1"use strict";(self.webpackChunkapp=self.webpackChunkapp||[]).push([[5909],{6362:($,W,l)=>{l.d(W,{O:()=>d});var d=function(a){return a.JWE="JWE",a.KMS="KMS",a}(d||{})},339:($,W,l)=>{l.d(W,{h:()=>Dt});var d=l(467),a=l(7673),w=l(6648);const p=crypto,f=t=>t instanceof CryptoKey,m=function(){var t=(0,d.A)(function*(e,r){const n=`SHA-${e.slice(-3)}`;return new Uint8Array(yield p.subtle.digest(n,r))});return function(r,n){return t.apply(this,arguments)}}(),y=new TextEncoder,u=new TextDecoder,g=2**32;function P(...t){const e=t.reduce((o,{length:s})=>o+s,0),r=new Uint8Array(e);let n=0;for(const o of t)r.set(o,n),n+=o.length;return r}function A(t,e,r){if(e<0||e>=g)throw new RangeError(`value must be >= 0 and <= ${g-1}. Received ${e}`);t.set([e>>>24,e>>>16,e>>>8,255&e],r)}function _(t){const e=new Uint8Array(4);return A(e,t),e}function T(t){return P(_(t.length),t)}function C(){return(C=(0,d.A)(function*(t,e,r){const n=Math.ceil((e>>3)/32),o=new Uint8Array(32*n);for(let s=0;s<n;s++){const c=new Uint8Array(4+t.length+r.length);c.set(_(s+1)),c.set(t,4),c.set(r,4+t.length),o.set(yield m("sha256",c),32*s)}return o.slice(0,e>>3)})).apply(this,arguments)}const K=t=>(t=>{let e=t;"string"==typeof e&&(e=y.encode(e));const n=[];for(let o=0;o<e.length;o+=32768)n.push(String.fromCharCode.apply(null,e.subarray(o,o+32768)));return btoa(n.join(""))})(t).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_"),U=t=>{let e=t;e instanceof Uint8Array&&(e=u.decode(e)),e=e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"");try{return(t=>{const e=atob(t),r=new Uint8Array(e.length);for(let n=0;n<e.length;n++)r[n]=e.charCodeAt(n);return r})(e)}catch{throw new TypeError("The input to be decoded is not correctly encoded.")}};let ne=(()=>{class t extends Error{constructor(r,n){super(r,n),this.code="ERR_JOSE_GENERIC",this.name=this.constructor.name,Error.captureStackTrace?.(this,this.constructor)}}return t.code="ERR_JOSE_GENERIC",t})(),v=(()=>{class t extends ne{constructor(){super(...arguments),this.code="ERR_JOSE_NOT_SUPPORTED"}}return t.code="ERR_JOSE_NOT_SUPPORTED",t})(),B=(()=>{class t extends ne{constructor(){super(...arguments),this.code="ERR_JWE_INVALID"}}return t.code="ERR_JWE_INVALID",t})();(class Ve extends ne{constructor(e="multiple matching keys found in the JSON Web Key Set",r){super(e,r),this.code="ERR_JWKS_MULTIPLE_MATCHING_KEYS"}}).code="ERR_JWKS_MULTIPLE_MATCHING_KEYS";const ve=function(){var t=(0,d.A)(function*(e){if(!e.alg)throw new TypeError('"alg" argument is required when "jwk.alg" is not present');const{algorithm:r,keyUsages:n}=function ke(t){let e,r;switch(t.kty){case"RSA":switch(t.alg){case"PS256":case"PS384":case"PS512":e={name:"RSA-PSS",hash:`SHA-${t.alg.slice(-3)}`},r=t.d?["sign"]:["verify"];break;case"RS256":case"RS384":case"RS512":e={name:"RSASSA-PKCS1-v1_5",hash:`SHA-${t.alg.slice(-3)}`},r=t.d?["sign"]:["verify"];break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":e={name:"RSA-OAEP",hash:`SHA-${parseInt(t.alg.slice(-3),10)||1}`},r=t.d?["decrypt","unwrapKey"]:["encrypt","wrapKey"];break;default:throw new v('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"EC":switch(t.alg){case"ES256":e={name:"ECDSA",namedCurve:"P-256"},r=t.d?["sign"]:["verify"];break;case"ES384":e={name:"ECDSA",namedCurve:"P-384"},r=t.d?["sign"]:["verify"];break;case"ES512":e={name:"ECDSA",namedCurve:"P-521"},r=t.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":e={name:"ECDH",namedCurve:t.crv},r=t.d?["deriveBits"]:[];break;default:throw new v('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;case"OKP":switch(t.alg){case"EdDSA":e={name:t.crv},r=t.d?["sign"]:["verify"];break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":e={name:t.crv},r=t.d?["deriveBits"]:[];break;default:throw new v('Invalid or unsupported JWK "alg" (Algorithm) Parameter value')}break;default:throw new v('Invalid or unsupported JWK "kty" (Key Type) Parameter value')}return{algorithm:e,keyUsages:r}}(e),o=[r,e.ext??!1,e.key_ops??n],s={...e};return delete s.alg,delete s.use,p.subtle.importKey("jwk",s,...o)});return function(r){return t.apply(this,arguments)}}();function oe(t){if(!function je(t){return"object"==typeof t&&null!==t}(t)||"[object Object]"!==Object.prototype.toString.call(t))return!1;if(null===Object.getPrototypeOf(t))return!0;let e=t;for(;null!==Object.getPrototypeOf(e);)e=Object.getPrototypeOf(e);return Object.getPrototypeOf(t)===e}function ce(){return(ce=(0,d.A)(function*(t,e){if(!oe(t))throw new TypeError("JWK must be an object");switch(e||(e=t.alg),t.kty){case"oct":if("string"!=typeof t.k||!t.k)throw new TypeError('missing "k" (Key Value) Parameter value');return U(t.k);case"RSA":if(void 0!==t.oth)throw new v('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');case"EC":case"OKP":return ve({...t,alg:e});default:throw new v('Unsupported "kty" (Key Type) Parameter value')}})).apply(this,arguments)}const Xe=Symbol(),le=p.getRandomValues.bind(p);
