1(globalThis.TURBOPACK||(globalThis.TURBOPACK=[])).push(["object"==typeof document?document.currentScript:void 0,300059,789694,132610,256591,708842,e=>{"use strict";var t=e.i(837474),r=e.i(944445),n=e.i(417896),i=e.i(211916);let o=BigInt(0),a=BigInt(1),l=BigInt(2),f=BigInt(3),s=BigInt(4),u=BigInt(5),d=BigInt(8);function c(e,t){let r=e%t;return r>=o?r:t+r}function h(e,t,r){let n=e;for(;t-- >o;)n*=n,n%=r;return n}function m(e,t){if(e===o)throw Error("invert: expected non-zero number");if(t<=o)throw Error("invert: expected positive modulus, got "+t);let r=c(e,t),n=t,i=o,l=a,f=a,s=o;for(;r!==o;){let e=n/r,t=n%r,o=i-f*e,a=l-s*e;n=r,r=t,i=f,l=s,f=o,s=a}if(n!==a)throw Error("invert: does not exist");return c(i,t)}function p(e,t){let r=(e.ORDER+a)/s,n=e.pow(t,r);if(!e.eql(e.sqr(n),t))throw Error("Cannot find square root");return n}function g(e,t){let r=(e.ORDER-u)/d,n=e.mul(t,l),i=e.pow(n,r),o=e.mul(t,i),a=e.mul(e.mul(o,l),i),f=e.mul(o,e.sub(a,e.ONE));if(!e.eql(e.sqr(f),t))throw Error("Cannot find square root");return f}let y=["create","isValid","is0","neg","inv","sqrt","sqr","eql","add","sub","mul","pow","div","addN","subN","mulN","sqrN"];function b(e){let t=y.reduce((e,t)=>(e[t]="function",e),{ORDER:"bigint",MASK:"bigint",BYTES:"isSafeInteger",BITS:"isSafeInteger"});return(0,i.validateObject)(e,t)}function E(e,t,r=!1){let n=Array(t.length).fill(r?e.ZERO:void 0),i=t.reduce((t,r,i)=>e.is0(r)?t:(n[i]=t,e.mul(t,r)),e.ONE),o=e.inv(i);return t.reduceRight((t,r,i)=>e.is0(r)?t:(n[i]=e.mul(t,n[i]),e.mul(t,r)),o),n}function w(e,t){let r=(e.ORDER-a)/l,n=e.pow(t,r),i=e.eql(n,e.ONE),o=e.eql(n,e.ZERO),f=e.eql(n,e.neg(e.ONE));if(!i&&!o&&!f)throw Error("invalid Legendre symbol result");return i?1:o?0:-1}function B(e,t){void 0!==t&&(0,r.anumber)(t);let n=void 0!==t?t:e.toString(2).length,i=Math.ceil(n/8);return{nBitLength:n,nByteLength:i}}function v(e,t,r=!1,n={}){let h;if(e<=o)throw Error("invalid field: expected ORDER > 0, got "+e);let{nBitLength:y,nByteLength:b}=B(e,t);if(b>2048)throw Error("invalid field: expected ORDER of <= 2048 bytes");let x=Object.freeze({ORDER:e,isLE:r,BITS:y,BYTES:b,MASK:(0,i.bitMask)(y),ZERO:o,ONE:a,create:t=>c(t,e),isValid:t=>{if("bigint"!=typeof t)throw Error("invalid field element: expected bigint, got "+typeof t);return o<=t&&t<e},is0:e=>e===o,isOdd:e=>(e&a)===a,neg:t=>c(-t,e),eql:(e,t)=>e===t,sqr:t=>c(t*t,e),add:(t,r)=>c(t+r,e),sub:(t,r)=>c(t-r,e),mul:(t,r)=>c(t*r,e),pow:(e,t)=>(function(e,t,r){if(r<o)throw Error("invalid exponent, negatives unsupported");if(r===o)return e.ONE;if(r===a)return t;let n=e.ONE,i=t;for(;r>o;)r&a&&(n=e.mul(n,i)),i=e.sqr(i),r>>=a;return n})(x,e,t),div:(t,r)=>c(t*m(r,e),e),sqrN:e=>e*e,addN:(e,t)=>e+t,subN:(e,t)=>e-t,mulN:(e,t)=>e*t,inv:t=>m(t,e),sqrt:n.sqrt||(t=>(h||(h=e%s===f?p:e%d===u?g:function(e){if(e<BigInt(3))throw Error("sqrt is not defined for small field");let t=e-a,r=0;for(;t%l===o;)t/=l,r++;let n=l,i=v(e);for(;1===w(i,n);)if(n++>1e3)throw Error("Cannot find square root: probably non-prime P");if(1===r)return p;let f=i.pow(n,t),s=(t+a)/l;return function(e,n){if(e.is0(n))return n;if(1!==w(e,n))throw Error("Cannot find square root");let i=r,o=e.mul(e.ONE,f),l=e.pow(n,t),u=e.pow(n,s);for(;!e.eql(l,e.ONE);){if(e.is0(l))return e.ZERO;let t=1,r=e.sqr(l);for(;!e.eql(r,e.ONE);)if(t++,r=e.sqr(r),t===i)throw Error("Cannot find square root");let n=a<<BigInt(i-t-1),f=e.pow(o,n);i=t,o=e.sqr(f),l=e.mul(l,o),u=e.mul(u,f)}return u}}(e)),h(x,t))),toBytes:e=>r?(0,i.numberToBytesLE)(e,b):(0,i.numberToBytesBE)(e,b),fromBytes:e=>{if(e.length!