UNPKG

@accounter/client

Version:
5 lines • 208 kB
import{s as e}from"./dist-ypP48_Ax.js";import{o as t}from"./utils-CbS-oR5I.js";import{n,t as r}from"./dist-DY51vb3q.js";n();var i=e(t()),a=function(e,t){return a=Object.setPrototypeOf||{__proto__:[]}instanceof Array&&function(e,t){e.__proto__=t}||function(e,t){for(var n in t)Object.prototype.hasOwnProperty.call(t,n)&&(e[n]=t[n])},a(e,t)};function o(e,t){if(typeof t!=`function`&&t!==null)throw TypeError(`Class extends value `+String(t)+` is not a constructor or null`);a(e,t);function n(){this.constructor=e}e.prototype=t===null?Object.create(t):(n.prototype=t.prototype,new n)}var s=function(){return s=Object.assign||function(e){for(var t,n=1,r=arguments.length;n<r;n++)for(var i in t=arguments[n],t)Object.prototype.hasOwnProperty.call(t,i)&&(e[i]=t[i]);return e},s.apply(this,arguments)};function c(e,t){var n={};for(var r in e)Object.prototype.hasOwnProperty.call(e,r)&&t.indexOf(r)<0&&(n[r]=e[r]);if(e!=null&&typeof Object.getOwnPropertySymbols==`function`)for(var i=0,r=Object.getOwnPropertySymbols(e);i<r.length;i++)t.indexOf(r[i])<0&&Object.prototype.propertyIsEnumerable.call(e,r[i])&&(n[r[i]]=e[r[i]]);return n}function l(e,t,n,r){function i(e){return e instanceof n?e:new n(function(t){t(e)})}return new(n||=Promise)(function(n,a){function o(e){try{c(r.next(e))}catch(e){a(e)}}function s(e){try{c(r.throw(e))}catch(e){a(e)}}function c(e){e.done?n(e.value):i(e.value).then(o,s)}c((r=r.apply(e,t||[])).next())})}function u(e,t){var n={label:0,sent:function(){if(a[0]&1)throw a[1];return a[1]},trys:[],ops:[]},r,i,a,o=Object.create((typeof Iterator==`function`?Iterator:Object).prototype);return o.next=s(0),o.throw=s(1),o.return=s(2),typeof Symbol==`function`&&(o[Symbol.iterator]=function(){return this}),o;function s(e){return function(t){return c([e,t])}}function c(s){if(r)throw TypeError(`Generator is already executing.`);for(;o&&(o=0,s[0]&&(n=0)),n;)try{if(r=1,i&&(a=s[0]&2?i.return:s[0]?i.throw||((a=i.return)&&a.call(i),0):i.next)&&!(a=a.call(i,s[1])).done)return a;switch(i=0,a&&(s=[s[0]&2,a.value]),s[0]){case 0:case 1:a=s;break;case 4:return n.label++,{value:s[1],done:!1};case 5:n.label++,i=s[1],s=[0];continue;case 7:s=n.ops.pop(),n.trys.pop();continue;default:if(a=n.trys,!(a=a.length>0&&a[a.length-1])&&(s[0]===6||s[0]===2)){n=0;continue}if(s[0]===3&&(!a||s[1]>a[0]&&s[1]<a[3])){n.label=s[1];break}if(s[0]===6&&n.label<a[1]){n.label=a[1],a=s;break}if(a&&n.label<a[2]){n.label=a[2],n.ops.push(s);break}a[2]&&n.ops.pop(),n.trys.pop();continue}s=t.call(e,n)}catch(e){s=[6,e],i=0}finally{r=a=0}if(s[0]&5)throw s[1];return{value:s[0]?s[1]:void 0,done:!0}}}function d(e,t,n){if(n||arguments.length===2)for(var r=0,i=t.length,a;r<i;r++)(a||!(r in t))&&(a||=Array.prototype.slice.call(t,0,r),a[r]=t[r]);return e.concat(a||Array.prototype.slice.call(t))}function f(e,t){var n={};for(var r in e)Object.prototype.hasOwnProperty.call(e,r)&&t.indexOf(r)<0&&(n[r]=e[r]);if(e!=null&&typeof Object.getOwnPropertySymbols==`function`){var i=0;for(r=Object.getOwnPropertySymbols(e);i<r.length;i++)t.indexOf(r[i])<0&&Object.prototype.propertyIsEnumerable.call(e,r[i])&&(n[r[i]]=e[r[i]])}return n}function p(e,t,n,r){if(n===`a`&&!r)throw TypeError(`Private accessor was defined without a getter`);if(typeof t==`function`?e!==t||!r:!t.has(e))throw TypeError(`Cannot read private member from an object whose class did not declare it`);return n===`m`?r:n===`a`?r.call(e):r?r.value:t.get(e)}function m(e,t,n,r,i){if(r===`m`)throw TypeError(`Private method is not writable`);if(r===`a`&&!i)throw TypeError(`Private accessor was defined without a setter`);if(typeof t==`function`?e!==t||!i:!t.has(e))throw TypeError(`Cannot write private member to an object whose class did not declare it`);return r===`a`?i.call(e,n):i?i.value=n:t.set(e,n),n}function h(e,t){this.v=e,this.k=t}function g(e,t){(t==null||t>e.length)&&(t=e.length);for(var n=0,r=Array(t);n<t;n++)r[n]=e[n];return r}function _(e,t,n){if(typeof e==`function`?e===t:e.has(t))return arguments.length<3?t:n;throw TypeError(`Private element is not present on this object`)}function v(e){return new h(e,0)}function y(e,t){if(t.has(e))throw TypeError(`Cannot initialize the same private elements twice on an object`)}function b(e,t){return e.get(_(e,t))}function x(e,t,n){y(e,t),t.set(e,n)}function S(e,t,n){return e.set(_(e,t),n),n}function ee(e,t){y(e,t),t.add(e)}function C(e,t,n){return(t=function(e){var t=function(e,t){if(typeof e!=`object`||!e)return e;var n=e[Symbol.toPrimitive];if(n!==void 0){var r=n.call(e,t||`default`);if(typeof r!=`object`)return r;throw TypeError(`@@toPrimitive must return a primitive value.`)}return(t===`string`?String:Number)(e)}(e,`string`);return typeof t==`symbol`?t:t+``}(t))in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function te(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);t&&(r=r.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,r)}return n}function w(e){for(var t=1;t<arguments.length;t++){var n=arguments[t]==null?{}:arguments[t];t%2?te(Object(n),!0).forEach(function(t){C(e,t,n[t])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):te(Object(n)).forEach(function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))})}return e}function ne(e,t){if(e==null)return{};var n,r,i=function(e,t){if(e==null)return{};var n={};for(var r in e)if({}.hasOwnProperty.call(e,r)){if(t.indexOf(r)!==-1)continue;n[r]=e[r]}return n}(e,t);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);for(r=0;r<a.length;r++)n=a[r],t.indexOf(n)===-1&&{}.propertyIsEnumerable.call(e,n)&&(i[n]=e[n])}return i}function T(e,t){return function(e){if(Array.isArray(e))return e}(e)||function(e,t){var n=e==null?null:typeof Symbol<`u`&&e[Symbol.iterator]||e[`@@iterator`];if(n!=null){var r,i,a,o,s=[],c=!0,l=!1;try{if(a=(n=n.call(e)).next,t===0){if(Object(n)!==n)return;c=!1}else for(;!(c=(r=a.call(n)).done)&&(s.push(r.value),s.length!==t);c=!0);}catch(e){l=!0,i=e}finally{try{if(!c&&n.return!=null&&(o=n.return(),Object(o)!==o))return}finally{if(l)throw i}}return s}}(e,t)||function(e,t){if(e){if(typeof e==`string`)return g(e,t);var n={}.toString.call(e).slice(8,-1);return n===`Object`&&e.constructor&&(n=e.constructor.name),n===`Map`||n===`Set`?Array.from(e):n===`Arguments`||/^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(n)?g(e,t):void 0}}(e,t)||function(){throw TypeError(`Invalid attempt to destructure non-iterable instance.