1function We(t){switch(t){case"A128GCM":case"A128GCMKW":case"A192GCM":case"A192GCMKW":case"A256GCM":case"A256GCMKW":return 96;case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return 128;default:throw new v(`Unsupported JWE Algorithm: ${t}`)}}const Te=(t,e)=>{const r=t.byteLength<<3;if(r!==e)throw new B(`Invalid Content Encryption Key length. Expected ${e} bits, got ${r} bits`)};function S(t,e="algorithm.name"){return new TypeError(`CryptoKey does not support this operation, its ${e} must be ${t}`)}function G(t,e){return t.name===e}function V(t,e,...r){switch(e){case"A128GCM":case"A192GCM":case"A256GCM":{if(!G(t.algorithm,"AES-GCM"))throw S("AES-GCM");const n=parseInt(e.slice(1,4),10);if(t.algorithm.length!==n)throw S(n,"algorithm.length");break}case"A128KW":case"A192KW":case"A256KW":{if(!G(t.algorithm,"AES-KW"))throw S("AES-KW");const n=parseInt(e.slice(1,4),10);if(t.algorithm.length!==n)throw S(n,"algorithm.length");break}case"ECDH":switch(t.algorithm.name){case"ECDH":case"X25519":case"X448":break;default:throw S("ECDH, X25519, or X448")}break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":if(!G(t.algorithm,"PBKDF2"))throw S("PBKDF2");break;case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":{if(!G(t.algorithm,"RSA-OAEP"))throw S("RSA-OAEP");const n=parseInt(e.slice(9),10)||1;if(function q(t){return parseInt(t.name.slice(4),10)}(t.algorithm.hash)!==n)throw S(`SHA-${n}`,"algorithm.hash");break}default:throw new TypeError("CryptoKey does not support this operation")}!function Ie(t,e){if(e.length&&!e.some(r=>t.usages.includes(r))){let r="CryptoKey does not support this operation, its usages must include ";if(e.length>2){const n=e.pop();r+=`one of ${e.join(", ")}, or ${n}.`}else r+=2===e.length?`one of ${e[0]} or ${e[1]}.`:`${e[0]}.`;throw new TypeError(r)}}(t,r)}function Re(t,e,...r){if((r=r.filter(Boolean)).length>2){const n=r.pop();t+=`one of type ${r.join(", ")}, or ${n}.`}else t+=2===r.length?`one of type ${r[0]} or ${r[1]}.`:`of type ${r[0]}.`;return null==e?t+=` Received ${e}`:"function"==typeof e&&e.name?t+=` Received function ${e.name}`:"object"==typeof e&&null!=e&&e.constructor?.name&&(t+=` Received an instance of ${e.constructor.name}`),t}const M=(t,...e)=>Re("Key must be ",t,...e);function xe(t,e,...r){return Re(`Key for the ${t} algorithm must be `,e,...r)}const Oe=t=>!!f(t)||"KeyObject"===t?.[Symbol.toStringTag],R=["CryptoKey"];function ue(){return(ue=(0,d.A)(function*(t,e,r,n,o){if(!(r instanceof Uint8Array))throw new TypeError(M(r,"Uint8Array"));const s=parseInt(t.slice(1,4),10),c=yield p.subtle.importKey("raw",r.subarray(s>>3),"AES-CBC",!1,["encrypt"]),h=yield p.subtle.importKey("raw",r.subarray(0,s>>3),{hash:"SHA-"+(s<<1),name:"HMAC"},!1,["sign"]),E=new Uint8Array(yield p.subtle.encrypt({iv:n,name:"AES-CBC"},c,e)),x=P(o,n,E,function D(t){const e=Math.floor(t/g),r=t%g,n=new Uint8Array(8);return A(n,e,0),A(n,r,4),n}(o.length<<3));return{ciphertext:E,tag:new Uint8Array((yield p.subtle.sign("HMAC",h,x)).slice(0,s>>3)),iv:n}})).apply(this,arguments)}function de(){return(de=(0,d.A)(function*(t,e,r,n,o){let s;r instanceof Uint8Array?s=yield p.subtle.importKey("raw",r,"AES-GCM",!1,["encrypt"]):(V(r,t,"encrypt"),s=r);const c=new Uint8Array(yield p.subtle.encrypt({additionalData:o,iv:n,name:"AES-GCM",tagLength:128},s,e)),h=c.slice(-16);return{ciphertext:c.slice(0,-16),tag:h,iv:n}})).apply(this,arguments)}const Me=function(){var t=(0,d.A)(function*(e,r,n,o,s){if(!(f(n)||n instanceof Uint8Array))throw new TypeError(M(n,...R,"Uint8Array"));switch(o?((t,e)=>{if(e.length<<3!==We(t))throw new B("Invalid Initialization Vector length")})(e,o):o=(t=>le(new Uint8Array(We(t)>>3)))(e),e){case"A128CBC-HS256":case"A192CBC-HS384":case"A256CBC-HS512":return n instanceof Uint8Array&&Te(n,parseInt(e.slice(-3),10)),function qe(t,e,r,n,o){return ue.apply(this,arguments)}(e,r,n,o,s);case"A128GCM":case"A192GCM":case"A256GCM":return n instanceof Uint8Array&&Te(n,parseInt(e.slice(1,4),10)),function et(t,e,r,n,o){return de.apply(this,arguments)}(e,r,n,o,s);default:throw new v("Unsupported JWE Content Encryption Algorithm")}});return function(r,n,o,s,c){return t.apply(this,arguments)}}