==b)throw Error("Field.fromBytes: expected "+b+" bytes, got "+e.length);return r?(0,i.bytesToNumberLE)(e):(0,i.bytesToNumberBE)(e)},invertBatch:e=>E(x,e),cmov:(e,t,r)=>r?t:e});return Object.freeze(x)}function x(e){if("bigint"!=typeof e)throw Error("field order must be bigint");return Math.ceil(e.toString(2).length/8)}function S(e){let t=x(e);return t+Math.ceil(t/2)}function O(e,t,r=!1){let n=e.length,o=x(t),l=S(t);if(n<16||n<l||n>1024)throw Error("expected "+l+"-1024 bytes of input, got "+n);let f=c(r?(0,i.bytesToNumberLE)(e):(0,i.bytesToNumberBE)(e),t-a)+a;return r?(0,i.numberToBytesLE)(f,o):(0,i.numberToBytesBE)(f,o)}e.s(["Field",0,v,"FpInvertBatch",0,E,"getMinHashLength",0,S,"invert",0,m,"mapHashToField",0,O,"mod",0,c,"nLength",0,B,"pow2",0,h,"validateField",0,b],789694);let R=BigInt(0),I=BigInt(1);function A(e,t){let r=t.negate();return e?r:t}function T(e,t){if(!Number.isSafeInteger(e)||e<=0||e>t)throw Error("invalid window size, expected [1.."+t+"], got W="+e)}function q(e,t){T(e,t);let r=Math.ceil(t/e)+1,n=2**(e-1),o=2**e;return{windows:r,windowSize:n,mask:(0,i.bitMask)(e),maxNumber:o,shiftBy:BigInt(e)}}function N(e,t,r){let{windowSize:n,mask:i,maxNumber:o,shiftBy:a}=r,l=Number(e&i),f=e>>a;l>n&&(l-=o,f+=I);let s=t*n,u=s+Math.abs(l)-1,d=0===l;return{nextN:f,offset:u,isZero:d,isNeg:l<0,isNegF:t%2!=0,offsetF:s}}let Z=new WeakMap,P=new WeakMap;function z(e){return P.get(e)||1}function C(e){return b(e.Fp),(0,i.validateObject)(e,{n:"bigint",h:"bigint",Gx:"field",Gy:"field"},{nBitLength:"isSafeInteger",nByteLength:"isSafeInteger"}),Object.freeze({...B(e.n,e.nBitLength),...e,...{p:e.Fp.ORDER}})}function D(e){void 0!==e.lowS&&(0,i.abool)("lowS",e.lowS),void 0!==e.prehash&&(0,i.abool)("prehash",e.prehash)}
1let H={Err:class extends Error{constructor(e=""){super(e)}},_tlv:{encode:(e,t)=>{let{Err:r}=H;if(e<0||e>256)throw new r("tlv.encode: wrong tag");if(1&t.length)throw new r("tlv.encode: unpadded data");let n=t.length/2,o=(0,i.numberToHexUnpadded)(n);if(o.length/2&128)throw new r("tlv.encode: long form length too big");let a=n>127?(0,i.numberToHexUnpadded)(o.length/2|128):"";return(0,i.numberToHexUnpadded)(e)+a+o+t},decode(e,t){let{Err:r}=H,n=0;if(e<0||e>256)throw new r("tlv.encode: wrong tag");if(t.length<2||t[n++]!==e)throw new r("tlv.decode: wrong tlv");let i=t[n++],o=0;if(128&i){let e=127&i;if(!e)throw new r("tlv.decode(long): indefinite length not supported");if(e>4)throw new r("tlv.decode(long): byte length is too big");let a=t.subarray(n,n+e);if(a.length!==e)throw new r("tlv.decode: length bytes not complete");if(0===a[0])throw new r("tlv.decode(long): zero leftmost byte");for(let e of a)o=o<<8|e;if(n+=e,o<128)throw new r("tlv.decode(long): not minimal encoding")}else o=i;let a=t.subarray(n,n+o);if(a.length!==o)throw new r("tlv.decode: wrong value length");return{v:a,l:t.subarray(n+o)}}},_int:{encode(e){let{Err:t}=H;if(e<U)throw new t("integer: negative integers are not allowed");let r=(0,i.numberToHexUnpadded)(e);if(8&Number.parseInt(r[0],16)&&(r="00"+r),1&r.length)throw new t("unexpected DER parsing assertion: unpadded hex");return r},decode(e){let{Err:t}=H;if(128&e[0])throw new t("invalid signature integer: negative");if(0===e[0]&&!