1import{ae as We,af as is,ag as as,ah as Ke,ai as cs,aj as Bn,ak as us,u as C,al as Wn,am as ls,an as ds,ao as kn}from"./vendor-B_ZKpJiR.js";/*! 2 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 3 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 4 * 5 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 6 * Unless required by applicable law or agreed to in writing, software 7 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 8 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 9 * 10 * See the License for the specific language governing permissions and limitations under the License. 11 */var oe;(function(n){n.SUCCESS="SUCCESS",n.PENDING="PENDING",n.FAILURE="FAILURE",n.TERMINAL="TERMINAL",n.CANCELED="CANCELED"})(oe||(oe={}));var z;(function(n){n.OKTA_PASSWORD="okta_password",n.OKTA_EMAIL="okta_email",n.PHONE_NUMBER="phone_number",n.GOOGLE_AUTHENTICATOR="google_otp",n.SECURITY_QUESTION="security_question",n.OKTA_VERIFY="okta_verify",n.WEBAUTHN="webauthn"})(z||(z={}));var Y;(function(n){n.PASSWORD_RECOVERY="recover-password",n.REGISTRATION="enroll-profile",n.SOCIAL_IDP="redirect-idp",n.ACCOUNT_UNLOCK="unlock-account"})(Y||(Y={}));function st(n){return n&&(n.key||n.id)}/*! 12 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 13 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 14 * 15 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 16 * Unless required by applicable law or agreed to in writing, software 17 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 18 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 19 * 20 * See the License for the specific language governing permissions and limitations under the License. 21 */function hs(){return typeof window<"u"?window.console:typeof console<"u"?console:void 0}function ke(){var n=hs();return n&&n.log?n:{log:function(){},warn:function(){},group:function(){},groupEnd:function(){}}}function K(n){ke().warn("[okta-auth-sdk] WARN: "+n)}/*! 22 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 23 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 24 * 25 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 26 * Unless required by applicable law or agreed to in writing, software 27 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 28 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 29 * 30 * See the License for the specific language governing permissions and limitations under the License. 31 */function B(n){var e={};for(var t in n)if(Object.prototype.hasOwnProperty.call(n,t)){var r=n[t];r!=null&&(e[t]=r)}return e}function D(n){if(n){var e=JSON.stringify(n);if(e)return JSON.parse(e)}return n}function Pe(n,...e){var t={};for(var r in n)Object.prototype.hasOwnProperty.call(n,r)&&e.indexOf(r)==-1&&(t[r]=n[r]);return D(t)}function At(n,e){for(var t=n.length;t--;){var r=n[t],s=!0;for(var o in e)if(Object.prototype.hasOwnProperty.call(e,o)&&r[o]!==e[o]){s=!1;break}if(s)return r}}function kt(n,e,t){if(!(!n||!n._links)){var r=D(n._links[e]);if(r&&r.name&&t){if(r.name===t)return r}else return r}}/*! 32 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 33 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 34 * 35 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 36 * Unless required by applicable law or agreed to in writing, software 37 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 38 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 39 * 40 * See the License for the specific language governing permissions and limitations under the License.
41 */class be extends Error{constructor(e){super(e),Object.setPrototypeOf(this,new.target.prototype)}}/*! 42 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 43 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 44 * 45 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 46 * Unless required by applicable law or agreed to in writing, software 47 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 48 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 49 * 50 * See the License for the specific language governing permissions and limitations under the License. 51 */function ve(n){return Object.prototype.toString.call(n)==="[object String]"}function Kn(n){return Object.prototype.toString.call(n)==="[object Object]"}function fs(n){return Object.prototype.toString.call(n)==="[object Number]"}function $n(n){return!!n&&{}.toString.call(n)==="[object Function]"}function gs(n){return n&&n.finally&&typeof n.finally=="function"}/*! 52 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 53 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 54 * 55 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 56 * Unless required by applicable law or agreed to in writing, software 57 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 58 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 59 * 60 * See the License for the specific language governing permissions and limitations under the License. 61 */class q extends be{constructor(e,t,r){var s;super((s=t.error)!==null&&s!==void 0?s:q.UNKNOWN_ERROR),this.name="WWWAuthError",this.resp=null,this.scheme=e,this.parameters=t,r&&(this.resp=r)}get error(){return this.parameters.error}get errorCode(){return this.error}get error_description(){return this.parameters.error_description}get errorDescription(){return this.error_description}get errorSummary(){return this.errorDescription}get realm(){return this.parameters.realm}static parseHeader(e){var t;if(!e)return null;const r=/(?:,|, )?([a-zA-Z0-9!#$%&'*+\-.^_`|~]+)=(?:"([a-zA-Z0-9!#$%&'*+\-.,^_`|~ /:]+)"|([a-zA-Z0-9!#$%&'*+\-.^_`|~/:]+))/g,s=e.indexOf(" "),o=e.slice(0,s),i=e.slice(s+1),a={};let c;for(;(c=r.exec(i))!==null;)a[c[1]]=(t=c[2])!==null&&t!==void 0?t:c[3];return new q(o,a)}static getWWWAuthenticateHeader(e={}){var t;return $n(e==null?void 0:e.get)?e.get("WWW-Authenticate"):(t=e["www-authenticate"])!==null&&t!==void 0?t:e["WWW-Authenticate"]}}q.UNKNOWN_ERROR="UNKNOWN_WWW_AUTH_ERROR";/*! 62 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 63 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 64 * 65 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 66 * Unless required by applicable law or agreed to in writing, software 67 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 68 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 69 * 70 * See the License for the specific language governing permissions and limitations under the License. 71 */function zn(n){for(var e="abcdefghijklnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789",t="",r=0,s=e.length;r<n;++r)t+=e[Math.floor(Math.random()*s)];return t}function En(n){return new Promise(function(e){setTimeout(e,n)})}function ps(n,e){const t=n.split(e);return[t[0],t.splice(1,t.length).join(e)]}/*! 72 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 73 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 74 * 75 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 76 * Unless required by applicable law or agreed to in writing, software 77 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 78 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 79 * 80 * See the License for the specific language governing permissions and limitations under the License. 81 */function qt(n){return/^[a-z][a-z0-9+.-]*:/i.test(n)}function ms(n="",e){return qt(n)?n:(e=H(e),n[0]==="/"?`${e}${n}`:`${e}/${n}`)}function J(n){var e=[];
81if(n!==null)for(var t in n)Object.prototype.hasOwnProperty.call(n,t)&&n[t]!==void 0&&n[t]!==null&&e.push(t+"="+encodeURIComponent(n[t]));return e.length?"?"+e.join("&"):""}function H(n){if(n){var e=n.replace(/^\s+|\s+$/gm,"");return e=e.replace(/\/+$/,""),e}}/*! 82 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 83 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 84 * 85 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 86 * Unless required by applicable law or agreed to in writing, software 87 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 88 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 89 * 90 * See the License for the specific language governing permissions and limitations under the License. 91 */class g extends be{constructor(e,t){super(e),this.name="AuthSdkError",this.errorCode="INTERNAL",this.errorSummary=e,this.errorLink="INTERNAL",this.errorId="INTERNAL",this.errorCauses=[],t&&(this.xhr=t)}}/*! 92 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 93 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 94 * 95 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 96 * Unless required by applicable law or agreed to in writing, software 97 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 98 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 99 * 100 * See the License for the specific language governing permissions and limitations under the License. 101 */function Bt(){return zn(64)}function vs(){return zn(64)}function Wt(n,e={}){return H(e.issuer)||n.options.issuer}function Gn(n,e={}){const t=Wt(n,e);return t.indexOf("/oauth2")>0?t:t+"/oauth2"}function ys(n,e={}){return Wt(n,e).split("/oauth2")[0]}function ee(n,e){if(arguments.length>2)throw new g('As of version 3.0, "getOAuthUrls" takes only a single set of options');e=e||{};var t=H(e.authorizeUrl)||n.options.authorizeUrl,r=Wt(n,e),s=H(e.userinfoUrl)||n.options.userinfoUrl,o=H(e.tokenUrl)||n.options.tokenUrl,i=H(e.logoutUrl)||n.options.logoutUrl,a=H(e.revokeUrl)||n.options.revokeUrl,c=Gn(n,e);return t=t||c+"/v1/authorize",s=s||c+"/v1/userinfo",o=o||c+"/v1/token",a=a||c+"/v1/revoke",i=i||c+"/v1/logout",{issuer:r,authorizeUrl:t,userinfoUrl:s,tokenUrl:o,revokeUrl:a,logoutUrl:i}}/*! 102 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 103 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 104 * 105 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 106 * Unless required by applicable law or agreed to in writing, software 107 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 108 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 109 * 110 * See the License for the specific language governing permissions and limitations under the License. 111 */function Jn(n,e){const t=n.options.issuer,r=ee(n,e),s={issuer:t,urls:r,clientId:e.clientId,redirectUri:e.redirectUri,responseType:e.responseType,responseMode:e.responseMode,scopes:e.scopes,state:e.state,nonce:e.nonce,ignoreSignature:e.ignoreSignature,acrValues:e.acrValues,extraParams:e.extraParams};return e.pkce===!1?s:Object.assign(Object.assign({},s),{codeVerifier:e.codeVerifier,codeChallengeMethod:e.codeChallengeMethod,codeChallenge:e.codeChallenge})}/*! 112 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 113 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 114 * 115 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 116 * Unless required by applicable law or agreed to in writing, software 117 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 118 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 119 * 120 * See the License for the specific language governing permissions and limitations under the License. 121 */const Re="oktaStateToken",Qn=500,Yn=3,Xn=300,Zn=86400,Kt="okta-token-storage",er="okta-cache-storage",ws="okta-pkce-storage",tr="okta-transaction-storage",nr="okta-shared-transaction-storage",rr="okta-original-uri-storage",sr="okta-idx-response-storage",Ts="accessToken",Ss="idToken",Et="refreshToken",Qe="referrerPath",_t=43,or=128,$t="S256",zt="1.0.0",_n=Object.freeze(Object.defineProperty({__proto__:null,ACCESS_TOKEN_STORAGE_KEY:Ts,CACHE_STORAGE_NAME:er,DEFAULT_CACHE_DURATION:Zn,DEFAULT_CODE_CHALLENGE_METHOD:$t,DEFAULT_MAX_CLOCK_SKEW:Xn,DEFAULT_POLLING_DELAY:Qn,IDX_API_VERSION:zt,IDX_RESPONSE_STORAGE_NAME:sr,ID_TOKEN_STORAGE_KEY:Ss,IOS_MAX_RETRY_COUNT:Yn,MAX_VERIFIER_LENGTH:or,MIN_VERIFIER_LENGTH:_t,ORIGINAL_URI_STORAGE_NAME:rr,PKCE_STORAGE_NAME:ws,REFERRER_PATH_STORAGE_KEY:Qe,REFRESH_TOKEN_STORAGE_KEY:Et,SHARED_TRANSACTION_STORAGE_NAME:nr,STATE_TOKEN_KEY_NAME:Re,TOKEN_STORAGE_NAME:Kt,TRANSACTION_STORAGE_NAME:tr},Symbol.toStringTag,{value:"Module"}));/*! 122 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 123 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 124 * 125 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 126 * Unless required by applicable law or agreed to in writing, softw
126are 127 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 128 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 129 * 130 * See the License for the specific language governing permissions and limitations under the License. 131 */class ue extends be{constructor(e,t,r){const s=e.errorSummary;super(s),this.name="AuthApiError",this.errorSummary=e.errorSummary,this.errorCode=e.errorCode,this.errorLink=e.errorLink,this.errorId=e.errorId,this.errorCauses=e.errorCauses,t&&(this.xhr=t),r&&(this.meta=r)}}/*! 132 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 133 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 134 * 135 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 136 * Unless required by applicable law or agreed to in writing, software 137 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 138 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 139 * 140 * See the License for the specific language governing permissions and limitations under the License. 141 */class ye extends be{constructor(e,t,r){super(t),this.resp=null,this.name="OAuthError",this.errorCode=e,this.errorSummary=t,this.error=e,this.error_description=t,r&&(this.resp=r)}}/*! 142 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 143 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 144 * 145 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 146 * Unless required by applicable law or agreed to in writing, software 147 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 148 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 149 * 150 * See the License for the specific language governing permissions and limitations under the License. 151 */const Gt=function(n){return atob(n)},Z=function(n){return btoa(n)},U=typeof crypto>"u"?null:crypto;/*! 152 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 153 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 154 * 155 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 156 * Unless required by applicable law or agreed to in writing, software 157 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 158 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 159 * 160 * See the License for the specific language governing permissions and limitations under the License. 161 */const bs=/windows phone|iemobile|wpdesktop/i;function I(){return typeof document<"u"&&typeof window<"u"}function at(){if(!I())return!1;const n=document.documentMode;return!!n&&n<=11}function ir(){return navigator.userAgent}function ar(){const n=ir();return n&&!bs.test(n)}function Os(){if(!I())return!1;const n=document.documentMode;var e=n&&n<10;return typeof window.postMessage<"u"&&!e}function cr(){return typeof U<"u"&&U!==null&&typeof U.subtle<"u"&&typeof Uint8Array<"u"}function ur(){return cr()}function Jt(){return typeof TextEncoder<"u"}function As(){return ur()&&Jt()}function lr(){return I()?window.location.protocol==="https:":!1}function dr(){return I()&&window.location.hostname==="localhost"}function ks(){return!at()&&typeof window.indexedDB<"u"&&Jt()&&cr()}function Es(){return I()&&typeof navigator<"u"&&typeof navigator.userAgent<"u"&&/iPad|iPhone|iPod/.test(navigator.userAgent)&&!window.MSStream}const St=Object.freeze(Object.defineProperty({__proto__:null,getUserAgent:ir,hasTextEncoder:Jt,isBrowser:I,isDPoPSupported:ks,isFingerprintSupported:ar,isHTTPS:lr,isIE11OrLess:at,isIOS:Es,isLocalhost:dr,isPKCESupported:As,isPopupPostMessageSupported:Os,isTokenVerifySupported:ur},Symbol.toStringTag,{value:"Module"}));/*! 162 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 163 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 164 * 165 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 166 * Unless required by applicable law or agreed to in writing, softw
166are 167 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 168 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 169 * 170 * See the License for the specific language governing permissions and limitations under the License. 171 */let Pt=0,Pn;I()&&(Pt=Date.now(),Pn=()=>{document.hidden||(Pt=Date.now())},document.addEventListener("visibilitychange",Pn));const _s=(n,e)=>{var t;if(e instanceof Error)return new ue({errorSummary:e.message});let r=e,s,o={};if(r.responseText&&ve(r.responseText))try{o=JSON.parse(r.responseText)}catch{o={errorSummary:"Unknown error"}}r.status>=500&&(o.errorSummary="Unknown error"),n.options.transformErrorXHR&&(r=n.options.transformErrorXHR(D(r)));const i=(t=q.getWWWAuthenticateHeader(r==null?void 0:r.headers))!==null&&t!==void 0?t:"";if(o.error&&o.error_description?s=new ye(o.error,o.error_description,r):s=new ue(o,r,{wwwAuthHeader:i}),i&&(r==null?void 0:r.status)>=400&&(r==null?void 0:r.status)<500){const a=q.parseHeader(i);if(r.status===403&&(a==null?void 0:a.error)==="insufficient_authentication_context"){const{max_age:c,acr_values:u}=a.parameters;s=new ue({errorSummary:a.error,errorCauses:[{errorSummary:a.errorDescription}]},r,Object.assign({max_age:+c},u&&{acr_values:u}))}else(a==null?void 0:a.scheme)==="DPoP"&&(s=a)}return s};function $(n,e){var t;if(e=e||{},n.options.httpRequestInterceptors)for(const R of n.options.httpRequestInterceptors)R(e);var r=e.url,s=e.method,o=e.args,i=e.saveAuthnState,a=e.accessToken,c=e.withCredentials===!0,u=n.options.storageUtil,l=u.storage,f
171=n.storageManager.getHttpCache(n.options.cookies),d=e.pollingIntent,p=(t=n.options.pollDelay)!==null&&t!==void 0?t:0;if(e.cacheResponse){var v=f.getStorage(),m=v[r];if(m&&Date.now()/1e3<m.expiresAt)return Promise.resolve(m.response)}var T=n._oktaUserAgent.getHttpHeader(),w=Object.assign({Accept:"application/json","Content-Type":"application/json"},T);Object.assign(w,n.options.headers,e.headers),w=B(w),a&&ve(a)&&(w.Authorization="Bearer "+a);var A={headers:w,data:o||void 0,withCredentials:c},_,b,V;if(d&&I()&&p>0){let R,W,re,F=0;W=()=>{const L=Date.now()-Pt;return L<p?new Promise(x=>setTimeout(()=>{document.hidden?x(R()):x()},p-L)):Promise.resolve()},R=()=>{if(document.hidden){let L;return new Promise(x=>{L=()=>{document.hidden||(document.removeEventListener("visibilitychange",L),x(W()))},document.addEventListener("visibilitychange",L)})}else return W()};const yt=()=>n.options.httpRequestClient(s,r,A).catch(L=>{if((L==null?void 0:L.message)==="Load failed"&&F<Yn)return F++,re();throw L});re=()=>R().then(yt),V=re()}else V=n.options.httpRequestClient(s,r,A);return V.then(function(R){return b=R.responseText,b&&ve(b)&&(b=JSON.parse(b),b&&typeof b=="object"&&!b.headers&&(Array.isArray(b)?b.forEach(W=>{W.headers=R.headers}):b.headers=R.headers)),i&&(b.stateToken||l.delete(Re)),b&&b.stateToken&&b.expiresAt&&l.set(Re,b.stateToken,b.expiresAt,n.options.cookies),b&&e.cacheResponse&&f.updateStorage(r,{expiresAt:Math.floor(Date.now()/1e3)+Zn,response:b}),b}).catch(function(R){throw _=_s(n,R),_.errorCode==="E0000011"&&l.delete(Re),_})}function we(n,e,t){e=qt(e)?e:n.getIssuerOrigin()+e;var r={url:e,method:"GET"};return Object.assign(r,t),$(n,r)}function te(n,e,t,r){e=qt(e)?e:n.getIssuerOrigin()+e;var s={url:e,method:"POST",args:t,saveAuthnState:!0};return Object.assign(s,r),$(n,s)}var $e={exports:{}},Rn;function Ps(){return Rn||(Rn=1,(function(n,e){var t=typeof globalThis<"u"&&globalThis||typeof self<"u"&&self||typeof We<"u"&&We,r=(function(){function o(){this.fetch=!1,this.DOMException=t.DOMException}return o.prototype=t,new o})();(function(o){(function(i){var a=typeof o<"u"&&o||typeof self<"u"&&self||typeof We<"u"&&We||{},c={searchParams:"URLSearchParams"in a,iterable:"Symbol"in a&&"iterator"in Symbol,blob:"FileReader"in a&&"Blob"in a&&(function(){try{return new Blob,!0}catch{return!1}})(),formData:"FormData"in a,arrayBuffer:"ArrayBuffer"in a};function u(h){return h&&DataView.prototype.isPrototypeOf(h)}if(c.arrayBuffer)var l=["[object Int8Array]","[object Uint8Array]","[object Uint8ClampedArray]","[object Int16Array]","[object Uint16Array]","[object Int32Array]","[object Uint32Array]","[object Float32Array]","[object Float64Array]"],f=ArrayBuffer.isView||function(h){return h&&l.indexOf(Object.prototype.toString.call(h))>-1};function d(h){if(typeof h!="string"&&(h=String(h)),/[^a-z0-9\-#$%&'*+.^_`|~!]/i.test(h)||h==="")throw new TypeError('Invalid character in header field name: "'+h+'"');return h.toLowerCase()}function p(h){return typeof h!="string"&&(h=String(h)),h}function v(h){var y={next:function(){var S=h.shift();return{done:S===void 0,value:S}}};return c.iterable&&(y[Symbol.iterator]=function(){return y}),y}function m(h){this.map={},h instanceof m?h.forEach(function(y,S){this.append(S,y)},this):Array.isArray(h)?h.forEach(function(y){if(y.length!=2)throw new TypeError("Headers constructor: expected name/value pair to be length 2, found"+y.length);this.append(y[0],y[1])},this):h&&Object.getOwnPropertyNames(h).forEach(function(y){this.append(y,h[y])},this)}m.prototype.append=function(h,y){h=d(h),y=p(y);var S=this.map[h];this.map[h]=S?S+", "+y:y},m.prototype.delete=function(h){delete this.map[d(h)]},m.prototype.get=function(h){return h=d(h),this.has(h)?this.map[h]:null},m.prototype.has=function(h){return this.map.hasOwnProperty(d(h))},m.prototype.set=function(h,y){this.map[d(h)]=p(y)},m.prototype.forEach=function(h,y){for(var S in this.map)this.map.hasOwnProperty(S)&&h.call(y,this.map[S],S,this)},m.prototype.keys=function(){var h=[];return this.forEach(function(y,S){h.push(S)}),v(h)},m.prototype.values=function(){var h=[];return this.forEach(function(y){h.push(y)}),v(h)},m.prototype.entries=function(){var h=[];return this.forEach(function(y,S){h.push([S,y])}),v(h)},c.iterable&&(m.prototype[Symbol.iterator]=m.prototype.entries);
vendor: 9,386 bytes, lines 171-187
171function T(h){if(!h._noBody){if(h.bodyUsed)return Promise.reject(new TypeError("Already read"));h.bodyUsed=!0}}function w(h){return new Promise(function(y,S){h.onload=function(){y(h.result)},h.onerror=function(){S(h.error)}})}function A(h){var y=new FileReader,S=w(y);return y.readAsArrayBuffer(h),S}function _(h){var y=new FileReader,S=w(y),k=/charset=([A-Za-z0-9_-]+)/.exec(h.type),E=k?k[1]:"utf-8";return y.readAsText(h,E),S}function b(h){for(var y=new Uint8Array(h),S=new Array(y.length),k=0;k<y.length;k++)S[k]=String.fromCharCode(y[k]);return S.join("")}function V(h){if(h.slice)return h.slice(0);var y=new Uint8Array(h.byteLength);return y.set(new Uint8Array(h)),y.buffer}function R(){return this.bodyUsed=!1,this._initBody=function(h){this.bodyUsed=this.bodyUsed,this._bodyInit=h,h?typeof h=="string"?this._bodyText=h:c.blob&&Blob.prototype.isPrototypeOf(h)?this._bodyBlob=h:c.formData&&FormData.prototype.isPrototypeOf(h)?this._bodyFormData=h:c.searchParams&&URLSearchParams.prototype.isPrototypeOf(h)?this._bodyText=h.toString():c.arrayBuffer&&c.blob&&u(h)?(this._bodyArrayBuffer=V(h.buffer),this._bodyInit=new Blob([this._bodyArrayBuffer])):c.arrayBuffer&&(ArrayBuffer.prototype.isPrototypeOf(h)||f(h))?this._bodyArrayBuffer=V(h):this._bodyText=h=Object.prototype.toString.call(h):(this._noBody=!0,this._bodyText=""),this.headers.get("content-type")||(typeof h=="string"?this.headers.set("content-type","text/plain;charset=UTF-8"):this._bodyBlob&&this._bodyBlob.type?this.headers.set("content-type",this._bodyBlob.type):c.searchParams&&URLSearchParams.prototype.isPrototypeOf(h)&&this.headers.set("content-type","application/x-www-form-urlencoded;charset=UTF-8"))},c.blob&&(this.blob=function(){var h=T(this);if(h)return h;if(this._bodyBlob)return Promise.resolve(this._bodyBlob);if(this._bodyArrayBuffer)return Promise.resolve(new Blob([this._bodyArrayBuffer]));if(this._bodyFormData)throw new Error("could not read FormData body as blob");return Promise.resolve(new Blob([this._bodyText]))}),this.arrayBuffer=function(){if(this._bodyArrayBuffer){var h=T(this);return h||(ArrayBuffer.isView(this._bodyArrayBuffer)?Promise.resolve(this._bodyArrayBuffer.buffer.slice(this._bodyArrayBuffer.byteOffset,this._bodyArrayBuffer.byteOffset+this._bodyArrayBuffer.byteLength)):Promise.resolve(this._bodyArrayBuffer))}else{if(c.blob)return this.blob().then(A);throw new Error("could not read as ArrayBuffer")}},this.text=function(){var h=T(this);if(h)return h;if(this._bodyBlob)return _(this._bodyBlob);if(this._bodyArrayBuffer)return Promise.resolve(b(this._bodyArrayBuffer));if(this._bodyFormData)throw new Error("could not read FormData body as text");return Promise.resolve(this._bodyText)},c.formData&&(this.formData=function(){return this.text().then(yt)}),this.json=function(){return this.text().then(JSON.parse)},this}var W=["CONNECT","DELETE","GET","HEAD","OPTIONS","PATCH","POST","PUT","TRACE"];function re(h){var y=h.toUpperCase();return W.indexOf(y)>-1?y:h}function F(h,y){if(!(this instanceof F))throw new TypeError('Please use the "new" operator, this DOM object constructor cannot be called as a function.');y=y||{};var S=y.body;if(h instanceof F){if(h.bodyUsed)throw new TypeError("Already read");this.url=h.url,this.credentials=h.credentials,y.headers||(this.headers=new m(h.headers)),this.method=h.method,this.mode=h.mode,this.signal=h.signal,!S&&h._bodyInit!=null&&(S=h._bodyInit,h.bodyUsed=!0)}else this.url=String(h);if(this.credentials=y.credentials||this.credentials||"same-origin",(y.headers||!this.headers)&&(this.headers=new m(y.headers)),this.method=re(y.method||this.method||"GET"),this.mode=y.mode||this.mode||null,this.signal=y.signal||this.signal||(function(){if("AbortController"in a){var O=new AbortController;return O.signal}})(),this.referrer=null,(this.method==="GET"||this.method==="HEAD")&&S)throw new TypeError("Body not allowed for GET or HEAD requests");if(this._initBody(S),(this.method==="GET"||this.method==="HEAD")&&(y.cache==="no-store"||y.cache==="no-cache")){var k=/([?&])_=[^&]*/;if(k.test(this.url))this.url=this.url.replace(k,"$1_="+new Date().getTime());else{var E=/\?/;this.url+=(E.test(this.url)?"&":"?")+"_="+new Date().getTime()}}}F.prototype.clone=function(){return new F(this,{body:this._bodyInit})};function yt(h){var y=new FormData;return h.trim().split("&").forEach(function(S){if(S){var k=S.split("="),E=k.shift().replace(/\+/g," "),O=k.join("=").replace(/\+/g," ");y.append(decodeURIComponent(E),decodeURIComponent(O))}}),y}function L(h){var y=new m,S=h.replace(/\r?\n[\t ]+/g," ");return S.split("\r").map(function(k){return k.indexOf(` 172`)===0?k.substr(1,k.length):k}).forEach(function(k){var E=k.split(":"),O=E.shift().trim();if(O){var Be=E.join(":").trim();try{y.append(O,Be)}catch(Tt){console.warn("Response "+Tt.message)}}}),y}R.call(F.prototype);function x(h,y){if(!(this instanceof x))throw new TypeError('Please use the "new" operator, this DOM object constructor cannot be called as a function.');if(y||(y={}),this.type="default",this.status=y.status===void 0?200:y.status,this.status<200||this.status>599)throw new RangeError("Failed to construct 'Response': The status provided (0) is outside the range [200, 599].");this.ok=this.status>=200&&this.status<300,this.statusText=y.statusText===void 0?"":""+y.statusText,this.headers=new m(y.headers),this.url=y.url||"",this._initBody(h)}R.call(x.prototype),x.prototype.clone=function(){return new x(this._bodyInit,{status:this.status,statusText:this.statusText,headers:new m(this.headers),url:this.url})},x.error=function(){var h=new x(null,{status:200,statusText:""});return h.ok=!1,h.status=0,h.type="error",h};var os=[301,302,303,307,308];x.redirect=function(h,y){if(os.indexOf(y)===-1)throw new RangeError("Invalid status code");return new x(null,{status:y,headers:{location:h}})},i.DOMException=a.DOMException;try{new i.DOMException}catch{i.DOMException=function(y,S){this.message=y,this.name=S;var k=Error(y);this.stack=k.stack},i.DOMException.prototype=Object.create(Error.prototype),i.DOMException.prototype.constructor=i.DOMException}function wt(h,y){return new Promise(function(S,k){var E=new F(h,y);if(E.signal&&E.signal.aborted)return k(new i.DOMException("Aborted","AbortError"));var O=new XMLHttpRequest;function Be(){O.abort()}O.onload=function(){var M={statusText:O.statusText,headers:L(O.getAllResponseHeaders()||"")};E.url.indexOf("file://")===0&&(O.status<200||O.status>599)?M.status=200:M.status=O.status,M.url="responseURL"in O?O.responseURL:M.headers.get("X-Request-URL");var se="response"in O?O.response:O.responseText;setTimeout(function(){S(new x(se,M))},0)},O.onerror=function(){setTimeout(function(){k(new TypeError("Network request failed"))},0)},O.ontimeout=function(){setTimeout(function(){k(new TypeError("Network request timed out"))},0)},O.onabort=function(){setTimeout(function(){k(new i.DOMException("Aborted","AbortError"))},0)};function Tt(M){try{return M===""&&a.location.href?a.location.href:M}catch{return M}}if(O.open(E.method,Tt(E.url),!0),E.credentials==="include"?O.withCredentials=!0:E.credentials==="omit"&&(O.withCredentials=!1),"responseType"in O&&(c.blob?O.responseType="blob":c.arrayBuffer&&(O.responseType="arraybuffer")),y&&typeof y.headers=="object"&&!(y.headers instanceof m||a.Headers&&y.headers instanceof a.Headers)){var An=[];Object.getOwnPropertyNames(y.headers).forEach(function(M){An.push(d(M)),O.setRequestHeader(M,p(y.headers[M]))}),E.headers.forEach(function(M,se){An.indexOf(se)===-1&&O.setRequestHeader(se,M)})}else E.headers.forEach(function(M,se){O.setRequestHeader(se,M)});E.signal&&(E.signal.addEventListener("abort",Be),O.onreadystatechange=function(){O.readyState===4&&E.signal.removeEventListener("abort",Be)}),O.send(typeof E._bodyInit>"u"?null:E._bodyInit)})}return wt.polyfill=!0,a.fetch||(a.fetch=wt,a.Headers=m,a.Request=F,a.Response=x),i.Headers=m,i.Request=F,i.Response=x,i.fetch=wt,Object.defineProperty(i,"__esModule",{value:!0}),i})({})})(r),r.fetch.ponyfill=!0,delete r.fetch.polyfill;var s=t.fetch?t:r;e=s.fetch,e.default=s.fetch,e.fetch=s.fetch,e.Headers=s.Headers,e.Request=s.Request,e.Response=s.Response,n.exports=e})($e,$e.exports)),$e.exports}var Rs=Ps();const Is=is(Rs);/*! 173 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 174 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 175 * 176 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 177 * Unless required by applicable law or agreed to in writing, software 178 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 179 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 180 * 181 * See the License for the specific language governing permissions and limitations under the License. 182 */var Rt;(function(n){n.ACCESS="accessToken",n.ID="idToken",n.REFRESH="refreshToken"})(Rt||(Rt={}));function G(n){return n&&n.accessToken}function X(n){return n&&n.idToken}function ie(n){return n&&n.refreshToken}/*! 183 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 184 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 185 * 186 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 187 * Unless required by applicable law or agreed to in writing, softw