1(),He=[{hash:"SHA-256",name:"HMAC"},!0,["sign"]],pe=function(){var t=(0,d.A)(function*(e,r,n){const o=yield function rt(t,e,r){if(f(t))return V(t,e,r),t;if(t instanceof Uint8Array)return p.subtle.importKey("raw",t,"AES-KW",!0,[r]);throw new TypeError(M(t,...R,"Uint8Array"))}(r,e,"wrapKey");!function tt(t,e){if(t.algorithm.length!==parseInt(e.slice(1,4),10))throw new TypeError(`Invalid key size for alg: ${e}`)}(o,e);const s=yield p.subtle.importKey("raw",n,...He);return new Uint8Array(yield p.subtle.wrapKey("raw",s,o,"AES-KW"))});return function(r,n,o){return t.apply(this,arguments)}}();function he(){return he=(0,d.A)(function*(t,e,r,n,o=new Uint8Array(0),s=new Uint8Array(0)){if(!f(t))throw new TypeError(M(t,...R));if(V(t,"ECDH"),!f(e))throw new TypeError(M(e,...R));V(e,"ECDH","deriveBits");const c=P(T(y.encode(r)),T(o),T(s),_(n));let h;return h="X25519"===t.algorithm.name?256:"X448"===t.algorithm.name?448:Math.ceil(parseInt(t.algorithm.namedCurve.substr(-3),10)/8)<<3,function i(t,e,r){return C.apply(this,arguments)}(new Uint8Array(yield p.subtle.deriveBits({name:t.algorithm.name,public:t},e,h)),n,c)}),he.apply(this,arguments)}function ye(){return(ye=(0,d.A)(function*(t){if(!f(t))throw new TypeError(M(t,...R));return p.subtle.generateKey(t.algorithm,!0,["deriveBits"])})).apply(this,arguments)}function fe(){return(fe=(0,d.A)(function*(t,e,r,n){!function at(t){if(!(t instanceof Uint8Array)||t.length<8)throw new B("PBES2 Salt Input must be 8 or more octets")}(t);const o=function H(t,e){return P(y.encode(t),new Uint8Array([0]),e)}(e,t),s=parseInt(e.slice(13,16),10),c={hash:`SHA-${e.slice(8,11)}`,iterations:r,name:"PBKDF2",salt:o},h={length:s,name:"AES-KW"},E=yield function it(t,e){if(t instanceof Uint8Array)return p.subtle.importKey("raw",t,"PBKDF2",!1,["deriveBits"]);if(f(t))return V(t,e,"deriveBits","deriveKey"),t;throw new TypeError(M(t,...R,"Uint8Array"))}(n,e);if(E.usages.includes("deriveBits"))return new Uint8Array(yield p.subtle.deriveBits(c,E,s));if(E.usages.includes("deriveKey"))return p.subtle.deriveKey(c,E,h,!1,["wrapKey","unwrapKey"]);throw new TypeError('PBKDF2 key "usages" must include "deriveBits" or "deriveKey"')})).apply(this,arguments)}const lt=function(){var t=(0,d.A)(function*(e,r,n,o=2048,s=le(new Uint8Array(16))){const c=yield function ct(t,e,r,n){return fe.apply(this,arguments)}(s,e,o,r);return{encryptedKey:yield pe(e.slice(-6),c,n),p2c:o,p2s:K(s)}});return function(r,n,o){return t.apply(this,arguments)}}();function Je(t){switch(t){case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":return"RSA-OAEP";default:throw new v(`alg ${t} is not supported either by JOSE or your javascript runtime`)}}const dt=function(){var t=(0,d.A)(function*(e,r,n){if(!f(r))throw new TypeError(M(r,...R));if(V(r,e,"encrypt","wrapKey"),((t,e)=>{if(t.startsWith("RS")||t.startsWith("PS")){const{modulusLength:r}=e.algorithm;if("number"!=typeof r||r<2048)throw new TypeError(`${t} requires key modulusLength to be 2048 bits or larger`)}})(e,r),r.usages.includes("encrypt"))return new Uint8Array(yield p.subtle.encrypt(Je(e),r,n));if(r.usages.includes("wrapKey")){const o=yield p.subtle.importKey("raw",n,...He);return new Uint8Array(yield p.subtle.wrapKey("raw",o,r,Je(e)))}throw new TypeError('RSA-OAEP key "usages" must include "encrypt" or "wrapKey" for this operation')});return function(r,n,o){return t.apply(this,arguments)}}();function Y(t){return oe(t)&&"string"==typeof t.kty}let j;const ee=function(){var t=(0,d.A)(function*(e,r,n,o,s=!1){let c=e.get(r);if(c?.[o])return c[o];const h=yield ve({...n,alg:o});return s&&Object.freeze(r),c?c[o]=h:e.set(r,{[o]:h}),h});return function(r,n,o,s){return t.apply(this,arguments)}}(),ft_normalizePublicKey=(t,e)=>{if((t=>"KeyObject"===t?.