(128&e[1]))throw new t("invalid signature integer: unnecessary leading zero");return(0,i.bytesToNumberBE)(e)}},toSig(e){let{Err:t,_int:r,_tlv:n}=H,o=(0,i.ensureBytes)("signature",e),{v:a,l:l}=n.decode(48,o);if(l.length)throw new t("invalid signature: left bytes after parsing");let{v:f,l:s}=n.decode(2,a),{v:u,l:d}=n.decode(2,s);if(d.length)throw new t("invalid signature: left bytes after parsing");return{r:r.decode(f),s:r.decode(u)}},hexFromSig(e){let{_tlv:t,_int:r}=H,n=t.encode(2,r.encode(e.r)),i=t.encode(2,r.encode(e.s));return t.encode(48,n+i)}};function F(e,t){return(0,i.bytesToHex)((0,i.numberToBytesBE)(e,t))}let U=BigInt(0),L=BigInt(1),V=BigInt(2),_=BigInt(3),k=BigInt(4);function j(e){let t,r=(t=C(e),(0,i.validateObject)(t,{hash:"hash",hmac:"function",randomBytes:"function"},{bits2int:"function",bits2int_modN:"function",lowS:"boolean"}),Object.freeze({lowS:!0,...t})),{Fp:n,n:o,nByteLength:a,nBitLength:l}=r,f=n.BYTES+1,s=2*n.BYTES+1;function u(e){return c(e,o)}let{ProjectivePoint:d,normPrivateKeyToScalar:h,weierstrassEquation:p,isWithinCurveOrder:g}=function(e){var t;let r=function(e){let t=C(e);(0,i.validateObject)(t,{a:"field",b:"field"},{allowInfinityPoint:"boolean",allowedPrivateKeyLengths:"array",clearCofactor:"function",fromBytes:"function",isTorsionFree:"function",toBytes:"function",wrapPrivateKey:"boolean"});let{endo:r,Fp:n,a:o}=t;if(r){if(!n.eql(o,n.ZERO))throw Error("invalid endo: CURVE.a must be 0");if("object"!=typeof r||"bigint"!=typeof r.beta||"function"!=typeof r.splitScalar)throw Error('invalid endo: expected "beta": bigint and "splitScalar": function')}return Object.freeze({...t})}(e),{Fp:n}=r,o=v(r.n,r.nBitLength),a=r.toBytes||((e,t,r)=>{let o=t.toAffine();return(0,i.concatBytes)(Uint8Array.from([4]),n.toBytes(o.x),n.toBytes(o.y))}),l=r.fromBytes||(e=>{let t=e.subarray(1);return{x:n.fromBytes(t.subarray(0,n.BYTES)),y:n.fromBytes(t.subarray(n.BYTES,2*n.BYTES))}});function f(e){let{a:t,b:i}=r,o=n.sqr(e),a=n.mul(o,e);return n.add(n.add(a,n.mul(e,t)),i)}function s(e,t){let r=n.sqr(t),i=f(e);return n.eql(r,i)}if(!s(r.Gx,r.Gy))throw Error("bad curve params: generator point");let u=n.mul(n.pow(r.a,_),k),d=n.mul(n.sqr(r.b),BigInt(27));if(n.is0(n.add(u,d)))throw Error("bad curve params: a or b");function h(e){let t,{allowedPrivateKeyLengths:n,nByteLength:o,wrapPrivateKey:a,n:l}=r;if(n&&"bigint"!=typeof e){if((0,i.isBytes)(e)&&(e=(0,i.bytesToHex)(e)),"string"!=typeof e||!n.includes(e.length))throw Error("invalid private key");e=e.padStart(2*o,"0")}try{t="bigint"==typeof e?e:(0,i.bytesToNumberBE)((0,i.ensureBytes)("private key",e,o))}catch(t){throw Error("invalid private key, expected hex or "+o+" bytes, got "+typeof e)}return a&&(t=c(t,l)),(0,i.aInRange)("private key",t,L,l),t}function m(e){if(!(e instanceof y))throw Error("ProjectivePoint expected")}let p=(0,i.memoized)((e,t)=>{let{px:r,py:i,pz:o}=e;if(n.eql(o,n.ONE))return{x:r,y:i};let a=e.is0();null==t&&(t=a?n.ONE:n.inv(o));let l=n.mul(r,t),f=n.mul(i,t),s=n.mul(o,t);if(a)return{x:n.ZERO,y:n.ZERO};
vendor: 4,161 bytes, line 1
1if(!n.eql(s,n.ONE))throw Error("invZ was invalid");return{x:l,y:f}}),g=(0,i.memoized)(e=>{if(e.is0()){if(r.allowInfinityPoint&&!n.is0(e.py))return;throw Error("bad point: ZERO")}let{x:t,y:i}=e.toAffine();if(!n.isValid(t)||!n.isValid(i))throw Error("bad point: x or y not FE");if(!s(t,i))throw Error("bad point: equation left != right");if(!e.isTorsionFree())throw Error("bad point: not in prime-order subgroup");return!0});class y{constructor(e,t,r){if(null==e||!n.isValid(e))throw Error("x required");if(null==t||!n.isValid(t)||n.is0(t))throw Error("y required");if(null==r||!n.isValid(r))throw Error("z required");this.px=e,this.py=t,this.pz=r,Object.freeze(this)}static fromAffine(e){let{x:t,y:r}=e||{};if(!e||!n.isValid(t)||!n.isValid(r))throw Error("invalid affine point");if(e