In order to be iterable, non-array objects must have a [Symbol.iterator]() method.`)}()}function re(e){return function(){return new ie(e.apply(this,arguments))}}function ie(e){var t,n;function r(t,n){try{var a=e[t](n),o=a.value,s=o instanceof h;Promise.resolve(s?o.v:o).then(function(n){if(s){var c=t===`return`&&o.k?t:`next`;if(!o.k||n.done)return r(c,n);n=e[c](n).value}i(!!a.done,n)},function(e){r(`throw`,e)})}catch(e){i(2,e)}}function i(e,i){e===2?t.reject(i):t.resolve({value:i,done:e}),(t=t.next)?r(t.key,t.arg):n=null}this._invoke=function(e,i){return new Promise(function(a,o){var s={key:e,arg:i,resolve:a,reject:o,next:null};n?n=n.next=s:(t=n=s,r(e,i))})},typeof e.return!=`function`&&(this.return=void 0)}ie.prototype[typeof Symbol==`function`&&Symbol.asyncIterator||`@@asyncIterator`]=function(){return this},ie.prototype.next=function(e){return this._invoke(`next`,e)},ie.prototype.throw=function(e){return this._invoke(`throw`,e)},ie.prototype.return=function(e){return this._invoke(`return`,e)};var ae={timeoutInSeconds:60},oe=1e4,se=`memory`,ce=`online_access`,le={name:`auth0-spa-js`,version:`2.24.1`},ue=()=>Date.now(),E=`default`,D=class e extends Error{constructor(t,n){super(n),this.error=t,this.error_description=n,Object.setPrototypeOf(this,e.prototype)}static fromPayload(t){let n=t.error,r=t.error_description;return new e(n,r)}},de=class e extends D{constructor(t,n){super(`invalid_configuration`,`${t} ${n}`),this.suggestion=n,Object.setPrototypeOf(this,e.prototype)}},fe=class e extends D{constructor(t,n,r){let i=arguments.length>3&&arguments[3]!==void 0?arguments[3]:null;super(t,n),this.state=r,this.appState=i,Object.setPrototypeOf(this,e.prototype)}},pe=class e extends D{constructor(t,n,r,i){let a=arguments.length>4&&arguments[4]!==void 0?arguments[4]:null;super(t,n),this.connection=r,this.state=i,this.appState=a,Object.setPrototypeOf(this,e.prototype)}},me=class e extends D{constructor(){super(`timeout`,`Timeout`),Object.setPrototypeOf(this,e.prototype)}},he=class e extends me{constructor(t){super(),this.popup=t,Object.setPrototypeOf(this,e.prototype)}},ge=class e extends D{constructor(t){super(`cancelled`,`Popup closed`),this.popup=t,Object.setPrototypeOf(this,e.prototype)}},_e=class e extends D{constructor(){super(`popup_open`,"Unable to open a popup for loginWithPopup - window.open returned `null`"),Object.setPrototypeOf(this,e.prototype)}},ve=class e extends D{constructor(t,n,r,i){super(t,n),this.mfa_token=r,this.mfa_requirements=i,Object.setPrototypeOf(this,e.prototype)}},ye=class e extends D{constructor(t,n){super(`missing_refresh_token`,`Missing Refresh Token (audience: '${Se(t,[`default`])}', scope: '${Se(n)}')`),this.audience=t,this.scope=n,Object.setPrototypeOf(this,e.prototype)}},be=class e extends D{constructor(t,n){super(`missing_scopes`,`Missing requested scopes after refresh (audience: '${Se(t,[`default`])}', missing scope: '${Se(n)}')`),this.audience=t,this.scope=n,Object.setPrototypeOf(this,e.prototype)}},xe=class e extends D{constructor(t){super(`use_dpop_nonce`,`Server rejected DPoP proof: wrong nonce`),this.newDpopNonce=t,Object.setPrototypeOf(this,e.prototype)}};function Se(e){return e&&!(arguments.length>1&&arguments[1]!==void 0?arguments[1]:[]).includes(e)?e:``}var Ce=()=>window.crypto,we=()=>{let e=``;for(;e.length<43;){let t=Ce().getRandomValues(new Uint8Array(43-e.length));for(let n of t)e.length<43&&n<198&&(e+=`0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-_~.`[n%66])}return e},Te=e=>btoa(e),Ee=[{key:`name`,type:[`string`]},{key:`version`,type:[`string`,`number`]},{key:`env`,type:[`object`]}],De=function(e){let t=arguments.length>1&&arguments[1]!==void 0&&arguments[1];return Object.keys(e).reduce((n,r)=>{if(t&&r===`env`)return n;let i=Ee.find(e=>e.key===r);return i&&i.type.includes(typeof e[r])&&(n[r]=e[r]),n},{})},Oe=e=>{var t=e.clientId,n=f(e,[`clientId`]);return new URLSearchParams((e=>Object.keys(e).filter(t=>e[t]!==void 0).reduce((t,n)=>Object.assign(Object.assign({},t),{[n]:e[n]}),{}))(Object.assign({client_id:t},n))).toString()},ke=async e=>await Ce().subtle.digest({name:`SHA-256`},new TextEncoder().encode(e)),Ae=e=>(e=>decodeURIComponent(atob(e).split(``).map(e=>`%`+(`00`+e.charCodeAt(0).toString(16)).slice(-2)).join(``)))(e.replace(/_/g,`/`).replace(/-/g,`+`)),je=e=>{let t=new Uint8Array(e);return(e=>{let t={"+":`-`,"/":`_`,"=":``};return e.replace(/[+/=]/g,e=>t[e])})(window.btoa(String.fromCharCode(...Array.from(t))))},Me=typeof globalThis<`u`?globalThis:typeof window<`u`?window:r===void 0?typeof self<`u`?self:{}:r,Ne={},Pe={};Object.defineProperty(Pe,"__esModule",{value:!0});var Fe=function(){function e(){var e=this;this.locked=new Map,this.addToLocked=function(t,n){var r=e.locked.get(t);r===void 0?n===void 0?e.locked.set(t,[]):e.locked.set(t,[n]):n!==void 0&&(r.unshift(n),e.locked.set(t,r))},this.isLocked=function(t){return e.locked.has(t)},this.lock=function(t){return new Promise(function(n,r){e.isLocked(t)?e.addToLocked(t,n):(e.addToLocked(t),n())})},this.unlock=function(t){var n=e.locked.get(t);if(n!==void 0&&n.length!==0){var r=n.pop();e.locked.set(t,n),r!==void 0&&setTimeout(r,0)}else e.locked.delete(t)}}return e.getInstance=function(){return e.instance===void 0&&(e.instance=new e),e.instance},e}();Pe.default=function(){return Fe.getInstance()};var Ie=Me&&Me.__awaiter||function(e,t,n,r){return new(n||=Promise)(function(i,a){function o(e){try{c(r.next(e))}catch(e){a(e)}}function s(e){try{c(r.throw(e))}catch(e){a(e)}}function c(e){e.done?i(e.value):new n(function(t){t(e.value)}).then(o,s)}c((r=r.apply(e,t||[])).next())})},Le=Me&&Me.__generator||function(e,t){var n,r,i,a,o={label:0,sent:function(){if(1&i[0])throw i[1];return i[1]},trys:[],ops:[]};return a={next:s(0),throw:s(1),return:s(2)},typeof Symbol==`function`&&(a[Symbol.iterator]=function(){return this}),a;function s(a){return function(s){return function(a){if(n)throw TypeError(`Generator is already executing.`);for(;o;)try{if(n=1,r&&(i=2&a[0]?r.return:a[0]?r.throw||((i=r.return)&&i.call(r),0):r.next)&&!(i=i.call(r,a[1])).done)return i;switch(r=0,i&&(a=[2&a[0],i.value]),a[0]){case 0:case 1:i=a;break;case 4:return o.label++,{value:a[1],done:!1};case 5:o.label++,r=a[1],a=[0];continue;case 7:a=o.ops.pop(),o.trys.pop();continue;default:if(i=o.trys,!((i=i.length>0&&i[i.length-1])||a[0]!==6&&a[0]!