187are 188 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 189 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 190 * 191 * See the License for the specific language governing permissions and limitations under the License. 192 */function he(n,e){var t={};for(var r in n)Object.prototype.hasOwnProperty.call(n,r)&&e.indexOf(r)<0&&(t[r]=n[r]);if(n!=null&&typeof Object.getOwnPropertySymbols=="function")for(var s=0,r=Object.getOwnPropertySymbols(n);s<r.length;s++)e.indexOf(r[s])<0&&Object.prototype.propertyIsEnumerable.call(n,r[s])&&(t[r[s]]=n[r[s]]);return t}/*! 193 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 194 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 195 * 196 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 197 * Unless required by applicable law or agreed to in writing, software 198 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 199 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 200 * 201 * See the License for the specific language governing permissions and limitations under the License. 202 */async function Qt(n,e={}){const t=await n.token.prepareTokenParams(e),r=Jn(n,t);let{flow:s="default",withCredentials:o=!0,activationToken:i=void 0,recoveryToken:a=void 0,maxAge:c=void 0,acrValues:u=void 0}=Object.assign(Object.assign({},n.options),e);return Object.assign(Object.assign({},r),{flow:s,withCredentials:o,activationToken:i,recoveryToken:a,maxAge:c,acrValues:u})}function hr(n,e){const t=ne(n,e);return!!(t!=null&&t.interactionHandle)}function ne(n,e){e=B(e),e=Object.assign(Object.assign({},n.options),e);let t;try{t=n.transactionManager.load(e)}catch{}if(t){if(fr(t,e))return t;K("Saved transaction meta does not match the current configuration. This may indicate that two apps are sharing a storage key.")}}async function xs(n,e){e=B(e),e=Object.assign(Object.assign({},n.options),e);const t=ne(n,e);return t||Qt(n,e)}function Yt(n,e){n.transactionManager.save(e,{muteWarning:!0})}function Ms(n){n.transactionManager.clear()}function fr(n,e={}){if(js(n,e,["issuer","clientId","redirectUri","state","codeChallenge","codeChallengeMethod","activationToken","recoveryToken"])===!1)return!1;const{flow:r}=e;return Cs(n,r)!==!1}function Cs(n,e){return!(e&&e!=="default"&&e!=="proceed"&&e!==n.flow)}function js(n,e,t){return!t.some(s=>{const o=e[s];if(o&&o!==n[s])return!0})}/*! 203 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 204 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 205 * 206 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 207 * Unless required by applicable law or agreed to in writing, software 208 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 209 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 210 * 211 * See the License for the specific language governing permissions and limitations under the License. 212 */function In(n){return{meta:n,interactionHandle:n.interactionHandle,state:n.state}}async function gr(n,e={}){e=B(e);let t=ne(n,e);if(t!=null&&t.interactionHandle)return In(t);t=await Qt(n,Object.assign(Object.assign({},t),e));const r=Gn(n);let{clientId:s,redirectUri:o,state:i,scopes:a,withCredentials:c,codeChallenge:u,codeChallengeMethod:l,activationToken:f,recoveryToken:d,maxAge:p,acrValues:v,nonce:m}=t;const T=e.clientSecret||n.options.clientSecret;c=c??!0;const w=`${r}/v1/interact`,A=Object.assign(Object.assign(Object.assign(Object.assign(Object.assign(Object.assign({client_id:s,scope:a.join(" "),redirect_uri:o,code_challenge:u,code_challenge_method:l,state:i},f&&{activation_token:f}),d&&{recovery_token:d}),T&&{client_secret:T}),p&&{max_age:p}),v&&{acr_values:v}),m&&{nonce:m}),V=(await $(n,{method:"POST",url:w,headers:{"Content-Type":"application/x-www-form-urlencoded"},withCredentials:c,args:A})).interaction_handle,R=Object.assign(Object.assign({},t),{interactionHandle:V,withCredentials:c,state:i,scopes:a,recoveryToken:d,activationToken:f});return Yt(n,R),In(R)}/*! 213 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 214 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 215 * 216 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 217 * Unless required by applicable law or agreed to in writing, softw
217are 218 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 219 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 220 * 221 * See the License for the specific language governing permissions and limitations under the License. 222 */const Us=function(e){return e.mutable!==!1},Ds=function(e){var t,r;const s={},o=[],i={};if(!e.value)return o.push(e),{defaultParamsForAction:s,neededParamsForAction:o,immutableParamsForAction:i};for(let a of e.value)Us(a)?(o.push(a),(t=a.value)!==null&&t!==void 0&&t&&(s[a.name]=a.value)):i[a.name]=(r=a.value)!==null&&r!==void 0?r:"";return{defaultParamsForAction:s,neededParamsForAction:o,immutableParamsForAction:i}},Ns=function(e){e=Array.isArray(e)?e:[e];const t=[],r={},s={};for(let o of e){const{defaultParamsForAction:i,neededParamsForAction:a,immutableParamsForAction:c}=Ds(o);t.push(a),r[o.name]=i,s[o.name]=c}return{defaultParams:r,neededParams:t,immutableParams:s}};/*! 223 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 224 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 225 * 226 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 227 * Unless required by applicable law or agreed to in writing, software 228 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 229 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 230 * 231 * See the License for the specific language governing permissions and limitations under the License. 232 */const Fs=function(e,{actionDefinition:t,defaultParamsForAction:r={},immutableParamsForAction:s={},toPersist:o={}}){const i=t.href;return async function(a={}){var c,u;const l={"Content-Type":"application/json",Accept:t.accepts||"application/ion+json"},f=JSON.stringify(Object.assign(Object.assign(Object.assign({},r),a),s));try{const d={url:i,method:t.method,headers:l,args:f,withCredentials:(c=o==null?void 0:o.withCredentials)!==null&&c!==void 0?c:!0};(t.name==="poll"||((u=t.name)===null||u===void 0?void 0:u.endsWith("-poll")))&&(d.pollingIntent=!0);const v=await $(e,d);return e.idx.makeIdxResponse(Object.assign({},v),o,!0)}catch(d){if(!(d instanceof ue)||!(d!=null&&d.xhr))throw d;const p=d.xhr,v=p.responseJSON||JSON.parse(p.responseText),m=p.headers["WWW-Authenticate"]||p.headers["www-authenticate"],T=e.idx.makeIdxResponse(Object.assign({},v),o,!1);return p.status===401&&m==='Oktadevicejwt realm="Okta Device"'&&(T.stepUp=!0),T}}},It=function(e,t,r){const s=Fs,{defaultParams:o,neededParams:i,immutableParams:a}=Ns(t),c=s(e,{actionDefinition:t,defaultParamsForAction:o[t.name],immutableParamsForAction:a[t.name],toPersist:r});return c.neededParams=i,c};/*! 233 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 234 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 235 * 236 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 237 * Unless required by applicable law or agreed to in writing, software 238 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 239 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 240 * 241 * See the License for the specific language governing permissions and limitations under the License. 242 */const Ls=function(e,t,r={}){return t.reduce((s,o)=>Object.assign(Object.assign({},s),{[o.name]:It(e,o,r)}),{})};/*! 243 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 244 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 245 * 246 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 247 * Unless required by applicable law or agreed to in writing, software 248 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 249 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 250 * 251 * See the License for the specific language governing permissions and limitations under the License. 252 */const Hs=/\$?(?<step>\w+)|(?:\[(?<index>\d+)\])/g;function Vs({path:n,json:e}){var t,r,s;const o=[];let i;for(;(i=Hs.exec(n))!==null;){const u=(r=(t=i==null?void 0:i.groups)===null||t===void 0?void 0:t.step)!==null&&r!==void 0?r:(s=i==null?void 0:i.groups)===null||s===void 0?void 0:s.index;u&&o.push(u)}if(o.length<1)return;const a=o.pop();let c=e;for(const u of o)if(Object.prototype.hasOwnProperty.call(c,u)){if(typeof c[u]!="object")return;c=c[u]}return c[a]}/*! 253 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 254 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 255 * 256 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 257 * Unless required by applicable law or agreed to in writing, softw
257are 258 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 259 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 260 * 261 * See the License for the specific language governing permissions and limitations under the License. 262 */const qs={remediation:!0,context:!0},Bs=function(e,t,r={}){const s={},o={};return Object.keys(t).filter(i=>!qs[i]).forEach(i=>{if(!(typeof t[i]=="object"&&!!t[i])){o[i]=t[i];return}if(t[i].rel){s[t[i].name]=It(e,t[i],r);return}const c=t[i],{value:u,type:l}=c,f=he(c,["value","type"]);if(o[i]=Object.assign({type:l},f),l!=="object"){o[i].value=u;return}o[i].value={},Object.entries(u).forEach(([d,p])=>{p.rel?s[`${i}-${d.name||d}`]=It(e,p,r):o[i].value[d]=p})}),{context:o,actions:s}},pr=(n,e)=>{Object.keys(e).forEach(t=>{if(t==="relatesTo"){const r=Array.isArray(e[t])?e[t][0]:e[t];if(typeof r=="string"){const s=Vs({path:r,json:n});if(s){e[t]=s;return}else throw new g(`Cannot resolve relatesTo: ${r}`)}}Array.isArray(e[t])&&e[t].forEach(r=>pr(n,r))})},Ws=(n,e,t)=>{if(e.rel){const s=Ls(n,[e],t)[e.name];return Object.assign(Object.assign({},e),{action:s})}return e},Ks=function(e,t,r={}){var s;const o=((s=t.remediation)===null||s===void 0?void 0:s.value)||[];o.forEach(u=>{var l;if(u.name==="launch-authenticator"&&((l=u==null?void 0:u.relatesTo)===null||l===void 0?void 0:l[0])==="authenticatorChallenge"&&!(t!=null&&t.authenticatorChallenge)){delete u.relatesTo;return}return pr(t,u)});const i=o.map(u=>Ws(e,u,r)),{context:a,actions:c}=Bs(e,t,r);return{remediations:i,context:a,actions:c}};/*! 263 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 264 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 265 * 266 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 267 * Unless required by applicable law or agreed to in writing, software 268 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 269 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 270 * 271 * See the License for the specific language governing permissions and limitations under the License. 272 */function $s(n,e,t,r){var s,o,i;const a=e,{remediations:c,context:u,actions:l}=Ks(n,e,t),f=[...c],d=async function(m,T={}){const w=c.find(_=>_.name===m);return w?typeof w.action!="function"?Promise.reject(`Current remediation cannot make form submit action: [${m}]`):w.action(T):Promise.reject(`Unknown remediation choice: [${m}]`)},p=m=>m.name==="interaction_code",v=(i=(o=(s=a.successWithInteractionCode)===null||s===void 0?void 0:s.value)===null||o===void 0?void 0:o.find(p))===null||i===void 0?void 0:i.value;return{proceed:d,neededToProceed:f,actions:l,context:u,rawIdxState:a,interactionCode:v,toPersist:t,requestDidSucceed:r}}/*! 273 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 274 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 275 * 276 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 277 * Unless required by applicable law or agreed to in writing, software 278 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 279 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 280 * 281 * See the License for the specific language governing permissions and limitations under the License. 282 */var zs={makeIdxState:$s};/*! 283 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 284 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 285 * 286 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 287 * Unless required by applicable law or agreed to in writing, software 288 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 289 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 290 * 291 * See the License for the specific language governing permissions and limitations under the License. 292 */const mr=function(e){switch(e){case"1.0.0":return zs;case void 0:case null:throw new Error("Api version is required");default:throw new Error(`Unknown api version: ${e}. Use an exact semver version.`)}};function vr(n){if(!n)throw new Error("version is required");if((n??"").replace(/[^0-9a-zA-Z._-]/,"")!==n||!n)throw new Error("invalid version supplied - version is required and uses semver syntax");mr(n)}function yr(n,e,t,r){var s;const o=(s=e==null?void 0:e.version)!==null&&s!==void 0?s:zt;vr(o);const{makeIdxState:i}=mr(o);return i(n,e,t,r)}/*! 293 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 294 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 295 * 296 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 297 * Unless required by applicable law or agreed to in writing, softw
297are 298 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 299 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 300 * 301 * See the License for the specific language governing permissions and limitations under the License. 302 */function wr(n){return n&&n.version}/*! 303 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 304 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 305 * 306 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 307 * Unless required by applicable law or agreed to in writing, software 308 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 309 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 310 * 311 * See the License for the specific language governing permissions and limitations under the License. 312 */function Gs(n){return n instanceof ue}function Tr(n){return n instanceof ye}function Js(n){return n instanceof q}/*! 313 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 314 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 315 * 316 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 317 * Unless required by applicable law or agreed to in writing, software 318 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 319 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 320 * 321 * See the License for the specific language governing permissions and limitations under the License. 322 */async function xt(n,e={}){var t;let r,s;const o=n.transactionManager.loadIdxResponse(e);if(o&&(r=o.rawIdxResponse,s=o.requestDidSucceed),!r){const a=e.version||zt,c=ys(n),{interactionHandle:u,stateHandle:l}=e,f=(t=e.withCredentials)!==null&&t!==void 0?t:!0;try{s=!0,vr(a);const d=`${c}/idp/idx/introspect`,p=l?{stateToken:l}:{interactionHandle:u},v={"Content-Type":`application/ion+json; okta-version=${a}`,Accept:`application/ion+json; okta-version=${a}`};r=await $(n,{method:"POST",url:d,headers:v,withCredentials:f,args:p})}catch(d){if(Gs(d)&&d.xhr&&wr(d.xhr.responseJSON))r=d.xhr.responseJSON,s=!1;else throw d}}const{withCredentials:i}=e;return yr(n,r,{withCredentials:i},s)}/*! 323 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 324 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 325 * 326 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 327 * Unless required by applicable law or agreed to in writing, software 328 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 329 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 330 * 331 * See the License for the specific language governing permissions and limitations under the License. 332 */function Qs(n){var e;return(e=n.value)===null||e===void 0?void 0:e.map(t=>t.name)}function Ys(n){var e;return(e=n.value)===null||e===void 0?void 0:e.reduce((t,r)=>(r.required&&t.push(r.name),t),[])}function ze(n){return n.charAt(0).toUpperCase()+n.substring(1)}function ct(n){return n.value.find(({name:e})=>e==="authenticator")}/*! 333 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 334 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 335 * 336 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 337 * Unless required by applicable law or agreed to in writing, software 338 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 339 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 340 * 341 * See the License for the specific language governing permissions and limitations under the License. 342 */function xn(n){let e;if(st(n))e=n;else if(typeof n=="string")e={key:n};else throw new Error("Invalid format for authenticator");return e}function ge(n,e){return!n||!e?!1:n.id&&e.id?n.id===e.id:n.key&&e.key?n.key===e.key:!1}function Xs(n,e){let t;for(let r of n)if(t=e.find(({relatesTo:s})=>s.key&&s.key===r.key),t)break;return t}/*! 343 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 344 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 345 * 346 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 347 * Unless required by applicable law or agreed to in writing, softw
347are 348 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 349 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 350 * 351 * See the License for the specific language governing permissions and limitations under the License. 352 */class N{constructor(e,t={},r={}){this.values=Object.assign({},t),this.options=Object.assign({},r),this.formatAuthenticators(),this.remediation=e}formatAuthenticators(){if(this.values.authenticators=this.values.authenticators||[],this.values.authenticators=this.values.authenticators.map(e=>xn(e)),this.values.authenticator){const e=xn(this.values.authenticator);this.values.authenticators.some(r=>ge(e,r))||this.values.authenticators.push(e)}this.values.authenticatorsData=this.values.authenticators.reduce((e,t)=>(typeof t=="object"&&Object.keys(t).length>1&&e.push(t),e),this.values.authenticatorsData||[])}getName(){return this.remediation.name}canRemediate(e){return!Ys(this.remediation).find(s=>!this.hasData(s))}getData(e){if(!e)return Qs(this.remediation).reduce((s,o)=>(s[o]=this.getData(o),s),{});if(typeof this[`map${ze(e)}`]=="function"){const t=this[`map${ze(e)}`](this.remediation.value.find(({name:r})=>r===e));if(t)return t}if(this.map&&this.map[e]){const t=this.map[e];for(let r=0;r<t.length;r++){let s=this.values[t[r]];if(s)return s}}return this.values[e]}hasData(e){return!!this.getData(e)}getNextStep(e,t){const r=this.getName(),s=this.getInputs(),o=this.getAuthenticator(),i=o==null?void 0:o.type;return Object.assign(Object.assign({name:r,inputs:s},i&&{type:i}),o&&{authenticator:o})}getInputs(){const e=[];return(this.remediation.value||[]).forEach(r=>{let s,{name:o,type:i,visible:a,messages:c}=r;if(a!==!1){if(typeof this[`getInput${ze(o)}`]=="function")s=this[`getInput${ze(o)}`](r);else if(i!=="object"){let u;const l=(this.map?this.map[o]:null)||[];l.length===1?u=l[0]:u=l.find(f=>Object.keys(this.values).includes(f)),u&&(s=Object.assign(Object.assign({},r),{name:u}))}s||(s=r),Array.isArray(s)?s.forEach(u=>e.push(u)):(c&&(s.messages=c),e.push(s))}}),e}static getMessages(e){var t,r;if(e.value)return(r=(t=e.value[0])===null||t===void 0?void 0:t.form)===null||r===void 0?void 0:r.value.reduce((s,o)=>(o.messages&&(s=[...s,...o.messages.value]),s),[])}getValuesAfterProceed(){const e=this.remediation.value||[],t=this.getInputs(),r=[...e,...t];for(const s of r)delete this.values[s.name];return this.values}getAuthenticator(){var e,t;const r=(e=this.remediation.relatesTo)===null||e===void 0?void 0:e.value;if(!r)return;const s=ct(this.remediation);if(!s)return r;const o=s.form.value.find(({name:a})=>a==="id").value,i=(t=s.form.value.find(({name:a})=>a==="enrollmentId"))===null||t===void 0?void 0:t.value;return Object.assign(Object.assign({},r),{id:o,enrollmentId:i})}}/*! 353 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 354 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 355 * 356 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 357 * Unless required by applicable law or agreed to in writing, software 358 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 359 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 360 * 361 * See the License for the specific language governing permissions and limitations under the License. 362 */function Ye(n){if(Array.isArray(n))return n.map(t=>typeof t=="string"||typeof t=="number"||typeof t=="boolean"?t:Ye(t));const e={};for(const[t,r]of Object.entries(n))if(!(r===null||typeof r>"u"))if(typeof r=="object"){const s=Object.keys(r);if(["value","form"].includes(t)&&s.length===1&&["value","form"].includes(s[0])){const o=Ye(r);Object.entries(o).forEach(([i,a])=>{e[i]=a})}else e[t]=Ye(r)}else e[t]=r;return e}/*! 363 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 364 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 365 * 366 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 367 * Unless required by applicable law or agreed to in writing, softw
367are 368 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 369 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 370 * 371 * See the License for the specific language governing permissions and limitations under the License. 372 */class Xt extends N{canRemediate(){return typeof this.remediation.action!="function"?!1:!!(this.remediation.name==="poll"||this.remediation.name.endsWith("-poll")||this.options.step)}getData(){return this.getInputs().reduce((t,{name:r})=>(t[r]=this.values[r],t),{})}getNextStep(e,t){const r=this.getName(),s=this.getInputs(),o=this.remediation,{href:i,method:a,rel:c,accepts:u,produces:l,value:f,action:d}=o,p=he(o,["href","method","rel","accepts","produces","value","action"]);return d?Object.assign(Object.assign(Object.assign({},p),!!s.length&&{inputs:s}),{action:async v=>e.idx.proceed(Object.assign({step:r},v))}):Object.assign({},this.remediation)}getInputs(){return(this.remediation.value||[]).filter(({name:e})=>e!=="stateHandle").map(Ye).map(e=>(e.type=e.type||"string",e))}}/*! 373 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 374 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 375 * 376 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 377 * Unless required by applicable law or agreed to in writing, software 378 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 379 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 380 * 381 * See the License for the specific language governing permissions and limitations under the License. 382 */const Zt={remediators:{},getFlowSpecification:function(n,e="default"){return{remediators:{}}}};function Zs(n){Object.assign(Zt,n)}function eo(n,e="default"){return Zt.getFlowSpecification(n,e)}function ot(n){const{neededToProceed:e,interactionCode:t}=n;return!e.length&&!t}function to(n){return n.neededToProceed.some(({name:e})=>e==="skip")}function no(n){return Object.keys(n.actions).some(e=>e.includes("resend"))}function Mt(n){if(!(!n||!Array.isArray(n)))return n.reduce((e,t)=>{if(t.messages&&(e=[...e,...t.messages.value]),t.form){const r=Mt(t.form.value)||[];e=[...e,...r]}if(t.options){let r=[];t.options.forEach(o=>{!o.value||typeof o.value=="string"||(r=[...r,o.value])});const s=Mt(r)||[];e=[...e,...s]}return e},[])}function Sr(n,e){var t;let r=[];const{rawIdxState:s,neededToProceed:o}=n,i=(t=s.messages)===null||t===void 0?void 0:t.value.map(c=>c);if(i&&(r=[...r,...i]),!e.useGenericRemediator)for(let c of o){const u=Mt(c.value);u&&(r=[...r,...u])}const a={};return r=r.reduce((c,u)=>{var l;const f=(l=u.i18n)===null||l===void 0?void 0:l.key;return f&&a[f]&&u.message===a[f].message||(a[f]=u,c=[...c,u]),c},[]),r}function ro(n){const e=[],{actions:t,neededToProceed:r}=n;return t["currentAuthenticator-recover"]&&e.push(Y.PASSWORD_RECOVERY),r.some(({name:s})=>s==="select-enroll-profile")&&e.push(Y.REGISTRATION),r.some(({name:s})=>s==="redirect-idp")&&e.push(Y.SOCIAL_IDP),r.some(({name:s})=>s==="unlock-account")&&e.push(Y.ACCOUNT_UNLOCK),e}function so(n,e,t){var r;const s=[],o=Object.values(Zt.remediators).reduce((i,a)=>(a.remediationName&&(i[a.remediationName]=a),i),{});for(let i of e.neededToProceed){const a=Ct(i,{useGenericRemediator:t,remediators:o});if(a){const c=new a(i);s.push(c.getNextStep(n,e.context))}}for(const[i]of Object.entries(e.actions||{})){let a={name:i,action:async c=>n.idx.proceed({actions:[{name:i,params:c}]})};if(i.startsWith("currentAuthenticator")){const[c,u]=ps(i,"-"),l=e.rawIdxState[c].value[u],f=he(l,["href","method","rel","accepts","produces"]),d=(r=l.value)===null||r===void 0?void 0:r.filter(p=>p.name!=="stateHandle");a=Object.assign(Object.assign(Object.assign({},f),d&&{value:d}),a)}s.push(a)}return s}function oo(n,e,t){const s=(n.neededToProceed||[]).find(i=>i.name===e);return s?s.value.reduce((i,a)=>{const{name:c,value:u}=a;return c==="stateHandle"?i[c]=u:i[c]=t[c],i},{}):(K(`filterValuesForRemediation: "${e}" did not match any remediations`),t)}function Ct(n,e){const{useGenericRemediator:t,remediators:r}=e;if(n)return t?Xt:r[n.name]}function jt(n,e,t){const r=t.remediators,s=t.useGenericRemediator,{neededToProceed:o,context:i}=n;let a;if(t.step){const u=o.find(({name:l})=>l===t.step);if(u){const l=Ct(u,t);return l?new l(u,e,t):void 0}
382else{K(`step "${t.step}" did not match any remediations`);return}}const c=[];if(s)c.push(new Xt(o[0],e,t));else for(let u of o){if(!Object.keys(r).includes(u.name))continue;const f=Ct(u,t);if(a=new f(u,e,t),a.canRemediate(i))return a;c.push(a)}return c[0]}function Ut(n,e,t){const r=e.getNextStep(n,t.context),s=to(t),o=no(t);return Object.assign(Object.assign(Object.assign({},r),s&&{canSkip:s}),o&&{canResend:o})}function Ge(n,e,t={}){const r=ot(e),s=Sr(e,t);if(r)return{idxResponse:e,terminal:r,messages:s};{const o=jt(e,{},t),i=o&&Ut(n,o,e);return Object.assign({idxResponse:e,messages:s},i&&{nextStep:i})}}/*! 383 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 384 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 385 * 386 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 387 * Unless required by applicable law or agreed to in writing, software 388 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 389 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 390 * 391 * See the License for the specific language governing permissions and limitations under the License. 392 */function io(n,e){return Object.keys(e.actions).find(t=>!!n.resend&&t.includes("-resend"))}function ao(n){return Object.assign(Object.assign({},n),{resend:void 0})}function co(n,e){let t=n.actions||[];return t=t.filter(r=>typeof r=="string"?r!==e:r.name!==e),Object.assign(Object.assign({},n),{actions:t})}async function Xe(n,e,t,r){let{neededToProceed:s,interactionCode:o}=e;const{flow:i}=r;if(o)return{idxResponse:e};const a=jt(e,t,r),c=io(t,e),l=[...r.actions||[],...c&&[c]||[]];if(l)for(let v of l){let m={};typeof v!="string"&&(m=v.params||{},v=v.name);let T=ao(t),w=co(r,v);if(typeof e.actions[v]=="function")return e=await e.actions[v](m),e.requestDidSucceed===!1?Ge(n,e,r):v==="cancel"?{idxResponse:e,canceled:!0}:Xe(n,e,T,w);if(s.find(({name:_})=>_===v))return e=await e.proceed(v,m),e.requestDidSucceed===!1?Ge(n,e,r):Xe(n,e,t,w)}const f=ot(e);if(f)return{idxResponse:e,terminal:f};if(!a){if(r.step)return t=oo(e,r.step,t),e=await e.proceed(r.step,t),e.requestDidSucceed===!1?Ge(n,e,r):{idxResponse:e};if(i==="default")return{idxResponse:e};throw new g(` 393 No remediation can match current flow, check policy settings in your org. 394 Remediations: [${s.reduce((v,m)=>v?v+" ,"+m.name:m.name,"")}] 395 `)}if(!a.canRemediate()){const v=Ut(n,a,e);return{idxResponse:e,nextStep:v}}const d=a.getName(),p=a.getData();if(e=await e.proceed(d,p),e.requestDidSucceed===!1)return Ge(n,e,r);if(t=a.getValuesAfterProceed(),r=Object.assign(Object.assign({},r),{step:void 0}),r.useGenericRemediator&&!e.interactionCode&&!ot(e)){const v=jt(e,t,r),m=Ut(n,v,e);return{idxResponse:e,nextStep:m}}return Xe(n,e,t,r)}/*! 396 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 397 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 398 * 399 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 400 * Unless required by applicable law or agreed to in writing, software 401 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 402 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 403 * 404 * See the License for the specific language governing permissions and limitations under the License. 405 */function uo(n){const e=["flow","remediators","actions","withCredentials","step","useGenericRemediator","exchangeCodeForTokens"],t=Object.assign({},n);return e.forEach(r=>{delete t[r]}),t}function lo(n,e){var t,r,s,o;let{options:i}=e;i=Object.assign(Object.assign({},n.options.idx),i);let{flow:a,withCredentials:c,remediators:u,actions:l}=i;const f=oe.PENDING;if(a=a||((r=(t=n.idx).getFlow)===null||r===void 0?void 0:r.call(t))||"default",a){(o=(s=n.idx).setFlow)===null||o===void 0||o.call(s,a);const d=eo(n,a);c=typeof c<"u"?c:d.withCredentials,u=u||d.remediators,l=l||d.actions}return Object.assign(Object.assign({},e),{options:Object.assign(Object.assign({},i),{flow:a,withCredentials:c,remediators:u,actions:l}),status:f})}async function ho(n,e){const{options:t}=e,{stateHandle:r,withCredentials:s,version:o,state:i,scopes:a,recoveryToken:c,activationToken:u,maxAge:l,acrValues:f,nonce:d,useGenericRemediator:p}=t;let v,m=ne(n,{state:i,recoveryToken:c,activationToken:u});if(r)v=await xt(n,{withCredentials:s,version:o,stateHandle:r,useGenericRemediator:p});else{let T=m==null?void 0:m.interactionHandle;if(!T){n.transactionManager.clear();const w=await gr(n,{withCredentials:s,state:i,scopes:a,activationToken:u,recoveryToken:c,maxAge:l,acrValues:f,nonce:d});T=w.interactionHandle,m=w.meta}v=await xt(n,{withCredentials:s,version:o,interactionHandle:T,useGenericRemediator:p})}return Object.assign(Object.assign({},e),{idxResponse:v,meta:m})}async function fo(n,e){let{idxResponse:t,options:r,values:s}=e;const{autoRemediate:o,remediators:i,actions:a,flow:c,step:u,useGenericRemediator:l}=r;if(!(o!==!1&&(i||a||u)))return e;s=Object.assign(Object.assign({},s),{stateHandle:t.rawIdxState.stateHandle});const{idxResponse:d,nextStep:p,canceled:v}=await Xe(n,t,s,{remediators:i,actions:a,flow:c,step:u,useGenericRemediator:l});return t=d,Object.assign(Object.assign({},e),{idxResponse:t,nextStep:p,canceled:v})}async function go(n,e){let{meta:t,idxResponse:r}=e;const{interactionCode:s}=r,{clientId:o,codeVerifier:i,ignoreSignature:a,redirectUri:c,urls:u,scopes:l}=t;return(await n.token.exchangeCodeForTokens({interactionCode:s,clientId:o,codeVerifier:i,ignoreSignature:a,redirectUri:c,scopes:l},u)).tokens}async function po(n,e){let{options:t,idxResponse:r,canceled:s,status:o}=e;const{exchangeCodeForTokens:i}=t;let a=!1,c=!1,u=!0,l,f,d,p,v,m;if(r&&(a=!!(r.requestDidSucceed||r.stepUp),d=ro(r),p=so(n,r,t.useGenericRemediator),v=Sr(r,t),m=ot(r)),m){o=oe.TERMINAL;const T=Object.keys(r.actions).length>