instanceof y)throw Error("projective point not allowed");let i=e=>n.eql(e,n.ZERO);return i(t)&&i(r)?y.ZERO:new y(t,r,n.ONE)}get x(){return this.toAffine().x}get y(){return this.toAffine().y}static normalizeZ(e){let t=E(n,e.map(e=>e.pz));return e.map((e,r)=>e.toAffine(t[r])).map(y.fromAffine)}static fromHex(e){let t=y.fromAffine(l((0,i.ensureBytes)("pointHex",e)));return t.assertValidity(),t}static fromPrivateKey(e){return y.BASE.multiply(h(e))}static msm(e,t){return function(e,t,r,n){if(!Array.isArray(r))throw Error("array expected");r.forEach((t,r)=>{if(!(t instanceof e))throw Error("invalid point at index "+r)});if(!Array.isArray(n))throw Error("array of scalars expected");n.forEach((e,r)=>{if(!t.isValid(e))throw Error("invalid scalar at index "+r)});let o=r.length,a=n.length;if(o!==a)throw Error("arrays of points and scalars must have equal length");let l=e.ZERO,f=(0,i.bitLen)(BigInt(o)),s=1;f>12?s=f-3:f>4?s=f-2:f>0&&(s=2);let u=(0,i.bitMask)(s),d=Array(Number(u)+1).fill(l),c=Math.floor((t.BITS-1)/s)*s,h=l;for(let e=c;e>=0;e-=s){d.fill(l);for(let t=0;t<a;t++){let i=Number(n[t]>>BigInt(e)&u);d[i]=d[i].add(r[t])}let t=l;for(let e=d.length-1,r=l;e>0;e--)r=r.add(d[e]),t=t.add(r);if(h=h.add(t),0!==e)for(let e=0;e<s;e++)h=h.double()}return h}(y,o,e,t)}_setWindowSize(e){B.setWindowSize(this,e)}assertValidity(){g(this)}hasEvenY(){let{y:e}=this.toAffine();if(n.isOdd)return!n.isOdd(e);throw Error("Field doesn't support isOdd")}equals(e){m(e);let{px:t,py:r,pz:i}=this,{px:o,py:a,pz:l}=e,f=n.eql(n.mul(t,l),n.mul(o,i)),s=n.eql(n.mul(r,l),n.mul(a,i));return f&&s}negate(){return new y(this.px,n.neg(this.py),this.pz)}double(){let{a:e,b:t}=r,i=n.mul(t,_),{px:o,py:a,pz:l}=this,f=n.ZERO,s=n.ZERO,u=n.ZERO,d=n.mul(o,o),c=n.mul(a,a),h=n.mul(l,l),m=n.mul(o,a);return m=n.add(m,m),u=n.mul(o,l),u=n.add(u,u),f=n.mul(e,u),s=n.mul(i,h),s=n.add(f,s),f=n.sub(c,s),s=n.add(c,s),s=n.mul(f,s),f=n.mul(m,f),u=n.mul(i,u),h=n.mul(e,h),m=n.sub(d,h),m=n.mul(e,m),m=n.add(m,u),u=n.add(d,d),d=n.add(u,d),d=n.add(d,h),d=n.mul(d,m),s=n.add(s,d),h=n.mul(a,l),h=n.add(h,h),d=n.mul(h,m),f=n.sub(f,d),u=n.mul(h,c),u=n.add(u,u),new y(f,s,u=n.add(u,u))}add(e){m(e);let{px:t,py:i,pz:o}=this,{px:a,py:l,pz:f}=e,s=n.ZERO,u=n.ZERO,d=n.ZERO,c=r.a,h=n.mul(r.b,_),p=n.mul(t,a),g=n.mul(i,l),b=n.mul(o,f),E=n.add(t,i),w=n.add(a,l);E=n.mul(E,w),w=n.add(p,g),E=n.sub(E,w),w=n.add(t,o);let B=n.add(a,f);return w=n.mul(w,B),B=n.add(p,b),w=n.sub(w,B),B=n.add(i,o),s=n.add(l,f),B=n.mul(B,s),s=n.add(g,b),B=n.sub(B,s),d=n.mul(c,w),s=n.mul(h,b),d=n.add(s,d),s=n.sub(g,d),d=n.add(g,d),u=n.mul(s,d),g=n.add(p,p),g=n.add(g,p),b=n.mul(c,b),w=n.mul(h,w),g=n.add(g,b),b=n.sub(p,b),b=n.mul(c,b),w=n.add(w,b),p=n.mul(g,w),u=n.add(u,p),p=n.mul(B,w),s=n.mul(E,s),s=n.sub(s,p),p=n.mul(E,g),d=n.mul(B,d),new y(s,u,d=n.add(d,p))}subtract(e){return this.add(e.negate())}is0(){return this.equals(y.ZERO)}wNAF(e){return B.wNAFCached(this,e,y.normalizeZ)}multiplyUnsafe(e){let{endo:t,n:o}=r;(0,i.aInRange)("scalar",e,U,o);let a=y.ZERO;if(e===U)return a;if(this.is0()||e===L)return this;if(!t||B.hasPrecomputes(this))return B.wNAFCachedUnsafe(this,e,y.normalizeZ);let{k1neg:l,k1:f,k2neg:s,k2:u}=t.splitScalar(e),d=a,c=a,h=this;for(;f>U||u>U;)f&L&&(d=d.add(h)),u&L&&(c=c.add(h)),h=h.double(),f>>=L,u>>=L;return l&&(d=d.negate()),s&&(c=c.negate()),c=new y(n.mul(c.px,t.beta),c.py,c.pz),d.add(c)}multiply(e){let t,o,{endo:a,n:l}=r;