[Symbol.toStringTag])(t)){let r=t.export({format:"jwk"});return delete r.d,delete r.dp,delete r.dq,delete r.p,delete r.q,delete r.qi,r.k?(t=>U(t))(r.k):(j||(j=new WeakMap),ee(j,t,r,e))}return Y(t)?t.k?U(t.k):(j||(j=new WeakMap),ee(j,t,t,e,!0)):t};function Be(t){switch(t){case"A128GCM":return 128;case"A192GCM":return 192;case"A256GCM":case"A128CBC-HS256":return 256;case"A192CBC-HS384":return 384;case"A256CBC-HS512":return 512;default:throw new v(`Unsupported JWE Algorithm: ${t}`)}}const Q=t=>le(new Uint8Array(Be(t)>>3)),_t=function(){var t=(0,d.A)(function*(e){if(e instanceof Uint8Array)return{kty:"oct",k:K(e)};if(!f(e))throw new TypeError(M(e,...R,"Uint8Array"));if(!e.extractable)throw new TypeError("non-extractable CryptoKey cannot be exported as a JWK");const{ext:r,key_ops:n,alg:o,use:s,...c}=yield p.subtle.exportKey("jwk",e);return c});return function(r){return t.apply(this,arguments)}}();function Ee(){return(Ee=(0,d.A)(function*(t){return _t(t)})).apply(this,arguments)}const z=t=>t?.[Symbol.toStringTag],ge=(t,e,r)=>{if(void 0!==e.use&&"sig"!==e.use)throw new TypeError("Invalid key for this operation, when present its use must be sig");
1if(void 0!==e.key_ops&&!0!==e.key_ops.includes?.(r))throw new TypeError(`Invalid key for this operation, when present its key_ops must include ${r}`);if(void 0!==e.alg&&e.alg!==t)throw new TypeError(`Invalid key for this operation, when present its alg must be ${t}`);return!0};function Ge(t,e,r,n){e.startsWith("HS")||"dir"===e||e.startsWith("PBES2")||/^A\d{3}(?:GCM)?KW$/.test(e)?((t,e,r,n)=>{if(!(e instanceof Uint8Array)){if(n&&Y(e)){if(function yt(t){return Y(t)&&"oct"===t.kty&&"string"==typeof t.k}(e)&&ge(t,e,r))return;throw new TypeError('JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present')}if(!Oe(e))throw new TypeError(xe(t,e,...R,"Uint8Array",n?"JSON Web Key":null));if("secret"!==e.type)throw new TypeError(`${z(e)} instances for symmetric algorithms must be of type "secret"`)}})(e,r,n,t):((t,e,r,n)=>{if(n&&Y(e))switch(r){case"sign":if(function pt(t){return"oct"!==t.kty&&"string"==typeof t.d}(e)&&ge(t,e,r))return;throw new TypeError("JSON Web Key for this operation be a private JWK");case"verify":if(function ht(t){return"oct"!==t.kty&&typeof t.d>"u"}(e)&&ge(t,e,r))return;throw new TypeError("JSON Web Key for this operation be a public JWK")}if(!Oe(e))throw new TypeError(xe(t,e,...R,n?"JSON Web Key":null));if("secret"===e.type)throw new TypeError(`${z(e)} instances for asymmetric algorithms must not be of type "secret"`);if("sign"===r&&"public"===e.type)throw new TypeError(`${z(e)} instances for asymmetric algorithm signing must be of type "private"`);if("decrypt"===r&&"public"===e.type)throw new TypeError(`${z(e)} instances for asymmetric algorithm decryption must be of type "private"`);if(e.algorithm&&"verify"===r&&"private"===e.type)throw new TypeError(`${z(e)} instances for asymmetric algorithm verifying must be of type "public"`);if(e.algorithm&&"encrypt"===r&&"private"===e.type)throw new TypeError(`${z(e)} instances for asymmetric algorithm encryption must be of type "public"`)})(e,r,n,t)}const At=Ge.bind(void 0,!1);function Ae(){return(Ae=(0,d.A)(function*(t,e,r,n){const o=t.slice(0,7),s=yield Me(o,r,e,n,new Uint8Array(0));return{encryptedKey:s.ciphertext,iv:K(s.iv),tag:K(s.tag)}})).apply(this,arguments)}function Se(){return Se=(0,d.A)(function*(t,e,r,n,o={}){let s,c,h;switch(At(t,r,"encrypt"),r=(yield ft_normalizePublicKey?.(r,t))||r,t){case"dir":h=r;break;case"ECDH-ES":case"ECDH-ES+A128KW":case"ECDH-ES+A192KW":case"ECDH-ES+A256KW":{if(!function st(t){if(!f(t))throw new TypeError(M(t,...R));return["P-256","P-384","P-521"].includes(t.algorithm.namedCurve)||"X25519"===t.algorithm.name||"X448"===t.algorithm.name}(r))throw new v("ECDH with the provided key is not allowed or not supported by your javascript runtime");const{apu:E,apv:x}=o;let{epk:I}=o;I||(I=(yield function ot(t){return ye.apply(this,arguments)}(r)).privateKey);const{x:X,y:Pe,crv:te,kty:Z}=yield function mt(t){return Ee.apply(this,arguments)}(I),O=yield function nt(t,e,r,n){return he.apply(this,arguments)}(r,I,"ECDH-ES"===t?e:t,"ECDH-ES"===t?Be(e):parseInt(t.slice(-5,-2),10),E,x);if(c={epk:{x:X,crv:te,kty:Z}},"EC"===Z&&(c.epk.y=Pe),E&&(c.apu=K(E)),x&&(c.apv=K(x)),"ECDH-ES"===t){h=O;break}h=n||Q(e);const