4050,w=!!v.find(_=>_.class==="ERROR");!T&&!w&&r.requestDidSucceed===!0?c=!0:a=!!T,u=!1}else s?(o=oe.CANCELED,c=!0):r!=null&&r.interactionCode&&(l=r.interactionCode,i===!1?(o=oe.SUCCESS,c=!1):(f=await go(n,e),o=oe.SUCCESS,c=!0));return Object.assign(Object.assign({},e),{status:o,interactionCode:l,tokens:f,shouldSaveResponse:a,shouldClearTransaction:c,clearSharedStorage:u,enabledFeatures:d,availableSteps:p,messages:v,terminal:m})}async function fe(n,e={}){var t;let r={options:e,values:uo(e)};r=lo(n,r),r=await ho(n,r),r=await fo(n,r),r=await po(n,r);const{idxResponse:s,meta:o,shouldSaveResponse:i,shouldClearTransaction:a,clearSharedStorage:c,status:u,enabledFeatures:l,availableSteps:f,tokens:d,nextStep:p,messages:v,error:m,interactionCode:T}=r;if(a)n.transactionManager.clear({clearSharedStorage:c});else if(Yt(n,Object.assign({},o)),i){const{rawIdxState:re,requestDidSucceed:F}=s;n.transactionManager.saveIdxResponse({rawIdxResponse:re,requestDidSucceed:F,stateHandle:(t=s.context)===null||t===void 0?void 0:t.stateHandle,interactionHandle:o==null?void 0:o.interactionHandle})}const{actions:w,context:A,neededToProceed:_,proceed:b,rawIdxState:V,requestDidSucceed:R,stepUp:W}=s||{};return Object.assign(Object.assign(Object.assign(Object.assign(Object.assign(Object.assign(Object.assign(Object.assign(Object.assign({status:u},o&&{meta:o}),l&&{enabledFeatures:l}),f&&{availableSteps:f}),d&&{tokens:d}),p&&{nextStep:p}),v&&v.length&&{messages:v}),m&&{error:m}),W&&{stepUp:W}),{interactionCode:T,actions:w,context:A,neededToProceed:_,proceed:b,rawIdxState:V,requestDidSucceed:R})}/*! 406 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 407 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 408 * 409 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 410 * Unless required by applicable law or agreed to in writing, software 411 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 412 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 413 * 414 * See the License for the specific language governing permissions and limitations under the License. 415 */async function mo(n,e={}){return e.password&&!e.authenticator&&(e.authenticator=z.OKTA_PASSWORD),fe(n,Object.assign(Object.assign({},e),{flow:"authenticate"}))}/*! 416 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 417 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 418 * 419 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 420 * Unless required by applicable law or agreed to in writing, software 421 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 422 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 423 * 424 * See the License for the specific language governing permissions and limitations under the License. 425 */class Oe{constructor(e){this.meta=e}}/*! 426 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 427 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 428 * 429 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 430 * Unless required by applicable law or agreed to in writing, software 431 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 432 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 433 * 434 * See the License for the specific language governing permissions and limitations under the License. 435 */class br extends Oe{canVerify(e){return!!(e.credentials||e.verificationCode||e.otp)}mapCredentials(e){const{credentials:t,verificationCode:r,otp:s}=e;if(!(!t&&!r&&!s))return t||{passcode:r||s}}getInputs(e){var t;return Object.assign(Object.assign({},(t=e.form)===null||t===void 0?void 0:t.value[0]),{name:"verificationCode",type:"string",required:e.required})}}/*! 436 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 437 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 438 * 439 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 440 * Unless required by applicable law or agreed to in writing, softw
440are 441 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 442 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 443 * 444 * See the License for the specific language governing permissions and limitations under the License. 445 */class vo extends br{mapCredentials(e){const{verificationCode:t}=e;if(t)return{totp:t}}}/*! 446 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 447 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 448 * 449 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 450 * Unless required by applicable law or agreed to in writing, software 451 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 452 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 453 * 454 * See the License for the specific language governing permissions and limitations under the License. 455 */class Or extends Oe{canVerify(e){return!!(e.credentials||e.password||e.passcode)}mapCredentials(e){const{credentials:t,password:r,passcode:s,revokeSessions:o}=e;if(!(!t&&!r&&!s))return t||{passcode:s||r,revokeSessions:o}}getInputs(e){var t,r;const s=[Object.assign(Object.assign({},(t=e.form)===null||t===void 0?void 0:t.value[0]),{name:"password",type:"string",required:e.required})];return((r=e.form)===null||r===void 0?void 0:r.value.find(i=>i.name==="revokeSessions"))&&s.push({name:"revokeSessions",type:"boolean",label:"Sign me out of all other devices",required:!1}),s}}/*! 456 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 457 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 458 * 459 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 460 * Unless required by applicable law or agreed to in writing, software 461 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 462 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 463 * 464 * See the License for the specific language governing permissions and limitations under the License. 465 */class yo extends Oe{canVerify(e){const{credentials:t}=e;if(t&&t.questionKey&&t.answer)return!0;const{questionKey:r,question:s,answer:o}=e;return!!(r&&o)||!!(s&&o)}mapCredentials(e){const{questionKey:t,question:r,answer:s}=e;
465if(!(!s||!t&&!r))return{questionKey:r?"custom":t,question:r,answer:s}}getInputs(){return[{name:"questionKey",type:"string",required:!0},{name:"question",type:"string",label:"Create a security question"},{name:"answer",type:"string",label:"Answer",required:!0}]}}/*! 466 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 467 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 468 * 469 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 470 * Unless required by applicable law or agreed to in writing, software 471 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 472 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 473 * 474 * See the License for the specific language governing permissions and limitations under the License. 475 */class wo extends Oe{canVerify(e){const{credentials:t}=e;if(t&&t.answer)return!0;const{answer:r}=e;return!!r}mapCredentials(e){const{answer:t}=e;if(t)return{questionKey:this.meta.contextualData.enrolledQuestion.questionKey,answer:t}}getInputs(){return[{name:"answer",type:"string",label:"Answer",required:!0}]}}/*! 476 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 477 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 478 * 479 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 480 * Unless required by applicable law or agreed to in writing, software 481 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 482 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 483 * 484 * See the License for the specific language governing permissions and limitations under the License. 485 */class To extends Oe{canVerify(e){const{credentials:t}=e,r=t||e,{clientData:s,attestation:o}=r;return!!(s&&o)}mapCredentials(e){const{credentials:t,clientData:r,attestation:s,transports:o}=e;if(!(!t&&!r&&!s))return t||Object.assign({clientData:r,attestation:s},o&&{transports:o})}getInputs(){return[{name:"clientData",type:"string",required:!0,visible:!1,label:"Client Data"},{name:"attestation",type:"string",required:!0,visible:!1,label:"Attestation"}]}}/*! 486 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 487 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 488 * 489 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 490 * Unless required by applicable law or agreed to in writing, software 491 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 492 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 493 * 494 * See the License for the specific language governing permissions and limitations under the License. 495 */class So extends Oe{canVerify(e){const{credentials:t}=e,r=t||e,{clientData:s,authenticatorData:o,signatureData:i}=r;return!!(s&&o&&i)}mapCredentials(e){const{credentials:t,authenticatorData:r,clientData:s,signatureData:o}=e;if(!(!t&&!r&&!s&&!o))return t||{authenticatorData:r,clientData:s,signatureData:o}}getInputs(){return[{name:"authenticatorData",type:"string",label:"Authenticator Data",required:!0,visible:!1},{name:"clientData",type:"string",label:"Client Data",required:!0,visible:!1},{name:"signatureData",type:"string",label:"Signature Data",required:!0,visible:!1}]}}/*! 496 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 497 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 498 * 499 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 500 * Unless required by applicable law or agreed to in writing, software 501 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 502 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 503 * 504 * See the License for the specific language governing permissions and limitations under the License. 505 */function bo(n){var e,t;const r=n.relatesTo,s=(r==null?void 0:r.value)||{};switch(s.key){case z.OKTA_PASSWORD:return new Or(s);case z.SECURITY_QUESTION:return!((e=s.contextualData)===null||e===void 0)&&e.enrolledQuestion?new wo(s):new yo(s);case z.OKTA_VERIFY:return new vo(s);case z.WEBAUTHN:return!((t=s.contextualData)===null||t===void 0)&&t.challengeData?new So(s):new To(s);default:return new br(s)}}/*! 506 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 507 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 508 * 509 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 510 * Unless required by applicable law or agreed to in writing, softw
510are 511 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 512 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 513 * 514 * See the License for the specific language governing permissions and limitations under the License. 515 */class en extends N{constructor(e,t={}){super(e,t),this.authenticator=bo(e)}getNextStep(e,t){var r;const s=super.getNextStep(e,t),o=(r=t==null?void 0:t.authenticatorEnrollments)===null||r===void 0?void 0:r.value;return Object.assign(Object.assign({},s),{authenticatorEnrollments:o})}canRemediate(){return this.authenticator.canVerify(this.values)}mapCredentials(){return this.authenticator.mapCredentials(this.values)}getInputCredentials(e){return this.authenticator.getInputs(e)}getValuesAfterProceed(){return this.values=super.getValuesAfterProceed(),Object.keys(this.values).filter(t=>t!=="credentials").reduce((t,r)=>Object.assign(Object.assign({},t),{[r]:this.values[r]}),{})}}/*! 516 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 517 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 518 * 519 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 520 * Unless required by applicable law or agreed to in writing, software 521 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 522 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 523 * 524 * See the License for the specific language governing permissions and limitations under the License. 525 */class ut extends en{}ut.remediationName="enroll-authenticator";/*! 526 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 527 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 528 * 529 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 530 * Unless required by applicable law or agreed to in writing, software 531 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 532 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 533 * 534 * See the License for the specific language governing permissions and limitations under the License. 535 */class Ae extends N{canRemediate(){return!!this.values.startPolling||this.options.step==="enroll-poll"}getNextStep(e,t){const r=super.getNextStep(e,t);let s=this.getAuthenticator();return!s&&(t!=null&&t.currentAuthenticator)&&(s=t.currentAuthenticator.value),Object.assign(Object.assign({},r),{authenticator:s,poll:{required:!0,refresh:this.remediation.refresh}})}getValuesAfterProceed(){return Object.keys(this.values).filter(t=>t!=="startPolling").reduce((t,r)=>Object.assign(Object.assign({},t),{[r]:this.values[r]}),{})}}Ae.remediationName="enroll-poll";/*! 536 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 537 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 538 * 539 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 540 * Unless required by applicable law or agreed to in writing, software 541 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 542 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 543 * 544 * See the License for the specific language governing permissions and limitations under the License. 545 */class lt extends N{canRemediate(){if(this.values.channel)return!0;if(this.values.authenticator){const{id:e,channel:t}=this.values.authenticator;if(e&&t)return!0}return!1}getNextStep(e,t){const r=super.getNextStep(e,t),s=t.currentAuthenticator.value;return Object.assign(Object.assign({},r),{authenticator:s})}getData(){var e;return{authenticator:{id:this.remediation.value[0].value.form.value[0].value,channel:((e=this.values.authenticator)===null||e===void 0?void 0:e.channel)||this.values.channel},stateHandle:this.values.stateHandle}}getValuesAfterProceed(){this.values=super.getValuesAfterProceed(),delete this.values.authenticators;const e=this.values.channel?"channel":"authenticator";return Object.keys(this.values).filter(r=>r!==e).reduce((r,s)=>Object.assign(Object.assign({},r),{[s]:this.values[s]}),{})}}lt.remediationName="select-enrollment-channel";/*! 546 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 547 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 548 * 549 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 550 * Unless required by applicable law or agreed to in writing, softw
550are 551 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 552 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 553 * 554 * See the License for the specific language governing permissions and limitations under the License. 555 */class dt extends N{getInputEmail(){return[{name:"email",type:"string",required:!0,label:"Email"}]}getInputPhoneNumber(){return[{name:"phoneNumber",type:"string",required:!0,label:"Phone Number"}]}canRemediate(){return!!(this.values.email||this.values.phoneNumber)}getNextStep(e,t){const r=super.getNextStep(e,t),s=t.currentAuthenticator.value;return Object.assign(Object.assign({},r),{authenticator:s})}getData(){return{stateHandle:this.values.stateHandle,email:this.values.email,phoneNumber:this.values.phoneNumber}}getValuesAfterProceed(){return Object.keys(this.values).filter(t=>!["email","phoneNumber"].includes(t)).reduce((t,r)=>Object.assign(Object.assign({},t),{[r]:this.values[r]}),{})}}dt.remediationName="enrollment-channel-data";/*! 556 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 557 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 558 * 559 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 560 * Unless required by applicable law or agreed to in writing, software 561 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 562 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 563 * 564 * See the License for the specific language governing permissions and limitations under the License. 565 */class Ce extends en{}Ce.remediationName="challenge-authenticator";/*! 566 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 567 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 568 * 569 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 570 * Unless required by applicable law or agreed to in writing, software 571 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 572 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 573 * 574 * See the License for the specific language governing permissions and limitations under the License. 575 */class ht extends Ae{canRemediate(){return!!this.values.startPolling||this.options.step==="challenge-poll"}}ht.remediationName="challenge-poll";/*! 576 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 577 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 578 * 579 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 580 * Unless required by applicable law or agreed to in writing, software 581 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 582 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 583 * 584 * See the License for the specific language governing permissions and limitations under the License. 585 */class tn extends en{}tn.remediationName="reset-authenticator";/*! 586 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 587 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 588 * 589 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 590 * Unless required by applicable law or agreed to in writing, software 591 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 592 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 593 * 594 * See the License for the specific language governing permissions and limitations under the License. 595 */class nn extends N{constructor(e,t={},r={}){super(e,t,r),this.authenticator=null,this.getCredentialsFromRemediation()&&(this.authenticator=this.authenticator=new Or({}))}canRemediate(){if(this.authenticator&&!this.authenticator.canVerify(this.values))return!1;const e=this.getData().userProfile;return e?this.remediation.value.find(({name:r})=>r==="userProfile").form.value.reduce((r,s)=>(s.required&&(r=r&&!!e[s.name]),r),!0):!1}getCredentialsFromRemediation(){return this.remediation.value.find(({name:e})=>e==="credentials")}mapUserProfile({form:{value:e}}){const r=e.map(({name:s})=>s).reduce((s,o)=>this.values[o]?Object.assign(Object.assign({},s),{[o]:this.values[o]}):s,{});if(Object.keys(r).length!==0)return r}mapCredentials(){const e=this.authenticator&&this.authenticator.mapCredentials(this.values);if(e)return e}getInputUserProfile(e){return[...e.form.value]}getInputCredentials(e){return[...e.form.value]}getErrorMessages(e){return e.value[0].form.value.reduce((t,r)=>(r.messages&&t.push(r.messages.value[0].message),t),[])}}nn.remediationName="enroll-profile";/*! 596 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 597 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 598 * 599 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 600 * Unless required by applicable law or agreed to in writing, softw
600are 601 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 602 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 603 * 604 * See the License for the specific language governing permissions and limitations under the License. 605 */class Te extends N{constructor(){super(...arguments),this.map={identifier:["username"]}}canRemediate(){const{identifier:e}=this.getData();return!!e}mapCredentials(){const{credentials:e,password:t}=this.values;if(!(!e&&!t))return e||{passcode:t}}getInputCredentials(e){return Object.assign(Object.assign({},e.form.value[0]),{name:"password",required:e.required})}}Te.remediationName="identify";/*! 606 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 607 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 608 * 609 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 610 * Unless required by applicable law or agreed to in writing, software 611 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 612 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 613 * 614 * See the License for the specific language governing permissions and limitations under the License. 615 */class je extends N{mapCredentials(){const{newPassword:e}=this.values;if(e)return{passcode:e}}getInputCredentials(e){const r=this.getAuthenticator().type==="password"?"newPassword":"verificationCode";return Object.assign(Object.assign({},e.form.value[0]),{name:r})}}je.remediationName="reenroll-authenticator";/*! 616 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 617 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 618 * 619 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 620 * Unless required by applicable law or agreed to in writing, software 621 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 622 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 623 * 624 * See the License for the specific language governing permissions and limitations under the License. 625 */class Ue extends je{}Ue.remediationName="reenroll-authenticator-warning";/*! 626 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 627 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 628 * 629 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 630 * Unless required by applicable law or agreed to in writing, software 631 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 632 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 633 * 634 * See the License for the specific language governing permissions and limitations under the License. 635 */class rn extends N{canRemediate(){return!1}getNextStep(){const{name:e,type:t,idp:r,href:s}=this.remediation;return{name:e,type:t,idp:r,href:s}}}rn.remediationName="redirect-idp";/*! 636 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 637 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 638 * 639 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 640 * Unless required by applicable law or agreed to in writing, software 641 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 642 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 643 * 644 * See the License for the specific language governing permissions and limitations under the License. 645 */class sn extends N{findMatchedOption(e,t){let r;for(let s of e)if(r=t.find(({relatesTo:o})=>o.key&&o.key===s.key),r)break;return r}canRemediate(e){var t,r;const{authenticators:s,authenticator:o}=this.values,i=ct(this.remediation),{options:a}=i;if(!s||!s.length)return!1;if(st(o)&&o.id)return!0;const c=this.findMatchedOption(s,a);if(c){const u=(e==null?void 0:e.currentAuthenticator)&&(e==null?void 0:e.currentAuthenticator.value.id)===((t=c.relatesTo)===null||t===void 0?void 0:t.id),l=(e==null?void 0:e.currentAuthenticatorEnrollment)&&(e==null?void 0:e.currentAuthenticatorEnrollment.value.id)===((r=c.relatesTo)===null||r===void 0?void 0:r.id);return!u&&!l}return!1}mapAuthenticator(e){const{authenticators:t,authenticator:r}=this.values;if(st(r)&&r.id)return this.selectedAuthenticator=r,r;const{options:s}=e,o=Xs(t,s);return this.selectedAuthenticator=o.relatesTo,this.selectedOption=o,{id:o==null?void 0:o.value.form.value.find(({name:i})=>i==="id").value}}getInputAuthenticator(e){return{name:"authenticator",type:"string",options:e.options.map(({label:r,relatesTo:s})=>({label:r,value:s.key}))}}getValuesAfterProceed(){this.values=super.getValuesAfterProceed();const e=this.values.authenticators.filter(t=>ge(t,this.selectedAuthenticator)!==!0);return Object.assign(Object.assign({},this.values),{authenticators:e})}}/*! 646 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 647 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 648 * 649 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 650 * Unless required by applicable law or agreed to in writing, softw
650are 651 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 652 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 653 * 654 * See the License for the specific language governing permissions and limitations under the License. 655 */class De extends sn{constructor(e,t={},r={}){var s;super(e,t,r);const o=this.options.flow==="recoverPassword";((s=ct(e).options)===null||s===void 0?void 0:s.some(({relatesTo:a})=>(a==null?void 0:a.key)===z.OKTA_PASSWORD))&&(o||this.values.password)&&(this.values.authenticators=[...this.values.authenticators||[],{key:z.OKTA_PASSWORD}])}}De.remediationName="select-authenticator-authenticate";/*! 656 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 657 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 658 * 659 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 660 * Unless required by applicable law or agreed to in writing, software 661 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 662 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 663 * 664 * See the License for the specific language governing permissions and limitations under the License. 665 */class Ne extends sn{}Ne.remediationName="select-authenticator-enroll";/*! 666 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 667 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 668 * 669 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 670 * Unless required by applicable law or agreed to in writing, software 671 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 672 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 673 * 674 * See the License for the specific language governing permissions and limitations under the License. 675 */class on extends sn{constructor(){super(...arguments),this.map={identifier:["username"]}}canRemediate(){return!!this.getData("identifier")&&super.canRemediate()}mapAuthenticator(e){var t,r,s;const o=super.mapAuthenticator(e),i=(t=this.selectedOption)===null||t===void 0?void 0:t.value.form.value.find(({name:c})=>c==="methodType"),a=this.values.methodType||(i==null?void 0:i.value)||((s=(r=i==null?void 0:i.options)===null||r===void 0?void 0:r[0])===null||s===void 0?void 0:s.value);return a?Object.assign(Object.assign({},o),{methodType:a}):o}getInputUsername(){return{name:"username",type:"string"}}}on.remediationName="select-authenticator-unlock-account";/*! 676 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 677 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 678 * 679 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 680 * Unless required by applicable law or agreed to in writing, software 681 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 682 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 683 * 684 * See the License for the specific language governing permissions and limitations under the License. 685 */class an extends N{canRemediate(){return!0}}an.remediationName="select-enroll-profile";/*! 686 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 687 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 688 * 689 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 690 * Unless required by applicable law or agreed to in writing, software 691 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 692 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 693 * 694 * See the License for the specific language governing permissions and limitations under the License. 695 */class Ar extends N{constructor(e,t={}){super(e,t),this.authenticator=this.getAuthenticator(),this.formatAuthenticatorData()}formatAuthenticatorData(){if(this.getAuthenticatorData())this.values.authenticatorsData=this.values.authenticatorsData.map(t=>ge(this.authenticator,t)?this.mapAuthenticatorDataFromValues(t):t);else{const t=this.mapAuthenticatorDataFromValues();t&&this.values.authenticatorsData.push(t)}}getAuthenticatorData(){return this.values.authenticatorsData.find(e=>ge(this.authenticator,e))}canRemediate(){return this.values.authenticatorsData.some(e=>ge(this.authenticator,e))}mapAuthenticatorDataFromValues(e){let{methodType:t,authenticator:r}=this.values;!t&&st(r)&&(t=r==null?void 0:r.methodType);const{id:s,enrollmentId:o}=this.authenticator,i=Object.assign(Object.assign({id:s,enrollmentId:o},e&&e),t&&{methodType:t});return i.methodType?i:null}getAuthenticatorFromRemediation(){return this.remediation.value.find(({name:t})=>t==="authenticator")}getValuesAfterProceed(){this.values=super.getValuesAfterProceed();const e=this.values.authenticatorsData.filter(t=>ge(this.authenticator,t)!==!0);return Object.assign(Object.assign({},this.values),{authenticatorsData:e})}}/*! 696 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 697 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 698 * 699 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 700 * Unless required by applicable law or agreed to in writing, softw
700are 701 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 702 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 703 * 704 * See the License for the specific language governing permissions and limitations under the License. 705 */class Fe extends Ar{mapAuthenticator(){return this.getAuthenticatorData()}getInputAuthenticator(){const e=this.getAuthenticatorFromRemediation(),t=e.form.value.find(({name:s})=>s==="methodType");return t&&t.options?{name:"methodType",type:"string",required:!0,options:t.options}:[...e.form.value]}getValuesAfterProceed(){return this.values=super.getValuesAfterProceed(),Object.keys(this.values).filter(t=>t!=="authenticator").reduce((t,r)=>Object.assign(Object.assign({},t),{[r]:this.values[r]}),{})}}Fe.remediationName="authenticator-verification-data";/*! 706 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 707 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 708 * 709 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 710 * Unless required by applicable law or agreed to in writing, software 711 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 712 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 713 * 714 * See the License for the specific language governing permissions and limitations under the License. 715 */class Le extends Ar{mapAuthenticator(){const e=this.getAuthenticatorData();return{id:ct(this.remediation).form.value.find(({name:r})=>r==="id").value,methodType:e.methodType,phoneNumber:e.phoneNumber}}getInputAuthenticator(e){return[{name:"methodType",type:"string"},{name:"phoneNumber",label:"Phone Number",type:"string"}].map(t=>{const r=e.form.value.find(s=>s.name===t.name);return Object.assign(Object.assign({},r),t)})}mapAuthenticatorDataFromValues(e){e=super.mapAuthenticatorDataFromValues(e);const{phoneNumber:t}=this.values;if(!(!e&&!t))return Object.assign(Object.assign({},e&&e),t&&{phoneNumber:t})}}Le.remediationName="authenticator-enrollment-data";/*! 716 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 717 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 718 * 719 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 720 * Unless required by applicable law or agreed to in writing, software 721 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 722 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 723 * 724 * See the License for the specific language governing permissions and limitations under the License. 725 */class ft extends N{canRemediate(){return!!this.values.skip||this.options.step==="skip"}}ft.remediationName="skip";/*! 726 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 727 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 728 * 729 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 730 * Unless required by applicable law or agreed to in writing, software 731 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 732 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 733 * 734 * See the License for the specific language governing permissions and limitations under the License. 735 */const Mn={identify:Te,"select-authenticator-authenticate":De,"select-authenticator-enroll":Ne,"authenticator-enrollment-data":Le,"authenticator-verification-data":Fe,"enroll-authenticator":ut,"challenge-authenticator":Ce,"challenge-poll":ht,"reenroll-authenticator":je,"reenroll-authenticator-warning":Ue,"enroll-poll":Ae,"select-enrollment-channel":lt,"enrollment-channel-data":dt,"redirect-idp":rn,skip:ft};/*! 736 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 737 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 738 * 739 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 740 * Unless required by applicable law or agreed to in writing, softw