==2)){o=0;continue}if(a[0]===3&&(!i||a[1]>i[0]&&a[1]<i[3])){o.label=a[1];break}if(a[0]===6&&o.label<i[1]){o.label=i[1],i=a;break}if(i&&o.label<i[2]){o.label=i[2],o.ops.push(a);break}i[2]&&o.ops.pop(),o.trys.pop();continue}a=t.call(e,o)}catch(e){a=[6,e],r=0}finally{n=i=0}if(5&a[0])throw a[1];return{value:a[0]?a[1]:void 0,done:!0}}([a,s])}}},Re=Me;Object.defineProperty(Ne,"__esModule",{value:!0});var ze=Pe,Be=`browser-tabs-lock-key`,Ve={key:function(e){return Ie(Re,void 0,void 0,function(){return Le(this,function(e){throw Error(`Unsupported`)})})},getItem:function(e){return Ie(Re,void 0,void 0,function(){return Le(this,function(e){throw Error(`Unsupported`)})})},clear:function(){return Ie(Re,void 0,void 0,function(){return Le(this,function(e){return[2,window.localStorage.clear()]})})},removeItem:function(e){return Ie(Re,void 0,void 0,function(){return Le(this,function(e){throw Error(`Unsupported`)})})},setItem:function(e,t){return Ie(Re,void 0,void 0,function(){return Le(this,function(e){throw Error(`Unsupported`)})})},keySync:function(e){return window.localStorage.key(e)},getItemSync:function(e){return window.localStorage.getItem(e)},clearSync:function(){return window.localStorage.clear()},removeItemSync:function(e){return window.localStorage.removeItem(e)},setItemSync:function(e,t){return window.localStorage.setItem(e,t)}};function He(e){return new Promise(function(t){return setTimeout(t,e)})}function Ue(e){for(var t=`0123456789ABCDEFGHIJKLMNOPQRSTUVWXTZabcdefghiklmnopqrstuvwxyz`,n=``,r=0;r<e;r++)n+=t[Math.floor(61*Math.random())];return n}var We=Ne.default=function(){function e(t){this.acquiredIatSet=new Set,this.storageHandler=void 0,this.id=Date.now().toString()+Ue(15),this.acquireLock=this.acquireLock.bind(this),this.releaseLock=this.releaseLock.bind(this),this.releaseLock__private__=this.releaseLock__private__.bind(this),this.waitForSomethingToChange=this.waitForSomethingToChange.bind(this),this.refreshLockWhileAcquired=this.refreshLockWhileAcquired.bind(this),this.storageHandler=t,e.waiters===void 0&&(e.waiters=[])}return e.prototype.acquireLock=function(t,n){return n===void 0&&(n=5e3),Ie(this,void 0,void 0,function(){var r,i,a,o,s,c,l;return Le(this,function(u){switch(u.label){case 0:r=Date.now()+Ue(4),i=Date.now()+n,a=Be+`-`+t,o=this.storageHandler===void 0?Ve:this.storageHandler,u.label=1;case 1:return Date.now()<i?[4,He(30)]:[3,8];case 2:return u.sent(),o.getItemSync(a)===null?(s=this.id+`-`+t+`-`+r,[4,He(Math.floor(25*Math.random()))]):[3,5];case 3:return u.sent(),o.setItemSync(a,JSON.stringify({id:this.id,iat:r,timeoutKey:s,timeAcquired:Date.now(),timeRefreshed:Date.now()})),[4,He(30)];case 4:return u.sent(),(c=o.getItemSync(a))!==null&&(l=JSON.parse(c)).id===this.id&&l.iat===r?(this.acquiredIatSet.add(r),this.refreshLockWhileAcquired(a,r),[2,!0]):[3,7];case 5:return e.lockCorrector(this.storageHandler===void 0?Ve:this.storageHandler),[4,this.waitForSomethingToChange(i)];case 6:u.sent(),u.label=7;case 7:return r=Date.now()+Ue(4),[3,1];case 8:return[2,!1]}})})},e.prototype.refreshLockWhileAcquired=function(e,t){return Ie(this,void 0,void 0,function(){var n=this;return Le(this,function(r){return setTimeout(function(){return Ie(n,void 0,void 0,function(){var n,r,i;return Le(this,function(a){switch(a.label){case 0:return[4,ze.default().lock(t)];case 1:return a.sent(),this.acquiredIatSet.has(t)?(n=this.storageHandler===void 0?Ve:this.storageHandler,(r=n.getItemSync(e))===null?(ze.default().unlock(t),[2]):((i=JSON.parse(r)).timeRefreshed=Date.now(),n.setItemSync(e,JSON.stringify(i)),ze.default().unlock(t),this.refreshLockWhileAcquired(e,t),[2])):(ze.default().unlock(t),[2])}})})},1e3),[2]})})},e.prototype.waitForSomethingToChange=function(t){return Ie(this,void 0,void 0,function(){return Le(this,function(n){switch(n.label){case 0:return[4,new Promise(function(n){var r=!1,i=Date.now(),a=!1;function o(){if(a||=(window.removeEventListener(`storage`,o),e.removeFromWaiting(o),clearTimeout(s),!0),!r){r=!0;var t=50-(Date.now()-i);t>0?setTimeout(n,t):n(null)}}window.addEventListener(`storage`,o),e.addToWaiting(o);var s=setTimeout(o,Math.max(0,t-Date.now()))})];case 1:return n.sent(),[2]}})})},e.addToWaiting=function(t){this.removeFromWaiting(t),e.waiters!==void 0&&e.waiters.push(t)},e.removeFromWaiting=function(t){e.waiters!==void 0&&(e.waiters=e.waiters.filter(function(e){return e!==t}))},e.notifyWaiters=function(){e.waiters!==void 0&&e.waiters.slice().forEach(function(e){return e()})},e.prototype.releaseLock=function(e){return Ie(this,void 0,void 0,function(){return Le(this,function(t){switch(t.label){case 0:return[4,this.releaseLock__private__(e)];case 1:return[2,t.sent()]}})})},e.prototype.releaseLock__private__=function(t){return Ie(this,void 0,void 0,function(){var n,r,i,a;return Le(this,function(o){switch(o.label){case 0:return n=this.storageHandler===void 0?Ve:this.storageHandler,r=Be+`-`+t,(i=n.getItemSync(r))===null?[2]:(a=JSON.parse(i)).id===this.id?[4,ze.default().lock(a.iat)]:[3,2];case 1:o.sent(),this.acquiredIatSet.delete(a.iat),n.removeItemSync(r),ze.default().unlock(a.iat),e.notifyWaiters(),o.label=2;case 2:return[2]}})})},e.lockCorrector=function(t){for(var n=Date.now()-5e3,r=t,i=[],a=0;;){var o=r.keySync(a);if(o===null)break;i.push(o),a++}for(var s=!1,c=0;c<i.length;c++){var l=i[c];if(l.includes(Be)){var u=r.getItemSync(l);if(u!==null){var d=JSON.parse(u);(d.timeRefreshed===void 0&&d.timeAcquired<n||d.timeRefreshed!==void 0&&d.timeRefreshed<n)&&(r.removeItemSync(l),s=!0)}}}s&&e.notifyWaiters()},e.waiters=void 0,e}(),Ge=class{async runWithLock(e,t,n){let r=new AbortController,i=setTimeout(()=>r.abort(),t);try{return await navigator.locks.request(e,{mode:`exclusive`,signal:r.signal},async e=>{if(clearTimeout(i),!e)throw Error(`Lock not available`);return await n()})}catch(e){throw clearTimeout(i),e?.name===`AbortError`?new me:e}}},Ke=class{constructor(){this.activeLocks=new Set,this.lock=new We,this.pagehideHandler=()=>{this.activeLocks.forEach(e=>this.lock.releaseLock(e)),this.activeLocks.clear()}}async runWithLock(e,t,n){let r=!1;for(let n=0;n<10&&!r;n++)r=await this.lock.acquireLock(e,t);if(!r)throw new me;this.activeLocks.add(e),this.activeLocks.size===1&&typeof window<`u`&&window.addEventListener(`pagehide`,this.pagehideHandler);try{return await n()}finally{this.activeLocks.delete(e),await this.lock.releaseLock(e),this.activeLocks.size===0&&typeof window<`u`&&window.removeEventListener(`pagehide`,this.pagehideHandler)}}};function qe(){return typeof navigator<`u`&&typeof(e=navigator.locks)?.request==`function`?new Ge:new Ke;var e}var Je=null,Ye=new TextEncoder,Xe=new TextDecoder;function Ze(e){return typeof e==`string`?Ye.encode(e):Xe.decode(e)}function Qe(e){if(typeof e.modulusLength!