N=t.slice(-6);s=yield pe(N,O,h);break}case"RSA1_5":case"RSA-OAEP":case"RSA-OAEP-256":case"RSA-OAEP-384":case"RSA-OAEP-512":h=n||Q(e),s=yield dt(t,r,h);break;case"PBES2-HS256+A128KW":case"PBES2-HS384+A192KW":case"PBES2-HS512+A256KW":{h=n||Q(e);const{p2c:E,p2s:x}=o;({encryptedKey:s,...c}=yield lt(t,r,h,E,x));break}case"A128KW":case"A192KW":case"A256KW":h=n||Q(e),s=yield pe(t,r,h);break;case"A128GCMKW":case"A192GCMKW":case"A256GCMKW":{h=n||Q(e);const{iv:E}=o;({encryptedKey:s,...c}=yield function wt(t,e,r,n){return Ae.apply(this,arguments)}(t,r,h,E));break}default:throw new v('Invalid or unsupported "alg" (JWE Algorithm) header value')}return{cek:h,encryptedKey:s,parameters:c}}),Se.apply(this,arguments)}Ge.bind(void 0,!0);class vt{constructor(e){if(!(e instanceof Uint8Array))throw new TypeError("plaintext must be an instance of Uint8Array");this._plaintext=e}setKeyManagementParameters(e){if(this._keyManagementParameters)throw new TypeError("setKeyManagementParameters can only be called once");return this._keyManagementParameters=e,this}setProtectedHeader(e){if(this._protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setSharedUnprotectedHeader(e){if(this._sharedUnprotectedHeader)throw new TypeError("setSharedUnprotectedHeader can only be called once");return this._sharedUnprotectedHeader=e,this}setUnprotectedHeader(e){if(this._unprotectedHeader)throw new TypeError("setUnprotectedHeader can only be called once");return this._unprotectedHeader=e,this}setAdditionalAuthenticatedData(e){return this._aad=e,this}setContentEncryptionKey(e){if(this._cek)throw new TypeError("setContentEncryptionKey can only be called once");return this._cek=e,this}setInitializationVector(e){if(this._iv)throw new TypeError("setInitializationVector can only be called once");return this._iv=e,this}encrypt(e,r){var n=this;return(0,d.A)(function*(){if(!n._protectedHeader&&!n._unprotectedHeader&&!n._sharedUnprotectedHeader)throw new B("either setProtectedHeader, setUnprotectedHeader, or sharedUnprotectedHeader must be called before #encrypt()");if(!((...t)=>{const e=t.filter(Boolean);if(0===e.length||1===e.length)return!0;let r;for(const n of e){const o=Object.keys(n);if(r&&0!==r.size)for(const s of o){if(r.has(s))return!1;r.add(s)}else r=new Set(o)}return!0})(n._protectedHeader,n._unprotectedHeader,n._sharedUnprotectedHeader))throw new B("JWE Protected, JWE Shared Unprotected and JWE Per-Recipient Header Parameter names must be disjoint");const o={...n._protectedHeader,...n._unprotectedHeader,...n._sharedUnprotectedHeader};if(function Ct(t,e,r,n,o){if(void 0!==o.crit&&void 0===n?.crit)throw new t('"crit" (Critical) Header Parameter MUST be integrity protected');if(!n||void 0===n.crit)return new Set;if(!Array.isArray(n.crit)||0===n.crit.length||n.crit.some(c=>
1"string"!=typeof c||0===c.length))throw new t('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');let s;s=void 0!==r?new Map([...Object.entries(r),...e.entries()]):e;for(const c of n.crit){if(!s.has(c))throw new v(`Extension Header Parameter "${c}" is not recognized`);if(void 0===o[c])throw new t(`Extension Header Parameter "${c}" is missing`);if(s.get(c)&&void 0===n[c])throw new t(`Extension Header Parameter "${c}" MUST be integrity protected`)}new Set(n.crit)}(B,new Map,r?.crit,n._protectedHeader,o),void 0!==o.zip)throw new v('JWE "zip" (Compression Algorithm) Header Parameter is not supported.');const{alg:s,enc:c}=o;if("string"!=typeof s||!s)throw new B('JWE "alg" (Algorithm) Header Parameter missing or invalid');if("string"!=typeof c||!c)throw new B('JWE "enc" (Encryption Algorithm) Header Parameter missing or invalid');let h,E,x,I,X;if(n._cek&&("dir"===s||"ECDH-ES"===s))throw new TypeError(`setContentEncryptionKey cannot be called with JWE "alg" (Algorithm) Header ${s}`);{let N;({cek:E,encryptedKey:h,parameters:N}=yield function St(t,e,r,n){return Se.apply(this,arguments)}(s,c,e,n._cek,n._keyManagementParameters)),N&&(r&&Xe in r?n._unprotectedHeader?n._unprotectedHeader={...n._unprotectedHeader,...N}:n.setUnprotectedHeader(N):n._protectedHeader?n._protectedHeader={...n._protectedHeader,...N}:n.setProtectedHeader(N))}I=y.encode(n._protectedHeader?K(JSON.stringify(n._protectedHeader)):""),n._aad?