedHeader, setUnprotectedHeader, or sharedUnprotectedHeader must be called before #encrypt()");if(!ue(this._protectedHeader,this._unprotectedHeader,this._sharedUnprotectedHeader))throw new U("JWE Protected, JWE Shared Unprotected and JWE Per-Recipient Header Parameter names must be disjoint");const r={...this._protectedHeader,...this._unprotectedHeader,...this._sharedUnprotectedHeader};if(Ne(U,new Map,null==t?void 0:t.crit,this._protectedHeader,r),void 0!==r.zip){if(!this._protectedHeader||!this._protectedHeader.zip)throw new U('JWE "zip" (Compression Algorithm) Header MUST be integrity protected');if("DEF"!==r.zip)throw new J('Unsupported JWE "zip" (Compression Algorithm) Header Parameter value')}const{alg:n,enc:o}=r;if("string"!=typeof n||!n)throw new U('JWE "alg" (Algorithm) Header Parameter missing or invalid');if("string"!=typeof o||!o)throw new U('JWE "enc" (Encryption Algorithm) Header Parameter missing or invalid');let c,d,l,y,m,E,A;if("dir"===n){if(this._cek)throw new TypeError("setContentEncryptionKey cannot be called when using Direct Encryption")}else if("ECDH-ES"===n&&this._cek)throw new TypeError("setContentEncryptionKey cannot be called when using Direct Key Agreement");{let r;({cek:d,encryptedKey:c,parameters:r}=await Ye(n,o,e,this._cek,this._keyManagementParameters)),r&&(t&&Ze in t?this._unprotectedHeader?this._unprotectedHeader={...this._unprotectedHeader,...r}:this.setUnprotectedHeader(r):this._protectedHeader?this._protectedHeader={...this._protectedHeader,...r}:this.setProtectedHeader(r))}if(this._iv||(this._iv=L(o)),y=this._protectedHeader?h.encode(H(JSON.stringify(this._protectedHeader))):h.encode(""),this._aad?(m=H(this._aad),l=w(y,h.encode("."),h.encode(m))):l=y,"DEF"===r.zip){const e=await((null==t?void 0:t.deflateRaw)||de)(this._plaintext);({ciphertext:E,tag:A}=await Me(o,e,d,this._iv,l))}else({ciphertext:E,tag:A}=await Me(o,this._plaintext,d,this._iv,l));const S={ciphertext:H(E),iv:H(this._iv),tag:H(A)};return c&&(S.encrypted_key=H(c)),m&&(S.aad=m),this._protectedHeader&&(S.protected=f.decode(y)),this._sharedUnprotectedHeader&&(S.unprotected=this._sharedUnprotectedHeader),this._unprotectedHeader&&(S.header=this._unprotectedHeader),S}}class Qe{constructor(e,t,r){this.parent=e,this.key=t,this.options=r}setUnprotectedHeader(e){if(this.unprotectedHeader)throw new TypeError("setUnprotectedHeader can only be called once");return this.unprotectedHeader=e,this}addRecipient(...e){return this.parent.addRecipient(...e)}encrypt(...e){return this.parent.encrypt(...e)}done(){return this.parent}}class et{constructor(e){this._recipients=[],this._plaintext=e}addRecipient(e,t){const r=new Qe(this,e,{crit:null==t?void 0:t.crit});return this._recipients.push(r),r}setProtectedHeader(e){if(this._protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setSharedUnprotectedHeader(e){if(this._unprotectedHeader)throw new TypeError("setSharedUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}setAdditionalAuthenticatedData(e){return this._aad=e,this}async encrypt(e){var t,r,n;if(!this._recipients.length)throw new U("at least one recipient must be added");if(e={deflateRaw:null==e?void 0:e.deflateRaw},1===this._recipients.length){const[t]=this._recipients,r=await new qe(this._plaintext).setAdditionalAuthenticatedData(this._aad).setProtectedHeader(this._protectedHeader).setSharedUnprotectedHeader(this._unprotectedHeader).setUnprotectedHeader(t.unprotectedHeader).encrypt