740are 741 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 742 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 743 * 744 * See the License for the specific language governing permissions and limitations under the License. 745 */const Oo={identify:Te,"identify-recovery":Te,"select-authenticator-authenticate":De,"select-authenticator-enroll":Ne,"challenge-authenticator":Ce,"authenticator-verification-data":Fe,"authenticator-enrollment-data":Le,"reset-authenticator":tn,"reenroll-authenticator":je,"reenroll-authenticator-warning":Ue,"enroll-poll":Ae};/*! 746 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 747 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 748 * 749 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 750 * Unless required by applicable law or agreed to in writing, software 751 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 752 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 753 * 754 * See the License for the specific language governing permissions and limitations under the License. 755 */const Ao={"select-enroll-profile":an,"enroll-profile":nn,"authenticator-enrollment-data":Le,"select-authenticator-enroll":Ne,"enroll-poll":Ae,"select-enrollment-channel":lt,"enrollment-channel-data":dt,"enroll-authenticator":ut,skip:ft};/*! 756 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 757 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 758 * 759 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 760 * Unless required by applicable law or agreed to in writing, software 761 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 762 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 763 * 764 * See the License for the specific language governing permissions and limitations under the License. 765 */const ko={identify:Te,"select-authenticator-unlock-account":on,"select-authenticator-authenticate":De,"challenge-authenticator":Ce,"challenge-poll":ht,"authenticator-verification-data":Fe,"reenroll-authenticator-warning":Ue};/*! 766 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 767 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 768 * 769 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 770 * Unless required by applicable law or agreed to in writing, software 771 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 772 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 773 * 774 * See the License for the specific language governing permissions and limitations under the License. 775 */function cn(n,e="default"){let t,r,s=!0;switch(e){case"register":case"signup":case"enrollProfile":t=Ao,s=!1;break;case"recoverPassword":case"resetPassword":t=Oo,r=["currentAuthenticator-recover","currentAuthenticatorEnrollment-recover"],s=!1;break;case"unlockAccount":t=ko,s=!1,r=["unlock-account"];break;case"authenticate":case"login":case"signin":t=Mn;break;default:t=Mn;break}return{flow:e,remediators:t,actions:r,withCredentials:s}}/*! 776 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 777 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 778 * 779 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 780 * Unless required by applicable law or agreed to in writing, software 781 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 782 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 783 * 784 * See the License for the specific language governing permissions and limitations under the License. 785 */async function Eo(n,e){const t=n.transactionManager.load(),r=cn(n,t.flow);return fe(n,Object.assign(Object.assign(Object.assign({},e),r),{actions:["cancel"]}))}/*! 786 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 787 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 788 * 789 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 790 * Unless required by applicable law or agreed to in writing, softw
790are 791 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 792 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 793 * 794 * See the License for the specific language governing permissions and limitations under the License. 795 */function kr(n){var e=/\+/g,t=/([^&=]+)=?([^&]*)/g,r=n||"";r.charAt(0)==="#"&&r.charAt(1)==="/"&&(r=r.substring(2)),(r.charAt(0)==="#"||r.charAt(0)==="?")&&(r=r.substring(1));for(var s={},o;o=t.exec(r),!!o;){var i=o[1],a=o[2];i==="id_token"||i==="access_token"||i==="code"?s[i]=a:s[i]=decodeURIComponent(a.replace(e," "))}return s}/*! 796 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 797 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 798 * 799 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 800 * Unless required by applicable law or agreed to in writing, software 801 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 802 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 803 * 804 * See the License for the specific language governing permissions and limitations under the License. 805 */class _o extends be{constructor(e,t){super(`Enter the OTP code in the originating client: ${t}`),this.name="EmailVerifyCallbackError",this.state=e,this.otp=t}}function Po(n){return n.name==="EmailVerifyCallbackError"}function Er(n){return/(otp=)/i.test(n)&&/(state=)/i.test(n)}function _r(n){return kr(n)}async function Ro(n,e){if(Er(e)){const{state:t,otp:r}=_r(e);if(n.idx.canProceed({state:t}))return await n.idx.proceed({state:t,otp:r});throw new _o(t,r)}}/*! 806 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 807 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 808 * 809 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 810 * Unless required by applicable law or agreed to in writing, software 811 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 812 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 813 * 814 * See the License for the specific language governing permissions and limitations under the License. 815 */function Pr(n,e={}){return!!(ne(n,e)||e.stateHandle)}async function Rr(n,e={}){if(!Pr(n,e))throw new g("Unable to proceed: saved transaction could not be loaded");let{flow:t,state:r}=e;if(!t){const s=ne(n,{state:r});t=s==null?void 0:s.flow}return fe(n,Object.assign(Object.assign({},e),{flow:t}))}/*! 816 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 817 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 818 * 819 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 820 * Unless required by applicable law or agreed to in writing, software 821 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 822 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 823 * 824 * See the License for the specific language governing permissions and limitations under the License. 825 */async function Ir(n,e={}){var t;const{withCredentials:r,exchangeCodeForTokens:s}=e;let o=await Rr(n,{startPolling:!0,withCredentials:r,exchangeCodeForTokens:s});const i=ne(n);let a=(t=i==null?void 0:i.remediations)===null||t===void 0?void 0:t.find(c=>c.includes("poll"));return a!=null&&a.length||K("No polling remediations available at the current IDX flow stage"),Number.isInteger(e.refresh)?new Promise(function(c,u){setTimeout(async function(){var l,f;try{const d=(f=(l=o.nextStep)===null||l===void 0?void 0:l.poll)===null||f===void 0?void 0:f.refresh;c(d?Ir(n,{refresh:d}):o)}catch(d){u(d)}},e.refresh)}):o}/*! 826 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 827 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 828 * 829 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 830 * Unless required by applicable law or agreed to in writing, softw
830are 831 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 832 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 833 * 834 * See the License for the specific language governing permissions and limitations under the License. 835 */async function un(n,e={}){return n.transactionManager.clear(),fe(n,Object.assign({exchangeCodeForTokens:!1},e))}/*! 836 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 837 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 838 * 839 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 840 * Unless required by applicable law or agreed to in writing, software 841 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 842 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 843 * 844 * See the License for the specific language governing permissions and limitations under the License. 845 */async function Io(n,e={}){if(!hr(n)){const{enabledFeatures:t}=await un(n,Object.assign(Object.assign({},e),{flow:"register",autoRemediate:!1}));if(!e.activationToken&&t&&!t.includes(Y.REGISTRATION))throw new g("Registration is not supported based on your current org configuration.")}return fe(n,Object.assign(Object.assign({},e),{flow:"register"}))}/*! 846 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 847 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 848 * 849 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 850 * Unless required by applicable law or agreed to in writing, software 851 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 852 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 853 * 854 * See the License for the specific language governing permissions and limitations under the License. 855 */async function xo(n,e={}){const t=cn(n,"recoverPassword");return fe(n,Object.assign(Object.assign({},e),t))}/*! 856 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 857 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 858 * 859 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 860 * Unless required by applicable law or agreed to in writing, software 861 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 862 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 863 * 864 * See the License for the specific language governing permissions and limitations under the License. 865 */async function Mo(n,e){const t=n.transactionManager.load();if(!t)throw new g("No transaction data was found in storage");const{codeVerifier:r,state:s}=t,{searchParams:o}=new URL(e),i=o.get("state"),a=o.get("interaction_code"),c=o.get("error");if(c)throw new ye(c,o.get("error_description"));if(i!==s)throw new g("State in redirect uri does not match with transaction state");if(!a)throw new g("Unable to parse interaction_code from the url");const{tokens:u}=await n.token.exchangeCodeForTokens({interactionCode:a,codeVerifier:r});n.tokenManager.setTokens(u)}/*! 866 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 867 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 868 * 869 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 870 * Unless required by applicable law or agreed to in writing, software 871 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 872 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 873 * 874 * See the License for the specific language governing permissions and limitations under the License. 875 */async function Co(n,e={}){if(e.flow="unlockAccount",!hr(n)){const{enabledFeatures:t}=await un(n,Object.assign(Object.assign({},e),{autoRemediate:!1}));if(t&&!t.includes(Y.ACCOUNT_UNLOCK))throw new g("Self Service Account Unlock is not supported based on your current org configuration.")}return fe(n,Object.assign({},e))}/*! 876 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 877 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 878 * 879 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 880 * Unless required by applicable law or agreed to in writing, softw
880are 881 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 882 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 883 * 884 * See the License for the specific language governing permissions and limitations under the License. 885 */function xr(n){return n.name!=="OAuthError"?!1:n.errorCode==="interaction_required"}function jo(n){return Tr(n)&&n.errorCode==="invalid_grant"&&n.errorSummary==="The refresh token is invalid or expired."}/*! 886 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 887 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 888 * 889 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 890 * Unless required by applicable law or agreed to in writing, software 891 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 892 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 893 * 894 * See the License for the specific language governing permissions and limitations under the License. 895 */function Uo(n){return/[?&#](id|access)_token=/.test(n)}function Do(n){return/[?&#]code=/.test(n)}function No(n){return/[?&#]interaction_code=/.test(n)}function Fo(n){return/[?&#]error=/.test(n)||/[?&#]error_description/.test(n)}function Lo(n,e){var t=e.options;return!n||!t.redirectUri?!1:n.indexOf(t.redirectUri)===0}function Mr(n){return n.pkce||n.responseType==="code"||n.responseMode==="query"}function Ho(n,e){let t=!1;return Array.isArray(e.responseType)&&e.responseType.length?t=e.responseType.indexOf(n)>=0:t=e.responseType===n,t}function Cr(n){var e=Mr(n),t=e&&n.responseMode!=="fragment";return t?window.location.search:window.location.hash}function ln(n){if(!Lo(window.location.href,n))return!1;var e=Mr(n.options),t=Cr(n.options);if(Fo(t))return!0;if(e){var r=Do(t)||No(t);return r}return Uo(window.location.hash)}function Vo(n,e){if(!e){if(!ln(n))return!1;e=Cr(n.options)}return/(error=interaction_required)/i.test(e)}/*! 896 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 897 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 898 * 899 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 900 * Unless required by applicable law or agreed to in writing, software 901 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 902 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 903 * 904 * See the License for the specific language governing permissions and limitations under the License. 905 */const qo=Object.freeze(Object.defineProperty({__proto__:null,AuthenticatorEnrollmentData:Le,AuthenticatorVerificationData:Fe,ChallengeAuthenticator:Ce,ChallengePoll:ht,EnrollAuthenticator:ut,EnrollPoll:Ae,EnrollProfile:nn,EnrollmentChannelData:dt,GenericRemediator:Xt,Identify:Te,ReEnrollAuthenticator:je,ReEnrollAuthenticatorWarning:Ue,RedirectIdp:rn,Remediator:N,ResetAuthenticator:tn,SelectAuthenticatorAuthenticate:De,SelectAuthenticatorEnroll:Ne,SelectAuthenticatorUnlockAccount:on,SelectEnrollProfile:an,SelectEnrollmentChannel:lt,Skip:ft},Symbol.toStringTag,{value:"Module"}));/*! 906 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 907 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 908 * 909 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 910 * Unless required by applicable law or agreed to in writing, software 911 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 912 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 913 * 914 * See the License for the specific language governing permissions and limitations under the License. 915 */function Bo(n){Zs({remediators:qo,getFlowSpecification:cn});const e=un.bind(null,n);return{interact:gr.bind(null,n),introspect:xt.bind(null,n),makeIdxResponse:yr.bind(null,n),authenticate:mo.bind(null,n),register:Io.bind(null,n),start:e,startTransaction:e,poll:Ir.bind(null,n),proceed:Rr.bind(null,n),cancel:Eo.bind(null,n),recoverPassword:xo.bind(null,n),handleInteractionCodeRedirect:Mo.bind(null,n),isInteractionRequired:Vo.bind(null,n),isInteractionRequiredError:xr,handleEmailVerifyCallback:Ro.bind(null,n),isEmailVerifyCallback:Er,parseEmailVerifyCallback:_r,isEmailVerifyCallbackError:Po,getSavedTransactionMeta:ne.bind(null,n),createTransactionMeta:Qt.bind(null,n),getTransactionMeta:xs.bind(null,n),saveTransactionMeta:Yt.bind(null,n),clearTransactionMeta:Ms.bind(null,n),isTransactionMetaValid:fr,setFlow:r=>{n.options.flow=r},getFlow:()=>n.options.flow,canProceed:Pr.bind(null,n),unlockAccount:Co.bind(null,n)}}/*! 916 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 917 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 918 * 919 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 920 * Unless required by applicable law or agreed to in writing, softw
920are 921 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 922 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 923 * 924 * See the License for the specific language governing permissions and limitations under the License. 925 */function Wo(n){class e{constructor(...r){const s=new n(r.length?r[0]||{}:{});this.options=B(s),this.emitter=new as,this.features=St}}return e.features=St,e.constants=_n,e.features=e.prototype.features=St,Object.assign(e,{constants:_n}),e}/*! 926 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 927 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 928 * 929 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 930 * Unless required by applicable law or agreed to in writing, software 931 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 932 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 933 * 934 * See the License for the specific language governing permissions and limitations under the License. 935 */function Ko(n,e){return class extends n{constructor(...r){super(...r);const{storageManager:s,cookies:o,storageUtil:i}=this.options;this.storageManager=new e(s,o,i)}clearStorage(){}}}/*! 936 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 937 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 938 * 939 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 940 * Unless required by applicable law or agreed to in writing, software 941 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 942 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 943 * 944 * See the License for the specific language governing permissions and limitations under the License. 945 */class $o{constructor(){this.environments=["okta-auth-js/7.14.3"],this.maybeAddNodeEnvironment()}addEnvironment(e){this.environments.push(e)}getHttpHeader(){return{"X-Okta-User-Agent-Extended":this.environments.join(" ")}}getVersion(){return"7.14.3"}maybeAddNodeEnvironment(){if(I()||!process||!process.versions)return;const{node:e}=process.versions;this.environments.push(`nodejs/${e}`)}}/*! 946 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 947 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 948 * 949 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 950 * Unless required by applicable law or agreed to in writing, software 951 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 952 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 953 * 954 * See the License for the specific language governing permissions and limitations under the License. 955 */function zo(n,e,t){n.options.headers=n.options.headers||{},n.options.headers[e]=t}/*! 956 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 957 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 958 * 959 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 960 * Unless required by applicable law or agreed to in writing, software 961 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 962 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 963 * 964 * See the License for the specific language governing permissions and limitations under the License. 965 */function Go(n){return class extends n{constructor(...t){super(...t),this._oktaUserAgent=new $o,this.http={setRequestHeader:zo.bind(null,this)}}setHeaders(t){this.options.headers=Object.assign({},this.options.headers,t)}getIssuerOrigin(){return this.options.issuer.split("/oauth2/")[0]}webfinger(t){var r="/.well-known/webfinger"+J(t),s={headers:{Accept:"application/jrd+json"}};return we(this,r,s)}}}/*! 966 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 967 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 968 * 969 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 970 * Unless required by applicable law or agreed to in writing, softw
970are 971 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 972 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 973 * 974 * See the License for the specific language governing permissions and limitations under the License. 975 */function xe(n){var e=Z(n);return dn(e)}function dn(n){return n.replace(/\+/g,"-").replace(/\//g,"_").replace(/=+$/,"")}function hn(n){return n.replace(/-/g,"+").replace(/_/g,"/")}function Dt(n){var e=hn(n);switch(e.length%4){case 0:break;case 2:e+="==";break;case 3:e+="=";break;default:throw new g("Not a valid Base64Url")}var t=Gt(e);try{return decodeURIComponent(escape(t))}catch{return t}}function it(n){for(var e=new Uint8Array(n.length),t=0;t<n.length;t++)e[t]=n.charCodeAt(t);return e}function fn(n){return Gt(hn(n))}function Me(n){return Uint8Array.from(fn(n),e=>e.charCodeAt(0))}function le(n){return Z(new Uint8Array(n).reduce((e,t)=>e+String.fromCharCode(t),""))}/*! 976 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 977 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 978 * 979 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 980 * Unless required by applicable law or agreed to in writing, software 981 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 982 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 983 * 984 * See the License for the specific language governing permissions and limitations under the License. 985 */function jr(n){var e=new TextEncoder().encode(n);return U.subtle.digest("SHA-256",e).then(function(t){var r=new Uint8Array(t),s=r.slice(0,16),o=String.fromCharCode.apply(null,s),i=xe(o);return i})}/*! 986 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 987 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 988 * 989 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 990 * Unless required by applicable law or agreed to in writing, software 991 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 992 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 993 * 994 * See the License for the specific language governing permissions and limitations under the License. 995 */function Ur(n,e){e=D(e);var t="jwk",r={name:"RSASSA-PKCS1-v1_5",hash:{name:"SHA-256"}},s=!0,o=["verify"];return delete e.use,U.subtle.importKey(t,e,r,s,o).then(function(i){var a=n.split("."),c=it(a[0]+"."+a[1]),u=fn(a[2]),l=it(u);return U.subtle.verify(r,i,l,c)})}/*! 996 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 997 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 998 * 999 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1000 * Unless required by applicable law or agreed to in writing, software 1001 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1002 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1003 * 1004 * See the License for the specific language governing permissions and limitations under the License. 1005 */const Jo=Object.freeze(Object.defineProperty({__proto__:null,atob:Gt,base64ToBase64Url:dn,base64UrlDecode:fn,base64UrlToBase64:hn,base64UrlToBuffer:Me,base64UrlToString:Dt,btoa:Z,bufferToBase64Url:le,getOidcHash:jr,stringToBase64Url:xe,stringToBuffer:it,verifyToken:Ur,webcrypto:U},Symbol.toStringTag,{value:"Module"}));/*! 1006 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1007 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1008 * 1009 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1010 * Unless required by applicable law or agreed to in writing, software 1011 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1012 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1013 * 1014 * See the License for the specific language governing permissions and limitations under the License. 1015 */class gn{constructor(e={quiet:!1}){this.queue=[],this.running=!1,this.options=e}push(e,t,...r){return new Promise((s,o)=>{this.queue.length>0&&this.options.quiet!==!1&&K("Async method is being called but another async method is already running. The new method will be delayed until the previous method completes."),this.queue.push({method:e,thisObject:t,args:r,resolve:s,reject:o}),this.run()})}run(){if(!this.running&&this.queue.length!==0){this.running=!0;var e=this.queue.shift(),t=e.method.apply(e.thisObject,e.args);gs(t)?t.then(e.resolve,e.reject).finally(()=>{this.running=!1,this.run()}):(e.resolve(t),this.running=!1,this.run())}}}/*! 1016 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1017 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1018 * 1019 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1020 * Unless required by applicable law or agreed to in writing, softw
1020are 1021 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1022 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1023 * 1024 * See the License for the specific language governing permissions and limitations under the License. 1025 */function Qo(n){return("0"+n.toString(16)).substr(-2)}function Yo(n){var e=new Uint8Array(Math.ceil(n/2));U.getRandomValues(e);var t=Array.from(e,Qo).join("");return t.slice(0,n)}function Xo(n){var e=n||"";return e.length<_t&&(e=e+Yo(_t-e.length)),encodeURIComponent(e).slice(0,or)}function Zo(n){var e=new TextEncoder().encode(n);return U.subtle.digest("SHA-256",e).then(function(t){var r=String.fromCharCode.apply(null,new Uint8Array(t)),s=xe(r);return s})}var Ie={DEFAULT_CODE_CHALLENGE_METHOD:$t,generateVerifier:Xo,computeChallenge:Zo};/*! 1026 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1027 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1028 * 1029 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1030 * Unless required by applicable law or agreed to in writing, software 1031 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1032 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1033 * 1034 * See the License for the specific language governing permissions and limitations under the License. 1035 */function Dr(n){var e=n.split("."),t;try{t={header:JSON.parse(Dt(e[0])),payload:JSON.parse(Dt(e[1])),signature:e[2]}}catch{throw new g("Malformed token")}return t}/*! 1036 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1037 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1038 * 1039 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1040 * Unless required by applicable law or agreed to in writing, software 1041 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1042 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1043 * 1044 * See the License for the specific language governing permissions and limitations under the License. 1045 */function gt(n){const{pkce:e,clientId:t,redirectUri:r,responseType:s,responseMode:o,scopes:i,acrValues:a,maxAge:c,state:u,ignoreSignature:l,dpop:f}=n.options,d=I()?window.location.href:void 0;return B({pkce:e,clientId:t,redirectUri:r||d,responseType:s||["token","id_token"],responseMode:o,state:u||Bt(),nonce:vs(),scopes:i||["openid","email"],acrValues:a,maxAge:c,ignoreSignature:l,dpop:f})}/*! 1046 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1047 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1048 * 1049 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1050 * Unless required by applicable law or agreed to in writing, software 1051 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1052 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1053 * 1054 * See the License for the specific language governing permissions and limitations under the License. 1055 */const ei="OktaAuthJs",bt="DPoPKeys";function Nr(n){return(Tr(n)||Js(n))&&n.errorCode==="use_dpop_nonce"}async function ti(n,e,t){const r=xe(JSON.stringify(n)),s=xe(JSON.stringify(e)),o=await U.subtle.sign({name:t.algorithm.name},t,it(`${r}.${s}`));return`${r}.${s}.${dn(le(o))}`}function Fr(n=32){return[...U.getRandomValues(new Uint8Array(n))].map(e=>e.toString(16)).join("")}async function ni(){const n={name:"RSASSA-PKCS1-v1_5",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};return U.subtle.generateKey(n,!1,["sign","verify"])}async function ri(n){const e=new TextEncoder().encode(n),t=await U.subtle.digest("SHA-256",e);return Z(String.fromCharCode.apply(null,new Uint8Array(t))).replace(/\+/g,"-").replace(/\//g,"_").replace(/=+$/,"")}function si(){return new Promise((n,e)=>{try{const r=window.indexedDB.open(ei,1);r.onerror=function(){e(r.error)},r.onupgradeneeded=function(){r.result.createObjectStore(bt)},r.onsuccess=function(){const s=r.result,o=s.transaction(bt,"readwrite");o.onerror=function(){e(o.error)};const i=o.objectStore(bt);n(i),o.oncomplete=function(){s.close()}}}catch(t){e(t)}})}async function pt(n,...e){const t=await si();return new Promise((r,s)=>{const o=t[n](...e);o.onsuccess=function(){r(o)},o.onerror=function(){s(o.error)}})}async function oi(n,e){return await pt("add",e,n),e}async function pn(n){if(n){const e=await pt("get",n);if(e.result)return e.result}throw new g(`Unable to locate dpop key pair required for refresh${n?` (${n})`:""}`)}async function Nt(n){await pt("delete",n)}async function ii(){await pt("clear")}async function ai(){const n=Fr(4),e=await ni();return await oi(n,e),{keyPair:e,keyPairId:n}}async function Cn(n,e){var t;let r=!1;const{accessToken:s,refreshToken:o}=e;