(X=K(n._aad),x=P(I,y.encode("."),y.encode(X))):x=I;const{ciphertext:Pe,tag:te,iv:Z}=yield Me(c,n._plaintext,E,n._iv,x),O={ciphertext:K(Pe)};return Z&&(O.iv=K(Z)),te&&(O.tag=K(te)),h&&(O.encrypted_key=K(h)),X&&(O.aad=X),n._protectedHeader&&(O.protected=u.decode(I)),n._sharedUnprotectedHeader&&(O.unprotected=n._sharedUnprotectedHeader),n._unprotectedHeader&&(O.header=n._unprotectedHeader),O})()}}class Wt{constructor(e){this._flattened=new vt(e)}setContentEncryptionKey(e){return this._flattened.setContentEncryptionKey(e),this}setInitializationVector(e){return this._flattened.setInitializationVector(e),this}setProtectedHeader(e){return this._flattened.setProtectedHeader(e),this}setKeyManagementParameters(e){return this._flattened.setKeyManagementParameters(e),this}encrypt(e,r){var n=this;return(0,d.A)(function*(){const o=yield n._flattened.encrypt(e,r);return[o.protected,o.encrypted_key,o.iv,o.ciphertext,o.tag].join(".")})()}}const L=t=>Math.floor(t.getTime()/1e3),Rt=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i,be=t=>{const e=Rt.exec(t);if(!e||e[4]&&e[1])throw new TypeError("Invalid time period format");const r=parseFloat(e[2]);let o;switch(e[3].toLowerCase()){case"sec":case"secs":case"second":case"seconds":case"s":o=Math.round(r);break;case"minute":case"minutes":case"min":case"mins":case"m":o=Math.round(60*r);break;case"hour":case"hours":case"hr":case"hrs":case"h":o=Math.round(3600*r);break;case"day":case"days":case"d":o=Math.round(86400*r);break;case"week":case"weeks":case"w":o=Math.round(604800*r);break;default:o=Math.round(31557600*r)}return"-"===e[1]||"ago"===e[4]?-o:o};function F(t,e){if(!Number.isFinite(e))throw new TypeError(`Invalid ${t} input`);return e}class xt{constructor(e={}){if(!oe(e))throw new TypeError("JWT Claims Set MUST be an object");this._payload=e}setIssuer(e){return this._payload={...this._payload,iss:e},this}setSubject(e){return this._payload={...this._payload,sub:e},this}setAudience(e){return this._payload={...this._payload,aud:e},this}setJti(e){return this._payload={...this._payload,jti:e},this}setNotBefore(e){return this._payload="number"==typeof e?{...this._payload,nbf:F("setNotBefore",e)}:e instanceof Date?{...this._payload,nbf:F("setNotBefore",L(e))}:{...this._payload,nbf:L(new Date)+be(e)},this}setExpirationTime(e){return this._payload="number"==typeof e?{...this._payload,exp:F("setExpirationTime",e)}:e instanceof Date?{...this._payload,exp:F("setExpirationTime",L(e))}:{...this._payload,exp:L(new Date)+be(e)},this}setIssuedAt(e){return this._payload=typeof e>"u"?{...this._payload,iat:L(new Date)}:e instanceof Date?{...this._payload,iat:F("setIssuedAt",L(e))}:"string"==typeof e?{...this._payload,iat:F("setIssuedAt",L(new Date)+be(e))}:{...this._payload,iat:F("setIssuedAt",e)},this}}class Ot extends xt{setProtectedHeader(e){if(this._protectedHeader)throw new TypeError("setProtectedHeader can only be called once");return this._protectedHeader=e,this}setKeyManagementParameters(e){if(this._keyManagementParameters)throw new TypeError("setKeyManagementParameters can only be called once");return this._keyManagementParameters=e,this}setContentEncryptionKey(e){if(this._cek)throw new TypeError("setContentEncryptionKey can only be called once");return this._cek=e,this}setInitializationVector(e){if(this._iv)throw new TypeError("setInitializationVector can only be called once");return this._iv=e,this}replicateIssuerAsHeader(){return this._replicateIssuerAsHeader=!0,this}replicateSubjectAsHeader(){return this._replicateSubjectAsHeader=!0,this}replicateAudienceAsHeader(){return this._replicateAudienceAsHeader=!0,this}encrypt(e,r){var n=this;return(0,d.A)(function*(){const o=new Wt(y.encode(JSON.stringify(n._payload)));return n._replicateIssuerAsHeader&&(n._protectedHeader={...n._protectedHeader,iss:n._payload.iss}),n._replicateSubjectAsHeader&&(n._protectedHeader={...n._protectedHeader,sub:n._payload.sub}),n._replicateAudienceAsHeader&&(n._protectedHeader={...n._protectedHeader,aud:n._payload.aud}),o.setProtectedHeader(n._protectedHeader),n._iv&&o.setInitializationVector(n._iv),n._cek&&o.setContentEncryptionKey(n._cek),n._keyManagementParameters&&o.setKeyManagementParameters(n._keyManagementParameters),o.encrypt