1if((0,i.aInRange)("scalar",e,L,l),a){let{k1neg:r,k1:i,k2neg:l,k2:f}=a.splitScalar(e),{p:s,f:u}=this.wNAF(i),{p:d,f:c}=this.wNAF(f);s=B.constTimeNegate(r,s),d=B.constTimeNegate(l,d),d=new y(n.mul(d.px,a.beta),d.py,d.pz),t=s.add(d),o=u.add(c)}else{let{p:r,f:n}=this.wNAF(e);t=r,o=n}return y.normalizeZ([t,o])[0]}multiplyAndAddUnsafe(e,t,r){let n=y.BASE,i=(e,t)=>t!==U&&t!==L&&e.equals(n)?e.multiply(t):e.multiplyUnsafe(t),o=i(this,t).add(i(e,r));return o.is0()?void 0:o}toAffine(e){return p(this,e)}isTorsionFree(){let{h:e,isTorsionFree:t}=r;if(e===L)return!0;if(t)return t(y,this);throw Error("isTorsionFree() has not been declared for the elliptic curve")}clearCofactor(){let{h:e,clearCofactor:t}=r;return e===L?this:t?t(y,this):this.multiplyUnsafe(r.h)}toRawBytes(e=!0){return(0,i.abool)("isCompressed",e),this.assertValidity(),a(y,this,e)}toHex(e=!0){return(0,i.abool)("isCompressed",e),(0,i.bytesToHex)(this.toRawBytes(e))}}y.BASE=new y(r.Gx,r.Gy,n.ONE),y.ZERO=new y(n.ZERO,n.ONE,n.ZERO);let{endo:b,nBitLength:w}=r,B=(t=b?Math.ceil(w/2):w,{constTimeNegate:A,hasPrecomputes:e=>1!==z(e),unsafeLadder(e,t,r=y.ZERO){let n=e;for(;t>R;)t&I&&(r=r.add(n)),n=n.double(),t>>=I;return r},precomputeWindow(e,r){let{windows:n,windowSize:i}=q(r,t),o=[],a=e,l=a;for(let e=0;e<n;e++){l=a,o.push(l);for(let e=1;e<i;e++)l=l.add(a),o.push(l);a=l.double()}return o},wNAF(e,r,n){let i=y.ZERO,o=y.BASE,a=q(e,t);for(let e=0;e<a.windows;e++){let{nextN:t,offset:l,isZero:f,isNeg:s,isNegF:u,offsetF:d}=N(n,e,a);n=t,f?o=o.add(A(u,r[d])):i=i.add(A(s,r[l]))}return{p:i,f:o}},wNAFUnsafe(e,r,n,i=y.ZERO){let o=q(e,t);for(let e=0;e<o.windows&&n!==R;e++){let{nextN:t,offset:a,isZero:l,isNeg:f}=N(n,e,o);if(n=t,!l){let e=r[a];i=i.add(f?e.negate():e)}}return i},getPrecomputes(e,t,r){let n=Z.get(t);return n||(n=this.precomputeWindow(t,e),1!==e&&Z.set(t,r(n))),n},wNAFCached(e,t,r){let n=z(e);return this.wNAF(n,this.getPrecomputes(n,e,r),t)},wNAFCachedUnsafe(e,t,r,n){let i=z(e);return 1===i?this.unsafeLadder(e,t,n):this.wNAFUnsafe(i,this.getPrecomputes(i,e,r),t,n)},setWindowSize(e,r){T(r,t),P.set(e,r),Z.delete(e)}});return{CURVE:r,ProjectivePoint:y,normPrivateKeyToScalar:h,weierstrassEquation:f,isWithinCurveOrder:function(e){return(0,i.inRange)(e,L,r.n)}}}({...r,toBytes(e,t,r){let o=t.toAffine(),a=n.toBytes(o.x),l=i.concatBytes;return((0,i.abool)("isCompressed",r),r)?l(Uint8Array.from([t.hasEvenY()?2:3]),a):l(Uint8Array.from([4]),a,n.toBytes(o.y))},fromBytes(e){let t=e.length,r=e[0],o=e.subarray(1);if(t===f&&(2===r||3===r)){let e,t=(0,i.bytesToNumberBE)(o);if(!(0,i.inRange)(t,L,n.ORDER))throw Error("Point is not on curve");let a=p(t);try{e=n.sqrt(a)}catch(e){throw Error("Point is not on curve"+(e instanceof Error?": "+e.message:""))}return(1&r)==1!=((e&L)===L)&&(e=n.neg(e)),{x:t,y:e}}if(t===s&&4===r)return{x:n.fromBytes(o.subarray(0,n.BYTES)),y:n.fromBytes(o.subarray(n.BYTES,2*n.BYTES))};throw Error("invalid Point, expected length of "+f+", or uncompressed "+s+", got "+t)}}),y=(e,t,r)=>(0,i.bytesToNumberBE)(e.slice(t,r));class b{constructor(e,t,r){(0,i.aInRange)("r",e,L,o),(0,i.aInRange)("s",t,L,o),this.r=e,this.s=t,null!=r&&(this.recovery=r),Object.freeze(this)}static fromCompact(e){return new b(y(e=(0,i.ensureBytes)("compactSignature",e,2*a),0,a),y(e,a,2*a))}static fromDER(e){let{r:t,s:r}=H.toSig((0,i.ensureBytes)("DER",e));return new b(t,r)}assertValidity(){}addRecoveryBit(e){return new b(this.r,this.s,e)}recoverPublicKey(e){let{r:t,s:a,recovery:l}=this,f=x((0,i.ensureBytes)("msgHash",e));if(null==l||![0,1,2,3].includes(l))throw Error("recovery id invalid");let s=2===l||3===l?t+r.n:t;if(s>=n.ORDER)throw Error("recovery id 2 or 3 invalid");let