1055n==="access"&&s&&s.tokenType==="DPoP"&&!o&&(r=!0),n==="refresh"&&o&&!s&&(r=!0);const i=(t=s==null?void 0:s.dpopPairId)!==null&&t!==void 0?t:o==null?void 0:o.dpopPairId;r&&i&&await Nt(i)}async function Lr({keyPair:n,url:e,method:t,nonce:r,accessToken:s}){const{kty:o,crv:i,e:a,n:c,x:u,y:l}=await U.subtle.exportKey("jwk",n.publicKey),f={alg:"RS256",typ:"dpop+jwt",jwk:{kty:o,crv:i,e:a,n:c,x:u,y:l}},d={htm:t,htu:e,iat:Math.floor(Date.now()/1e3),jti:Fr()};return r&&(d.nonce=r),s&&(d.ath=await ri(s)),ti(f,d,n.privateKey)}async function ci({keyPair:n,url:e,method:t,nonce:r}){const s={keyPair:n,url:e,method:t};return r&&(s.nonce=r),Lr(s)}/*! 1056 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1057 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1058 * 1059 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1060 * Unless required by applicable law or agreed to in writing, software 1061 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1062 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1063 * 1064 * See the License for the specific language governing permissions and limitations under the License. 1065 */function ui(n){if(!n.clientId)throw new g("A clientId must be specified in the OktaAuth constructor to get a token");if(!n.redirectUri)throw new g("The redirectUri passed to /authorize must also be passed to /token");if(!n.authorizationCode&&!n.interactionCode)throw new g("An authorization code (returned from /authorize) must be passed to /token");if(!n.codeVerifier)throw new g('The "codeVerifier" (generated and saved by your app) must be passed to /token')}function li(n,e){var t=B({client_id:e.clientId,redirect_uri:e.redirectUri,grant_type:e.interactionCode?"interaction_code":"authorization_code",code_verifier:e.codeVerifier});e.interactionCode?t.interaction_code=e.interactionCode:e.authorizationCode&&(t.code=e.authorizationCode);const{clientSecret:r}=n.options;return r&&(t.client_secret=r),J(t).slice(1)}async function mn(n,{url:e,data:t,nonce:r,dpopKeyPair:s}){var o,i;const a="POST",c={"Content-Type":"application/x-www-form-urlencoded"};if(n.options.dpop){if(!s)throw new g("DPoP is configured but no key pair was provided");const u=await ci({url:e,method:a,nonce:r,keyPair:s});c.DPoP=u}try{return await $(n,{url:e,method:a,args:t,headers:c})}catch(u){if(Nr(u)&&!r){const l=(o=u.resp)===null||o===void 0?void 0:o.headers["dpop-nonce"];if(!l)throw new ue({errorSummary:"No `dpop-nonce` header found when required"},(i=u.resp)!==null&&i!==void 0?i:void 0);return mn(n,{url:e,data:t,dpopKeyPair:s,nonce:l})}throw u}}async function di(n,e,t){ui(e);var r=li(n,e);const s={url:t.tokenUrl,data:r,dpopKeyPair:e==null?void 0:e.dpopKeyPair};return mn(n,s)}async function hi(n,e,t){const r=Object.entries({client_id:e.clientId,grant_type:"refresh_token",scope:t.scopes.join(" "),refresh_token:t.refreshToken}).map(function([i,a]){return i+"="+encodeURIComponent(a)}).join("&");let s=t.tokenUrl;e.extraParams&&Object.keys(e.extraParams).length>=1&&(s+=J(e.extraParams));const o={url:s,data:r,dpopKeyPair:e==null?void 0:e.dpopKeyPair};return mn(n,o)}/*! 1066 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1067 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1068 * 1069 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1070 * Unless required by applicable law or agreed to in writing, software 1071 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1072 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1073 * 1074 * See the License for the specific language governing permissions and limitations under the License. 1075 */function mt(n,e){var t=e||n.options.issuer;return we(n,t+"/.well-known/openid-configuration",{cacheResponse:!0})}function fi(n,e,t){var r=n.storageManager.getHttpCache(n.options.cookies);return mt(n,e).then(function(s){var o=s.jwks_uri,i=r.getStorage(),a=i[o];if(a&&Date.now()/1e3<a.expiresAt){var c=At(a.response.keys,{kid:t});if(c)return c}return r.clearStorage(o),we(n,o,{cacheResponse:!0}).then(function(u){var l=At(u.keys,{kid:t});if(l)return l;throw new g("The key id, "+t+", was not found in the server's keys")})})}/*! 1076 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1077 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1078 * 1079 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1080 * Unless required by applicable law or agreed to in writing, softw
1080are 1081 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1082 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1083 * 1084 * See the License for the specific language governing permissions and limitations under the License. 1085 */function gi(n,e,t){const r=t.clientId,s=t.issuer,o=t.nonce,i=t.acrValues;if(!e||!s||!r)throw new g("The jwt, iss, and aud arguments are all required");if(o&&e.nonce!==o)throw new g("OAuth flow response nonce doesn't match request nonce");const a=Math.floor(Date.now()/1e3);if(e.iss!==s)throw new g("The issuer ["+e.iss+"] does not match ["+s+"]");if(Array.isArray(e.aud)&&e.aud.indexOf(r)<0||!Array.isArray(e.aud)&&e.aud!==r)throw new g("The audience ["+e.aud+"] does not match ["+r+"]");if(i&&e.acr!==i)throw new g("The acr ["+e.acr+"] does not match acr_values ["+i+"]");if(e.iat>e.exp)throw new g("The JWT expired before it was issued");if(!n.options.ignoreLifetime){if(a-n.options.maxClockSkew>e.exp)throw new g("The JWT expired and is no longer valid");if(e.iat>a+n.options.maxClockSkew)throw new g("The JWT was issued in the future")}}/*! 1086 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1087 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1088 * 1089 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1090 * Unless required by applicable law or agreed to in writing, software 1091 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1092 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1093 * 1094 * See the License for the specific language governing permissions and limitations under the License. 1095 */async function Hr(n,e,t){if(!e||!e.idToken)throw new g("Only idTokens may be verified");const r=Dr(e.idToken),s=(t==null?void 0:t.issuer)||n.options.issuer,{issuer:o}=await mt(n,s),i=Object.assign({clientId:n.options.clientId,ignoreSignature:n.options.ignoreSignature},t,{issuer:o});if(gi(n,r.payload,i),i.ignoreSignature==!0||!n.features.isTokenVerifySupported())return e;const a=await fi(n,e.issuer,r.header.kid);if(!await Ur(e.idToken,a))throw new g("The token signature is not valid");if(t&&t.accessToken&&e.claims.at_hash&&await jr(t.accessToken)!==e.claims.at_hash)throw new g("Token hash verification failed");return e}/*! 1096 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1097 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1098 * 1099 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1100 * Unless required by applicable law or agreed to in writing, software 1101 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1102 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1103 * 1104 * See the License for the specific language governing permissions and limitations under the License. 1105 */function pi(n,e){if(n.error&&n.error_description)throw new ye(n.error,n.error_description);if(n.state!==e.state)throw new g("OAuth flow response state doesn't match request state")}async function pe(n,e,t,r){var s,o;const i=n.options.pkce!==!1;if(e=e||gt(n),pi(t,e),i&&(t.code||t.interaction_code))return n.token.exchangeCodeForTokens(Object.assign({},e,{authorizationCode:t.code,interactionCode:t.interaction_code}),r);r=r||ee(n,e);let a=e.responseType||[];!Array.isArray(a)&&a!=="none"&&(a=[a]);let c;t.scope?c=t.scope.split(" "):c=D(e.scopes);const u=e.clientId||n.options.clientId;if(e.dpop){const{allowBearerTokens:w}=(o=(s=n.options)===null||s===void 0?void 0:s.dpopOptions)!==null&&o!==void 0?o:{allowBearerTokens:!1};if(!w&&t.token_type!=="DPoP")throw new g('Unable to parse OAuth flow response: DPoP was configured but "token_type" was not DPoP')}const l={},f=t.expires_in,d=t.token_type,p=t.access_token,v=t.id_token,m=t.refresh_token,T=Math.floor(Date.now()/1e3);if(p){const w=n.token.decode(p);l.accessToken={accessToken:p,claims:w.payload,expiresAt:Number(f)+T,tokenType:d,scopes:c,authorizeUrl:r.authorizeUrl,userinfoUrl:r.userinfoUrl},e.dpopPairId&&(l.accessToken.dpopPairId=e.dpopPairId),e.extraParams&&(l.accessToken.extraParams=e.extraParams)}if(m&&(l.refreshToken={refreshToken:m,expiresAt:Number(f)+T,scopes:c,tokenUrl:r.tokenUrl,authorizeUrl:r.authorizeUrl,issuer:r.issuer},e.dpopPairId&&(l.refreshToken.dpopPairId=e.dpopPairId),e.extraParams&&(l.refreshToken.extraParams=e.extraParams)),v){const w=n.token.decode(v),A={idToken:v,claims:w.payload,expiresAt:w.payload.exp-w.payload.iat+T,scopes:c,authorizeUrl:r.authorizeUrl,issuer:r.issuer,clientId:u};e.extraParams&&(A.extraParams=e.extraParams);const _={clientId:u,issuer:r.issuer,nonce:e.nonce,accessToken:p,acrValues:e.acrValues};e.ignoreSignature!==void 0&&(_.ignoreSignature=e.ignoreSignature),await Hr(n,A,_),l.idToken=A}if(a.indexOf("token")!==-1&&!l.accessToken)throw new g('Unable to parse OAuth flow response: response type "token" was requested but "access_token" was not returned.');if(a.indexOf("id_token")!==-1&&!l.idToken)throw new g('Unable to parse OAuth flow response: response type "id_token" was requested but "id_token" was not returned.');return{tokens:l,state:t.state,code:t.code,responseType:a}}/*! 1106 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1107 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1108 * 1109 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1110 * Unless required by applicable law or agreed to in writing, softw
1110are 1111 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1112 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1113 * 1114 * See the License for the specific language governing permissions and limitations under the License. 1115 */async function mi(n,e,t){t=t||ee(n,e),e=Object.assign({},gt(n),D(e));const{authorizationCode:r,interactionCode:s,codeVerifier:o,clientId:i,redirectUri:a,scopes:c,ignoreSignature:u,state:l,acrValues:f,dpop:d,dpopPairId:p,extraParams:v}=e,m={clientId:i,redirectUri:a,authorizationCode:r,interactionCode:s,codeVerifier:o,dpop:d},T=["token"];c.indexOf("openid")!==-1&&T.push("id_token");const w={clientId:i,redirectUri:a,scopes:c,responseType:T,ignoreSignature:u,acrValues:f,extraParams:v};try{if(d)if(p){const b=await pn(p);m.dpopKeyPair=b,w.dpop=d,w.dpopPairId=p}else{const{keyPair:b,keyPairId:V}=await ai();m.dpopKeyPair=b,w.dpop=d,w.dpopPairId=V}const A=await di(n,m,t),_=await pe(n,w,A,t);return _.code=r,_.state=l,_}finally{n.transactionManager.clear()}}/*! 1116 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1117 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1118 * 1119 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1120 * Unless required by applicable law or agreed to in writing, software 1121 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1122 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1123 * 1124 * See the License for the specific language governing permissions and limitations under the License. 1125 */async function vi(n,e,t){if(e||(e=(await n.tokenManager.getTokens()).accessToken),t||(t=(await n.tokenManager.getTokens()).idToken),!e||!G(e))return Promise.reject(new g("getUserInfo requires an access token object"));if(!t||!X(t))return Promise.reject(new g("getUserInfo requires an ID token object"));const r={url:e.userinfoUrl,method:"GET",accessToken:e.accessToken};if(n.options.dpop){const s=await n.getDPoPAuthorizationHeaders(Object.assign(Object.assign({},r),{accessToken:e}));r.headers=s,delete r.accessToken}return $(n,r).then(s=>s.sub===t.claims.sub?s:Promise.reject(new g("getUserInfo request was rejected due to token mismatch"))).catch(function(s){var o;if(s instanceof q&&!n.options.dpop){const{error:i,errorDescription:a}=s;throw new ye(i,a)}if(!n.options.dpop){let i=s;if(s instanceof ue&&(!((o=s==null?void 0:s.meta)===null||o===void 0)&&o.wwwAuthHeader)&&(i=q.parseHeader(s.meta.wwwAuthHeader)),i instanceof q){const{error:a,errorDescription:c}=i;throw new ye(a,c)}}throw s})}/*! 1126 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1127 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1128 * 1129 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1130 * Unless required by applicable law or agreed to in writing, software 1131 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1132 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1133 * 1134 * See the License for the specific language governing permissions and limitations under the License. 1135 */const Vr=12e4;function qr(n,e,t){n.addEventListener?n.addEventListener(e,t):n.attachEvent("on"+e,t)}function Br(n,e,t){n.removeEventListener?n.removeEventListener(e,t):n.detachEvent("on"+e,t)}function yi(n){var e=document.createElement("iframe");return e.style.display="none",e.src=n,document.body.appendChild(e)}function Wr(n,e){var t=e.popupTitle||"External Identity Provider User Authentication",r="toolbar=no, scrollbars=yes, resizable=yes, top=100, left=500, width=600, height=600";return window.open(n,t,r)}function jn(n,e,t){var r,s,o=new Promise(function(i,a){r=function(u){if(!(!u.data||u.data.state!==t)){if(u.origin!==n.getIssuerOrigin())return a(new g("The request does not match client configuration"));i(u.data)}},qr(window,"message",r),s=setTimeout(function(){a(new g("OAuth flow timed out"))},e||Vr)});return o.finally(function(){clearTimeout(s),Br(window,"message",r)})}function wi(n,e,t,r){let s;return new Promise((i,a)=>{t.onmessage=c=>
1135{if(!(!c.isTrusted||!c.data)){if(typeof c.data=="object"&&r===c.data.state)return i(Object.assign({},c.data));a(new g("Unable to complete auth code exchange"))}},s=setTimeout(function(){a(new g("OAuth flow timed out"))},e||Vr)}).finally(()=>{clearTimeout(s),t.close()})}/*! 1136 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1137 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1138 * 1139 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1140 * Unless required by applicable law or agreed to in writing, software 1141 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1142 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1143 * 1144 * See the License for the specific language governing permissions and limitations under the License. 1145 */function Ti(n){if(!n.features.isPKCESupported()){var e="PKCE requires a modern browser with encryption support running in a secure context.";throw n.features.isHTTPS()||(e+=` 1146The current page is not being served with HTTPS protocol. PKCE requires secure HTTPS protocol.`),n.features.hasTextEncoder()||(e+=` 1147"TextEncoder" is not defined. To use PKCE, you may need to include a polyfill/shim for this browser.`),new g(e)}}async function Si(n,e){e=e||n.options.codeChallengeMethod||$t;var r=(await mt(n)).code_challenge_methods_supported||[];if(r.indexOf(e)===-1)throw new g("Invalid code_challenge_method");return e}async function bi(n,e){let{codeVerifier:t,codeChallenge:r,codeChallengeMethod:s}=e;return r=r||n.options.codeChallenge,r||(Ti(n),t=t||Ie.generateVerifier(),r=await Ie.computeChallenge(t)),s=await Si(n,s),e=Object.assign(Object.assign({},e),{responseType:"code",codeVerifier:t,codeChallenge:r,codeChallengeMethod:s}),e}async function vn(n,e={}){const t=gt(n);if(e=Object.assign(Object.assign({},t),e),e.dpop&&!n.features.isDPoPSupported())throw new g("DPoP has been configured, but is not supported by browser");return e.pkce===!1?e:bi(n,e)}/*! 1148 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1149 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1150 * 1151 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1152 * Unless required by applicable law or agreed to in writing, software 1153 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1154 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1155 * 1156 * See the License for the specific language governing permissions and limitations under the License. 1157 */function Oi(n){if(!n.clientId)throw new g("A clientId must be specified in the OktaAuth constructor to get a token");if(ve(n.responseType)&&n.responseType.indexOf(" ")!==-1)throw new g("Multiple OAuth responseTypes must be defined as an array");var e={client_id:n.clientId,code_challenge:n.codeChallenge,code_challenge_method:n.codeChallengeMethod,display:n.display,idp:n.idp,idp_scope:n.idpScope,login_hint:n.loginHint,max_age:n.maxAge,nonce:n.nonce,prompt:n.prompt,redirect_uri:n.redirectUri,response_mode:n.responseMode,response_type:n.responseType,sessionToken:n.sessionToken,state:n.state,acr_values:n.acrValues,enroll_amr_values:n.enrollAmrValues};if(e=B(e),["idp_scope","response_type","enroll_amr_values"].forEach(function(t){Array.isArray(e[t])&&(e[t]=e[t].join(" "))}),n.responseType.indexOf("id_token")!==-1&&n.scopes.indexOf("openid")===-1)throw new g("openid scope must be specified in the scopes argument when requesting an id_token");return n.scopes&&(e.scope=n.scopes.join(" ")),e}function yn(n){var e=Oi(n);return J(Object.assign(Object.assign({},e),n.extraParams&&Object.assign({},n.extraParams)))}/*! 1158 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1159 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1160 * 1161 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1162 * Unless required by applicable law or agreed to in writing, softw
1162are 1163 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1164 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1165 * 1166 * See the License for the specific language governing permissions and limitations under the License. 1167 */function wn(n,e){if(arguments.length>2)return Promise.reject(new g('As of version 3.0, "getToken" takes only a single set of options'));e=e||{};const t=e.popupWindow;return e.popupWindow=void 0,vn(n,e).then(function(r){var s={prompt:"none",responseMode:"okta_post_message",display:null},o={display:"popup"};e.sessionToken?Object.assign(r,s):e.idp&&Object.assign(r,o);var i,a,c;c=ee(n,r),a=e.codeVerifier?c.tokenUrl:c.authorizeUrl,i=a+yn(r);var u="IMPLICIT";switch(r.sessionToken||r.display===null?u="IFRAME":r.display==="popup"?u=e.idpPopup?"IDP_POPUP":"POPUP":u="IMPLICIT",u){case"IFRAME":var l=jn(n,e.timeout,r.state),f=yi(i);return l.then(function(m){return pe(n,r,m,c)}).finally(function(){var m;document.body.contains(f)&&((m=f.parentElement)===null||m===void 0||m.removeChild(f))});case"POPUP":var d;if(r.responseMode==="okta_post_message"){if(!n.features.isPopupPostMessageSupported())throw new g("This browser doesn't have full postMessage support");d=jn(n,e.timeout,r.state)}t&&t.location.assign(i);var p=new Promise(function(m,T){var w=setInterval(function(){(!t||t.closed)&&(clearInterval(w),T(new g("Unable to parse OAuth flow response")))},100);d.then(function(A){clearInterval(w),m(A)}).catch(function(A){clearInterval(w),T(A)})});return p.then(function(m){return pe(n,r,m,c)}).finally(function(){t&&!t.closed&&t.close()});case"IDP_POPUP":var v=wi(n,e.timeout,e.channel,r.state);if(t)t.location.assign(i);else throw new g("Unable to open popup window");return v.then(function(m){return pe(n,r,m,c)});default:throw new g("The full page redirect flow is not supported")}})}/*! 1168 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1169 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1170 * 1171 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1172 * Unless required by applicable law or agreed to in writing, software 1173 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1174 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1175 * 1176 * See the License for the specific language governing permissions and limitations under the License. 1177 */function Tn(n,e){return arguments.length>2?Promise.reject(new g('As of version 3.0, "getWithoutPrompt" takes only a single set of options')):(e=D(e)||{},Object.assign(e,{prompt:"none",responseMode:"okta_post_message",display:null}),wn(n,e))}/*! 1178 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1179 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1180 * 1181 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1182 * Unless required by applicable law or agreed to in writing, software 1183 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1184 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1185 * 1186 * See the License for the specific language governing permissions and limitations under the License. 1187 */function Ai(n,e){if(arguments.length>2)return Promise.reject(new g('As of version 3.0, "getWithPopup" takes only a single set of options'));const{initialPath:t}=e,r=he(e,["initialPath"]),s=Wr(t??"/",r);return e=D(r)||{},Object.assign(r,{display:"popup",responseMode:"okta_post_message",popupWindow:s}),wn(n,r)}function ki(n,e){try{if(!BroadcastChannel)throw new g("Modern browser with `BroadcastChannel` support is required to use this method");if(!e.redirectUri)throw new g("`redirectUri` is a required param for `getWithIDPPopup`");e.state||(e.state=Bt());const t=Wr("/",e),r=new BroadcastChannel(`popup-callback:${e.state}`);e=D(e)||{},Object.assign(e,{display:"popup",responseMode:"query",popupWindow:t,idpPopup:!0,channel:r});let s;return{promise:new Promise((a,c)=>(s=c,wn(n,e).then(u=>a(u)).catch(u=>c(u)))),cancel:()=>{r.close(),s(new g("Popup flow canceled"))}}}catch(t){return{promise:Promise.reject(t),cancel:()=>{}}}}/*! 1188 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1189 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1190 * 1191 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1192 * Unless required by applicable law or agreed to in writing, softw
1192are 1193 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1194 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1195 * 1196 * See the License for the specific language governing permissions and limitations under the License. 1197 */async function Ei(n,e){if(arguments.length>2)return Promise.reject(new g('As of version 3.0, "getWithRedirect" takes only a single set of options'));e=D(e)||{};const t=await vn(n,e),r=Jn(n,t),s=r.urls.authorizeUrl+yn(t);n.transactionManager.save(r),n.options.setLocation?n.options.setLocation(s):window.location.assign(s)}/*! 1198 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1199 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1200 * 1201 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1202 * Unless required by applicable law or agreed to in writing, software 1203 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1204 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1205 * 1206 * See the License for the specific language governing permissions and limitations under the License. 1207 */function _i(n){var e=n.token.parseFromUrl._getHistory(),t=n.token.parseFromUrl._getDocument(),r=n.token.parseFromUrl._getLocation();e&&e.replaceState?e.replaceState(null,t.title,r.pathname+r.search):r.hash=""}function Pi(n){var e=n.token.parseFromUrl._getHistory(),t=n.token.parseFromUrl._getDocument(),r=n.token.parseFromUrl._getLocation();e&&e.replaceState?e.replaceState(null,t.title,r.pathname+r.hash):r.search=""}function Kr(n){var e=n.options.pkce?"query":"fragment",t=n.options.responseMode||e;return t}function Ft(n,e){e=e||{},ve(e)?e={url:e}:e=e;var t=e.url,r=e.responseMode||Kr(n),s=n.token.parseFromUrl._getLocation(),o;if(r==="query"?o=t?t.substring(t.indexOf("?")):s.search:o=t?t.substring(t.indexOf("#")):s.hash,!o)throw new g("Unable to parse a token from the url");return kr(o)}function Ri(n,e){(e.responseMode||Kr(n))==="query"?Pi(n):_i(n)}async function Ii(n,e){e=e||{},ve(e)?e={url:e}:e=e;const t=Ft(n,e),r=t.state,s=n.transactionManager.load({state:r});if(!s)throw n.options.pkce?new g("Could not load PKCE codeVerifier from storage. This may indicate the auth flow has already completed or multiple auth flows are executing concurrently.",void 0):new g("Unable to retrieve OAuth redirect params from storage");const o=s.urls;return delete s.urls,e.url||Ri(n,e),pe(n,s,t,o).catch(i=>{throw xr(i)||n.transactionManager.clear({state:r}),i}).then(i=>(n.transactionManager.clear({state:r}),i))}/*! 1208 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1209 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1210 * 1211 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1212 * Unless required by applicable law or agreed to in writing, software 1213 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1214 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1215 * 1216 * See the License for the specific language governing permissions and limitations under the License. 1217 */function xi(n,e){return n.refreshToken===e.refreshToken}/*! 1218 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1219 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1220 * 1221 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1222 * Unless required by applicable law or agreed to in writing, software 1223 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1224 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1225 * 1226 * See the License for the specific language governing permissions and limitations under the License. 1227 */async function Sn(n,e,t){const{clientId:r,dpop:s}=n.options;if(!r)throw new g("A clientId must be specified in the OktaAuth constructor to renew tokens");try{const o=Object.assign({},e,{clientId:r});t.extraParams&&(o.extraParams=t.extraParams);const i=Object.assign({},o);if(s){const f=await pn(t==null?void 0:t.dpopPairId);i.dpopKeyPair=f,o.dpop=s,o.dpopPairId=t.dpopPairId}const a=await hi(n,i,t),c=ee(n,e),{tokens:u}=await pe(n,o,a,c),{refreshToken:l}=u;return l&&!xi(l,t)&&n.tokenManager.updateRefreshToken(l),u}catch(o){throw jo(o)&&n.tokenManager.removeRefreshToken(),o}}/*! 1228 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1229 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1230 * 1231 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1232 * Unless required by applicable law or agreed to in writing, softw
1232are 1233 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1234 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1235 * 1236 * See the License for the specific language governing permissions and limitations under the License. 1237 */function $r(){throw new g("Renew must be passed a token with an array of scopes and an accessToken or idToken")}function Un(n,e){if(X(n))return e.idToken;if(G(n))return e.accessToken;$r()}async function Mi(n,e){!X(e)&&!G(e)&&$r();let t=n.tokenManager.getTokensSync();if(t.refreshToken)return t=await Sn(n,{scopes:e.scopes},t.refreshToken),Un(e,t);var r;n.options.pkce?r="code":G(e)?r="token":r="id_token";const{scopes:s,authorizeUrl:o,userinfoUrl:i,issuer:a,dpopPairId:c,extraParams:u}=e;return Tn(n,{responseType:r,scopes:s,authorizeUrl:o,userinfoUrl:i,issuer:a,dpopPairId:c,extraParams:u}).then(function(l){return Un(e,l.tokens)})}/*! 1238 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1239 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1240 * 1241 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1242 * Unless required by applicable law or agreed to in writing, software 1243 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1244 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1245 * 1246 * See the License for the specific language governing permissions and limitations under the License. 1247 */async function Ci(n,e){var t;const r=(t=e==null?void 0:e.tokens)!==null&&t!==void 0?t:n.tokenManager.getTokensSync();if(r.refreshToken)return Sn(n,e||{},r.refreshToken);if(!r.accessToken&&!r.idToken)throw new g("renewTokens() was called but there is no existing token");const s=r.accessToken||{},o=r.idToken||{},i=s.scopes||o.scopes;if(!i)throw new g("renewTokens: invalid tokens: could not read scopes");const a=s.authorizeUrl||o.authorizeUrl;if(!a)throw new g("renewTokens: invalid tokens: could not read authorizeUrl");const c=s.userinfoUrl||n.options.userinfoUrl,u=o.issuer||n.options.issuer,l=s==null?void 0:s.dpopPairId,f=(s==null?void 0:s.extraParams)||(o==null?void 0:o.extraParams);if(e=Object.assign({scopes:i,authorizeUrl:a,userinfoUrl:c,issuer:u,dpopPairId:l,extraParams:f},e),n.options.pkce)e.responseType="code";else{const{responseType:d}=gt(n);e.responseType=d}return Tn(n,e).then(d=>d.tokens)}/*! 1248 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1249 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1250 * 1251 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1252 * Unless required by applicable law or agreed to in writing, software 1253 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1254 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1255 * 1256 * See the License for the specific language governing permissions and limitations under the License. 1257 */async function ji(n,e){let t="",r="";if(e&&(t=e.accessToken,r=e.refreshToken),!t&&!r)throw new g("A valid access or refresh token object is required");var s=n.options.clientId,o=n.options.clientSecret;if(!s)throw new g("A clientId must be specified in the OktaAuth constructor to revoke a token");var i=ee(n).revokeUrl,a=J({token_type_hint:r?"refresh_token":"access_token",token:r||t}).slice(1),c=Z(o?`${s}:${o}`:s);return te(n,i,a,{headers:{"Content-Type":"application/x-www-form-urlencoded",Authorization:"Basic "+c}})}/*! 1258 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1259 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1260 * 1261 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1262 * Unless required by applicable law or agreed to in writing, software 1263 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1264 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1265 * 1266 * See the License for the specific language governing permissions and limitations under the License. 1267 */const Ui={accessToken:"access_token",idToken:"id_token",refreshToken:"refresh_token"};async function Di(n,e,t){var r;let s,o=n.options.clientId,i=n.options.clientSecret;if(t||(t=n.tokenManager.getTokens()[e]),!t)throw new g(`unable to find ${e} in storage or fn params`);if(e!==Rt.ACCESS?s=t==null?void 0:t.issuer:s=(r=t==null?void 0:t.claims)===null||r===void 0?void 0:r.iss,s=s||n.options.issuer,!o)throw new g("A clientId must be specified in the OktaAuth constructor to introspect a token");if(!s)throw new g("Unable to find issuer");const{introspection_endpoint:a}=await mt(n,s),c=Z(i?`${o}:${i}`:o),u=J({token_type_hint:Ui[e],token:t[e]}).slice(1);return te(n,a,u,{headers:{"Content-Type":"application/x-www-form-urlencoded",Authorization:"Basic "+c}})}/*! 1268 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1269 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1270 * 1271 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1272 * Unless required by applicable law or agreed to in writing, softw