=`number`||e.modulusLength<2048)throw new rt(`${e.name} modulusLength must be at least 2048 bits`)}async function $e(e,t,n){if(!1===n.usages.includes(`sign`))throw TypeError(`private CryptoKey instances used for signing assertions must include "sign" in their "usages"`);let r=`${tt(Ze(JSON.stringify(e)))}.${tt(Ze(JSON.stringify(t)))}`;return`${r}.${tt(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case`ECDSA`:return{name:e.algorithm.name,hash:`SHA-256`};case`RSA-PSS`:return Qe(e.algorithm),{name:e.algorithm.name,saltLength:32};case`RSASSA-PKCS1-v1_5`:return Qe(e.algorithm),{name:e.algorithm.name};case`Ed25519`:return{name:e.algorithm.name}}throw new nt}(n),n,Ze(r)))}`}var et;if(Uint8Array.prototype.toBase64)et=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:`base64url`,omitPadding:!0}));else{let e=32768;et=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));let n=[];for(let r=0;r<t.byteLength;r+=e)n.push(String.fromCharCode.apply(null,t.subarray(r,r+e)));return btoa(n.join(``)).replace(/=/g,``).replace(/\+/g,`-`).replace(/\//g,`_`)}}function tt(e){return et(e)}var nt=class extends Error{constructor(e){var t;super(e??`operation not supported`),this.name=this.constructor.name,(t=Error.captureStackTrace)==null||t.call(Error,this,this.constructor)}},rt=class extends Error{constructor(e){var t;super(e),this.name=this.constructor.name,(t=Error.captureStackTrace)==null||t.call(Error,this,this.constructor)}};function it(e){switch(e.algorithm.name){case`RSA-PSS`:return function(e){if(e.algorithm.hash.name===`SHA-256`)return`PS256`;throw new nt(`unsupported RsaHashedKeyAlgorithm hash name`)}(e);case`RSASSA-PKCS1-v1_5`:return function(e){if(e.algorithm.hash.name===`SHA-256`)return`RS256`;throw new nt(`unsupported RsaHashedKeyAlgorithm hash name`)}(e);case`ECDSA`:return function(e){if(e.algorithm.namedCurve===`P-256`)return`ES256`;throw new nt(`unsupported EcKeyAlgorithm namedCurve`)}(e);case`Ed25519`:return`Ed25519`;default:throw new nt(`unsupported CryptoKey algorithm name`)}}function at(e){return e instanceof CryptoKey}function ot(e){return at(e)&&e.type===`public`}async function st(e,t,n,r,i,a){let o=e?.privateKey,s=e?.publicKey;if(!at(c=o)||c.type!==`private`)throw TypeError(`"keypair.privateKey" must be a private CryptoKey`);var c;if(!ot(s))throw TypeError(`"keypair.publicKey" must be a public CryptoKey`);if(!0!==s.extractable)throw TypeError(`"keypair.publicKey.extractable" must be true`);if(typeof t!=`string`)throw TypeError(`"htu" must be a string`);if(typeof n!=`string`)throw TypeError(`"htm" must be a string`);if(r!==void 0&&typeof r!=`string`)throw TypeError(`"nonce" must be a string or undefined`);if(i!==void 0&&typeof i!=`string`)throw TypeError(`"accessToken" must be a string or undefined`);if(a!==void 0&&(typeof a!=`object`||!a||Array.isArray(a)))throw TypeError(`"additional" must be an object`);return $e({alg:it(o),typ:`dpop+jwt`,jwk:await ct(s)},Object.assign(Object.assign({},a),{iat:Math.floor(Date.now()/1e3),jti:crypto.randomUUID(),htm:n,nonce:r,htu:t,ath:i?tt(await crypto.subtle.digest(`SHA-256`,Ze(i))):void 0}),o)}async function ct(e){let{kty:t,e:n,n:r,x:i,y:a,crv:o}=await crypto.subtle.exportKey(`jwk`,e);return{kty:t,crv:o,e:n,n:r,x:i,y:a}}var lt=`dpop-nonce`,ut=[`authorization_code`,`refresh_token`,`urn:ietf:params:oauth:grant-type:token-exchange`,`urn:okta:params:oauth:grant-type:webauthn`,`http://auth0.com/oauth/grant-type/mfa-oob`,`http://auth0.com/oauth/grant-type/mfa-otp`,`http://auth0.com/oauth/grant-type/mfa-recovery-code`];function dt(){return async function(e,t){var n;let r;if(typeof e!=`string`||e.length===0)throw TypeError(`"alg" must be a non-empty string`);switch(e){case`PS256`:r={name:`RSA-PSS`,hash:`SHA-256`,modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case`RS256`:r={name:`RSASSA-PKCS1-v1_5`,hash:`SHA-256`,modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case`ES256`:r={name:`ECDSA`,namedCurve:`P-256`};break;case`Ed25519`:r={name:`Ed25519`};break;default:throw new nt}return crypto.subtle.generateKey(r,(n=t?.extractable)!=null&&n,[`sign`,`verify`])}(`ES256`,{extractable:!1})}function ft(e){return async function(e){if(!ot(e))throw TypeError(`"publicKey" must be a public CryptoKey`);if(!0!==e.extractable)throw TypeError(`"publicKey.extractable" must be true`);let t=await ct(e),n;switch(t.kty){case`EC`:n={crv:t.crv,kty:t.kty,x:t.x,y:t.y};break;case`OKP`:n={crv:t.crv,kty:t.kty,x:t.x};break;case`RSA`:n={e:t.e,kty:t.kty,n:t.n};break;default:throw new nt(`unsupported JWK kty`)}return tt(await crypto.subtle.digest({name:`SHA-256`},Ze(JSON.stringify(n))))}(e.publicKey)}function pt(e){let t=e.keyPair,n=e.url,r=e.method,i=e.nonce,a=e.accessToken;return st(t,function(e){let t=new URL(e);return t.search=``,t.hash=``,t.href}(n),r,i,a)}var mt=(e,t)=>new Promise(function(n,r){let i=new MessageChannel;i.port1.onmessage=function(e){e.data.error?r(Error(e.data.error)):n(e.data),i.port1.close()},t.postMessage(e,[i.port2])}),ht=(e,t,n)=>{let r=new AbortController,i;return t.signal=r.signal,Promise.race([fetch(e,t),new Promise((e,t)=>{i=setTimeout(()=>{r.abort(),t(Error(`Timeout when executing 'fetch'`))},n)})]).finally(()=>{clearTimeout(i)})},gt=async function(e,t,n,r,i,a){let o=arguments.length>6&&arguments[6]!==void 0?arguments[6]:oe;return i?(async(e,t,n,r,i,a,o,s,c,l)=>mt({type:`refresh`,auth:{audience:t,scope:n},timeout:i,fetchUrl:e,fetchOptions:r,useFormData:o,useMrrt:s,skipTokenStorage:c,preserveRefreshToken:l},a))(e,t,n,r,o,i,a,arguments.length>7?arguments[7]:void 0,arguments.length>8?arguments[8]:void 0,arguments.length>9?arguments[9]:void 0):(async(e,t,n)=>{let r=await ht(e,t,n);return{ok:r.ok,json:await r.json(),headers:(i=r.headers,[...i].reduce((e,t)=>{let n=T(t,2),r=n[0];return e[r]=n[1],e},{}))};var i})(e,r,o)};async function _t(e,t,n,r,i,a,o,s,c,l,u,d){if(c){let t=await c.generateProof({url:e,method:i.method||`GET`,nonce:await c.getNonce()});i.headers=Object.assign(Object.assign({},i.headers),{dpop:t})}let p,m=null;for(let c=0;c<3;c++)try{p=await gt(e,n,r,i,a,o,t,s,u,d),m=null;break}catch(e){m=e}if(m)throw m;let h=p.json,g=h.error,_=h.error_description,v=f(h,[`error`,`error_description`]),y=p,b=y.headers,x=y.ok,S;if(c&&(S=b[lt],S&&await c.setNonce(S)),!x){let f=_||`HTTP error. Unable to fetch ${e}`;if(g===`mfa_required`)throw new ve(g,f,v.mfa_token,v.mfa_requirements);if(g===`missing_refresh_token`)throw new ye(n,r);if(g===`use_dpop_nonce`){if(!c||!S||l)throw new xe(S);return _t(e,t,n,r,i,a,o,s,c,!0,u,d)}throw new D(g||`request_error`,f)}return v}async function vt(e,t,n){var r=e.baseUrl,i=e.timeout,a=e.audience,o=e.scope,s=e.auth0Client,c=e.useFormData,l=e.useMrrt,u=e.dpop,d=e.preserveRefreshToken,p=f(e,[`baseUrl`,`timeout`,`audience`,`scope`,`auth0Client`,`useFormData`,`useMrrt`,`dpop`,`preserveRefreshToken`]);let m=p.grant_type===`urn:ietf:params:oauth:grant-type:token-exchange`,h=p.grant_type===`urn:okta:params:oauth:grant-type:webauthn`,g=p.grant_type===`refresh_token`&&l,_=m||h||g,v=Object.assign(Object.assign(Object.assign({},p),_&&a&&{audience:a}),_&&o&&{scope:o}),y=h||!c,b=y?JSON.stringify(v):Oe(v),x=(S=p.grant_type,ut.includes(S));var S;return await _t(`${r}/oauth/token`,i,a||E,o,{method:`POST`,body:b,headers:{"Content-Type":y?