c=(1&l)==0?"02":"03",h=d.fromHex(c+F(s,n.BYTES)),p=m(s,o),g=u(-f*p),y=u(a*p),b=d.BASE.multiplyAndAddUnsafe(h,g,y);if(!b)throw Error("point at infinify");return b.assertValidity(),b}hasHighS(){return this.s>o>>L}normalizeS(){return this.hasHighS()?new b(this.r,u(-this.s),this.recovery):this}toDERRawBytes(){return(0,i.hexToBytes)(this.toDERHex())}toDERHex(){return H.hexFromSig(this)}toCompactRawBytes(){return(0,i.hexToBytes)(this.toCompactHex())}toCompactHex(){return F(this.r,a)+F(this.s,a)}}function w(e){if("bigint"==typeof e)return!1;if(e instanceof d)return!0;let t=(0,i.ensureBytes)("key",e).length,o=n.BYTES,l=o+1;if(!r.allowedPrivateKeyLengths&&a!==l)return t===l||t===2*o+1}let B=r.bits2int||function(e){if(e.length>8192)throw Error("input is too large");let t=(0,i.bytesToNumberBE)(e),r=8*e.length-l;return r>0?t>>BigInt(r):t},x=r.bits2int_modN||function(e){return u(B(e))},V=(0,i.bitMask)(l);function j(e){return(0,i.aInRange)("num < 2^"+l,e,U,V),(0,i.numberToBytesBE)(e,a)}let M={lowS:r.lowS,prehash:!1},K={lowS:r.lowS,prehash:!1};return d.BASE._setWindowSize(8),{CURVE:r,getPublicKey:function(e,t=!0){return d.fromPrivateKey(e).toRawBytes(t)},getSharedSecret:function(e,t,r=!0){if(!0===w(e))throw Error("first arg must be private key");if(!1===w(t))throw Error("second arg must be public key");return d.fromHex(t).multiply(h(e)).toRawBytes(r)},sign:function(e,t,a=M){let{seed:l,k2sig:f}=function(e,t,a=M){if(["recovered","canonical"].some(e=>e in a))throw Error("sign() legacy options not supported");let{hash:l,randomBytes:f}=r,{lowS:s,prehash:c,extraEntropy:p}=a;null==s&&(s=!0),e=(0,i.ensureBytes)("msgHash",e),D(a),c&&(e=(0,i.ensureBytes)("prehashed msgHash",l(e)));let y=x(e),E=h(t),w=[j(E),j(y)];if(null!=p&&!1!==p){let e=!0===p?f(n.BYTES):p;w.push((0,i.ensureBytes)("extraEntropy",e))}return{seed:(0,i.concatBytes)(...w),k2sig:function(e){var t;let r=B(e);if(!g(r))return;let n=m(r,o),i=d.BASE.multiply(r).toAffine(),a=u(i.x);if(a===U)return;let l=u(n*u(y+a*E));if(l===U)return;let f=2*(i.x!==a)|Number(i.y&L),c=l;return s&&l>o>>L&&(c=(t=l)>o>>L?u(-t):t,f^=1),new b(a,c,f)}}}(e,t,a);return(0,i.createHmacDrbg)(r.hash.outputLen,r.nByteLength,r.hmac)(l,f)},verify:function(e,t,n,a=K){let l,f;t=(0,i.ensureBytes)("msgHash",t),n=(0,i.ensureBytes)("publicKey",n);let{lowS:s,prehash:c,format:h}=a;if(D(a),"strict"in a)throw Error("options.strict was renamed to lowS");if(void 0!==h&&"compact"!==h&&"der"!==h)throw Error("format must be compact or der");
1let p="string"==typeof e||(0,i.isBytes)(e),g=!p&&!h&&"object"==typeof e&&null!==e&&"bigint"==typeof e.r&&"bigint"==typeof e.s;if(!p&&!g)throw Error("invalid signature, expected Uint8Array, hex string or Signature instance");try{if(g&&(f=new b(e.r,e.s)),p){try{"compact"!==h&&(f=b.fromDER(e))}catch(e){if(!(e instanceof H.Err))throw e}f||"der"===h||(f=b.fromCompact(e))}l=d.fromHex(n)}catch(e){return!1}if(!f||s&&f.hasHighS())return!1;c&&(t=r.hash(t));let{r:y,s:E}=f,w=x(t),B=m(E,o),v=u(w*B),S=u(y*B),O=d.BASE.multiplyAndAddUnsafe(l,v,S)?.toAffine();return!!O&&u(O.x)===y},ProjectivePoint:d,Signature:b,utils:{isValidPrivateKey(e){try{return h(e),!0}catch(e){return!1}},normPrivateKeyToScalar:h,randomPrivateKey:()=>{let e=S(r.n);return O(r.randomBytes(e),r.n)},precompute:(e=8,t=d.BASE)=>(t._setWindowSize(e),t.multiply(BigInt(3)),t)}}}function M(e,t){if(b(e),!e.isValid(t.A)||!e.isValid(t.B)||!e.isValid(t.Z))throw Error("mapToCurveSimpleSWU: invalid opts");let r=function(e,t){let r=e.ORDER,n=U;for(let e=r-L;e%V===U;e/=V)n+=L;let