1(e,r)})()}}const Mt=(t,e)=>e?(0,w.H)(function ze(t,e){return ce.apply(this,arguments)}(e.publicKey,"RSA-OAEP-256").then(r=>Promise.all(t.map(n=>Ht(n,e.nonce,r))))):(0,a.of)(t),Ht=(t,e,r)=>new Ot({password:t}).setProtectedHeader({alg:"RSA-OAEP-256",enc:"A128GCM",nonce:e}).encrypt(r);var Fe=l(6362),Ce=l(2412),$e=l(4438),Jt=l(7475);let Dt=(()=>{class t{constructor(r){this.rsaEncryptionService=r}handleE2ee(r,n){if(!n)return(0,a.of)(r);switch(n.type){case Fe.O.JWE:return Mt(r,n);case Fe.O.KMS:return(0,w.H)(Promise.all(r.map(o=>this.rsaEncryptPassword(o,n))))}}rsaEncryptPassword(r,n){var o=this;return(0,d.A)(function*(){return o.toJson(yield o.rsaEncryptionService.encrypt(r,n))})()}toJson(r){return JSON.stringify({password:(0,Ce.nk)(r.password),key:(0,Ce.nk)(r.key),iv:(0,Ce.nk)(r.iv)})}static#e=this.\u0275fac=function(n){return new(n||t)($e.KVO(Jt.D))};static#t=this.\u0275prov=$e.jDH({token:t,factory:t.\u0275fac})}return t})()},2568:($,W,l)=>{l.d(W,{g:()=>p});var d=l(339),a=l(7475),w=l(4438);let p=(()=>{class f{static#e=this.\u0275fac=function(y){return new(y||f)};static#t=this.\u0275mod=w.$C({type:f});static#r=this.\u0275inj=w.G2t({providers:[a.D,d.h]})}return f})()},7475:($,W,l)=>{l.d(W,{D:()=>p});var d=l(467);class a{constructor(b,m){this.name=b,this.hash=m}
1static parse(b){if("RSAES_OAEP_SHA_1"===b)return new a("RSA-OAEP","SHA-1");if("RSAES_OAEP_SHA_256"===b)return new a("RSA-OAEP","SHA-256");throw new Error("Failed to parse RSA algorithm: "+b+" - Only RSAES_OAEP_SHA_1 and RSAES_OAEP_SHA_256 are supported.")}}var w=l(4438);let p=(()=>{class f{constructor(){this.textEncoder=new TextEncoder}static#e=this.IV_SIZE_BYTE=12;encrypt(m,y){var u=this;return(0,d.A)(function*(){const g=yield u.generateAesGcmKey(),P=u.getSecureRandomByteArray(f.IV_SIZE_BYTE),H=yield u.encryptAesGcm(m,g,P,y.nonce),A=yield u.toRawKey(g),D=a.parse(y.algorithm),_=yield u.toCryptoKey(y.publicKey,D);return u.encryptRsa(A,_,D).then(T=>u.mapToResult(H,T,P))})()}generateAesGcmKey(){return window.crypto.subtle.generateKey({name:"AES-GCM",length:256},!0,["encrypt"])}encryptAesGcm(m,y,u,g){return window.crypto.subtle.encrypt({name:"AES-GCM",iv:u,additionalData:this.textEncoder.encode(g)},y,this.textEncoder.encode(m))}encryptRsa(m,y,u){return window.crypto.subtle.encrypt({name:u.name},y,m)}toCryptoKey(m,y){const u=Uint8Array.from(atob(m),g=>g.charCodeAt(0));return window.crypto.subtle.importKey("spki",u,{name:y.name,hash:{name:y.hash}},!1,["encrypt"])}toRawKey(m){return window.crypto.subtle.exportKey("raw",m)}mapToResult(m,y,u){return{password:m,key:y,iv:u}}getSecureRandomByteArray(m){return window.crypto.getRandomValues(new Uint8Array(m))}static#t=this.\u0275fac=function(y){return new(y||f)};static#r=this.\u0275prov=w.jDH({token:f,factory:f.\u0275fac})}return f})()},5033:($,W,l)=>{l.d(W,{Q:()=>D});var d=l(6247),a=l(2315),w=l(6884),p=l(7673),f=l(8141),b=l(6354),m=l(5558),y=l(7613),u=l(4438),g=l(1400),P=l(177),H=l(4160);function A(_,T){if(1&_){const i=u.RV6();u.j41(0,"iam-button",1),u.bIt("buttonClick",function(){const J=u.eBV(i).ngIf,K=u.XpG();return u.Njj(K.cancelFlow(J.targetUri))}),u.k0s()}if(2&_){const i=u.XpG();u.Y8G("id",i.buttonId)("submit",!1)("right",i.right)("text",i.text||i.translationKey)("disableWhenBusy",i.disableWhenBusy)}}let D=(()=>{class _{set buttonId(i){i&&(this._id=i)}get buttonId(){return this._id}constructor(i,C,J,K,re){this.flowPageService=i,this.flowNavigationService=C,this.pageAlertService=J,this.routes=K,this.currentFlow=re,this.right=!0,this.disableWhenBusy=!0,this.beforeCancelFlow=this.nopBeforeCancelFlow,this._id="cancelButton",this.cancelButton=this.flowPageService.getStepUiConfig().pipe((0,f.M)(U=>{this._translationPrefix=U.getResourceKeyPrefix(),this.translationKey=this._translationPrefix+".pages.actions.cancel"}),(0,b.T)(U=>U.pageAttribute("cancelButtonSettings")))}get hostCss(){return"iam-btn-cancel"}cancelFlow(i){this.beforeCancelFlow().pipe((0,m.n)(()=>this.flowPageService.cancelFlow())).subscribe(()=>{this._translationPrefix&&this.pageAlertService.info(this._translationPrefix+".pages.messages.cancel");const C=this.currentFlow.retrieveId();this.flowPageService.clearState(),i?this.routes.navigateTo(i):this.flowNavigationService.navigateToFlow(C)})}nopBeforeCancelFlow(){return(0,p.of)(!0)}static#e=this.\u0275fac=function(C){return new(C||_)(u.rXU(d.z),u.rXU(g._),u.rXU(w.D),u.rXU(y.BV),u.rXU(a.E))};static#t=this.