`application/json`:`application/x-www-form-urlencoded`,"Auth0-Client":btoa(JSON.stringify(De(s||le)))}},t,c,l,x?u:void 0,void 0,n,d)}var yt=function(){return(e=[...arguments].filter(Boolean).join(` `).trim().split(/\s+/),Array.from(new Set(e))).join(` `);var e},bt=(e,t,n)=>{let r;return n&&(r=e[n]),r||=e[E],yt(r,t)},xt=`@@auth0spajs@@`,St=`@@user@@`,O=class e{constructor(e){let t=arguments.length>1&&arguments[1]!==void 0?arguments[1]:xt,n=arguments.length>2?arguments[2]:void 0;this.prefix=t,this.suffix=n,this.clientId=e.clientId,this.scope=e.scope,this.audience=e.audience}toKey(){return[this.prefix,this.clientId,this.audience,this.scope,this.suffix].filter(Boolean).join(`::`)}static fromKey(t){let n=T(t.split(`::`),4),r=n[0],i=n[1],a=n[2],o=n[3];return new e({clientId:i,scope:o,audience:a},r)}static fromCacheEntry(t){let n=t.scope,r=t.audience,i=t.client_id;return new e({scope:n,audience:r,clientId:i})}},Ct=class{set(e,t){localStorage.setItem(e,JSON.stringify(t))}get(e){let t=window.localStorage.getItem(e);if(t)try{return JSON.parse(t)}catch{return}}remove(e){localStorage.removeItem(e)}allKeys(){return Object.keys(window.localStorage).filter(e=>e.startsWith(xt))}},wt=class{constructor(){this.enclosedCache=function(){let e={};return{set(t,n){e[t]=n},get(t){let n=e[t];if(n)return n},remove(t){delete e[t]},allKeys:()=>Object.keys(e)}}()}},Tt=class{constructor(e,t,n){this.cache=e,this.keyManifest=t,this.nowProvider=n||ue}async setIdToken(e,t,n){let r=this.getIdTokenCacheKey(e);await this.cache.set(r,{id_token:t,decodedToken:n}),await this.keyManifest?.add(r)}async getIdToken(e){let t=await this.cache.get(this.getIdTokenCacheKey(e.clientId));if(!t&&e.scope&&e.audience){let t=await this.get(e);return!t||!t.id_token||!t.decodedToken?void 0:{id_token:t.id_token,decodedToken:t.decodedToken}}if(t)return{id_token:t.id_token,decodedToken:t.decodedToken}}async get(e){let t=arguments.length>1&&arguments[1]!==void 0?arguments[1]:0,n=arguments.length>2&&arguments[2]!==void 0&&arguments[2],r=arguments.length>3?arguments[3]:void 0,i=await this.cache.get(e.toKey()),a=e;if(!i){let t=await this.getCacheKeys();if(!t)return;let o=this.matchExistingCacheKey(e,t);if(o&&(i=await this.cache.get(o),a=O.fromKey(o)),!i&&n&&r!==`cache-only`)return this.getEntryWithRefreshToken(e,t)}if(!i)return;let o=await this.nowProvider(),s=Math.floor(o/1e3);return i.expiresAt-t<s?i.body.refresh_token?this.modifiedCachedEntry(i,a):(await this.cache.remove(a.toKey()),void await this.keyManifest?.remove(a.toKey())):i.body}async modifiedCachedEntry(e,t){let n={refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope},r={body:n,expiresAt:e.expiresAt};return await this.cache.set(t.toKey(),r),{refresh_token:n.refresh_token,audience:n.audience,scope:n.scope}}async set(e){let t=new O({clientId:e.client_id,scope:e.scope,audience:e.audience}),n=await this.wrapCacheEntry(e);await this.cache.set(t.toKey(),n),await this.keyManifest?.add(t.toKey())}async remove(e,t,n){let r=new O({clientId:e,scope:n,audience:t});await this.cache.remove(r.toKey())}async stripRefreshToken(e){let t=await this.getCacheKeys();if(t)for(let n of t){let t=await this.cache.get(n);t?.body?.refresh_token===e&&(delete t.body.refresh_token,await this.cache.set(n,t))}}async clear(e){let t=await this.getCacheKeys();t&&(await t.filter(t=>!e||t.includes(e)).reduce(async(e,t)=>{await e,await this.cache.remove(t)},Promise.resolve()),await this.keyManifest?.clear())}async wrapCacheEntry(e){let t=await this.nowProvider();return{body:e,expiresAt:Math.floor(t/1e3)+e.expires_in}}async getCacheKeys(){return this.keyManifest?(await this.keyManifest.get())?.keys:this.cache.allKeys?this.cache.allKeys():void 0}getIdTokenCacheKey(e){return new O({clientId:e},xt,St).toKey()}matchExistingCacheKey(e,t){return t.filter(t=>{let n=O.fromKey(t),r=new Set(n.scope&&n.scope.split(` `)),i=e.scope?.split(` `)||[],a=n.scope&&i.reduce((e,t)=>e&&r.has(t),!0);return n.prefix===xt&&n.clientId===e.clientId&&n.audience===e.audience&&a})[0]}async getEntryWithRefreshToken(e,t){for(let n of t){let t=O.fromKey(n);if(t.prefix===xt&&t.clientId===e.clientId){let e=await this.cache.get(n);if(e?.body?.refresh_token)return{refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope}}}}async getRefreshTokensByAudience(e,t){var n;let r=await this.getCacheKeys();if(!r)return[];let i=new Set;for(let a of r){let r=O.fromKey(a);if(r.prefix===xt&&r.clientId===t&&r.audience===e){let e=await this.cache.get(a);(n=e?.body)!=null&&n.refresh_token&&i.add(e.body.refresh_token)}}return Array.from(i)}async updateEntry(e,t,n){let r=arguments.length>3&&arguments[3]!==void 0&&arguments[3],i=await this.getCacheKeys();if(i)for(let a of i){if(O.fromKey(a).clientId!==n)continue;let i=await this.cache.get(a);if(!i?.body)continue;let o=i.body.refresh_token;o&&(r||o===e)&&(i.body.refresh_token=t,await this.cache.set(a,i))}}},Et=class{constructor(e,t,n){this.storage=e,this.clientId=t,this.cookieDomain=n,this.storageKey=`a0.spajs.txs.${this.clientId}`}create(e){this.storage.save(this.storageKey,e,{daysUntilExpire:1,cookieDomain:this.cookieDomain})}get(){return this.storage.get(this.storageKey)}remove(){this.storage.remove(this.storageKey,{cookieDomain:this.cookieDomain})}},Dt=e=>typeof e==`number`,Ot=`iss.aud.exp.nbf.iat.jti.azp.nonce.auth_time.at_hash.c_hash.acr.amr.sub_jwk.cnf.sip_from_tag.sip_date.sip_callid.sip_cseq_num.sip_via_branch.orig.dest.mky.events.toe.txn.rph.sid.vot.vtm`.split(`.`),kt=e=>{if(!e.id_token)throw Error(`ID token is required but missing`);let t=(e=>{let t=e.split(`.`),n=T(t,3),r=n[0],i=n[1],a=n[2];if(t.length!