i=n,o=V<<i-L-L,a=o*V,l=(r-L)/a,f=(l-L)/V,s=a-L,u=e.pow(t,l),d=e.pow(t,(l+L)/V),c=(t,r)=>{let n=u,a=e.pow(r,s),l=e.sqr(a);l=e.mul(l,r);let c=e.mul(t,l);c=e.pow(c,f),c=e.mul(c,a),a=e.mul(c,r),l=e.mul(c,t);let h=e.mul(l,a);c=e.pow(h,o);let m=e.eql(c,e.ONE);a=e.mul(l,d),c=e.mul(h,n),l=e.cmov(a,l,m),h=e.cmov(c,h,m);for(let t=i;t>L;t--){let r=t-V;r=V<<r-L;let i=e.pow(h,r),o=e.eql(i,e.ONE);a=e.mul(l,n),n=e.mul(n,n),i=e.mul(h,n),l=e.cmov(a,l,o),h=e.cmov(i,h,o)}return{isValid:m,value:l}};if(e.ORDER%k===_){let r=(e.ORDER-_)/k,n=e.sqrt(e.neg(t));c=(t,i)=>{let o=e.sqr(i),a=e.mul(t,i);o=e.mul(o,a);let l=e.pow(o,r);l=e.mul(l,a);let f=e.mul(l,n),s=e.mul(e.sqr(l),i),u=e.eql(s,t),d=e.cmov(f,l,u);return{isValid:u,value:d}}}return c}(e,t.Z);if(!e.isOdd)throw Error("Fp.isOdd is not implemented!");return n=>{let i,o,a,l,f,s,u,d;i=e.sqr(n),i=e.mul(i,t.Z),o=e.sqr(i),o=e.add(o,i),a=e.add(o,e.ONE),a=e.mul(a,t.B),l=e.cmov(t.Z,e.neg(o),!e.eql(o,e.ZERO)),l=e.mul(l,t.A),o=e.sqr(a),s=e.sqr(l),f=e.mul(s,t.A),o=e.add(o,f),o=e.mul(o,a),s=e.mul(s,l),f=e.mul(s,t.B),o=e.add(o,f),u=e.mul(i,a);let{isValid:c,value:h}=r(o,s);d=e.mul(i,n),d=e.mul(d,h),u=e.cmov(u,a,c),d=e.cmov(d,h,c);let m=e.isOdd(n)===e.isOdd(d);d=e.cmov(e.neg(d),d,m);let p=E(e,[l],!0)[0];return{x:u=e.mul(u,p),y:d}}}function K(e,t){let i=t=>j({...e,...{hash:t,hmac:(e,...i)=>(0,n.hmac)(t,e,(0,r.concatBytes)(...i)),randomBytes:r.randomBytes}});return{...i(t),create:i}}e.s(["mapToCurveSimpleSWU",0,M,"weierstrass",0,j],132610),e.s(["createCurve",0,K],256591);let W=i.bytesToNumberBE;function Y(e,t){if(G(e),G(t),e<0||e>=1<<8*t)throw Error("invalid I2OSP input: "+e);let r=Array.from({length:t}).fill(0);for(let n=t-1;n>=0;n--)r[n]=255&e,e>>>=8;return new Uint8Array(r)}function G(e){if(!Number.isSafeInteger(e))throw Error("number expected")}function X(e,t,r){let n;(0,i.validateObject)(r,{DST:"stringOrUint8Array",p:"bigint",m:"isSafeInteger",k:"isSafeInteger",hash:"hash"});let{p:o,k:a,m:l,hash:f,expand:s,DST:u}=r;(0,i.abytes)(e),G(t);let d="string"==typeof u?(0,i.utf8ToBytes)(u):u,h=Math.ceil((o.toString(2).length+a)/8),m=t*l*h;if("xmd"===s)n=function(e,t,r,n){(0,i.abytes)(e),(0,i.abytes)(t),G(r),t.length>255&&(t=n((0,i.concatBytes)((0,i.utf8ToBytes)("H2C-OVERSIZE-DST-"),t)));let{outputLen:o,blockLen:a}=n,l=Math.ceil(r/o);if(r>65535||l>255)throw Error("expand_message_xmd: invalid lenInBytes");let f=(0,i.concatBytes)(t,Y(t.length,1)),s=Y(0,a),u=Y(r,2),d=Array(l),c=n((0,i.concatBytes)(s,e,u,Y(0,1),f));d[0]=n((0,i.concatBytes)(c,Y(1,1),f));for(let e=1;e<=l;e++){let t=[function(e,t){let r=new Uint8Array(e.length);for(let n=0;n<e.length;n++)r[n]=e[n]^t[n];return r}(c,d[e-1]),Y(e+1,1),f];d[e]=n((0,i.concatBytes)(...t))}return(0,i.concatBytes)(...d).slice(0,r)}(e,d,m,f);else if("xof"===s)n=function(e,t,r,n,o){if((0,i.abytes)(e),(0,i.abytes)(t),G(r),t.length>255){let e=Math.ceil(2*n/8);t=o.create({dkLen:e}).update((0,i.utf8ToBytes)("H2C-OVERSIZE-DST-")).update(t).digest()}if(r>65535||t.length>255)throw Error("expand_message_xof: invalid lenInBytes");return o.create({dkLen:r}).update(e).update(Y(r,2)).update(t).update(Y(t.length,1)).digest()}(e,d,m,a,f);else if("_internal_pass"===s)n=e;else throw Error('expand must be "xmd" or "xof"');let p=Array(t);for(let e=0;e<t;e++){let t=Array(l);for(let r=0;r<l;r++){let i=h*(r+e*l),a=n.subarray(i,i+h);t[r]=c(W(a),o)}p[e]=t}return p}function J(e,t){let r=t.map(e=>Array.from(e).reverse());return(t,n)=>{let[i,o,a,l]=r.map(r=>r.reduce((r,n)=>e.add(e.mul(r,t),n))),[f,s]=E(e,[o,l],!0);return t=e.mul(i,f),n=e.mul(n,e.mul(a,s)),{x:t,y:n}}}function Q(e,t,r){if("function"!=typeof t)throw Error("mapToCurve() must be defined");function n(r){return e.fromAffine(t(r))}function i(t){let r=t.clearCofactor();return r.equals(e.ZERO)?e.ZERO:(r.assertValidity(),r)}return{defaults:r,hashToCurve(e,t){let o=X(e,2,{...r,DST:r.DST,...t}),a=n(o[0]),l=n(o[1]);return i(a.add(l))},encodeToCurve:(e,t)=>