2(t.key,{...t.options,...e});let n={ciphertext:r.ciphertext,iv:r.iv,recipients:[{}],tag:r.tag};return r.aad&&(n.aad=r.aad),r.protected&&(n.protected=r.protected),r.unprotected&&(n.unprotected=r.unprotected),r.encrypted_key&&(n.recipients[0].encrypted_key=r.encrypted_key),r.header&&(n.recipients[0].header=r.header),n}let o;for(let i=0;i<this._recipients.length;i++){const e=this._recipients[i];if(!ue(this._protectedHeader,this._unprotectedHeader,e.unprotectedHeader))throw new U("JWE Protected, JWE Shared Unprotected and JWE Per-Recipient Header Parameter names must be disjoint");const t={...this._protectedHeader,...this._unprotectedHeader,...e.unprotectedHeader},{alg:r}=t;if("string"!=typeof r||!r)throw new U('JWE "alg" (Algorithm) Header Parameter missing or invalid');if("dir"===r||"ECDH-ES"===r)throw new U('"dir" and "ECDH-ES" alg may only be used with a single recipient');if("string"!=typeof t.enc||!t.enc)throw new U('JWE "enc" (Encryption Algorithm) Header Parameter missing or invalid');if(o){if(o!==t.enc)throw new U('JWE "enc" (Encryption Algorithm) Header Parameter must be the same for all recipients')}else o=t.enc;if(Ne(U,new Map,e.options.crit,this._protectedHeader,t),!(void 0===t.zip||this._protectedHeader&&this._protectedHeader.zip))throw new U('JWE "zip" (Compression Algorithm) Header MUST be integrity protected')}const c=be(o);let d={ciphertext:"",iv:"",recipients:[],tag:""};for(let i=0;i<this._recipients.length;i++){const l=this._recipients[i],h={};d.recipients.push(h);const f={...this._protectedHeader,...this._unprotectedHeader,...l.unprotectedHeader}.alg.startsWith("PBES2")?2048+i:void 0;if(0===i){const t=await new qe(this._plaintext).setAdditionalAuthenticatedData(this._aad).setContentEncryptionKey(c).setProtectedHeader(this._protectedHeader).setSharedUnprotectedHeader(this._unprotectedHeader).setUnprotectedHeader(l.unprotectedHeader).setKeyManagementParameters({p2c:f}).encrypt(l.key,{...l.options,...e,[Ze]:!0});d.ciphertext=t.ciphertext,d.iv=t.iv,d.tag=t.tag,t.aad&&(d.aad=t.aad),t.protected&&(d.protected=t.protected),t.unprotected&&(
2d.unprotected=t.unprotected),h.encrypted_key=t.encrypted_key,t.header&&(h.header=t.header);continue}const{encryptedKey:y,parameters:w}=await Ye((null===(t=l.unprotectedHeader)||void 0===t?void 0:t.alg)||(null===(r=this._protectedHeader)||void 0===r?void 0:r.alg)||(null===(n=this._unprotectedHeader)||void 0===n?void 0:n.alg),o,l.key,c,{p2c:f});h.encrypted_key=H(y),(l.unprotectedHeader||w)&&(h.header={...l.unprotectedHeader,...w})}return d}}function tt(e,t){const r=`SHA-${e.slice(-3)}`;switch(e){case"HS256":case"HS384":case"HS512":return{hash:r,name:"HMAC"};case"PS256":case"PS384":case"PS512":return{hash:r,name:"RSA-PSS",saltLength:e.slice(-3)>>3};case"RS256":case"RS384":case"RS512":return{hash:r,name:"RSASSA-PKCS1-v1_5"};case"ES256":case"ES384":case"ES512":return{hash:r,name:"ECDSA",namedCurve:t.namedCurve};case V()&&"EdDSA":const{namedCurve:n}=t;return{name:n,namedCurve:n};case"EdDSA":return{name:t.name};default:throw new J(`alg ${e} is not supported either by JOSE or your javascript runtime`)}}function nt(e,t,r){if(d(t))return ee(t,e,r),t;if(t instanceof Uint8Array){if(!e.startsWith("HS"))throw new TypeError(ne(t,...oe));return c.subtle.importKey("raw",t,{hash:`SHA-${e.slice(-3)}`,name:"HMAC"},!1,[r])}throw new TypeError(ne(t,...oe,"Uint8Array"))}var at=async(e,t,r,data)=>{const n=await nt(e,t,"verify");Se(e,n);const o=tt(e,n.algorithm);try{return await c.subtle.verify(o,n,r,data)}catch(e){return!1}};async function it(e,t,r){var n;if(!pe(e))throw new R("Flattened JWS must be an object");if(void 0===e.protected&&void 0===e.header)throw new R('Flattened JWS must have either of the "protected" or "header" members');if(void 0!==e.protected&&"string"!