==3||!r||!i||!a)throw Error(`ID token could not be decoded`);let o=JSON.parse(Ae(i)),s={__raw:e},c={};return Object.keys(o).forEach(e=>{s[e]=o[e],Ot.includes(e)||(c[e]=o[e])}),{encoded:{header:r,payload:i,signature:a},header:JSON.parse(Ae(r)),claims:s,user:c}})(e.id_token);if(!t.claims.iss)throw Error(`Issuer (iss) claim must be a string present in the ID token`);if(t.claims.iss!==e.iss)throw Error(`Issuer (iss) claim mismatch in the ID token; expected "${e.iss}", found "${t.claims.iss}"`);if(!t.user.sub)throw Error(`Subject (sub) claim must be a string present in the ID token`);if(t.header.alg!==`RS256`)throw Error(`Signature algorithm of "${t.header.alg}" is not supported. Expected the ID token to be signed with "RS256".`);if(!t.claims.aud||typeof t.claims.aud!=`string`&&!Array.isArray(t.claims.aud))throw Error(`Audience (aud) claim must be a string or array of strings present in the ID token`);if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e.aud))throw Error(`Audience (aud) claim mismatch in the ID token; expected "${e.aud}" but was not one of "${t.claims.aud.join(`, `)}"`);if(t.claims.aud.length>1){if(!t.claims.azp)throw Error(`Authorized Party (azp) claim must be a string present in the ID token when Audience (aud) claim has multiple values`);if(t.claims.azp!==e.aud)throw Error(`Authorized Party (azp) claim mismatch in the ID token; expected "${e.aud}", found "${t.claims.azp}"`)}}else if(t.claims.aud!==e.aud)throw Error(`Audience (aud) claim mismatch in the ID token; expected "${e.aud}" but found "${t.claims.aud}"`);if(e.nonce){if(!t.claims.nonce)throw Error(`Nonce (nonce) claim must be a string present in the ID token`);if(t.claims.nonce!==e.nonce)throw Error(`Nonce (nonce) claim mismatch in the ID token; expected "${e.nonce}", found "${t.claims.nonce}"`)}if(e.max_age&&!Dt(t.claims.auth_time))throw Error(`Authentication Time (auth_time) claim must be a number present in the ID token when Max Age (max_age) is specified`);if(t.claims.exp==null||!Dt(t.claims.exp))throw Error(`Expiration Time (exp) claim must be a number present in the ID token`);if(!Dt(t.claims.iat))throw Error(`Issued At (iat) claim must be a number present in the ID token`);let n=e.leeway||60,r=new Date(e.now||Date.now()),i=new Date(0);if(i.setUTCSeconds(t.claims.exp+n),r>i)throw Error(`Expiration Time (exp) claim error in the ID token; current time (${r}) is after expiration time (${i})`);if(t.claims.nbf!=null&&Dt(t.claims.nbf)){let e=new Date(0);if(e.setUTCSeconds(t.claims.nbf-n),r<e)throw Error(`Not Before time (nbf) claim in the ID token indicates that this token can't be used just yet. Current time (${r}) is before ${e}`)}if(t.claims.auth_time!=null&&Dt(t.claims.auth_time)){let i=new Date(0);if(i.setUTCSeconds(parseInt(t.claims.auth_time)+e.max_age+n),r>i)throw Error(`Authentication Time (auth_time) claim in the ID token indicates that too much time has passed since the last end-user authentication. Current time (${r}) is after last auth at ${i}`)}if(e.organization){let n=e.organization.trim();if(n.startsWith(`org_`)){let e=n;if(!t.claims.org_id)throw Error(`Organization ID (org_id) claim must be a string present in the ID token`);if(e!==t.claims.org_id)throw Error(`Organization ID (org_id) claim mismatch in the ID token; expected "${e}", found "${t.claims.org_id}"`)}else{let e=n.toLowerCase();if(!t.claims.org_name)throw Error(`Organization Name (org_name) claim must be a string present in the ID token`);if(e!==t.claims.org_name)throw Error(`Organization Name (org_name) claim mismatch in the ID token; expected "${e}", found "${t.claims.org_name}"`)}}return t},At=Me&&Me.__assign||function(){return At=Object.assign||function(e){for(var t,n=1,r=arguments.length;n<r;n++)for(var i in t=arguments[n])Object.prototype.hasOwnProperty.call(t,i)&&(e[i]=t[i]);return e},At.apply(this,arguments)};function jt(e,t){if(!t)return``;var n=`; `+e;return!0===t?n:n+`=`+t}function Mt(e,t,n){return encodeURIComponent(e).replace(/%(23|24|26|2B|5E|60|7C)/g,decodeURIComponent).replace(/\(/g,`%28`).replace(/\)/g,`%29`)+`=`+encodeURIComponent(t).replace(/%(23|24|26|2B|3A|3C|3E|3D|2F|3F|40|5B|5D|5E|60|7B|7D|7C)/g,decodeURIComponent)+function(e){if(typeof e.expires==`number`){var t=new Date;t.setMilliseconds(t.getMilliseconds()+864e5*e.expires),e.expires=t}return jt(`Expires`,e.expires?e.expires.toUTCString():``)+jt(`Domain`,e.domain)+jt(`Path`,e.path)+jt(`Secure`,e.secure)+jt(`SameSite`,e.sameSite)}(n)}function Nt(){return function(e){for(var t={},n=e?e.split(`; `):[],r=/(%[\dA-F]{2})+/gi,i=0;i<n.length;i++){var a=n[i].split(`=`),o=a.slice(1).join(`=`);o.charAt(0)===`"`&&(o=o.slice(1,-1));try{t[a[0].replace(r,decodeURIComponent)]=o.replace(r,decodeURIComponent)}catch{}}return t}(document.cookie)}var Pt=function(e){return Nt()[e]};function Ft(e,t,n){document.cookie=Mt(e,t,At({path:`/`},n))}var It=Ft,Lt=function(e,t){Ft(e,``,At(At({},t),{expires:-1}))},Rt={get(e){let t=Pt(e);if(t!==void 0)return JSON.parse(t)},save(e,t,n){let r={};window.location.protocol===`https:`&&(r={secure:!0,sameSite:`none`}),n!=null&&n.daysUntilExpire&&(r.expires=n.daysUntilExpire),n!=null&&n.cookieDomain&&(r.domain=n.cookieDomain),It(e,JSON.stringify(t),r)},remove(e,t){let n={};t!=null&&t.cookieDomain&&(n.domain=t.cookieDomain),Lt(e,n)}},zt=`_legacy_`,Bt={get(e){return Rt.get(e)||Rt.get(`${zt}${e}`)},save(e,t,n){let r={};window.location.protocol===`https:`&&(r={secure:!0}),n!=null&&n.daysUntilExpire&&(r.expires=n.daysUntilExpire),n!=null&&n.cookieDomain&&(r.domain=n.cookieDomain),It(`${zt}${e}`,JSON.stringify(t),r),Rt.save(e,t,n)},remove(e,t){let n={};t!=null&&t.cookieDomain&&(n.domain=t.cookieDomain),Lt(e,n),Rt.remove(e,t),Rt.remove(`${zt}${e}`,t)}},Vt={get(e){if(typeof sessionStorage>`u`)return;let t=sessionStorage.getItem(e);return t==null?void 0:JSON.parse(t)},save(e,t){sessionStorage.setItem(e,JSON.stringify(t))},remove(e){sessionStorage.removeItem(e)}},Ht;(function(e){e.Code=`code`,e.ConnectCode=`connect_code`})(Ht||={});function Ut(e,t,n){var r=t===void 0?null:t,i=function(e,t){var n=atob(e);if(t){for(var r=new Uint8Array(n.length),i=0,a=n.length;i<a;++i)r[i]=n.charCodeAt(i);return String.fromCharCode.apply(null,new Uint16Array(r.buffer))}return n}(e,n!==void 0&&n),a=i.indexOf(`