\u0275cmp=u.VBU({type:_,selectors:[["iam-cancel-button"]],hostVars:2,hostBindings:function(C,J){2&C&&u.HbH(J.hostCss)},inputs:{right:"right",text:"text",disableWhenBusy:"disableWhenBusy",buttonId:"buttonId",beforeCancelFlow:"beforeCancelFlow"},standalone:!1,decls:2,vars:3,consts:[[3,"id","submit","right","text","disableWhenBusy","buttonClick",4,"ngIf"],[3,"buttonClick","id","submit","right","text","disableWhenBusy"]],template:function(C,J){1&C&&(u.DNE(0,A,1,5,"iam-button",0),u.nI1(1,"async")),2&C&&u.Y8G("ngIf",u.bMT(1,1,J.cancelButton))},dependencies:[P.bT,H.Q,P.Jj],encapsulation:2})}return _})()},9710:($,W,l)=>{l.d(W,{s:()=>f});var d=l(4438),w=(l(2263),l(9417));const p=["*"];let f=(()=>{class b{constructor(){this.autocomplete="off",this.formSubmit=new d.bkB}static#e=this.\u0275fac=function(u){return new(u||b)};static#t=this.\u0275cmp=d.VBU({type:b,selectors:[["iam-form"]],inputs:{autocomplete:"autocomplete",form:"form"},outputs:{formSubmit:"formSubmit"},standalone:!1,ngContentSelectors:p,decls:2,vars:2,consts:[[3,"ngSubmit","formGroup"]],template:function(u,g){1&u&&(d.NAR(),d.j41(0,"form",0),d.bIt("ngSubmit",function(H){return g.formSubmit.emit(H)}),d.SdG(1),d.k0s()),2&u&&(d.Y8G("formGroup",g.form.formGroup),d.BMQ("autocomplete",g.autocomplete))},dependencies:[w.qT,w.cb,w.j4],encapsulation:2})}return b})()},3001:($,W,l)=>{l.d(W,{e:()=>H});var d=l(3719),a=l(4438),w=l(177),p=l(9417),f=l(9276),b=l(9856),m=l(1463);const y=["*"],u=()=>({display:"none"});function g(A,D){if(1&A){const _=a.RV6();a.j41(0,"button",4),a.bIt("click",function(){a.eBV(_);const i=a.XpG();return a.Njj(i.isPasswordConcealed=!i.isPasswordConcealed)}),a.nrm(1,"img",5),a.nI1(2,"translate"),a.k0s()}if(2&A){const _=a.XpG();a.AVh("iam-invalid",_.hasError()),a.Y8G("ngStyle",a.lJ4(7,u)),a.R7$(),a.Y8G("ngSrc",_.isPasswordConcealed?"assets/custom/img/eye
1-regular.svg":"assets/custom/img/eye-slash-regular.svg")("alt",a.bMT(2,5,"authentication.password.show-password"))}}function P(A,D){if(1&A&&a.nrm(0,"iam-errors",3),2&A){const _=a.XpG();a.Y8G("id",_.errorFor(_.id))("errors",_.getErrors())}}let H=(()=>{class A extends d.G{constructor(){super(...arguments),this.label="",this.placeholder="",this.focus=!1,this.readonly=!1,this.inputNgClass={},this.required=!1,this.autocapitalize=!1,this.spellcheck=!1,this.isPasswordConcealed=!0}get hostCss(){return"iam-row-group"}determineType(){return"password"===this.type?this.isPasswordConcealed?"password":"text":this.type||"text"}static#e=this.\u0275fac=(()=>{let _;return function(i){return(_||(_=a.xGo(A)))(i||A)}})();static#t=this.\u0275cmp=a.VBU({type:A,selectors:[["iam-input-row"]],hostVars:2,hostBindings:function(T,i){2&T&&a.HbH(i.hostCss)},inputs:{id:"id",name:"name",label:"label",type:"type",textArguments:"textArguments",placeholder:"placeholder",focus:"focus",readonly:"readonly",inputNgClass:"inputNgClass",required:"required",autocapitalize:"autocapitalize",spellcheck:"spellcheck"},standalone:!1,features:[a.Vt3],ngContentSelectors:y,decls:6,vars:23,consts:[[3,"label","labelFor","required"],[1,"iam-form-control",3,"formControl","name","autofocus","readonly","ngClass"],["type","button",1,"iam-btn","iam-btn-outline-secondary","iam-show-password-toggle",3,"ngStyle","iam-invalid"],[3,"id","errors"],["type","button",1,"iam-btn","iam-btn-outline-secondary","iam-show-password-toggle",3,"click","ngStyle"],["height","16","width","16",3,"ngSrc","alt"]],template:function(T,i){1&T&&(a.NAR(),a.j41(0,"iam-row-with-label",0),a.nrm(1,"input",1),a.nI1(2,"translate"),a.DNE(3,g,3,8,"button",2),a.SdG(4),a.DNE(5,P,1,2,"iam-errors",3),a.k0s()),2&T&&(a.Y8G("label",i.label)("labelFor",i.name||i.id)("required",i.required),a.R7$(),a.AVh("iam-is-invalid",i.hasError())("iam-password-input-field","password"===i.type),a.Y8G("formControl",i.control)("name",i.name||i.id)("autofocus",i.focus)("readonly",i.readonly)("ngClass",i.inputNgClass),a.BMQ("type",i.determineType())("id",i.id)("placeholder",a.i5U(2,20,i.placeholder,i.textArguments))("autocapitalize",i.autocapitalize?"on":"off")("spellcheck",i.spellcheck)("aria-describedby",i.hasError()?i.errorFor(i.id):void 0),a.R7$(2),a.vxM("password"===i.type?3:-1),a.R7$(2),a.vxM(i.hasError()?5:-1))},dependencies:[w.YU,w.B3,p.me,p.BC,p.l_,w.kt,f.I,b.U,m.t],encapsulation:2})}return A})()}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.