=typeof e.protected)throw new R("JWS Protected Header incorrect type");if(void 0===e.payload)throw new R("JWS Payload missing");if("string"!=typeof e.signature)throw new R("JWS Signature missing or incorrect type");if(void 0!==e.header&&!pe(e.header))throw new R("JWS Unprotected Header incorrect type");let o={};if(e.protected)try{const t=_(e.protected);o=JSON.parse(f.decode(t))}catch(e){throw new R("JWS Protected Header is invalid")}if(!ue(o,e.header))throw new R("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");const c={...o,...e.header};let d=!0;if(Ne(R,new Map([["b64",!0]]),null==r?void 0:r.crit,o,c).has("b64")&&(d=o.b64,"boolean"!=typeof d))throw new R('The "b64" (base64url-encode payload) Header Parameter must be a boolean');const{alg:l}=c;if("string"!=typeof l||!l)throw new R('JWS "alg" (Algorithm) Header Parameter missing or invalid');const y=r&&Be("algorithms",r.algorithms);if(y&&!y.has(l))throw new W('"alg" (Algorithm) Header Parameter not allowed');if(d){if("string"!=typeof e.payload)throw new R("JWS Payload must be a string")}else if("string"!=typeof e.payload&&!(e.payload instanceof Uint8Array))throw new R("JWS Payload must be a string or an Uint8Array instance");let m=!1;"function"==typeof t&&(t=await t(o,e),m=!0),Ie(l,t,"verify");const data=w(h.encode(null!==(n=e.protected)&&void 0!==n?n:""),h.encode("."),"string"==typeof e.payload?h.encode(e.payload):e.payload),E=_(e.signature);if(!await at(l,t,E,data))throw new N;let A;A=d?_(e.payload):"string"==typeof e.payload?h.encode(e.payload):e.payload;const S={payload:A};return void 0!==e.protected&&(S.protectedHeader=o),void 0!==e.header&&(S.unprotectedHeader=e.header),m?{...S,key:t}:S}async function ot(e,t,r){if(e instanceof Uint8Array&&(e=f.decode(e)),"string"!=typeof e)throw new R("Compact JWS must be a string or Uint8Array");const{0:n,1:o,2:c,length:d}=e.split(".");if(3!==d)throw new R("Invalid Compact JWS");const l=await it({payload:o,protected:n,signature:c},t,r),h={payload:l.payload,protectedHeader:l.protectedHeader};return"function"==typeof t?{...h,key:l.key}:h}async function st(e,t,r){if(!pe(e))throw new R("General JWS must be an object");if(!Array.isArray(e.signatures)||!e.signatures.every(pe))throw new R("JWS Signatures missing or incorrect type");for(const n of e.signatures)try{return await it({header:n.header,payload:e.payload,protected:n.protected,signature:n.signature},t,r)}catch(e){}throw new N}var ct=e=>Math.floor(e.getTime()/1e3);const ut=86400,pt=/^(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)$/i;var lt=e=>{const t=pt.exec(e);if(!t)throw new TypeError("Invalid time period format");const r=parseFloat(t[1]);switch(t[2].toLowerCase()){case"sec":case"secs":case"second":case"seconds":case"s":return Math.round(r);case"minute":case"minutes":case"min":case"mins":case"m":return Math.round(60*r);case"hour":case"hours":case"hr":case"hrs":case"h":return Math.round(3600*r);case"day":case"days":case"d":return Math.round(r*ut);case"week":case"weeks":case"w":return Math.round(604800*r);default:return Math.round(31557600*r)}};const ht=e=>e.toLowerCase().replace(/^application\//,"");var ft=(e,t,r={})=>{const{typ:n}=r;if(n&&("string"!=typeof e.typ||ht(e.typ)!==ht(n)))throw new K('unex