`,10)+1,o=i.substring(a)+(r?`//# sourceMappingURL=`+r:``),s=new Blob([o],{type:`application/javascript`});return URL.createObjectURL(s)}var Wt,Gt,Kt,qt,Jt=(Wt=`Lyogcm9sbHVwLXBsdWdpbi13ZWItd29ya2VyLWxvYWRlciAqLwohZnVuY3Rpb24oKXsidXNlIHN0cmljdCI7ZnVuY3Rpb24gZShlLHQpeyhudWxsPT10fHx0PmUubGVuZ3RoKSYmKHQ9ZS5sZW5ndGgpO2Zvcih2YXIgcj0wLG89QXJyYXkodCk7cjx0O3IrKylvW3JdPWVbcl07cmV0dXJuIG99ZnVuY3Rpb24gdCh0LHIpe3JldHVybiBmdW5jdGlvbihlKXtpZihBcnJheS5pc0FycmF5KGUpKXJldHVybiBlfSh0KXx8ZnVuY3Rpb24oZSx0KXt2YXIgcj1udWxsPT1lP251bGw6InVuZGVmaW5lZCIhPXR5cGVvZiBTeW1ib2wmJmVbU3ltYm9sLml0ZXJhdG9yXXx8ZVsiQEBpdGVyYXRvciJdO2lmKG51bGwhPXIpe3ZhciBvLG4scyxpLGE9W10sYz0hMCxsPSExO3RyeXtpZihzPShyPXIuY2FsbChlKSkubmV4dCwwPT09dCl7aWYoT2JqZWN0KHIpIT09cilyZXR1cm47Yz0hMX1lbHNlIGZvcig7IShjPShvPXMuY2FsbChyKSkuZG9uZSkmJihhLnB1c2goby52YWx1ZSksYS5sZW5ndGghPT10KTtjPSEwKTt9Y2F0Y2goZSl7bD0hMCxuPWV9ZmluYWxseXt0cnl7aWYoIWMmJm51bGwhPXIucmV0dXJuJiYoaT1yLnJldHVybigpLE9iamVjdChpKSE9PWkpKXJldHVybn1maW5hbGx5e2lmKGwpdGhyb3cgbn19cmV0dXJuIGF9fSh0LHIpfHxmdW5jdGlvbih0LHIpe2lmKHQpe2lmKCJzdHJpbmciPT10eXBlb2YgdClyZXR1cm4gZSh0LHIpO3ZhciBvPXt9LnRvU3RyaW5nLmNhbGwodCkuc2xpY2UoOCwtMSk7cmV0dXJuIk9iamVjdCI9PT1vJiZ0LmNvbnN0cnVjdG9yJiYobz10LmNvbnN0cnVjdG9yLm5hbWUpLCJNYXAiPT09b3x8IlNldCI9PT1vP0FycmF5LmZyb20odCk6IkFyZ3VtZW50cyI9PT1vfHwvXig/OlVpfEkpbnQoPzo4fDE2fDMyKSg/OkNsYW1wZWQpP0FycmF5JC8udGVzdChvKT9lKHQscik6dm9pZCAwfX0odCxyKXx8ZnVuY3Rpb24oKXt0aHJvdyBuZXcgVHlwZUVycm9yKCJJbnZhbGlkIGF0dGVtcHQgdG8gZGVzdHJ1Y3R1cmUgbm9uLWl0ZXJhYmxlIGluc3RhbmNlLlxuSW4gb3JkZXIgdG8gYmUgaXRlcmFibGUsIG5vbi1hcnJheSBvYmplY3RzIG11c3QgaGF2ZSBhIFtTeW1ib2wuaXRlcmF0b3JdKCkgbWV0aG9kLiIpfSgpfWNsYXNzIHIgZXh0ZW5kcyBFcnJvcntjb25zdHJ1Y3RvcihlLHQpe3N1cGVyKHQpLHRoaXMuZXJyb3I9ZSx0aGlzLmVycm9yX2Rlc2NyaXB0aW9uPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsci5wcm90b3R5cGUpfXN0YXRpYyBmcm9tUGF5bG9hZChlKXtsZXQgdD1lLmVycm9yLG89ZS5lcnJvcl9kZXNjcmlwdGlvbjtyZXR1cm4gbmV3IHIodCxvKX19Y2xhc3MgbyBleHRlbmRzIHJ7Y29uc3RydWN0b3IoZSx0KXtzdXBlcigibWlzc2luZ19yZWZyZXNoX3Rva2VuIiwiTWlzc2luZyBSZWZyZXNoIFRva2VuIChhdWRpZW5jZTogJyIuY29uY2F0KG4oZSxbImRlZmF1bHQiXSksIicsIHNjb3BlOiAnIikuY29uY2F0KG4odCksIicpIikpLHRoaXMuYXVkaWVuY2U9ZSx0aGlzLnNjb3BlPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsby5wcm90b3R5cGUpfX1mdW5jdGlvbiBuKGUpe3JldHVybiBlJiYhKGFyZ3VtZW50cy5sZW5ndGg+MSYmdm9pZCAwIT09YXJndW1lbnRzWzFdP2FyZ3VtZW50c1sxXTpbXSkuaW5jbHVkZXMoZSk/ZToiIn0iZnVuY3Rpb24iPT10eXBlb2YgU3VwcHJlc3NlZEVycm9yJiZTdXBwcmVzc2VkRXJyb3I7Y29uc3Qgcz1lPT57dmFyIHQ9ZS5jbGllbnRJZCxyPWZ1bmN0aW9uKGUsdCl7dmFyIHI9e307Zm9yKHZhciBvIGluIGUpT2JqZWN0LnByb3RvdHlwZS5oYXNPd25Qcm9wZXJ0eS5jYWxsKGUsbykmJnQuaW5kZXhPZihvKTwwJiYocltvXT1lW29dKTtpZihudWxsIT1lJiYiZnVuY3Rpb24iPT10eXBlb2YgT2JqZWN0LmdldE93blByb3BlcnR5U3ltYm9scyl7dmFyIG49MDtmb3Iobz1PYmplY3QuZ2V0T3duUHJvcGVydHlTeW1ib2xzKGUpO248by5sZW5ndGg7bisrKXQuaW5kZXhPZihvW25dKTwwJiZPYmplY3QucHJvdG90eXBlLnByb3BlcnR5SXNFbnVtZXJhYmxlLmNhbGwoZSxvW25dKSYmKHJbb1tuXV09ZVtvW25dXSl9cmV0dXJuIHJ9KGUsWyJjbGllbnRJZCJdKTtyZXR1cm4gbmV3IFVSTFNlYXJjaFBhcmFtcygoZT0+T2JqZWN0LmtleXMoZSkuZmlsdGVyKHQ9PnZvaWQgMCE9PWVbdF0pLnJlZHVjZSgodCxyKT0+T2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHQpLHtbcl06ZVtyXX0pLHt9KSkoT2JqZWN0LmFzc2lnbih7Y2xpZW50X2lkOnR9LHIpKSkudG9TdHJpbmcoKX07bGV0IGk9e30sYT1udWxsO2NvbnN0IGM9KGUsdCk9PiIiLmNvbmNhdChlLCJ8IikuY29uY2F0KHQpLGw9KGUsdCk9PnQuc3RhcnRzV2l0aCgiIi5jb25jYXQoZSwifCIpKSx1PWU9PntPYmplY3QuZW50cmllcyhpKS5mb3JFYWNoKHI9PntsZXQgbz10KHIsMiksbj1vWzBdO29bMV09PT1lJiZkZWxldGUgaVtuXX0pfSxmPWU9Pntjb25zdCB0PW5ldyBVUkxTZWFyY2hQYXJhbXMoZSkscj17fTtyZXR1cm4gdC5mb3JFYWNoKChlLHQpPT57clt0XT1lfSkscn0saD1hc3luYyBlPT57bGV0IHIsbixhPWUuZGF0YSx1PWEudGltZW91dCxoPWEuYXV0aCxkPWEuZmV0Y2hVcmwscD1hLmZldGNoT3B0aW9ucyx5PWEudXNlRm9ybURhdGEsZz1hLnVzZU1ycnQsYj1hLnNraXBUb2tlblN0b3JhZ2UsTz1hLnByZXNlcnZlUmVmcmVzaFRva2VuLGs9dChlLnBvcnRzLDEpWzBdLG09e307Y29uc3Qgaj1ofHx7fSx2PWouYXVkaWVuY2UsXz1qLnNjb3BlO3RyeXtjb25zdCBlPXk/ZihwLmJvZHkpOkpTT04ucGFyc2UocC5ib2R5KTtpZighZS5yZWZyZXNoX3Rva2VuJiYicmVmcmVzaF90b2tlbiI9PT1lLmdyYW50X3R5cGUpe2lmKG49KChlLHQpPT5pW2MoZSx0KV0pKHYsXyksIW4mJmcpe2NvbnN0IGU9aS5sYXRlc3RfcmVmcmVzaF90b2tlbix0PSgoZSx0KT0+ISFPYmplY3Qua2V5cyhpKS5maW5kKHI9PntpZigibGF0ZXN0X3JlZnJlc2hfdG9rZW4iIT09cil7Y29uc3Qgbz1sKHQsciksbj1yLnNwbGl0KCJ8IilbMV0uc3BsaXQoIiAiKSxzPWUuc3BsaXQoIiAiKS5ldmVyeShlPT5uLmluY2x1ZGVzKGUpKTtyZXR1cm4gbyYmc319KSkoXyx2KTtlJiYhdCYmKG49ZSl9aWYoIW4pdGhyb3cgbmV3IG8odixfKTtwLmJvZHk9eT9zKE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpfWxldCBhLGg7ImZ1bmN0aW9uIj09dHlwZW9mIEFib3J0Q29udHJvbGxlciYmKGE9bmV3IEFib3J0Q29udHJvbGxlcixwLnNpZ25hbD1hLnNpZ25hbCk7dHJ5e2g9YXdhaXQgUHJvbWlzZS5yYWNlKFsoVT11LG5ldyBQcm9taXNlKGU9PnNldFRpbWVvdXQoZSxVKSkpLGZldGNoKGQsT2JqZWN0LmFzc2lnbih7fSxwKSldKX1jYXRjaChlKXtyZXR1cm4gdm9pZCBrLnBvc3RNZXNzYWdlKHtlcnJvcjplLm1lc3NhZ2V9KX1pZighaClyZXR1cm4gYSYmYS5hYm9ydCgpLHZvaWQgay5wb3N0TWVzc2FnZSh7ZXJyb3I6IlRpbWVvdXQgd2hlbiBleGVjdXRpbmcgJ2ZldGNoJyJ9KTtpZihNPWguaGVhZGVycyxtPVsuLi5NXS5yZWR1Y2UoKGUscik9PntsZXQgbz10KHIsMiksbj1vWzBdLHM9b1sxXTtyZXR1cm4gZVtuXT1zLGV9LHt9KSxyPWF3YWl0IGguanNvbigpLGIpcmV0dXJuIGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4sdm9pZCBrLnBvc3RNZXNzYWdlKHtvazpoLm9rLGpzb246cixoZWFkZXJzOm19KTtyLnJlZnJlc2hfdG9rZW4/KGcmJihpLmxhdGVzdF9yZWZyZXNoX3Rva2VuPXIucmVmcmVzaF90b2tlbix3PW4sUz1yLnJlZnJlc2hfdG9rZW4sT2JqZWN0LmVudHJpZXMoaSkuZm9yRWFjaChlPT57bGV0IHI9dChlLDIpLG89clswXTtyWzFdPT09dyYmKGlbb109Uyl9KSksKChlLHQscik9PntpW2ModCxyKV09ZX0pKHIucmVmcmVzaF90b2tlbix2LF8pLGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4pOk98fCgoZSx0KT0+e2RlbGV0ZSBpW2MoZSx0KV19KSh2LF8pLGsucG9zdE1lc3NhZ2Uoe29rOmgub2ssanNvbjpyLGhlYWRlcnM6bX0pfWNhdGNoKGUpe2sucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOmUuZXJyb3IsZXJyb3JfZGVzY3JpcHRpb246ZS5tZXNzYWdlfSxoZWFkZXJzOm19KX12YXIgdyxTLE0sVX0sZD1hc3luYyBlPT57bGV0IHI9ZS5kYXRhLG89ci50aW1lb3V0LG49ci5hdXRoLGE9ci5mZXRjaFVybCxjPXIuZmV0Y2hPcHRpb25zLGg9ci51c2VGb3JtRGF0YSxkPXQoZS5wb3J0cywxKVswXTtjb25zdCBwPShufHx7fSkuYXVkaWVuY2U7dHJ5e2NvbnN0IGU9KGU9Pntjb25zdCByPW5ldyBTZXQ7cmV0dXJuIE9iamVjdC5lbnRyaWVzKGkpLmZvckVhY2gobz0+e2xldCBuPXQobywyKSxzPW5bMF0saT1uWzFdO2woZSxzKSYmci5hZGQoaSl9KSxBcnJheS5mcm9tKHIpfSkocCk7aWYoMD09PWUubGVuZ3RoKXJldHVybiB2b2lkIGQucG9zdE1lc3NhZ2Uoe29rOiEwfSk7Y29uc3Qgcj1oP2YoYy5ib2R5KTpKU09OLnBhcnNlKGMuYm9keSk7Zm9yKGNvbnN0IHQgb2YgZSl7Y29uc3QgZT1oP3MoT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHIpLHt0b2tlbjp0fSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxyKSx7dG9rZW46dH0pKTtsZXQgbixpLGwsZjsiZnVuY3Rpb24iPT10eXBlb2YgQWJvcnRDb250cm9sbGVyJiYobj1uZXcgQWJvcnRDb250cm9sbGVyLGk9bi5zaWduYWwpO3RyeXtmPWF3YWl0IFByb21pc2UucmFjZShbbmV3IFByb21pc2UoZT0+e2w9c2V0VGltZW91dChlLG8pfSksZmV0Y2goYSxPYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30sYykse2JvZHk6ZSxzaWduYWw6aX0pKV0pLmZpbmFsbHkoKCk9PmNsZWFyVGltZW91dChsKSl9Y2F0Y2goZSl7cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZS5tZXNzYWdlfSl9aWYoIWYpcmV0dXJuIG4mJm4uYWJvcnQoKSx2b2lkIGQucG9zdE1lc3NhZ2Uoe2Vycm9yOiJUaW1lb3V0IHdoZW4gZXhlY3V0aW5nICdmZXRjaCcifSk7aWYoIWYub2spe2xldCBlO3RyeXtjb25zdCB0PUpTT04ucGFyc2UoYXdhaXQgZi50ZXh0KCkpO2U9dC5lcnJvcl9