1272are 1273 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1274 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1275 * 1276 * See the License for the specific language governing permissions and limitations under the License. 1277 */function Ni(n,e){const t=n.options.issuer,r=ee(n,e);return{issuer:t,urls:r,clientId:e.clientId,redirectUri:e.redirectUri,responseType:e.responseType,responseMode:e.responseMode,state:e.state,acrValues:e.acrValues,enrollAmrValues:e.enrollAmrValues}}/*! 1278 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1279 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1280 * 1281 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1282 * Unless required by applicable law or agreed to in writing, software 1283 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1284 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1285 * 1286 * See the License for the specific language governing permissions and limitations under the License. 1287 */function Fi(n){const{clientId:e,redirectUri:t,responseMode:r,state:s}=n.options,o=I()?window.location.href:void 0;return B({clientId:e,redirectUri:t||o,responseMode:r,state:s||Bt(),responseType:"none",prompt:"enroll_authenticator"})}/*! 1288 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1289 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1290 * 1291 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1292 * Unless required by applicable law or agreed to in writing, software 1293 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1294 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1295 * 1296 * See the License for the specific language governing permissions and limitations under the License. 1297 */function Li(n){if(n=Object.assign(Object.assign({},n),{responseType:"none",prompt:"enroll_authenticator",maxAge:0}),!n.enrollAmrValues)throw new g("enroll_amr_values must be specified");if(!n.acrValues)throw new g("acr_values must be specified");return delete n.scopes,delete n.nonce,n}function Hi(n,e){return Li(Object.assign(Object.assign({},Fi(n)),e))}/*! 1298 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1299 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1300 * 1301 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1302 * Unless required by applicable law or agreed to in writing, software 1303 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1304 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1305 * 1306 * See the License for the specific language governing permissions and limitations under the License. 1307 */function Vi(n,e){e=D(e)||{};const t=Hi(n,e),r=Ni(n,t),s=r.urls.authorizeUrl+yn(t);n.transactionManager.save(r),n.options.setLocation?n.options.setLocation(s):window.location.assign(s)}/*! 1308 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1309 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1310 * 1311 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1312 * Unless required by applicable law or agreed to in writing, software 1313 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1314 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1315 * 1316 * See the License for the specific language governing permissions and limitations under the License. 1317 */function qi(n,e){const t=c=>gn.prototype.push.bind(e,c,null),r=t(Ei.bind(null,n)),s=t(Ii.bind(null,n)),o=Object.assign(s,{_getHistory:function(){return window.history},_getLocation:function(){return window.location},_getDocument:function(){return window.document}}),i={prepareTokenParams:vn.bind(null,n),exchangeCodeForTokens:mi.bind(null,n),getWithoutPrompt:Tn.bind(null,n),getWithPopup:Ai.bind(null,n),getWithIDPPopup:ki.bind(null,n),getWithRedirect:r,parseFromUrl:o,decode:Dr,revoke:ji.bind(null,n),renew:Mi.bind(null,n),renewTokensWithRefresh:Sn.bind(null,n),renewTokens:Ci.bind(null,n),getUserInfo:(c,u)=>vi(n,c,u),verify:Hr.bind(null,n),isLoginRedirect:ln.bind(null,n),introspect:Di.bind(null,n)};return["getWithoutPrompt","getWithPopup","revoke","renew","renewTokensWithRefresh","renewTokens"].forEach(c=>{i[c]=t(i[c])}),i}function Bi(n){return{authorize:{enrollAuthenticator:Vi.bind(null,n)}}}/*! 1318 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1319 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1320 * 1321 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1322 * Unless required by applicable law or agreed to in writing, softw
1322are 1323 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1324 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1325 * 1326 * See the License for the specific language governing permissions and limitations under the License. 1327 */function Je(n,e){if(!X(n)&&!G(n)&&!ie(n))throw new g("Token must be an Object with scopes, expiresAt, and one of: an idToken, accessToken, or refreshToken property");if(e==="accessToken"&&!G(n))throw new g("invalid accessToken");if(e==="idToken"&&!X(n))throw new g("invalid idToken");if(e==="refreshToken"&&!ie(n))throw new g("invalid refreshToken")}/*! 1328 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1329 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1330 * 1331 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1332 * Unless required by applicable law or agreed to in writing, software 1333 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1334 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1335 * 1336 * See the License for the specific language governing permissions and limitations under the License. 1337 */class bn{constructor(e){this.localOffset=parseInt(e||0)}static create(){var e=0;return new bn(e)}now(){var e=(Date.now()+this.localOffset)/1e3;return e}}/*! 1338 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1339 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1340 * 1341 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1342 * Unless required by applicable law or agreed to in writing, software 1343 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1344 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1345 * 1346 * See the License for the specific language governing permissions and limitations under the License. 1347 */const Lt="expired",Ee="renewed",ae="added",ce="removed",Wi="error",_e="set_storage";/*! 1348 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1349 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1350 * 1351 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1352 * Unless required by applicable law or agreed to in writing, software 1353 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1354 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1355 * 1356 * See the License for the specific language governing permissions and limitations under the License. 1357 */const Dn={autoRenew:!0,autoRemove:!0,syncStorage:!0,clearPendingRemoveTokens:!0,storage:void 0,expireEarlySeconds:30,storageKey:Kt};function Ki(){return{expireTimeouts:{},renewPromise:null}}class $i{constructor(e,t={}){if(this.sdk=e,this.emitter=e.emitter,!this.emitter)throw new g("Emitter should be initialized before TokenManager");t=Object.assign({},Dn,B(t)),dr()||(t.expireEarlySeconds=Dn.expireEarlySeconds),this.options=t;const r=B({storageKey:t.storageKey,secure:t.secure});typeof t.storage=="object"?r.storageProvider=t.storage:t.storage&&(r.storageType=t.storage),this.storage=e.storageManager.getTokenStorage(Object.assign(Object.assign({},r),{useSeparateCookies:!0})),this.clock=bn.create(),this.state=Ki()}on(e,t,r){r?this.emitter.on(e,t,r):this.emitter.on(e,t)}off(e,t){t?this.emitter.off(e,t):this.emitter.off(e)}start(){this.options.clearPendingRemoveTokens&&this.clearPendingRemoveTokens(),this.setExpireEventTimeoutAll(),this.state.started=!0}stop(){this.clearExpireEventTimeoutAll(),this.state.started=!1}isStarted(){return!!this.state.started}getOptions(){return D(this.options)}getExpireTime(e){const t=this.options.expireEarlySeconds||0;var r=e.expiresAt-t;return r}hasExpired(e){var t=this.getExpireTime(e);return t<=this.clock.now()}emitExpired(e,t){this.emitter.emit(Lt,e,t)}emitRenewed(e,t,r){this.emitter.emit(Ee,e,t,r)}emitAdded(e,t){this.emitter.emit(ae,e,t)}emitRemoved(e,t){this.emitter.emit(ce,e,t)}emitError(e){this.emitter.emit(Wi,e)}clearExpireEventTimeout(e){clearTimeout(this.state.expireTimeouts[e]),delete this.state.expireTimeouts[e],this.state.renewPromise=null}clearExpireEventTimeoutAll(){var e=this.state.expireTimeouts;for(var t in e)Object.prototype.hasOwnProperty.call(e,t)&&this.clearExpireEventTimeout(t)}setExpireEventTimeout(e,t){if(!ie(t)){var r=this.getExpireTime(t),s=Math.max(r-this.clock.now(),0)*1e3;this.clearExpireEventTimeout(e);var o=setTimeout(()=>{this.emitExpired(e,t)},s);this.state.expireTimeouts[e]=o}}setExpireEventTimeoutAll(){var e=this.storage.getStorage();for(var t in e)if(Object.prototype.hasOwnProperty.call(e,t)){var r=e[t];this.setExpireEventTimeout(t,r)}}resetExpireEventTimeoutAll(){this.clearExpireEventTimeoutAll(),this.setExpireEventTimeoutAll()}add(e,t){var r=this.storage.getStorage();Je(t),r[e]=t,this.storage.setStorage(r),this.emitSetStorageEvent(),this.emitAdded(e,t),this.setExpireEventTimeout(e,t)}getSync(e){var t=this.storage.getStorage();return t[e]}
1357async get(e){return this.getSync(e)}getTokensSync(){const e={},t=this.storage.getStorage();return Object.keys(t).forEach(r=>{const s=t[r];G(s)?e.accessToken=s:X(s)?e.idToken=s:ie(s)&&(e.refreshToken=s)}),e}async getTokens(){return this.getTokensSync()}getStorageKeyByType(e){const t=this.storage.getStorage();return Object.keys(t).filter(s=>{const o=t[s];return G(o)&&e==="accessToken"||X(o)&&e==="idToken"||ie(o)&&e==="refreshToken"})[0]}getTokenType(e){if(G(e))return"accessToken";if(X(e))return"idToken";if(ie(e))return"refreshToken";throw new g("Unknown token type")}emitSetStorageEvent(){if(at()){const e=this.storage.getStorage();this.emitter.emit(_e,e)}}getStorage(){return this.storage}setTokens(e,t,r,s){const o=(d,p)=>{const v=this.getTokenType(p);v==="accessToken"?t&&t(d,p):v==="idToken"?r&&r(d,p):v==="refreshToken"&&s&&s(d,p)},i=(d,p)=>{this.emitAdded(d,p),this.setExpireEventTimeout(d,p),o(d,p)},a=(d,p,v)=>{this.emitRenewed(d,p,v),this.clearExpireEventTimeout(d),this.setExpireEventTimeout(d,p),o(d,p)},c=(d,p)=>{this.clearExpireEventTimeout(d),this.emitRemoved(d,p),o(d,p)},u=["idToken","accessToken","refreshToken"],l=this.getTokensSync();u.forEach(d=>{const p=e[d];p&&Je(p,d)});const f=u.reduce((d,p)=>{const v=e[p];if(v){const m=this.getStorageKeyByType(p)||p;d[m]=v}return d},{});this.storage.setStorage(f),this.emitSetStorageEvent(),u.forEach(d=>{const p=e[d],v=l[d],m=this.getStorageKeyByType(d)||d;p&&v?(c(m,v),i(m,p),a(m,p,v)):p?i(m,p):v&&c(m,v)})}remove(e){this.clearExpireEventTimeout(e);var t=this.storage.getStorage(),r=t[e];delete t[e],this.storage.setStorage(t),this.emitSetStorageEvent(),this.emitRemoved(e,r)}async renewToken(e){var t;return(t=this.sdk.token)===null||t===void 0?void 0:t.renew(e)}validateToken(e){return Je(e)}renew(e){if(this.state.renewPromise)return this.state.renewPromise;try{var t=this.getSync(e);let s=t!==void 0;if(!t&&e==="accessToken"){const o=this.getStorageKeyByType("refreshToken");s=this.getSync(o)!==void 0}if(!s)throw new g("The tokenManager has no token for the key: "+e)}catch(s){return this.emitError(s),Promise.reject(s)}return this.clearExpireEventTimeout(e),this.state.renewPromise=this.sdk.token.renewTokens().then(s=>{if(this.setTokens(s),!t&&e==="accessToken"){const i=s.accessToken;return this.emitRenewed(e,i,null),i}const o=this.getTokenType(t);return s[o]}).catch(s=>{throw this.remove(e),s.tokenKey=e,this.emitError(s),s}).finally(()=>{this.state.renewPromise=null})}clear(){const e=this.getTokensSync();this.clearExpireEventTimeoutAll(),this.storage.clearStorage(),this.emitSetStorageEvent(),Object.keys(e).forEach(t=>{this.emitRemoved(t,e[t])})}clearPendingRemoveTokens(){const e=this.storage.getStorage(),t={};Object.keys(e).forEach(r=>{e[r].pendingRemove&&(t[r]=e[r],delete e[r])}),this.storage.setStorage(e),this.emitSetStorageEvent(),Object.keys(t).forEach(r=>{this.clearExpireEventTimeout(r),this.emitRemoved(r,t[r])})}updateRefreshToken(e){const t=this.getStorageKeyByType("refreshToken")||Et;var r=this.storage.getStorage();Je(e),r[t]=e,this.storage.setStorage(r),this.emitSetStorageEvent()}removeRefreshToken(){const e=this.getStorageKeyByType("refreshToken")||Et;this.remove(e)}addPendingRemoveFlags(){const e=this.getTokensSync();Object.keys(e).forEach(t=>{e[t].pendingRemove=!0}),this.setTokens(e)}}/*! 1358 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1359 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1360 * 1361 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1362 * Unless required by applicable law or agreed to in writing, software 1363 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1364 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1365 * 1366 * See the License for the specific language governing permissions and limitations under the License. 1367 */var Ze={browserHasLocalStorage:function(){try{var n=this.getLocalStorage();return this.testStorage(n)}catch{return!1}},browserHasSessionStorage:function(){try{var n=this.getSessionStorage();return this.testStorage(n)}catch{return!1}},testStorageType:function(n){var e=!1;switch(n){case"sessionStorage":e=this.browserHasSessionStorage();break;case"localStorage":e=this.browserHasLocalStorage();break;case"cookie":case"memory":e=!0;break;default:e=!1;break}return e},getStorageByType:function(n,e){let t;switch(n){case"sessionStorage":t=this.getSessionStorage();break;case"localStorage":t=this.getLocalStorage();break;case"cookie":t=this.getCookieStorage(e);break;case"memory":t=this.getInMemoryStorage();break;default:throw new g(`Unrecognized storage option: ${n}`)}return t},findStorageType:function(n){let e,t;return n=n.slice(),e=n.shift(),t=n.length?n[0]:null,!t||this.testStorageType(e)?e:(K(`This browser doesn't support ${e}. Switching to ${t}.`),this.findStorageType(n))},getLocalStorage:function(){return at()&&!window.onstorage&&(window.onstorage=function(){}),localStorage},getSessionStorage:function(){return sessionStorage},getCookieStorage:function(n){const e=n.secure,t=n.sameSite,r=n.sessionCookie;if(typeof e>"u"||typeof t>"u")throw new g('getCookieStorage: "secure" and "sameSite" options must be provided');const s={getItem:this.storage.get,setItem:(o,i,a="2200-01-01T00:00:00.000Z")=>{a=r?null:a,this.storage.set(o,i,a,{secure:e,sameSite:t})},removeItem:o=>{this.storage.delete(o)}};return n.useSeparateCookies?{getItem:function(o){var i=s.getItem(),a={};
1367return Object.keys(i).forEach(c=>{c.indexOf(o)===0&&(a[c.replace(`${o}_`,"")]=JSON.parse(i[c]))}),JSON.stringify(a)},setItem:function(o,i){var a=JSON.parse(this.getItem(o));i=JSON.parse(i),Object.keys(i).forEach(c=>{var u=o+"_"+c,l=JSON.stringify(i[c]);s.setItem(u,l),delete a[c]}),Object.keys(a).forEach(c=>{s.removeItem(o+"_"+c)})},removeItem:function(o){var i=JSON.parse(this.getItem(o));Object.keys(i).forEach(a=>{s.removeItem(o+"_"+a)})}}:s},inMemoryStore:{},getInMemoryStorage:function(){return{getItem:n=>this.inMemoryStore[n],setItem:(n,e)=>{this.inMemoryStore[n]=e}}},testStorage:function(n){var e="okta-test-storage";try{return n.setItem(e,e),n.removeItem(e),!0}catch{return!1}},storage:{set:function(n,e,t,r){const{sameSite:s,secure:o}=r;if(typeof o>"u"||typeof s>"u")throw new g('storage.set: "secure" and "sameSite" options must be provided');var i={path:r.path||"/",secure:o,sameSite:s};return Date.parse(t)&&(i.expires=new Date(t)),Ke.set(n,e,i),this.get(n)},get:function(n){return arguments.length?Ke.get(n):Ke.get()},delete:function(n){return Ke.remove(n,{path:"/"})}}};/*! 1368 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1369 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1370 * 1371 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1372 * Unless required by applicable law or agreed to in writing, software 1373 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1374 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1375 * 1376 * See the License for the specific language governing permissions and limitations under the License. 1377 */function zi(n){return class extends n{setOriginalUri(t,r){Ze.getSessionStorage().setItem(Qe,t),r=r||this.options.state,r&&this.storageManager.getOriginalUriStorage().setItem(r,t)}getOriginalUri(t){if(t=t||this.options.state,t){const o=this.storageManager.getOriginalUriStorage().getItem(t);if(o)return o}const r=Ze.getSessionStorage();return r&&r.getItem(Qe)||void 0}removeOriginalUri(t){if(Ze.getSessionStorage().removeItem(Qe),t=t||this.options.state,t){const s=this.storageManager.getOriginalUriStorage();s.removeItem&&s.removeItem(t)}}}}/*! 1378 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1379 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1380 * 1381 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1382 * Unless required by applicable law or agreed to in writing, software 1383 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1384 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1385 * 1386 * See the License for the specific language governing permissions and limitations under the License. 1387 */function Gi(n,e){var t;const r=zi(n);return t=class extends r{constructor(...o){super(...o),this.transactionManager=new e(Object.assign({storageManager:this.storageManager},this.options.transactionManager)),this.pkce={DEFAULT_CODE_CHALLENGE_METHOD:Ie.DEFAULT_CODE_CHALLENGE_METHOD,generateVerifier:Ie.generateVerifier,computeChallenge:Ie.computeChallenge},this._pending={handleLogin:!1},this._tokenQueue=new gn,this.token=qi(this,this._tokenQueue),this.tokenManager=new $i(this,this.options.tokenManager),this.endpoints=Bi(this)}clearStorage(){super.clearStorage(),this.tokenManager.clear()}async isAuthenticated(o={}){const{autoRenew:i,autoRemove:a}=this.tokenManager.getOptions(),c=o.onExpiredToken?o.onExpiredToken==="renew":i,u=o.onExpiredToken?o.onExpiredToken==="remove":a;let{accessToken:l}=this.tokenManager.getTokensSync();if(l&&this.tokenManager.hasExpired(l))if(l=void 0,c)try{l=await this.tokenManager.renew("accessToken")}catch{}else u&&this.tokenManager.remove("accessToken");let{idToken:f}=this.tokenManager.getTokensSync();if(f&&this.tokenManager.hasExpired(f))if(f=void 0,c)try{f=await this.tokenManager.renew("idToken")}catch{}else u&&this.tokenManager.remove("idToken");return!!(l&&f)}async signInWithRedirect(o={}){const{originalUri:i}=o,a=he(o,["originalUri"]);
1387if(!this._pending.handleLogin){this._pending.handleLogin=!0;try{i&&this.setOriginalUri(i);const c=Object.assign({scopes:this.options.scopes||["openid","email","profile"]},a);await this.token.getWithRedirect(c)}finally{this._pending.handleLogin=!1}}}async getUser(){const{idToken:o,accessToken:i}=this.tokenManager.getTokensSync();return this.token.getUserInfo(i,o)}getIdToken(){const{idToken:o}=this.tokenManager.getTokensSync();return o?o.idToken:void 0}getAccessToken(){const{accessToken:o}=this.tokenManager.getTokensSync();return o?o.accessToken:void 0}getRefreshToken(){const{refreshToken:o}=this.tokenManager.getTokensSync();return o?o.refreshToken:void 0}async getOrRenewAccessToken(){var o;const{accessToken:i}=this.tokenManager.getTokensSync();if(i&&!this.tokenManager.hasExpired(i))return i.accessToken;try{const a=this.tokenManager.getStorageKeyByType("accessToken"),c=await this.tokenManager.renew(a??"accessToken");return(o=c==null?void 0:c.accessToken)!==null&&o!==void 0?o:null}catch(a){return this.emitter.emit("error",a),null}}async storeTokensFromRedirect(){const{tokens:o,responseType:i}=await this.token.parseFromUrl();i!=="none"&&this.tokenManager.setTokens(o)}isLoginRedirect(){return ln(this)}isPKCE(){return!!this.options.pkce}hasResponseType(o){return Ho(o,this.options)}isAuthorizationCodeFlow(){return this.hasResponseType("code")}async invokeApiMethod(o){if(!o.accessToken){const i=(await this.tokenManager.getTokens()).accessToken;o.accessToken=i==null?void 0:i.accessToken}return $(this,o)}async revokeAccessToken(o){if(!o){const i=await this.tokenManager.getTokens();o=i.accessToken;const a=this.tokenManager.getStorageKeyByType("accessToken");this.tokenManager.remove(a),this.options.dpop&&await Cn("access",i)}return o?this.token.revoke(o):Promise.resolve(null)}async revokeRefreshToken(o){if(!o){const i=await this.tokenManager.getTokens();o=i.refreshToken;const a=this.tokenManager.getStorageKeyByType("refreshToken");this.tokenManager.remove(a),this.options.dpop&&await Cn("refresh",i)}return o?this.token.revoke(o):Promise.resolve(null)}getSignOutRedirectUrl(o={}){let{idToken:i,postLogoutRedirectUri:a,state:c}=o;if(i||(i=this.tokenManager.getTokensSync().idToken),!i)return"";a===void 0&&(a=this.options.postLogoutRedirectUri);const u=ee(this).logoutUrl,l=i.idToken;let f=u+"?id_token_hint="+encodeURIComponent(l);return a&&(f+="&post_logout_redirect_uri="+encodeURIComponent(a)),c&&(f+="&state="+encodeURIComponent(c)),f}async signOut(o){var i;o=Object.assign({},o);const a=window.location.origin,c=window.location.href,u=o.postLogoutRedirectUri===null?null:o.postLogoutRedirectUri||this.options.postLogoutRedirectUri||a,l=o==null?void 0:o.state;let f=o.accessToken,d=o.refreshToken;const p=o.revokeAccessToken!==!1,v=o.revokeRefreshToken!==!1;v&&typeof d>"u"&&(d=this.tokenManager.getTokensSync().refreshToken),p&&typeof f>"u"&&(f=this.tokenManager.getTokensSync().accessToken),o.idToken||(o.idToken=this.tokenManager.getTokensSync().idToken),v&&d&&await this.revokeRefreshToken(d),p&&f&&await this.revokeAccessToken(f);const m=(i=f==null?void 0:f.dpopPairId)!==null&&i!==void 0?i:d==null?void 0:d.dpopPairId;this.options.dpop&&m&&await Nt(m);const T=this.getSignOutRedirectUrl(Object.assign(Object.assign({},o),{postLogoutRedirectUri:u}));if(T)return o.clearTokensBeforeRedirect?this.tokenManager.clear():this.tokenManager.addPendingRemoveFlags(),window.location.assign(T),!0;{const w=await this.closeSession(),A=new URL(u||a);return l&&A.searchParams.append("state",l),u===c?window.location.href=A.href:window.location.assign(A.href),w}}async getDPoPAuthorizationHeaders(o){if(!this.options.dpop)throw new g("DPoP is not configured for this client instance");let{accessToken:i}=o;if(i||(i=this.tokenManager.getTokensSync().accessToken),!i)throw new g("AccessToken is required to generate a DPoP Proof");const a=await pn(i==null?void 0:i.dpopPairId),c=await Lr(Object.assign(Object.assign({},o),{keyPair:a,accessToken:i.accessToken}));return{Authorization:`DPoP ${i.accessToken}`,Dpop:c}}async clearDPoPStorage(o=!1){var i,a;if(o)return ii();const c=await this.tokenManager.getTokens(),u=((i=c.accessToken)===null||i===void 0?void 0:i.dpopPairId)||
1387((a=c.refreshToken)===null||a===void 0?void 0:a.dpopPairId);u&&await Nt(u)}parseUseDPoPNonceError(o){var i;const a=q.getWWWAuthenticateHeader(o),c=q.parseHeader(a??"");if(Nr(c)){let u=null;return $n(o==null?void 0:o.get)&&(u=o.get("DPoP-Nonce")),u=(i=u??o["dpop-nonce"])!==null&&i!==void 0?i:o["DPoP-Nonce"],u}return null}},t.crypto=Jo,t}/*! 1388 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1389 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1390 * 1391 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1392 * Unless required by applicable law or agreed to in writing, software 1393 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1394 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1395 * 1396 * See the License for the specific language governing permissions and limitations under the License. 1397 */const Ji=null,Nn={updateAuthStatePromise:null,canceledTimes:0},Ot="authStateChange",Qi=10,Yi=(n,e)=>n?n.isAuthenticated===e.isAuthenticated&&JSON.stringify(n.idToken)===JSON.stringify(e.idToken)&&JSON.stringify(n.accessToken)===JSON.stringify(e.accessToken)&&n.error===e.error:!1;class Xi{constructor(e){if(!e.emitter)throw new g("Emitter should be initialized before AuthStateManager");this._sdk=e,this._pending=Object.assign({},Nn),this._authState=Ji,this._logOptions={},this._prevAuthState=null,this._transformQueue=new gn({quiet:!0}),e.tokenManager.on(ae,(t,r)=>{this._setLogOptions({event:ae,key:t,token:r}),this.updateAuthState()}),e.tokenManager.on(ce,(t,r)=>{this._setLogOptions({event:ce,key:t,token:r}),this.updateAuthState()})}_setLogOptions(e){this._logOptions=e}getAuthState(){return this._authState}getPreviousAuthState(){return this._prevAuthState}async updateAuthState(){const{transformAuthState:e,devMode:t}=this._sdk.options,r=a=>{const{event:c,key:u,token:l}=this._logOptions;ke().group(`OKTA-AUTH-JS:updateAuthState: Event:${c} Status:${a}`),ke().log(u,l),ke().log("Current authState",this._authState),ke().groupEnd(),this._logOptions={}},s=a=>{if(Yi(this._authState,a)){t&&r("unchanged");return}this._prevAuthState=this._authState,this._authState=a,this._sdk.emitter.emit(Ot,Object.assign({},a)),t&&r("emitted")},o=a=>this._pending.updateAuthStatePromise.then(()=>{const c=this._pending.updateAuthStatePromise;return c&&c!==a?o(c):this.getAuthState()});if(this._pending.updateAuthStatePromise){if(this._pending.canceledTimes>=Qi)return t&&r("terminated"),o(this._pending.updateAuthStatePromise);this._pending.updateAuthStatePromise.cancel()}const i=new cs((a,c,u)=>{u.shouldReject=!1,u(()=>{this._pending.updateAuthStatePromise=null,this._pending.canceledTimes=this._pending.canceledTimes+1,t&&r("canceled")});const l=f=>{if(i.isCanceled){a();return}s(f),a(),this._pending=Object.assign({},Nn)};this._sdk.isAuthenticated().then(()=>{if(i.isCanceled){a();return}const{accessToken:f,idToken:d,refreshToken:p}=this._sdk.tokenManager.getTokensSync(),v={accessToken:f,idToken:d,refreshToken:p,isAuthenticated:!!(f&&d)};(e?this._transformQueue.push(e,null,this._sdk,v):Promise.resolve(v)).then(T=>l(T)).catch(T=>l({accessToken:f,idToken:d,refreshToken:p,isAuthenticated:!1,error:T}))})});return this._pending.updateAuthStatePromise=i,o(i)}subscribe(e){this._sdk.emitter.on(Ot,e)}unsubscribe(e){this._sdk.emitter.off(Ot,e)}}/*! 1398 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1399 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1400 * 1401 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1402 * Unless required by applicable law or agreed to in writing, software 1403 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1404 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1405 * 1406 * See the License for the specific language governing permissions and limitations under the License. 1407 */class Zi{constructor(e,t={}){this.started=!1,this.tokenManager=e,this.options=t,this.renewTimeQueue=[],this.onTokenExpiredHandler=this.onTokenExpiredHandler.bind(this)}shouldThrottleRenew(){let e=!1;if(this.renewTimeQueue.push(Date.now()),this.renewTimeQueue.length>=10){const t=this.renewTimeQueue.shift();e=this.renewTimeQueue[this.renewTimeQueue.length-1]-t<30*1e3}return e}requiresLeadership(){return!!this.options.syncStorage&&I()}processExpiredTokens(){const t=this.tokenManager.getStorage().getStorage();Object.keys(t).forEach(r=>{const s=t[r];!ie(s)&&this.tokenManager.hasExpired(s)&&this.onTokenExpiredHandler(r)})}onTokenExpiredHandler(e){if(this.options.autoRenew)if(this.shouldThrottleRenew()){const t=new g("Too many token renew requests");this.tokenManager.emitError(t)}else this.tokenManager.renew(e).catch(()=>{});else this.options.autoRemove&&this.tokenManager.remove(e)}canStart(){return(!!this.options.autoRenew||!!this.options.autoRemove)&&!this.started}async start(){this.canStart()&&(this.tokenManager.on(Lt,this.onTokenExpiredHandler),this.tokenManager.isStarted()&&this.processExpiredTokens(),this.started=!0)}async stop(){this.started&&(this.tokenManager.off(Lt,this.onTokenExpiredHandler),this.renewTimeQueue=[],this.started=!1)}isStarted(){return this.started}}/*! 1408 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1409 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1410 * 1411 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1412 * Unless required by applicable law or agreed to in writing, softw
1412are 1413 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1414 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1415 * 1416 * See the License for the specific language governing permissions and limitations under the License. 1417 */class ea{constructor(e,t={}){this.started=!1,this.enablePostMessage=!0,this.tokenManager=e,this.options=t,this.onTokenAddedHandler=this.onTokenAddedHandler.bind(this),this.onTokenRemovedHandler=this.onTokenRemovedHandler.bind(this),this.onTokenRenewedHandler=this.onTokenRenewedHandler.bind(this),this.onSetStorageHandler=this.onSetStorageHandler.bind(this),this.onSyncMessageHandler=this.onSyncMessageHandler.bind(this)}requiresLeadership(){return!1}isStarted(){return this.started}canStart(){return!!this.options.syncStorage&&I()&&!this.started}async start(){if(!this.canStart())return;const{syncChannelName:e}=this.options;try{this.channel=new Bn(e)}catch{throw new g("SyncStorageService is not supported in current browser.")}this.tokenManager.on(ae,this.onTokenAddedHandler),this.tokenManager.on(ce,this.onTokenRemovedHandler),this.tokenManager.on(Ee,this.onTokenRenewedHandler),this.tokenManager.on(_e,this.onSetStorageHandler),this.channel.addEventListener("message",this.onSyncMessageHandler),this.started=!0}async stop(){var e,t;this.started&&(this.tokenManager.off(ae,this.onTokenAddedHandler),this.tokenManager.off(ce,this.onTokenRemovedHandler),this.tokenManager.off(Ee,this.onTokenRenewedHandler),this.tokenManager.off(_e,this.onSetStorageHandler),(e=this.channel)===null||e===void 0||e.removeEventListener("message",this.onSyncMessageHandler),await((t=this.channel)===null||t===void 0?void 0:t.close()),this.channel=void 0,this.started=!1)}onTokenAddedHandler(e,t){var r;this.enablePostMessage&&((r=this.channel)===null||r===void 0||r.postMessage({type:ae,key:e,token:t}))}onTokenRemovedHandler(e,t){var r;this.enablePostMessage&&((r=this.channel)===null||r===void 0||r.postMessage({type:ce,key:e,token:t}))}onTokenRenewedHandler(e,t,r){var s;this.enablePostMessage&&((s=this.channel)===null||s===void 0||s.postMessage({type:Ee,key:e,token:t,oldToken:r}))}onSetStorageHandler(e){var t;(t=this.channel)===null||t===void 0||t.postMessage({type:_e,storage:e})}onSyncMessageHandler(e){switch(this.enablePostMessage=!1,e.type){case _e:this.tokenManager.getStorage().setStorage(e.storage);break;case ae:this.tokenManager.emitAdded(e.key,e.token),this.tokenManager.setExpireEventTimeout(e.key,e.token);break;case ce:this.tokenManager.clearExpireEventTimeout(e.key),this.tokenManager.emitRemoved(e.key,e.token);break;case Ee:this.tokenManager.emitRenewed(e.key,e.token,e.oldToken);break}this.enablePostMessage=!0}}/*! 1418 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1419 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1420 * 1421 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1422 * Unless required by applicable law or agreed to in writing, software 1423 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1424 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1425 * 1426 * See the License for the specific language governing permissions and limitations under the License. 1427 */class ta{constructor(e={}){this.started=!1,this.options=e,this.onLeaderDuplicate=this.onLeaderDuplicate.bind(this),this.onLeader=this.onLeader.bind(this)}onLeaderDuplicate(){}async onLeader(){var e,t;await((t=(e=this.options).onLeader)===null||t===void 0?void 0:t.call(e))}isLeader(){var e;return!!(!((e=this.elector)===null||e===void 0)&&e.isLeader)}hasLeader(){var e;return!!(!((e=this.elector)===null||e===void 0)&&e.hasLeader)}async start(){if(this.canStart()){const{electionChannelName:e}=this.options;this.channel=new Bn(e),this.elector=us(this.channel),this.elector.onduplicate=this.onLeaderDuplicate,this.elector.awaitLeadership().then(this.onLeader),this.started=!0}}async stop(){this.started&&(this.elector&&(await this.elector.die(),this.elector=void 0),this.channel&&(this.channel.postInternal=()=>Promise.resolve(),await this.channel.close(),this.channel=void 0),this.started=!1)}requiresLeadership(){return!1}isStarted(){return this.started}canStart(){return I()&&!this.started}}/*! 1428 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1429 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1430 * 1431 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1432 * Unless required by applicable law or agreed to in writing, softw