2pected "typ" JWT header value',"typ","check_failed");let o;try{o=JSON.parse(f.decode(t))}catch(e){}if(!pe(o))throw new O("JWT Claims Set must be a top-level JSON object");const{issuer:c}=r;if(c&&!(Array.isArray(c)?c:[c]).includes(o.iss))throw new K('unexpected "iss" claim value',"iss","check_failed");const{subject:d}=r;if(d&&o.sub!==d)throw new K('unexpected "sub" claim value',"sub","check_failed");const{audience:l}=r;if(l&&(h=o.aud,y="string"==typeof l?[l]:l,!("string"==typeof h?y.includes(h):Array.isArray(h)&&y.some(Set.prototype.has.bind(new Set(h))))))throw new K('unexpected "aud" claim value',"aud","check_failed");var h,y;let w;switch(typeof r.clockTolerance){case"string":w=lt(r.clockTolerance);break;case"number":w=r.clockTolerance;break;case"undefined":w=0;break;default:throw new TypeError("Invalid clockTolerance option type")}const{currentDate:m}=r,E=ct(m||new Date);if((void 0!==o.iat||r.maxTokenAge)&&"number"!=typeof o.iat)throw new K('"iat" claim must be a number',"iat","invalid");if(void 0!==o.nbf){if("number"!=typeof o.nbf)throw new K('"nbf" claim must be a number',"nbf","invalid");if(o.nbf>E+w)throw new K('"nbf" claim timestamp check failed',"nbf","check_failed")}if(void 0!==o.exp){if("number"!=typeof o.exp)throw new K('"exp" claim must be a number',"exp","invalid");if(o.exp<=E-w)throw new k('"exp" claim timestamp check failed',"exp","check_failed")}if(r.maxTokenAge){const e=E-o.iat;if(e-w>("number"==typeof r.maxTokenAge?r.maxTokenAge:lt(r.maxTokenAge)))throw new k('"iat" claim timestamp check failed (too far in the past)',"iat","check_failed");if(e<0-w)throw new K('"iat" claim timestamp check failed (it should be in the past)',"iat","check_failed")}return o};async function yt(e,t,r){var n;const o=await ot(e,t,r);if((null===(n=o.protectedHeader.crit)||void 0===n?void 0:n.includes("b64"))&&!1===o.protectedHeader.b64)throw new O("JWTs MUST NOT use unencoded payload");const c={payload:ft(o.protectedHeader,o.payload,r),protectedHeader:o.protectedHeader};return"function"==typeof t?{...c,key:o.key}:c}async function wt(e,t,r){const n=await Le(e,t,r),o=ft(n.protectedHeader,n.plaintext,r),{protectedHeader:c}=n;if(void 0!==c.iss&&c.iss!==o.iss)throw new K('replicated "iss" claim header parameter mismatch',"iss","mismatch");if(void 0!==c.sub&&c.sub!==o.sub)throw new K('replicated "sub" claim header parameter mismatch',"sub","mismatch");if(void 0!==c.aud&&JSON.stringify(c.aud)!==JSON.stringify(o.aud))throw new K('replicated "aud" claim header parameter mismatch',"aud","mismatch");const d={payload:o,protectedHeader:c};return"function"==typeof t?{...d,key:n.key}:d}class gt{constructor(e){this._flattened=new qe(e)}setContentEncryptionKey(e){return this._flattened.setContentEncryptionKey(e),this}setInitializationVector(e){return this._flattened.setInitializationVector(e),this}setProtectedHeader(e){return this._flattened.setProtectedHeader(e),this}setKeyManagementParameters(e){return this._flattened.setKeyManagementParameters(e),this}async encrypt(e,t){const r=await this._flattened.encrypt(e,t);return[r.protected,r.encrypted_key,r.iv,r.ciphertext,r.tag].join(".")}}var mt=async(e,t,data)=>{const r=await nt(e,t,"sign");Se(e,r);const n=await c.subtle.sign(tt(e,r.algorithm),r,data);return new Uint8Array(n)};class Et{constructor(e){if(!(e instanceof Uint8Array))throw new TypeError("payload must be an instance of Uint8Array");this._payload=e}setProtectedHeader(e){if(this._protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setUnprotectedHeader(e){if(this._unprotectedHeader)throw new TypeError("setUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}async sign(e,t){if(!this._protectedHeader&&!this._unprotectedHeader)throw new R("either setProtectedHeader or setUnprotectedHeader must be called before #sign()");if(!ue(this._protectedHeader,this._unprotectedHeader))throw new R("JWS Protected and JWS Unprotected Header Parameter names must be disjoint");const r={...this._protectedHeader,...this._unprotectedHeader};let n=!0;if(Ne(R,new Map([["b64",!0]]),null==t?void 0:t.crit,this._protectedHeader,r).has("b64")&&(n=this._protectedHeader.b64,"boolean"!