1i(n(X(e,1,{...r,DST:r.encodeDST,...t})[0])),mapToCurve(e){if(!Array.isArray(e))throw Error("expected array of bigints");for(let t of e)if("bigint"!=typeof t)throw Error("expected array of bigints");return i(n(e))}}}e.s(["createHasher",0,Q,"isogenyMap",0,J],708842);let $=BigInt("0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2f"),ee=BigInt("0xfffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141"),et=BigInt(0),er=BigInt(1),en=BigInt(2),ei=(e,t)=>(e+t/en)/t,eo=v($,void 0,void 0,{sqrt:function(e){let t=BigInt(3),r=BigInt(6),n=BigInt(11),i=BigInt(22),o=BigInt(23),a=BigInt(44),l=BigInt(88),f=e*e*e%$,s=f*f*e%$,u=h(s,t,$)*s%$,d=h(u,t,$)*s%$,c=h(d,en,$)*f%$,m=h(c,n,$)*c%$,p=h(m,i,$)*m%$,g=h(p,a,$)*p%$,y=h(g,l,$)*g%$,b=h(y,a,$)*p%$,E=h(b,t,$)*s%$,w=h(E,o,$)*m%$,B=h(w,r,$)*f%$,v=h(B,en,$);if(!eo.eql(eo.sqr(v),e))throw Error("Cannot find square root");return v}}),ea=K({a:et,b:BigInt(7),Fp:eo,n:ee,Gx:BigInt("55066263022277343669578718895168534326250603453777594175500187360389116729240"),Gy:BigInt("32670510020758816978083085130507043184471273380659243275938904335757337482424"),h:BigInt(1),lowS:!0,endo:{beta:BigInt("0x7ae96a2b657c07106e64479eac3434e99cf0497512f58995c1396c28719501ee"),splitScalar:e=>{let t=BigInt("0x3086d221a7d46bcde86c90e49284eb15"),r=-er*BigInt("0xe4437ed6010e88286f547fa90abfe4c3"),n=BigInt("0x114ca50f7a8e2f3f657c1108d9d44cfd8"),i=BigInt("0x100000000000000000000000000000000"),o=ei(t*e,ee),a=ei(-r*e,ee),l=c(e-o*t-a*n,ee),f=c(-o*r-a*t,ee),s=l>i,u=f>i;if(s&&(l=ee-l),u&&(f=ee-f),l>i||f>i)throw Error("splitScalar: Endomorphism failed, k="+e);return{k1neg:s,k1:l,k2neg:u,k2:f}}}},t.sha256);ea.ProjectivePoint;i.bytesToNumberBE;let el=J(eo,[["0x8e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38daaaaa8c7","0x7d3d4c80bc321d5b9f315cea7fd44c5d595d2fc0bf63b92dfff1044f17c6581","0x534c328d23f234e6e2a413deca25caece4506144037c40314ecbd0b53d9dd262","0x8e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38e38daaaaa88c"],["0xd35771193d94918a9ca34ccbb7b640dd86cd409542f8487d9fe6b745781eb49b","0xedadc6f64383dc1df7c4b2d51b54225406d36b641f5e41bbc52a56612a8c6d14","0x0000000000000000000000000000000000000000000000000000000000000001"],["0x4bda12f684bda12f684bda12f684bda12f684bda12f684bda12f684b8e38e23c","0xc75e0c32d5cb7c0fa9d0a54b12a0a6d5647ab046d686da6fdffc90fc201d71a3","0x29a6194691f91a73715209ef6512e576722830a201be2018a765e85a9ecee931","0x2f684bda12f684bda12f684bda12f684bda12f684bda12f684bda12f38e38d84"],["0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffefffff93b","0x7a06534bb8bdb49fd5e9e6632722c2989467c1bfc8e8d978dfb425d2685c2573","0x6484aa716545ca2cf3a70c3fa8fe337e0a3d21162f0d6299a7bf8192bfd2a76f","0x0000000000000000000000000000000000000000000000000000000000000001"]].map(e=>e.map(e=>BigInt(e)))),ef=M(eo,{A:BigInt("0x3f8731abdd661adca08a5558f0f5d272e953d363cb6f0e5d405447c01a444533"),B:BigInt("1771"),Z:eo.create(BigInt("-11"))});Q(ea.ProjectivePoint,e=>{let{x:t,y:r}=ef(eo.create(e[0]));return el(t,r)},{DST:"secp256k1_XMD:SHA-256_SSWU_RO_",encodeDST:"secp256k1_XMD:SHA-256_SSWU_NU_",p:eo.ORDER,m:1,k:128,expand:"xmd",hash:t.sha256}),e.s(["secp256k1",0,ea],300059)}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.