1432are 1433 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1434 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1435 * 1436 * See the License for the specific language governing permissions and limitations under the License. 1437 */const Fn=()=>Math.floor(Date.now()/1e3);class na{constructor(e,t={}){this.started=!1,this.lastHidden=-1,this.tokenManager=e,this.options=t,this.onPageVisbilityChange=this._onPageVisbilityChange.bind(this)}_onPageVisbilityChange(){if(document.hidden)this.lastHidden=Fn();else if(this.lastHidden>0&&Fn()-this.lastHidden>=this.options.tabInactivityDuration){const{accessToken:e,idToken:t}=this.tokenManager.getTokensSync();if(e&&this.tokenManager.hasExpired(e)){const r=this.tokenManager.getStorageKeyByType("accessToken");this.tokenManager.renew(r).catch(()=>{})}else if(t&&this.tokenManager.hasExpired(t)){const r=this.tokenManager.getStorageKeyByType("idToken");this.tokenManager.renew(r).catch(()=>{})}}}async start(){this.canStart()&&document&&(document.addEventListener("visibilitychange",this.onPageVisbilityChange),this.started=!0)}async stop(){document&&(document.removeEventListener("visibilitychange",this.onPageVisbilityChange),this.started=!1)}canStart(){return I()&&!!this.options.autoRenew&&!!this.options.renewOnTabActivation&&!this.started}requiresLeadership(){return!1}isStarted(){return this.started}}/*! 1438 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1439 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1440 * 1441 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1442 * Unless required by applicable law or agreed to in writing, software 1443 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1444 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1445 * 1446 * See the License for the specific language governing permissions and limitations under the License. 1447 */const zr="autoRenew",Gr="syncStorage",et="leaderElection",Jr="renewOnTabActivation";class Se{constructor(e,t={}){this.sdk=e,this.onLeader=this.onLeader.bind(this);const{autoRenew:r,autoRemove:s,syncStorage:o}=e.tokenManager.getOptions();t.electionChannelName=t.electionChannelName||t.broadcastChannelName,this.options=Object.assign({},Se.defaultOptions,{autoRenew:r,autoRemove:s,syncStorage:o},{electionChannelName:`${e.options.clientId}-election`,syncChannelName:`${e.options.clientId}-sync`},B(t)),this.started=!1,this.services=new Map,Se.knownServices.forEach(i=>{const a=this.createService(i);a&&this.services.set(i,a)})}async onLeader(){this.started&&await this.startServices()}isLeader(){var e;return(e=this.getService(et))===null||e===void 0?void 0:e.isLeader()}isLeaderRequired(){return[...this.services.values()].some(e=>e.canStart()&&e.requiresLeadership())}async start(){this.started||(await this.startServices(),this.started=!0)}async stop(){await this.stopServices(),this.started=!1}getService(e){return this.services.get(e)}async startServices(){for(const[e,t]of this.services.entries())this.canStartService(e,t)&&await t.start()}async stopServices(){for(const e of this.services.values())await e.stop()}canStartService(e,t){let r=t.canStart()&&!t.isStarted();return e===et?r&&(r=this.isLeaderRequired()):t.requiresLeadership()&&r&&(r=this.isLeader()),r}createService(e){const t=this.sdk.tokenManager;let r;switch(e){case et:r=new ta(Object.assign(Object.assign({},this.options),{onLeader:this.onLeader}));break;case zr:r=new Zi(t,Object.assign({},this.options));break;case Gr:r=new ea(t,Object.assign({},this.options));break;case Jr:r=new na(t,Object.assign({},this.options));break;default:throw new Error(`Unknown service ${e}`)}return r}}Se.knownServices=[zr,Gr,et,Jr];Se.defaultOptions={autoRenew:!0,autoRemove:!0,syncStorage:!0,renewOnTabActivation:!0,tabInactivityDuration:1800};/*! 1448 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1449 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1450 * 1451 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1452 * Unless required by applicable law or agreed to in writing, softw
1452are 1453 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1454 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1455 * 1456 * See the License for the specific language governing permissions and limitations under the License. 1457 */function ra(n){return class extends n{constructor(...t){super(...t),this.authStateManager=new Xi(this),this.serviceManager=new Se(this,this.options.services)}async start(){await this.serviceManager.start(),this.tokenManager.start(),this.token.isLoginRedirect()||await this.authStateManager.updateAuthState()}async stop(){this.tokenManager.stop(),await this.serviceManager.stop()}async handleRedirect(t){await this.handleLoginRedirect(void 0,t)}async handleLoginRedirect(t,r){let s=this.options.state;if(t)this.tokenManager.setTokens(t),r=r||this.getOriginalUri(this.options.state);else if(this.isLoginRedirect())try{s=(await Ft(this,{})).state,r=r||this.getOriginalUri(s),await this.storeTokensFromRedirect()}catch(i){throw await this.authStateManager.updateAuthState(),i}else return;await this.authStateManager.updateAuthState(),this.removeOriginalUri(s);const{restoreOriginalUri:o}=this.options;o?await o(this,r):r&&window.location.replace(r)}handleIDPPopupRedirect(t=window.location.href){const r=Ft(this,{responseMode:"query",url:t});if(r.state){const s=new BroadcastChannel(`popup-callback:${r.state}`);s.postMessage(r),s.close()}else throw new g("Unable to parse auth code params")}}}/*! 1458 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1459 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1460 * 1461 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1462 * Unless required by applicable law or agreed to in writing, software 1463 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1464 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1465 * 1466 * See the License for the specific language governing permissions and limitations under the License. 1467 */function sa(n){return n.session.get().then(function(e){return e.status==="ACTIVE"}).catch(function(){return!1})}function oa(n){return we(n,"/api/v1/sessions/me",{withCredentials:!0}).then(function(e){var t=Pe(e,"_links");return t.refresh=function(){return te(n,kt(e,"refresh").href,{},{withCredentials:!0})},t.user=function(){return we(n,kt(e,"user").href,{withCredentials:!0})},t}).catch(function(){return{status:"INACTIVE"}})}function ia(n){return $(n,{url:n.getIssuerOrigin()+"/api/v1/sessions/me",method:"DELETE",withCredentials:!0})}function aa(n){return te(n,"/api/v1/sessions/me/lifecycle/refresh",{},{withCredentials:!0})}function ca(n,e,t){t=t||window.location.href,window.location.assign(n.getIssuerOrigin()+"/login/sessionCookieRedirect"+J({checkAccountSetupComplete:!0,token:e,redirectUrl:t}))}/*! 1468 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1469 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1470 * 1471 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1472 * Unless required by applicable law or agreed to in writing, software 1473 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1474 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1475 * 1476 * See the License for the specific language governing permissions and limitations under the License. 1477 */function ua(n){return{close:ia.bind(null,n),exists:sa.bind(null,n),get:oa.bind(null,n),refresh:aa.bind(null,n),setCookieAndRedirect:ca.bind(null,n)}}/*! 1478 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1479 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1480 * 1481 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1482 * Unless required by applicable law or agreed to in writing, software 1483 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1484 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1485 * 1486 * See the License for the specific language governing permissions and limitations under the License. 1487 */function la(n){return class extends n{constructor(...t){super(...t),this.session=ua(this)}closeSession(){return this.session.close().then(async()=>(this.clearStorage(),!0)).catch(function(t){if(t.name==="AuthApiError"&&t.errorCode==="E0000007")return!1;throw t})}}}/*! 1488 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1489 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1490 * 1491 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1492 * Unless required by applicable law or agreed to in writing, softw
1492are 1493 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1494 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1495 * 1496 * See the License for the specific language governing permissions and limitations under the License. 1497 */function da(n,e,t){const r=Wo(e),s=Ko(r,n),o=Go(s),i=la(o),a=Gi(i,t);return ra(a)}/*! 1498 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1499 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1500 * 1501 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1502 * Unless required by applicable law or agreed to in writing, software 1503 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1504 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1505 * 1506 * See the License for the specific language governing permissions and limitations under the License. 1507 */const ha=(n,e)=>e.source===n.contentWindow;function Qr(n,e){var t;if(!ar())return Promise.reject(new g("Fingerprinting is not supported on this device"));const r=(t=e==null?void 0:e.container)!==null&&t!==void 0?t:document.body;let s,o,i;return new Promise(function(c,u){o=document.createElement("iframe"),o.style.display="none",i=function(f){var d;if(!ha(o,f)||!f||!f.data||f.origin!==n.getIssuerOrigin())return;let p;try{p=JSON.parse(f.data)}catch{return}if(p){if(p.type==="FingerprintAvailable")return c(p.fingerprint);if(p.type==="FingerprintServiceReady")(d=o==null?void 0:o.contentWindow)===null||d===void 0||d.postMessage(JSON.stringify({type:"GetFingerprint"}),f.origin);else return u(new g("No data"))}},qr(window,"message",i),o.src=n.getIssuerOrigin()+"/auth/services/devicefingerprint",r.appendChild(o),s=setTimeout(function(){u(new g("Fingerprinting timed out"))},(e==null?void 0:e.timeout)||15e3)}).finally(function(){var c;clearTimeout(s),Br(window,"message",i),r.contains(o)&&((c=o.parentElement)===null||c===void 0||c.removeChild(o))})}/*! 1508 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1509 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1510 * 1511 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1512 * Unless required by applicable law or agreed to in writing, software 1513 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1514 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1515 * 1516 * See the License for the specific language governing permissions and limitations under the License. 1517 */const Yr=(n=[])=>{const e=[];return n.forEach(t=>{var r,s;if(t.key==="webauthn"){const o={type:"public-key",id:Me(t.credentialId)},i=(r=t.transports)!==null&&r!==void 0?r:(s=t.profile)===null||s===void 0?void 0:s.transports;Array.isArray(i)&&(o.transports=i),e.push(o)}}),e},fa=(n,e)=>({publicKey:Object.assign({rp:n.rp,user:{id:Me(n.user.id),name:n.user.name,displayName:n.user.displayName},challenge:Me(n.challenge),pubKeyCredParams:n.pubKeyCredParams,attestation:n.attestation,authenticatorSelection:n.authenticatorSelection,excludeCredentials:Yr(e)},n.hints&&{hints:n.hints})}),ga=(n,e)=>({publicKey:Object.assign(Object.assign({challenge:Me(n.challenge),userVerification:n.userVerification,allowCredentials:Yr(e)},n.rpId&&{rpId:n.rpId}),n.hints&&{hints:n.hints})}),pa=n=>{const e=n.response,t=n.id,r=le(e.clientDataJSON),s=le(e.attestationObject),o=e.getTransports,i={id:t,clientData:r,attestation:s};return typeof o=="function"&&(i.transports=JSON.stringify(o.call(e))),i},ma=n=>{const e=n.response,t=n.id,r=le(e.clientDataJSON),s=le(e.authenticatorData),o=le(e.signature);return{id:t,clientData:r,authenticatorData:s,signatureData:o}},va=Object.freeze(Object.defineProperty({__proto__:null,buildCredentialCreationOptions:fa,buildCredentialRequestOptions:ga,getAssertion:ma,getAttestation:pa},Symbol.toStringTag,{value:"Module"}));/*! 1518 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1519 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1520 * 1521 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1522 * Unless required by applicable law or agreed to in writing, softw
1522are 1523 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1524 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1525 * 1526 * See the License for the specific language governing permissions and limitations under the License. 1527 */function ya(n){var e;return e=class extends n{constructor(...r){super(...r),this.idx=Bo(this),this.fingerprint=Qr.bind(null,this)}},e.webauthn=va,e}/*! 1528 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1529 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1530 * 1531 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1532 * Unless required by applicable law or agreed to in writing, software 1533 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1534 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1535 * 1536 * See the License for the specific language governing permissions and limitations under the License. 1537 */function wa(n,e,t){const r=da(n,e,t);return ya(r)}/*! 1538 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1539 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1540 * 1541 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1542 * Unless required by applicable law or agreed to in writing, software 1543 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1544 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1545 * 1546 * See the License for the specific language governing permissions and limitations under the License. 1547 */function Ta(){return class{constructor(e){this.devMode=!!e.devMode}}}/*! 1548 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1549 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1550 * 1551 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1552 * Unless required by applicable law or agreed to in writing, software 1553 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1554 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1555 * 1556 * See the License for the specific language governing permissions and limitations under the License. 1557 */function Sa(){return Object.assign({},Ze,{inMemoryStore:{}})}const ba={token:{storageTypes:["localStorage","sessionStorage","cookie"]},cache:{storageTypes:["localStorage","sessionStorage","cookie"]},transaction:{storageTypes:["sessionStorage","localStorage","cookie"]},"shared-transaction":{storageTypes:["localStorage"]},"original-uri":{storageTypes:["localStorage"]}};function Oa(n={},e){var t=n.cookies||{};return typeof t.secure>"u"&&(t.secure=e),typeof t.sameSite>"u"&&(t.sameSite=t.secure?"none":"lax"),t.secure&&!e&&(K(`The current page is not being served with the HTTPS protocol. 1558For security reasons, we strongly recommend using HTTPS. 1559If you cannot use HTTPS, set "cookies.secure" option to false.`),t.secure=!1),t.sameSite==="none"&&!t.secure&&(t.sameSite="lax"),t}/*! 1560 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1561 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1562 * 1563 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1564 * Unless required by applicable law or agreed to in writing, software 1565 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1566 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1567 * 1568 * See the License for the specific language governing permissions and limitations under the License. 1569 */function Aa(){const n=Ta();return class extends n{constructor(t){super(t),this.cookies=Oa(t,lr()),this.storageUtil=t.storageUtil||Sa(),this.storageManager=Object.assign(Object.assign({},ba),t.storageManager)}}}/*! 1570 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1571 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1572 * 1573 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1574 * Unless required by applicable law or agreed to in writing, softw
1574are 1575 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1576 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1577 * 1578 * See the License for the specific language governing permissions and limitations under the License. 1579 */const ka=/application\/\w*\+?json/;function Ea(n){return n.headers.get("Content-Type")&&n.headers.get("Content-Type").toLowerCase().indexOf("application/json")>=0?n.json().catch(e=>({error:e,errorSummary:"Could not parse server response"})):n.text()}function _a(n,e,t){const r=typeof e=="object",s={};for(const i of t.headers.entries())s[i[0]]=i[1];const o={responseText:r?JSON.stringify(e):e,status:n,headers:s};return r&&(o.responseType="json",o.responseJSON=e),o}function Pa(n,e,t){var r=t.data,s=t.headers||{},o=s["Content-Type"]||s["content-type"]||"";r&&typeof r!="string"&&(ka.test(o)?r=JSON.stringify(r):o==="application/x-www-form-urlencoded"&&(r=Object.entries(r).map(([c,u])=>`${c}=${encodeURIComponent(u)}`).join("&")));var i=window.fetch||Is,a=i(e,{method:n,headers:t.headers,body:r,credentials:t.withCredentials?"include":"omit"});return a.finally||(a=Promise.resolve(a)),a.then(function(c){var u=!c.ok,l=c.status;return Ea(c).then(f=>_a(l,f,c)).then(f=>{var d;if(u||!((d=f.responseJSON)===null||d===void 0)&&d.error)throw f;return f})})}/*! 1580 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1581 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1582 * 1583 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1584 * Unless required by applicable law or agreed to in writing, software 1585 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1586 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1587 * 1588 * See the License for the specific language governing permissions and limitations under the License. 1589 */function Ra(){const n=Aa();return class extends n{constructor(t){super(t),this.issuer=t.issuer,this.transformErrorXHR=t.transformErrorXHR,this.headers=t.headers,this.httpRequestClient=t.httpRequestClient||Pa,this.httpRequestInterceptors=t.httpRequestInterceptors,this.pollDelay=t.pollDelay}}}/*! 1590 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1591 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1592 * 1593 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1594 * Unless required by applicable law or agreed to in writing, software 1595 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1596 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1597 * 1598 * See the License for the specific language governing permissions and limitations under the License. 1599 */const Ia=!0;/*! 1600 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1601 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1602 * 1603 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1604 * Unless required by applicable law or agreed to in writing, software 1605 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1606 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1607 * 1608 * See the License for the specific language governing permissions and limitations under the License. 1609 */function xa(n){n=n||{};var e=n.scopes;if(e&&!Array.isArray(e))throw new g('scopes must be a array of strings. Required usage: new OktaAuth({scopes: ["openid", "email"]})');var t=n.issuer;if(!t)throw new g('No issuer passed to constructor. Required usage: new OktaAuth({issuer: "https://{yourOktaDomain}.com/oauth2/{authServerId}"})');var r=new RegExp("^http?s?://.+");if(!r.test(t))throw new g('Issuer must be a valid URL. Required usage: new OktaAuth({issuer: "https://{yourOktaDomain}.com/oauth2/{authServerId}"})');if(t.indexOf("-admin.okta")!==-1)throw new g('Issuer URL passed to constructor contains "-admin" in subdomain. Required usage: new OktaAuth({issuer: "https://{yourOktaDomain}.com})')}function Ma(){const n=Ra();return class extends n{constructor(t){super(t),xa(t),this.issuer=H(t.issuer),this.tokenUrl=H(t.tokenUrl),this.authorizeUrl=H(t.authorizeUrl),this.userinfoUrl=H(t.userinfoUrl),this.revokeUrl=H(t.revokeUrl),this.logoutUrl=H(t.logoutUrl),this.pkce=t.pkce!==!1,this.clientId=t.clientId,this.redirectUri=t.redirectUri,I()&&(this.redirectUri=ms(t.redirectUri,window.location.origin)),this.responseType=t.responseType,this.responseMode=t.responseMode,this.state=t.state,this.scopes=t.scopes,this.ignoreSignature=!!t.ignoreSignature,this.co
1609deChallenge=t.codeChallenge,this.codeChallengeMethod=t.codeChallengeMethod,this.acrValues=t.acrValues,this.maxAge=t.maxAge,this.dpop=t.dpop===!0,this.dpopOptions=Object.assign({allowBearerTokens:!1},t.dpopOptions),this.tokenManager=t.tokenManager,this.postLogoutRedirectUri=t.postLogoutRedirectUri,this.restoreOriginalUri=t.restoreOriginalUri,this.transactionManager=Object.assign({enableSharedStorage:Ia},t.transactionManager),this.clientSecret=t.clientSecret,this.setLocation=t.setLocation,this.ignoreLifetime=!!t.ignoreLifetime,!t.maxClockSkew&&t.maxClockSkew!==0?this.maxClockSkew=Xn:this.maxClockSkew=t.maxClockSkew}}}/*! 1610 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1611 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1612 * 1613 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1614 * Unless required by applicable law or agreed to in writing, software 1615 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1616 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1617 * 1618 * See the License for the specific language governing permissions and limitations under the License. 1619 */function Ca(){const n=Ma();return class extends n{constructor(t){super(t),this.services=t.services,this.transformAuthState=t.transformAuthState}}}/*! 1620 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1621 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1622 * 1623 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1624 * Unless required by applicable law or agreed to in writing, software 1625 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1626 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1627 * 1628 * See the License for the specific language governing permissions and limitations under the License. 1629 */function ja(){const n=Ca();return class extends n{constructor(t){super(t),this.flow=t.flow,this.activationToken=t.activationToken,this.recoveryToken=t.recoveryToken,this.idx=t.idx}}}/*! 1630 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1631 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1632 * 1633 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1634 * Unless required by applicable law or agreed to in writing, software 1635 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1636 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1637 * 1638 * See the License for the specific language governing permissions and limitations under the License. 1639 */class me{constructor(e,t){if(!e)throw new g('"storage" is required');if(typeof t!="string"||!t.length)throw new g('"storageName" is required');this.storageName=t,this.storageProvider=e}getItem(e){return this.getStorage()[e]}setItem(e,t){return this.updateStorage(e,t)}removeItem(e){return this.clearStorage(e)}getStorage(){var e=this.storageProvider.getItem(this.storageName);e=e||"{}";try{return JSON.parse(e)}catch{throw new g("Unable to parse storage string: "+this.storageName)}}setStorage(e){try{var t=e?JSON.stringify(e):"{}";this.storageProvider.setItem(this.storageName,t)}catch{throw new g("Unable to set storage: "+this.storageName)}}clearStorage(e){if(!e){this.storageProvider.removeItem?this.storageProvider.removeItem(this.storageName):this.setStorage();return}var t=this.getStorage();delete t[e],this.setStorage(t)}updateStorage(e,t){var r=this.getStorage();r[e]=t,this.setStorage(r)}}/*! 1640 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1641 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1642 * 1643 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1644 * Unless required by applicable law or agreed to in writing, softw
1644are 1645 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1646 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1647 * 1648 * See the License for the specific language governing permissions and limitations under the License. 1649 */function tt(n){!I()&&!n.storageProvider&&!n.storageKey&&K("Memory storage can only support simple single user use case on server side, please provide custom storageProvider or storageKey if advanced scenarios need to be supported.")}class Ua{constructor(e,t,r){this.storageManagerOptions=e,this.cookieOptions=t,this.storageUtil=r}getOptionsForSection(e,t){return Object.assign({},this.storageManagerOptions[e],t)}getStorage(e){if(e=Object.assign({},this.cookieOptions,e),e.storageProvider)return e.storageProvider;let{storageType:t,storageTypes:r}=e;if(t==="sessionStorage"&&(e.sessionCookie=!0),t&&r){const s=r.indexOf(t);s>=0&&(r=r.slice(s),t=void 0)}return t||(t=this.storageUtil.findStorageType(r)),this.storageUtil.getStorageByType(t,e)}getTokenStorage(e){e=this.getOptionsForSection("token",e),tt(e);const t=this.getStorage(e),r=e.storageKey||Kt;return new me(t,r)}getHttpCache(e){e=this.getOptionsForSection("cache",e);const t=this.getStorage(e),r=e.storageKey||er;return new me(t,r)}}/*! 1650 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1651 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1652 * 1653 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1654 * Unless required by applicable law or agreed to in writing, software 1655 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1656 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1657 * 1658 * See the License for the specific language governing permissions and limitations under the License. 1659 */function Da(){return class extends Ua{constructor(e,t,r){super(e,t,r)}getTransactionStorage(e){e=this.getOptionsForSection("transaction",e),tt(e);const t=this.getStorage(e),r=e.storageKey||tr;return new me(t,r)}getSharedTansactionStorage(e){e=this.getOptionsForSection("shared-transaction",e),tt(e);const t=this.getStorage(e),r=e.storageKey||nr;return new me(t,r)}getOriginalUriStorage(e){e=this.getOptionsForSection("original-uri",e),tt(e);const t=this.getStorage(e),r=e.storageKey||rr;return new me(t,r)}}}/*! 1660 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1661 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1662 * 1663 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1664 * Unless required by applicable law or agreed to in writing, software 1665 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1666 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1667 * 1668 * See the License for the specific language governing permissions and limitations under the License. 1669 */function Na(){return Da()}/*! 1670 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1671 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1672 * 1673 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1674 * Unless required by applicable law or agreed to in writing, software 1675 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1676 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1677 * 1678 * See the License for the specific language governing permissions and limitations under the License. 1679 */function Fa(){const n=Na();return class extends n{constructor(t,r,s){super(t,r,s)}getIdxResponseStorage(t){let r;if(I())try{r=this.storageUtil.getStorageByType("memory",t)}catch{K("No response storage found, you may want to provide custom implementation for intermediate idx responses to optimize the network traffic")}else{const s=this.getTransactionStorage(t);s&&(r={getItem:o=>{const i=s.getStorage();return i&&i[o]?i[o]:null},setItem:(o,i)=>
1679{const a=s.getStorage();if(!a)throw new g("Transaction has been cleared, failed to save idxState");a[o]=i,s.setStorage(a)},removeItem:o=>{const i=s.getStorage();i&&(delete i[o],s.setStorage(i))}})}return r?new me(r,sr):null}}}/*! 1680 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1681 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1682 * 1683 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1684 * Unless required by applicable law or agreed to in writing, software 1685 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1686 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1687 * 1688 * See the License for the specific language governing permissions and limitations under the License. 1689 */function Xr(n){return!(!n||typeof n!="object"||Object.values(n).length===0)}function La(n){return Xr(n)?!!n.redirectUri||!!n.responseType:!1}function Ha(n){return Xr(n)?Object.values(n).find(t=>typeof t!="string")===void 0:!1}function nt(n){return!!(La(n)||Ha(n))}/*! 1690 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1691 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1692 * 1693 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1694 * Unless required by applicable law or agreed to in writing, software 1695 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1696 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1697 * 1698 * See the License for the specific language governing permissions and limitations under the License. 1699 */const Va=1800*1e3;function qa(n){const e=n.getSharedTansactionStorage(),t=e.getStorage();Object.keys(t).forEach(r=>{const s=t[r];Date.now()-s.dateCreated>Va&&delete t[r]}),e.setStorage(t)}function Ba(n,e,t){const r=n.getSharedTansactionStorage(),s=r.getStorage();s[e]={dateCreated:Date.now(),transaction:t},r.setStorage(s)}function Wa(n,e){const s=n.getSharedTansactionStorage().getStorage()[e];return s&&s.transaction&&nt(s.transaction)?s.transaction:null}function Ka(n,e){const t=n.getSharedTansactionStorage(),r=t.getStorage();delete r[e],t.setStorage(r)}/*! 1700 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1701 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1702 * 1703 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1704 * Unless required by applicable law or agreed to in writing, software 1705 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1706 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1707 * 1708 * See the License for the specific language governing permissions and limitations under the License. 1709 */function $a(){return class{constructor(e){this.storageManager=e.storageManager,this.enableSharedStorage=e.enableSharedStorage!==!1,this.saveLastResponse=e.saveLastResponse!==!1,this.options=e}clear(e={}){const t=this.storageManager.getTransactionStorage(),r=t.getStorage();if(t.clearStorage(),this.enableSharedStorage&&e.clearSharedStorage!==!1){const s=e.state||(r==null?void 0:r.state);s&&Ka(this.storageManager,s)}}save(e,t={}){let r=this.storageManager.getTransactionStorage();const s=r.getStorage();nt(s)&&!t.muteWarning&&K("a saved auth transaction exists in storage. This may indicate another auth flow is already in progress."),r.setStorage(e),this.enableSharedStorage&&e.state&&Ba(this.storageManager,e.state,e)}exists(e={}){try{return!!this.load(e)}catch{return!1}}load(e={}){let t;return this.enableSharedStorage&&e.state&&(qa(this.storageManager),t=Wa(this.storageManager,e.state),nt(t))||(t=this.storageManager.getTransactionStorage().getStorage(),nt(t))?t:null}}}/*! 1710 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1711 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1712 * 1713 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1714 * Unless required by applicable law or agreed to in writing, softw