=typeof n))throw new R('The "b64" (base64url-encode payload) Header Parameter must be a boolean');const{alg:o}=r;if("string"!=typeof o||!o)throw new R('JWS "alg" (Algorithm) Header Parameter missing or invalid');Ie(o,e,"sign");let c,d=this._payload;n&&(d=h.encode(H(d))),c=this._protectedHeader?h.encode(H(JSON.stringify(this._protectedHeader))):h.encode("");const data=w(c,h.encode("."),d),l=await mt(o,e,data),y={signature:H(l),payload:""};return n&&(y.payload=f.decode(d)),this._unprotectedHeader&&(y.header=this._unprotectedHeader),this._protectedHeader&&(y.protected=f.decode(c)),y}}class At{constructor(e){this._flattened=new Et(e)}setProtectedHeader(e){return this._flattened.setProtectedHeader(e),this}async sign(e,t){const r=await this._flattened.sign(e,t);if(void 0===r.payload)throw new TypeError("use the flattened module for creating JWS with b64: false");return`${r.protected}.${r.payload}.${r.signature}`}}class St{constructor(e,t,r){this.parent=e,this.key=t,this.options=r}setProtectedHeader(e){if(this.protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this.protectedHeader=e,this}setUnprotectedHeader(e){if(this.unprotectedHeader)throw new TypeError("setUnprotectedHeader can only be called once");return this.unprotectedHeader=e,this}addSignature(...e){return this.parent.addSignature(...e)}sign(...e){return this.parent.sign(...e)}done(){return this.parent}}class vt{constructor(e){this._signatures=[],this._payload=e}addSignature(e,t){const r=new St(this,e,t);return this._signatures.push(r),r}async sign(){if(!this._signatures.length)throw new R("at least one signature must be added");const e={signatures:[],payload:""};for(let i=0;i<this._signatures.length;i++){const t=this._signatures[i],r=new Et(this._payload);r.setProtectedHeader(t.protectedHeader),r.setUnprotectedHeader(t.unprotectedHeader);const{payload:n,...o}=await r.sign(t.key,t.options);if(0===i)e.payload=n;else if(e.payload!==n)throw new R("inconsistent use of JWS Unencoded Payload Option (RFC7797)");e.signatures.push(o)}return e}}class bt{constructor(e){if(!pe(e))throw new TypeError("JWT Claims Set MUST be an object");this._payload=e}setIssuer(e){return this._payload={...this._payload,iss:e},this}setSubject(e){return this._payload={...this._payload,sub:e},this}setAudience(e){return this._payload={...this._payload,aud:e},this}setJti(e){return this._payload={...this._payload,jti:e},this}setNotBefore(input){return this._payload="number"==typeof input?{...this._payload,nbf:input}:{...this._payload,nbf:ct(new Date)+lt(input)},this}setExpirationTime(input){return this._payload="number"==typeof input?{...this._payload,exp:input}:{...this._payload,exp:ct(new Date)+lt(input)},this}setIssuedAt(input){return this._payload=void 0===input?{...this._payload,iat:ct(new Date)}:{...this._payload,iat:input},this}}class Ht extends bt{setProtectedHeader(e){return this._protectedHeader=e,this}async sign(e,t){var r;const n=new At(h.encode(JSON.stringify(this._payload)));if(n.setProtectedHeader(this._protectedHeader),Array.isArray(null===(r=this._protectedHeader)||void 0===r?void 0:r.crit)&&this._protectedHeader.crit.includes("b64")&&!1===this._protectedHeader.b64)throw new O("JWTs MUST NOT use unencoded payload");return n.sign(e,t)}}class Ct extends bt{setProtectedHeader(e){if(this._protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setKeyManagementParameters(e){if(this._keyManagementParameters)throw new TypeError("setKeyManagementParameters can only be called once");return this._keyManagementParameters=e,this}setContentEncryptionKey(e){if(this._cek)throw new TypeError("setContentEncryptionKey can only be called once");return this._cek=e,this}setInitializationVector(e){if(this._iv)throw new TypeError("setInitializationVector can only be called once");return this._iv=e,this}replicateIssuerAsHeader(){return this._replicateIssuerAsHeader=!0,this}replicateSubjectAsHeader(){return this._replicateSubjectAsHeader=!0,this}replicateAudienceAsHeader(){return this._replicateAudienceAsHeader=!0,this}async encrypt(e,t){const r=new gt(h.encode(JSON.stringify(this._payload)));return this._replicateIssuerAsHeader&&(this._protectedHeader={...this._protectedHeader,iss:this._payload.iss}),this._replicateSubjectAsHeader&&(this._protectedHeader={...this._protectedHeader,sub:this._payload.sub}),this._replicateAudienceAsHeader&&(this._protectedHeader={...this._protectedHeader,aud:this._payload.aud}),r.setProtectedHeader(this._protectedHeader),this._iv&&r.setInitializationVector(this._iv),this._cek&&r.setContentEncryptionKey(this._cek),this._keyManagementParameters&&r.setKeyManagementParameters(this._keyManagementParameters),r.encrypt(e,t)}}const _t=(e,t)=>{if("string"!=typeof e||!e)throw new x(`${t} missing or invalid`)};async function Pt(e,t){if(!pe(e))throw new TypeError("JWK must be an object");
2if(null!=t||(t="sha256"),"sha256"!==t&&"sha384"!==t&&"sha512"!==t)throw new TypeError('digestAlgorithm must one of "sha256", "sha384", or "sha512"');let r;switch(e.kty){case"EC":_t(e.crv,'"crv" (Curve) Parameter'),_t(e.x,'"x" (X Coordinate) Parameter'),_t(e.y,'"y" (Y Coordinate) Parameter'),r={crv:e.crv,kty:e.kty,x:e.x,y:e.y};break;case"OKP":_t(e.crv,'"crv" (Subtype of Key Pair) Parameter'),_t(e.x,'"x" (Public Key) Parameter'),r={crv:e.crv,kty:e.kty,x:e.x};break;case"RSA":_t(e.e,'"e" (Exponent) Parameter'),_t(e.n,'"n" (Modulus) Parameter'),r={e:e.e,kty:e.kty,n:e.n};break;case"oct":_t(e.k,'"k" (Key Value) Parameter'),r={k:e.k,kty:e.kty};break;default:throw new J('"kty" (Key Type) Parameter missing or unsupported')}const data=h.encode(JSON.stringify(r));return H(await l(t,data))}async function Kt(e,t){null!=t||(t="sha256");const r=await Pt(e,t);return`urn:ietf:params:oauth:jwk-thumbprint:sha-${t.slice(-3)}:${r}`}async function kt(e,t){const r={...e,...t.header};if(!pe(r.jwk))throw new R('"jwk" (JSON Web Key) Header Parameter must be a JSON object');const n=await De({...r.jwk,ext:!0},r.alg,!0);if(n instanceof Uint8Array||"public"!==n.type)throw new R('"jwk" (JSON Web Key) Header Parameter must be a public key');return n}function Wt(e){return e&&"object"==typeof e&&Array.isArray(e.keys)&&e.keys.every(Jt)}function Jt(e){return pe(e)}class Tt{constructor(e){if(this._cached=new WeakMap,!Wt(e))throw new D("JSON Web Key Set malformed");var t;this._jwks=(t=e,"function"==typeof structuredClone?structuredClone(t):JSON.parse(JSON.stringify(t)))}async getKey(e,t){const{alg:r,kid:n}={...e,...t.header},o=function(e){switch("string"==typeof e&&e.slice(0,2)){case"RS":case"PS":return"RSA";case"ES":return"EC";case"Ed":return"OKP";default:throw new J('Unsupported "alg" value for a JSON Web Key Set')}}(r),c=this._jwks.keys.filter((e=>{let t=o===e.kty;if(t&&"string"==typeof n&&(t=n===e.kid),t&&"string"==typeof e.alg&&(t=r===e.alg),t&&"string"==typeof e.use&&(t="sig"===e.use),t&&Array.isArray(e.key_ops)&&(t=e.key_ops.includes("verify")),t&&"EdDSA"===r&&(t="Ed25519"===e.crv||"Ed448"===e.crv),t)switch(r){case"ES256":t="P-256"===e.crv;break;case"ES256K":t="secp256k1"===e.crv;break;case"ES384":t="P-384"===e.crv;break;case"ES512":t="P-521"===e.crv}return t})),{0:d,length:l}=c;if(0===l)throw new I;if(1!