1714are 1715 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1716 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1717 * 1718 * See the License for the specific language governing permissions and limitations under the License. 1719 */function za(){const n=$a();return class extends n{constructor(t){super(t)}clear(t={}){super.clear(t),t.clearIdxResponse!==!1&&this.clearIdxResponse()}saveIdxResponse(t){if(!this.saveLastResponse)return;const r=this.storageManager.getIdxResponseStorage();r&&r.setStorage(t)}loadIdxResponse(t){if(!this.saveLastResponse)return null;const r=this.storageManager.getIdxResponseStorage();if(!r)return null;const s=r.getStorage();if(!s||!wr(s.rawIdxResponse))return null;if(t){const{stateHandle:o,interactionHandle:i}=t;if(!t.useGenericRemediator&&o&&s.stateHandle!==o||i&&s.interactionHandle!==i)return null}return s}clearIdxResponse(){if(!this.saveLastResponse)return;const t=this.storageManager.getIdxResponseStorage();t==null||t.clearStorage()}}}/*! 1720 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1721 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1722 * 1723 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1724 * Unless required by applicable law or agreed to in writing, software 1725 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1726 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1727 * 1728 * See the License for the specific language governing permissions and limitations under the License. 1729 */class Q{constructor(e,t){const{res:r}=t,{headers:s}=r,o=he(r,["headers"]);s&&(this.headers=s),Object.keys(o).forEach(i=>{i!=="_links"&&(this[i]=o[i])})}}/*! 1730 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1731 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1732 * 1733 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1734 * Unless required by applicable law or agreed to in writing, software 1735 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1736 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1737 * 1738 * See the License for the specific language governing permissions and limitations under the License. 1739 */async function P(n,e,t=Q){const{accessToken:r}=n.tokenManager.getTokensSync(),s=e.accessToken||r,o=n.getIssuerOrigin(),{url:i,method:a,payload:c}=e,u=i.startsWith(o)?i:`${o}${i}`;if(!s)throw new g("AccessToken is required to request MyAccount API endpoints.");let l=s;const f=Object.assign({headers:{Accept:"*/*;okta-version=1.0.0"},url:u,method:a},c&&{args:c});if(n.options.dpop){if(typeof l=="string")throw new g("AccessToken object must be provided when using dpop");const{Authorization:v,Dpop:m}=await n.getDPoPAuthorizationHeaders({method:a,url:u,accessToken:l});f.headers.Authorization=v,f.headers.Dpop=m}else l=typeof l=="string"?l:l.accessToken,f.accessToken=l;const d=await $(n,f);let p;return Array.isArray(d)?p=d.map(v=>new t(n,{res:v,accessToken:l})):p=new t(n,{res:d,accessToken:l}),p}function j({oktaAuth:n,accessToken:e,methodName:t,links:r},s=Q){for(const i of["GET","POST","PUT","DELETE"])if(i.toLowerCase()===t){const a=r.self;return(async c=>P(n,{accessToken:e,url:a.href,method:i,payload:c},s))}const o=r[t];if(!o)throw new g(`No link is found with methodName: ${t}`);return(async i=>P(n,{accessToken:e,url:o.href,method:o.hints.allow[0],payload:i},s))}/*! 1740 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1741 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1742 * 1743 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1744 * Unless required by applicable law or agreed to in writing, software 1745 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1746 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1747 * 1748 * See the License for the specific language governing permissions and limitations under the License. 1749 */class Zr extends Q{constructor(e,t){super(e,t);const{createdAt:r,modifiedAt:s,profile:o}=t.res;this.createdAt=r,this.modifiedAt=s,this.profile=o}}/*! 1750 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1751 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1752 * 1753 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1754 * Unless required by applicable law or agreed to in writing, softw
1754are 1755 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1756 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1757 * 1758 * See the License for the specific language governing permissions and limitations under the License. 1759 */class Ga extends Q{constructor(e,t){super(e,t),this.properties=t.res.properties}}/*! 1760 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1761 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1762 * 1763 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1764 * Unless required by applicable law or agreed to in writing, software 1765 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1766 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1767 * 1768 * See the License for the specific language governing permissions and limitations under the License. 1769 */var Ln;(function(n){n.PRIMARY="PRIMARY",n.SECONDARY="SECONDARY"})(Ln||(Ln={}));var Hn;(function(n){n.VERIFIED="VERIFIED",n.UNVERIFIED="UNVERIFIED"})(Hn||(Hn={}));var Ht;(function(n){n.NOT_ENROLLED="NOT_ENROLLED",n.ACTIVE="ACTIVE"})(Ht||(Ht={}));/*! 1770 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1771 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1772 * 1773 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1774 * Unless required by applicable law or agreed to in writing, software 1775 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1776 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1777 * 1778 * See the License for the specific language governing permissions and limitations under the License. 1779 */const Ja=async(n,e)=>await P(n,{url:"/idp/myaccount/profile",method:"GET",accessToken:e==null?void 0:e.accessToken},Zr),Qa=async(n,e)=>{const{payload:t,accessToken:r}=e;return await P(n,{url:"/idp/myaccount/profile",method:"PUT",payload:t,accessToken:r},Zr)},Ya=async(n,e)=>await P(n,{url:"/idp/myaccount/profile/schema",method:"GET",accessToken:e==null?void 0:e.accessToken},Ga);/*! 1780 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1781 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1782 * 1783 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1784 * Unless required by applicable law or agreed to in writing, software 1785 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1786 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1787 * 1788 * See the License for the specific language governing permissions and limitations under the License. 1789 */class es extends Q{constructor(e,t){super(e,t);const{res:r}=t,{id:s,profile:o,expiresAt:i,status:a}=r;this.id=s,this.expiresAt=i,this.profile=o,this.status=a}}/*! 1790 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1791 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1792 * 1793 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1794 * Unless required by applicable law or agreed to in writing, software 1795 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1796 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1797 * 1798 * See the License for the specific language governing permissions and limitations under the License. 1799 */class He extends Q{constructor(e,t){super(e,t);const{accessToken:r,res:s}=t,{id:o,expiresAt:i,profile:a,status:c,_links:u}=s;this.id=o,this.expiresAt=i,this.profile=a,this.status=c,this.poll=async()=>await j({oktaAuth:e,accessToken:r,methodName:"poll",links:u},es)(),this.verify=async l=>await j({oktaAuth:e,accessToken:r,methodName:"verify",links:u},He)(l)}}/*! 1800 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1801 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1802 * 1803 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1804 * Unless required by applicable law or agreed to in writing, softw
1804are 1805 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1806 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1807 * 1808 * See the License for the specific language governing permissions and limitations under the License. 1809 */class Ve extends Q{constructor(e,t){super(e,t);const{accessToken:r,res:s}=t,{id:o,profile:i,roles:a,status:c,_links:u}=s;this.id=o,this.profile=i,this.roles=a,this.status=c,this.get=async()=>await j({oktaAuth:e,accessToken:r,methodName:"get",links:u},Ve)(),this.delete=async()=>await j({oktaAuth:e,accessToken:r,methodName:"delete",links:u})(),this.challenge=async()=>await j({oktaAuth:e,accessToken:r,methodName:"challenge",links:u},He)(),u.poll&&(this.poll=async()=>await j({oktaAuth:e,accessToken:r,methodName:"poll",links:u},es)()),u.verify&&(this.verify=async l=>await j({oktaAuth:e,accessToken:r,methodName:"verify",links:u})(l))}}/*! 1810 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1811 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1812 * 1813 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1814 * Unless required by applicable law or agreed to in writing, software 1815 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1816 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1817 * 1818 * See the License for the specific language governing permissions and limitations under the License. 1819 */const Xa=async(n,e)=>await P(n,{url:"/idp/myaccount/emails",method:"GET",accessToken:e==null?void 0:e.accessToken},Ve),Za=async(n,e)=>{const{id:t,accessToken:r}=e;return await P(n,{url:`/idp/myaccount/emails/${t}`,method:"GET",accessToken:r},Ve)},ec=async(n,e)=>{const{accessToken:t,payload:r}=e;return await P(n,{url:"/idp/myaccount/emails",method:"POST",payload:r,accessToken:t},Ve)},tc=async(n,e)=>{const{id:t,accessToken:r}=e;return await P(n,{url:`/idp/myaccount/emails/${t}`,method:"DELETE",accessToken:r})},nc=async(n,e)=>{const{id:t,accessToken:r}=e;return await P(n,{url:`/idp/myaccount/emails/${t}/challenge`,method:"POST",accessToken:r},He)},rc=async(n,e)=>{const{emailId:t,challengeId:r,accessToken:s}=e;return await P(n,{url:`/idp/myaccount/emails/${t}/challenge/${r}`,method:"POST",accessToken:s},He)},sc=async(n,e)=>{const{emailId:t,challengeId:r,payload:s,accessToken:o}=e;return await P(n,{url:`/idp/myaccount/emails/${t}/challenge/${r}/verify`,method:"POST",payload:s,accessToken:o})};/*! 1820 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1821 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1822 * 1823 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1824 * Unless required by applicable law or agreed to in writing, software 1825 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1826 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1827 * 1828 * See the License for the specific language governing permissions and limitations under the License. 1829 */class qe extends Q{constructor(e,t){super(e,t);const{res:r,accessToken:s}=t,{id:o,profile:i,status:a,_links:c}=r;this.id=o,this.profile=i,this.status=a,this.get=async()=>await j({oktaAuth:e,accessToken:s,methodName:"get",links:c},qe)(),this.delete=async()=>await j({oktaAuth:e,accessToken:s,methodName:"delete",links:c})(),this.challenge=async u=>await j({oktaAuth:e,accessToken:s,methodName:"challenge",links:c})(u),c.verify&&(this.verify=async u=>await j({oktaAuth:e,accessToken:s,methodName:"verify",links:c})(u))}}/*! 1830 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1831 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1832 * 1833 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1834 * Unless required by applicable law or agreed to in writing, software 1835 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1836 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1837 * 1838 * See the License for the specific language governing permissions and limitations under the License. 1839 */const oc=async(n,e)=>await P(n,{url:"/idp/myaccount/phones",method:"GET",accessToken:e==null?void 0:e.accessToken},qe),ic=async(n,e)=>{const{accessToken:t,id:r}=e;return await P(n,{url:`/idp/myaccount/phones/${r}`,method:"GET",accessToken:t},qe)},ac=async(n,e)=>{const{accessToken:t,payload:r}=e;return await P(n,{url:"/idp/myaccount/phones",method:"POST",payload:r,accessToken:t},qe)},cc=async(n,e)=>{const{id:t,accessToken:r}=e;return await P(n,{url:`/idp/myaccount/phones/${t}`,method:"DELETE",accessToken:r})},uc=async(n,e)=>{const{accessToken:t,id:r,payload:s}=e;return await P(n,{url:`/idp/myaccount/phones/${r}/challenge`,method:"POST",payload:s,accessToken:t})},lc=async(n,e)=>{const{id:t,payload:r,accessToken:s}=e;return await P(n,{url:`/idp/myaccount/phones/${t}/verify`,method:"POST",payload:r,accessToken:s})};/*! 1840 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1841 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1842 * 1843 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1844 * Unless required by applicable law or agreed to in writing, softw
1844are 1845 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1846 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1847 * 1848 * See the License for the specific language governing permissions and limitations under the License. 1849 */class de extends Q{constructor(e,t){super(e,t);const{res:r,accessToken:s}=t,{id:o,status:i,created:a,lastUpdated:c,_links:u}=r;this.id=o,this.status=i,this.created=a,this.lastUpdated=c,this.status==Ht.NOT_ENROLLED?this.enroll=async l=>await j({oktaAuth:e,accessToken:s,methodName:"enroll",links:u},de)(l):(this.get=async()=>await j({oktaAuth:e,accessToken:s,methodName:"get",links:u},de)(),this.update=async l=>await j({oktaAuth:e,accessToken:s,methodName:"put",links:u},de)(l),this.delete=async()=>await j({oktaAuth:e,accessToken:s,methodName:"delete",links:u})())}}/*! 1850 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1851 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1852 * 1853 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1854 * Unless required by applicable law or agreed to in writing, software 1855 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1856 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1857 * 1858 * See the License for the specific language governing permissions and limitations under the License. 1859 */const dc=async(n,e)=>await P(n,{url:"/idp/myaccount/password",method:"GET",accessToken:e==null?void 0:e.accessToken},de),hc=async(n,e)=>{const{accessToken:t,payload:r}=e;return await P(n,{url:"/idp/myaccount/password",method:"POST",payload:r,accessToken:t},de)},fc=async(n,e)=>{const{accessToken:t,payload:r}=e;return await P(n,{url:"/idp/myaccount/password",method:"PUT",payload:r,accessToken:t},de)},gc=async(n,e)=>await P(n,{url:"/idp/myaccount/password",method:"DELETE",accessToken:e==null?void 0:e.accessToken});/*! 1860 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1861 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1862 * 1863 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1864 * Unless required by applicable law or agreed to in writing, software 1865 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1866 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1867 * 1868 * See the License for the specific language governing permissions and limitations under the License. 1869 */const pc=Object.freeze(Object.defineProperty({__proto__:null,addEmail:ec,addPhone:ac,deleteEmail:tc,deletePassword:gc,deletePhone:cc,enrollPassword:hc,getEmail:Za,getEmailChallenge:rc,getEmails:Xa,getPassword:dc,getPhone:ic,getPhones:oc,getProfile:Ja,getProfileSchema:Ya,sendEmailChallenge:nc,sendPhoneChallenge:uc,updatePassword:fc,updateProfile:Qa,verifyEmailChallenge:sc,verifyPhoneChallenge:lc},Symbol.toStringTag,{value:"Module"}));/*! 1870 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1871 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1872 * 1873 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1874 * Unless required by applicable law or agreed to in writing, software 1875 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1876 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1877 * 1878 * See the License for the specific language governing permissions and limitations under the License. 1879 */function mc(n){return class extends n{constructor(...t){super(...t),this.myaccount=Object.entries(pc).filter(([r])=>r!=="default").reduce((r,[s,o])=>(r[s]=o.bind(null,this),r),{})}}}/*! 1880 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1881 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1882 * 1883 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1884 * Unless required by applicable law or agreed to in writing, softw
1884are 1885 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1886 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1887 * 1888 * See the License for the specific language governing permissions and limitations under the License. 1889 */function vt(n,e){var t={};return Object.assign(t,e),!t.stateToken&&n.stateToken&&(t.stateToken=n.stateToken),t}function vc(n){return vt(n)}/*! 1890 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1891 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1892 * 1893 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1894 * Unless required by applicable law or agreed to in writing, software 1895 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1896 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1897 * 1898 * See the License for the specific language governing permissions and limitations under the License. 1899 */function ts(n,e){return e=vt(n,e),te(n,n.getIssuerOrigin()+"/api/v1/authn",e,{withCredentials:!0})}function yc(n,e,t){if(!t||!t.stateToken){var r=On(n);if(r)t={stateToken:r};else return Promise.reject(new g("No transaction to resume"))}return ts(n,t).then(function(s){return e.createTransaction(s)})}function wc(n,e,t){if(!t||!t.stateToken){var r=On(n);if(r)t={stateToken:r};else return Promise.reject(new g("No transaction to evaluate"))}return Tc(n,t).then(function(s){return e.createTransaction(s)})}function Tc(n,e){return e=vt(n,e),te(n,n.getIssuerOrigin()+"/api/v1/authn/introspect",e,{withCredentials:!0})}function Sc(n){return!!On(n)}function ns(n,e,t,r,s){return s=Object.assign({withCredentials:!0},s),te(n,t,r,s).then(function(o){return e.createTransaction(o)})}function On(n){return n.options.storageUtil.storage.get(Re)}/*! 1900 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1901 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1902 * 1903 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1904 * Unless required by applicable law or agreed to in writing, software 1905 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1906 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1907 * 1908 * See the License for the specific language governing permissions and limitations under the License. 1909 */function rs(n,e,t,r,s,o){if(Array.isArray(s))return function(a,c){if(!a)throw new g("Must provide a link name");var u=At(s,{name:a});if(!u)throw new g("No link found for that name");return rs(n,e,t,r,u,o)(c)};if(s.hints&&s.hints.allow&&s.hints.allow.length===1){var i=s.hints.allow[0];switch(i){case"GET":return function(){return we(n,s.href,{withCredentials:!0})};case"POST":return function(a){o&&o.isPolling&&(o.isPolling=!1);var c=vt(t,a);(t.status==="MFA_ENROLL"||t.status==="FACTOR_ENROLL")&&Object.assign(c,{factorType:r.factorType,provider:r.provider});var u={},l=c.autoPush;if(l!==void 0){if(typeof l=="function")try{u.autoPush=!!l()}catch{return Promise.reject(new g("AutoPush resulted in an error."))}else l!==null&&(u.autoPush=!!l);c=Pe(c,"autoPush")}var f=c.rememberDevice;if(f!==void 0){if(typeof f=="function")try{u.rememberDevice=!!f()}catch{return Promise.reject(new g("RememberDevice resulted in an error."))}else f!==null&&(u.rememberDevice=!!f);c=Pe(c,"rememberDevice")}else c.profile&&c.profile.updatePhone!==void 0&&(c.profile.updatePhone&&(u.updatePhone=!0),c.profile=Pe(c.profile,"updatePhone"));var d=s.href+J(u);return ns(n,e,d,c)}}}}/*! 1910 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1911 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1912 * 1913 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1914 * Unless required by applicable law or agreed to in writing, software 1915 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1916 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1917 * 1918 * See the License for the specific language governing permissions and limitations under the License. 1919 */class Vn extends be{constructor(){super("The poll was stopped by the sdk")}}/*! 1920 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1921 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1922 * 1923 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1924 * Unless required by applicable law or agreed to in writing, softw
1924are 1925 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1926 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1927 * 1928 * See the License for the specific language governing permissions and limitations under the License. 1929 */function bc(n,e,t){return function(r){var s,o,i,a;fs(r)?s=r:Kn(r)&&(r=r,s=r.delay,o=r.rememberDevice,i=r.autoPush,a=r.transactionCallBack),!s&&s!==0&&(s=Qn);var c=kt(e,"next","poll");function u(){var d={};if(typeof i=="function")try{d.autoPush=!!i()}catch{return Promise.reject(new g("AutoPush resulted in an error."))}else i!=null&&(d.autoPush=!!i);if(typeof o=="function")try{d.rememberDevice=!!o()}catch{return Promise.reject(new g("RememberDevice resulted in an error."))}else o!=null&&(d.rememberDevice=!!o);var p=c.href+J(d);return te(n,p,vc(e),{saveAuthnState:!1,withCredentials:!0,pollingIntent:!0})}t.isPolling=!0;var l=0,f=function(){return t.isPolling?u().then(function(d){if(l=0,d.factorResult&&d.factorResult==="WAITING"){if(!t.isPolling)throw new Vn;return typeof a=="function"&&a(d),En(s).then(f)}else return t.isPolling=!1,n.tx.createTransaction(d)}).catch(function(d){if(d.xhr&&(d.xhr.status===0||d.xhr.status===429)&&l<=4){var p=Math.pow(2,l)*1e3;return l++,En(p).then(f)}throw d}):Promise.reject(new Vn)};return f().catch(function(d){throw t.isPolling=!1,d})}}/*! 1930 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1931 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1932 * 1933 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1934 * Unless required by applicable law or agreed to in writing, software 1935 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1936 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1937 * 1938 * See the License for the specific language governing permissions and limitations under the License. 1939 */function Oc(n,e,t,r,s){var o={};for(var i in r._links)if(Object.prototype.hasOwnProperty.call(r._links,i)){var a=r._links[i];if(i==="next"&&(i=a.name),a.type){o[i]=a;continue}switch(i){case"poll":o.poll=bc(n,t,s);break;default:var c=rs(n,e,t,r,a,s);c&&(o[i]=c)}}return o}/*! 1940 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1941 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1942 * 1943 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1944 * Unless required by applicable law or agreed to in writing, software 1945 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1946 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1947 * 1948 * See the License for the specific language governing permissions and limitations under the License. 1949 */function Vt(n,e,t,r,s){if(r=r||t,r=D(r),Array.isArray(r)){for(var o=[],i=0,a=r.length;i<a;i++)o.push(Vt(n,e,t,r[i],s));return o}var c=r._embedded||{};for(var u in c)Object.prototype.hasOwnProperty.call(c,u)&&(Kn(c[u])||Array.isArray(c[u]))&&(c[u]=Vt(n,e,t,c[u],s));var l=Oc(n,e,t,r,s);return Object.assign(c,l),r=Pe(r,"_embedded","_links"),Object.assign(r,c),r}/*! 1950 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1951 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1952 * 1953 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1954 * Unless required by applicable law or agreed to in writing, software 1955 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1956 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1957 * 1958 * See the License for the specific language governing permissions and limitations under the License. 1959 */class Ac{constructor(e,t,r=null){this.data=void 0,this.status=void 0,r&&(this.data=r,Object.assign(this,Vt(e,t,r,r,{})),delete this.stateToken,r.status==="RECOVERY_CHALLENGE"&&!r._links&&(this.cancel=function(){return Promise.resolve(t.createTransaction())}))}}/*! 1960 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1961 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1962 * 1963 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1964 * Unless required by applicable law or agreed to in writing, softw
1964are 1965 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1966 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1967 * 1968 * See the License for the specific language governing permissions and limitations under the License. 1969 */function kc(n){const e={status:ts.bind(null,n),resume(t){return yc(n,e,t)},exists:Sc.bind(null,n),introspect(t){return wc(n,e,t)},createTransaction:t=>new Ac(n,e,t),postToTransaction:(t,r,s)=>ns(n,e,t,r,s)};return e}/*! 1970 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1971 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1972 * 1973 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1974 * Unless required by applicable law or agreed to in writing, software 1975 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1976 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1977 * 1978 * See the License for the specific language governing permissions and limitations under the License. 1979 */function Ec(n){return class extends n{constructor(...t){super(...t),this.authn=this.tx=kc(this),this.fingerprint=Qr.bind(null,this)}async signIn(t){t=D(t||{});const r=s=>(delete t.sendFingerprint,this.tx.postToTransaction("/api/v1/authn",t,s));return t.sendFingerprint?this.fingerprint().then(function(s){return r({headers:{"X-Device-Fingerprint":s}})}):r()}async signInWithCredentials(t){return this.signIn(t)}forgotPassword(t){return this.tx.postToTransaction("/api/v1/authn/recovery/password",t)}unlockAccount(t){return this.tx.postToTransaction("/api/v1/authn/recovery/unlock",t)}verifyRecoveryToken(t){const{multiOptionalFactorEnroll:r}=t,s=he(t,["multiOptionalFactorEnroll"]);return r&&(s.options={multiOptionalFactorEnroll:r}),this.tx.postToTransaction("/api/v1/authn/recovery/token",s)}}}/*! 1980 * Copyright (c) 2015-present, Okta, Inc. and/or its affiliates. All rights reserved. 1981 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1982 * 1983 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1984 * Unless required by applicable law or agreed to in writing, software 1985 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1986 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1987 * 1988 * See the License for the specific language governing permissions and limitations under the License. 1989 */const _c=ja(),Pc=Fa(),Rc=za(),Ic=wa(Pc,_c,Rc),xc=mc(Ic),Mc=Ec(xc);class eu extends Mc{constructor(e){super(e)}}/*! 1990 * Copyright (c) 2017-Present, Okta, Inc. and/or its affiliates. All rights reserved. 1991 * The Okta software accompanied by this notice is provided pursuant to the Apache License, Version 2.0 (the "License.") 1992 * 1993 * You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0. 1994 * Unless required by applicable law or agreed to in writing, software 1995 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 1996 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 1997 * 1998 * See the License for the specific language governing permissions and limitations under the License. 1999 */var ss=C.createContext(null),Cc=function(){return C.useContext(ss)},rt=function(e){var t=e.error;return t.name&&t.message?C.createElement("p",null,t.name,": ",t.message):C.createElement("p",null,"Error: ",t.toString())},tu=function(e){var t=e.oktaAuth,r=e.restoreOriginalUri,s=e.onAuthRequired,o=e.children,i=C.useState(function(){return t?t.authStateManager.getAuthState():null}),a=Wn(i,2),c=a[0],u=a[1];C.useEffect(function(){!t||!r||(t.options.restoreOriginalUri&&console.warn("Two custom restoreOriginalUri callbacks are detected. The one from the OktaAuth configuration will be overridden by the provided restoreOriginalUri prop from the Security component."),t.options.restoreOriginalUri=(function(){var m=ds(kn.mark(function T(w,A){return kn.wrap(function(b){for(;;)switch(b.prev=b.next){case 0:return b.abrupt("return",r(w,A));case 1:case"end":return b.stop()}},T)}));return function(T,w){return m.apply(this,arguments)}})())},[]),C.useEffect(function(){if(t){t._oktaUserAgent?t._oktaUserAgent.addEnvironment("@okta/okta-react".concat("/","6.11.
19990")):console.warn("_oktaUserAgent is not available on auth SDK instance. Please use okta-auth-js@^5.3.1 .");var m=t.authStateManager.getAuthState();m!==c&&u(m);var T=function(A){u(A)};return t.authStateManager.subscribe(T),t.start(),function(){t.authStateManager.unsubscribe(T)}}},[t]);var l=C.useMemo(function(){return{oktaAuth:t,authState:c,_onAuthRequired:s}},[t,c,s]);if(!t){var f=new g("No oktaAuth instance passed to Security Component.");return C.createElement(rt,{error:f})}if(!r){var d=new g("No restoreOriginalUri callback passed to Security Component.");return C.createElement(rt,{error:d})}if(!t._oktaUserAgent)console.warn("_oktaUserAgent is not available on auth SDK instance. Please use okta-auth-js@^5.3.1 .");else{var p=ls(t._oktaUserAgent.getVersion(),"5.3.1",">=");if(!p){var v=new g(` 2000 Passed in oktaAuth is not compatible with the SDK, 2001 minimum supported okta-auth-js version is `.concat("5.3.1",`. 2002 `));return C.createElement(rt,{error:v})}}return C.createElement(ss.Provider,{value:l},o)},qn=!1,nu=function(e){var t=e.errorComponent,r=e.loadingElement,s=r===void 0?null:r,o=e.onAuthResume,i=Cc(),a=i.oktaAuth,c=i.authState,u=C.useState(null),l=Wn(u,2),f=l[0],d=l[1],p=t||rt;C.useEffect(function(){var T=a.idx.isInteractionRequired||a.isInteractionRequired.bind(a);if(o&&T()){o();return}qn||(a.handleLoginRedirect().catch(function(w){d(w)}),qn=!0)},[a]);var v=c==null?void 0:c.error,m=f||v;return m?C.createElement(p,{error:m}):s};export{nu as L,eu as O,tu as S,Cc as u}; 2003//# sourceMappingURL=okta-CUUf_pth.js.map
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.