==l)throw new M;const h=this._cached.get(d)||this._cached.set(d,{}).get(d);if(void 0===h[r]){const e=await De({...d,ext:!0},r);if(e instanceof Uint8Array||"public"!==e.type)throw new D("JSON Web Key Set members must be public keys");h[r]=e}return h[r]}}function Ut(e){return Tt.prototype.getKey.bind(new Tt(e))}var Rt=async(e,t,r)=>{let n,o,c=!1;"function"==typeof AbortController&&(n=new AbortController,o=setTimeout((()=>{c=!0,n.abort()}),t));const d=await fetch(e.href,{signal:n?n.signal:void 0,redirect:"manual",headers:r.headers}).catch((e=>{if(c)throw new j;throw e}));if(void 0!==o&&clearTimeout(o),200!==d.status)throw new P("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await d.json()}catch(e){throw new P("Failed to parse the JSON Web Key Set HTTP response as JSON")}};class Ot extends Tt{constructor(e,t){if(super({keys:[]}),this._jwks=void 0,!(e instanceof URL))throw new TypeError("url must be an instance of URL");this._url=new URL(e.href),this._options={agent:null==t?void 0:t.agent,headers:null==t?void 0:t.headers},this._timeoutDuration="number"==typeof(null==t?void 0:t.timeoutDuration)?null==t?void 0:t.timeoutDuration:5e3,this._cooldownDuration="number"==typeof(null==t?void 0:t.cooldownDuration)?null==t?void 0:t.cooldownDuration:3e4,this._cacheMaxAge="number"==typeof(null==t?void 0:t.cacheMaxAge)?null==t?void 0:t.cacheMaxAge:6e5}coolingDown(){return"number"==typeof this._jwksTimestamp&&Date.now()<this._jwksTimestamp+this._cooldownDuration}fresh(){return"number"==typeof this._jwksTimestamp&&Date.now()<this._jwksTimestamp+this._cacheMaxAge}async getKey(e,t){this._jwks&&this.fresh()||await this.reload();try{return await super.getKey(e,t)}catch(r){if(r instanceof I&&!1===this.coolingDown())return await this.reload(),super.getKey(e,t);throw r}}
2async reload(){if(this._pendingFetch&&V())return new Promise((e=>{const t=()=>{void 0===this._pendingFetch?e():setTimeout(t,5)};t()}));this._pendingFetch||(this._pendingFetch=Rt(this._url,this._timeoutDuration,this._options).then((e=>{if(!Wt(e))throw new D("JSON Web Key Set malformed");this._jwks={keys:e.keys},this._jwksTimestamp=Date.now(),this._pendingFetch=void 0})).catch((e=>{throw this._pendingFetch=void 0,e}))),await this._pendingFetch}}function xt(e,t){return Ot.prototype.getKey.bind(new Ot(e,t))}class Dt extends bt{encode(){return`${H(JSON.stringify({alg:"none"}))}.${H(JSON.stringify(this._payload))}.`}static decode(e,t){if("string"!=typeof e)throw new O("Unsecured JWT must be a string");const{0:r,1:n,2:o,length:c}=e.split(".");if(3!==c||""!==o)throw new O("Invalid Unsecured JWT");let header;try{if(header=JSON.parse(f.decode(_(r))),"none"!==header.alg)throw new Error}catch(e){throw new O("Invalid Unsecured JWT")}return{payload:ft(header,_(n),t),header:header}}}const It=H,Mt=_;function jt(e){let t;if("string"==typeof e){const r=e.split(".");3!==r.length&&5!==r.length||([t]=r)}else if("object"==typeof e&&e){if(!("protected"in e))throw new TypeError("Token does not contain a Protected Header");t=e.protected}try{if("string"!=typeof t||!t)throw new Error;const e=JSON.parse(f.decode(Mt(t)));if(!pe(e))throw new Error;return e}catch(e){throw new TypeError("Invalid Token or Protected Header formatting")}}function Nt(e){if("string"!=typeof e)throw new O("JWTs must use Compact JWS serialization, JWT must be a string");const{1:t,length:r}=e.split(".");if(5===r)throw new O("Only JWTs using Compact JWS serialization can be decoded");if(3!==r)throw new O("Invalid JWT");if(!t)throw new O("JWTs must contain a payload");let n,o;try{n=Mt(t)}catch(e){throw new O("Failed to parse the base64url encoded payload")}try{o=JSON.parse(f.decode(n))}catch(e){throw new O("Failed to parse the decoded payload as JSON")}if(!pe(o))throw new O("Invalid JWT Claims Set");return o}function Bt(e){var t;const r=null!==(t=null==e?void 0:e.modulusLength)&&void 0!==t?t:2048;if("number"!=typeof r||r<2048)throw new J("Invalid or unsupported modulusLength option provided, 2048 bits or larger keys must be used");return r}async function $t(e,t){return async function(e,t){var r,n,o;let d,l;switch(e){case"PS256":case"PS384":case"PS512":d={name:"RSA-PSS",hash:`SHA-${e.slice(-3)}`,publicExponent:new Uint8Array([1,0,1]),modulusLength:Bt(t)},l=["sign","verify"];break;case"RS256":case"RS384":case"RS512":d={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${e.slice(-3)}`,publicExponent:new Uint8Array([1,0,1]),modulusLength:Bt(t)},l=["sign","verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":d={name:"RSA-OAEP",hash:`SHA-${parseInt(e.slice(-3),10)||1}`,publicExponent:new Uint8Array([1,0,1]),modulusLength:Bt(t)},l=["decrypt","unwrapKey","encrypt","wrapKey"];break;case"ES256":d={name:"ECDSA",namedCurve:"P-256"},l=["sign","verify"];break;case"ES384":d={name:"ECDSA",namedCurve:"P-384"},l=["sign","verify"];break;case"ES512":d={name:"ECDSA",namedCurve:"P-521"},l=["sign","verify"];break;case V()&&"EdDSA":switch(null==t?void 0:t.crv){case void 0:case"Ed25519":d={name:"NODE-ED25519",namedCurve:"NODE-ED25519"},l=["sign","verify"];break;default:throw new J("Invalid or unsupported crv option provided")}break;case"EdDSA":l=["sign","verify"];const o=null!==(r=null==t?void 0:t.crv)&&void 0!==r?r:"Ed25519";
2switch(o){case"Ed25519":case"Ed448":d={name:o};break;default:throw new J("Invalid or unsupported crv option provided")}break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{l=["deriveKey","deriveBits"];const e=null!==(n=null==t?void 0:t.crv)&&void 0!==n?n:"P-256";switch(e){case"P-256":case"P-384":case"P-521":d={name:"ECDH",namedCurve:e};break;case"X25519":case"X448":d={name:e};break;default:throw new J("Invalid or unsupported crv option provided, supported values are P-256, P-384, P-521, X25519, and X448")}break}default:throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}return c.subtle.generateKey(d,null!==(o=null==t?void 0:t.extractable)&&void 0!==o&&o,l)}(e,t)}async function Lt(e,t){return async function(e,t){var r;let n,o,d;switch(e){case"HS256":case"HS384":case"HS512":n=parseInt(e.slice(-3),10),o={name:"HMAC",hash:`SHA-${n}`,length:n},d=["sign","verify"];break;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return n=parseInt(e.slice(-3),10),B(new Uint8Array(n>>3));case"A128KW":case"A192KW":case"A256KW":n=parseInt(e.slice(1,4),10),o={name:"AES-KW",length:n},d=["wrapKey","unwrapKey"];break;case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":case"A128GCM":case"A192GCM":case"A256GCM":n=parseInt(e.slice(1,4),10),o={name:"AES-GCM",length:n},d=["encrypt","decrypt"];break;default:throw new J('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}return c.subtle.generateKey(o,null!==(r=null==t?void 0:t.extractable)&&void 0!==r&&r,d)}(e,t)}},23:function(e,t){"function"==typeof Object.create?e.exports=function(e,t){t&&(e.super_=t,e.prototype=Object.create(t.prototype,{constructor:{value:e,enumerable:!1,writable:!0,configurable:!0}}))}:e.exports=function(e,t){if(t){e.super_=t;var r=function(){};r.prototype=t.prototype,e.prototype=new r,e.prototype.constructor=e}}},822:function(e,t){var r={}.toString;e.exports=Array.isArray||function(e){return"[object Array]"==r.call(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.