kZXNjcmlwdGlvbn1jYXRjaChlKXt9cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZXx8IkhUVFAgZXJyb3IgIi5jb25jYXQoZi5zdGF0dXMpfSl9dSh0KX1kLnBvc3RNZXNzYWdlKHtvazohMH0pfWNhdGNoKGUpe2QucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZXx8IlVua25vd24gZXJyb3IgZHVyaW5nIHRva2VuIHJldm9jYXRpb24ifSl9fSxwPShlLHQpPT57aWYoIWEpcmV0dXJuITE7dHJ5e2NvbnN0IHI9bmV3IFVSTChhKS5vcmlnaW4sbz1uZXcgVVJMKGUuZmV0Y2hVcmwpO3JldHVybiBvLm9yaWdpbj09PXImJm8ucGF0aG5hbWU9PT10fWNhdGNoKGUpe3JldHVybiExfX07YWRkRXZlbnRMaXN0ZW5lcigibWVzc2FnZSIsZT0+e2NvbnN0IHI9ZS5kYXRhLG89dChlLnBvcnRzLDEpWzBdO2lmKCEoInR5cGUiaW4gcil8fCJpbml0IiE9PXIudHlwZSlyZXR1cm4idHlwZSJpbiByJiYiY2xlYXIiPT09ci50eXBlPyhpPXt9LHZvaWQobnVsbD09b3x8by5wb3N0TWVzc2FnZSh7b2s6ITB9KSkpOiJ0eXBlImluIHImJiJyZXZva2UiPT09ci50eXBlP3AociwiL29hdXRoL3Jldm9rZSIpP3ZvaWQgZChlKTp2b2lkKG51bGw9PW98fG8ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOiJpbnZhbGlkX2ZldGNoX3VybCIsZXJyb3JfZGVzY3JpcHRpb246IlVuYXV0aG9yaXplZCBmZXRjaCBVUkwifSxoZWFkZXJzOnt9fSkpOnZvaWQoImZldGNoVXJsImluIHImJnAociwiL29hdXRoL3Rva2VuIik/aChlKTpudWxsPT1vfHxvLnBvc3RNZXNzYWdlKHtvazohMSxqc29uOntlcnJvcjoiaW52YWxpZF9mZXRjaF91cmwiLGVycm9yX2Rlc2NyaXB0aW9uOiJVbmF1dGhvcml6ZWQgZmV0Y2ggVVJMIn0saGVhZGVyczp7fX0pKTtpZihudWxsPT09YSl0cnl7bmV3IFVSTChyLmFsbG93ZWRCYXNlVXJsKSxhPXIuYWxsb3dlZEJhc2VVcmx9Y2F0Y2goZSl7cmV0dXJufX0pfSgpOwoK`,Gt=null,Kt=!1,function(e){return qt||=Ut(Wt,Gt,Kt),new Worker(qt,e)}),Yt=class{constructor(e,t){this.cache=e,this.clientId=t,this.manifestKey=this.createManifestKeyFrom(this.clientId)}async add(e){let t=new Set((await this.cache.get(this.manifestKey))?.keys||[]);t.add(e),await this.cache.set(this.manifestKey,{keys:[...t]})}async remove(e){let t=await this.cache.get(this.manifestKey);if(t){let n=new Set(t.keys);return n.delete(e),n.size>0?await this.cache.set(this.manifestKey,{keys:[...n]}):await this.cache.remove(this.manifestKey)}}get(){return this.cache.get(this.manifestKey)}clear(){return this.cache.remove(this.manifestKey)}createManifestKeyFrom(e){return`${xt}::${e}`}},Xt=`auth0.is.authenticated`,Zt={memory:()=>new wt().enclosedCache,localstorage:()=>new Ct},Qt=e=>Zt[e],$t=e=>{let t=e.openUrl,n=e.onRedirect,r=f(e,[`openUrl`,`onRedirect`]);return Object.assign(Object.assign({},r),{openUrl:!1===t||t?t:n})},en=(e,t,n)=>{let r=e?.split(` `)||[],i=n?r.filter(e=>e!==ce):r,a=t?.split(` `)||[];return i.filter(e=>a.indexOf(e)==-1).join(`,`)},tn={NONCE:`nonce`,KEYPAIR:`keypair`},nn=class{constructor(e){this.clientId=e}getVersion(){return 1}createDbHandle(){let e=window.indexedDB.open(`auth0-spa-js`,this.getVersion());return new Promise((t,n)=>{e.onupgradeneeded=()=>Object.values(tn).forEach(t=>e.result.createObjectStore(t)),e.onerror=()=>n(e.error),e.onsuccess=()=>t(e.result)})}async getDbHandle(){return this.dbHandle||=await this.createDbHandle(),this.dbHandle}async executeDbRequest(e,t,n){let r=n((await this.getDbHandle()).transaction(e,t).objectStore(e));return new Promise((e,t)=>{r.onsuccess=()=>e(r.result),r.onerror=()=>t(r.error)})}buildKey(e){let t=e?`_${e}`:`auth0`;return`${this.clientId}::${t}`}setNonce(e,t){return this.save(tn.NONCE,this.buildKey(t),e)}setKeyPair(e){return this.save(tn.KEYPAIR,this.buildKey(),e)}async save(e,t,n){await this.executeDbRequest(e,`readwrite`,e=>e.put(n,t))}findNonce(e){return this.find(tn.NONCE,this.buildKey(e))}findKeyPair(){return this.find(tn.KEYPAIR,this.buildKey())}find(e,t){return this.executeDbRequest(e,`readonly`,e=>e.get(t))}async deleteBy(e,t){let n=await this.executeDbRequest(e,`readonly`,e=>e.getAllKeys());await Promise.all(n?.filter(t).map(t=>this.executeDbRequest(e,`readwrite`,e=>e.delete(t)))||[])}deleteByClientId(e,t){return this.deleteBy(e,e=>typeof e==`string`&&e.startsWith(`${t}::`))}clearNonces(){return this.deleteByClientId(tn.NONCE,this.clientId)}clearKeyPairs(){return this.deleteByClientId(tn.KEYPAIR,this.clientId)}},rn=class{constructor(e){this.storage=new nn(e)}getNonce(e){return this.storage.findNonce(e)}setNonce(e,t){return this.storage.setNonce(e,t)}async getOrGenerateKeyPair(){let e=await this.storage.findKeyPair();return e||(e=await dt(),await this.storage.setKeyPair(e)),e}async generateProof(e){let t=await this.getOrGenerateKeyPair();return pt(Object.assign({keyPair:t},e))}async calculateThumbprint(){return ft(await this.getOrGenerateKeyPair())}async clear(){await Promise.all([this.storage.clearNonces(),this.storage.clearKeyPairs()])}},an;(function(e){e.Bearer=`Bearer`,e.DPoP=`DPoP`})(an||={});var on=class{constructor(e,t){this.hooks=t,this.config=Object.assign(Object.assign({},e),{fetch:e.fetch||(typeof window>`u`?fetch:window.fetch.bind(window))})}isAbsoluteUrl(e){return/^(https?:)?\/\//i.test(e)}buildUrl(e,t){if(t){if(this.isAbsoluteUrl(t))return t;if(e)return`${e.replace(/\/?\/$/,``)}/${t.replace(/^\/+/,``)}`}throw TypeError("`url` must be absolute or `baseUrl` non-empty.")}getAccessToken(e){return this.config.getAccessToken?this.config.getAccessToken(e):this.hooks.getAccessToken(e)}extractUrl(e){return typeof e==`string`?e:e instanceof URL?e.href:e.url}buildBaseRequest(e,t){if(!this.config.baseUrl)return new Request(e,t);let n=this.buildUrl(this.config.baseUrl,this.extractUrl(e)),r=e instanceof Request?new Request(n,e):n;return new Request(r,t)}setAuthorizationHeader(e,t){let n=arguments.length>2&&arguments[2]!==void 0?arguments[2]:an.Bearer;e.headers.set(`authorization`,`${n} ${t}`)}async setDpopProofHeader(e,t){if(!this.config.dpopNonceId)return;let n=await this.hooks.getDpopNonce(),r=await this.hooks.generateDpopProof({accessToken:t,method:e.method,nonce:n,url:e.url});e.headers.set(`dpop`,r)}async prepareRequest(e,t){let n=await this.getAccessToken(t),r,i;typeof n==`string`?(r=this.config.dpopNonceId?an.DPoP:an.Bearer,i=n):(r=n.token_type,i=n.access_token),this.setAuthorizationHeader(e,i,r),r===an.DPoP&&await this.setDpopProofHeader(e,i)}getHeader(e,t){return Array.isArray(e)?new Headers(e).get(t)||``:typeof e.get==`function`?e.get(t)||``:e[t]||``}hasUseDpopNonceError(e){if(e.status!==401)return!1;let t=this.getHeader(e.headers,`www-authenticate`);return t.includes(`invalid_dpop_nonce`)||t.includes(`use_dpop_nonce`)}async handleResponse(e,t){let n=this.getHeader(e.headers,lt);if(n&&await this.hooks.setDpopNonce(n),!this.hasUseDpopNonceError(e))return e;if(!n||!t.onUseDpopNonceError)throw new xe(n);return t.onUseDpopNonceError()}async internalFetchWithAuth(e,t,n,r){let i=this.buildBaseRequest(e,t);await this.prepareRequest(i,r);let a=await this.config.fetch(i);return this.handleResponse(a,n)}fetchWithAuth(e,t,n){let r={onUseDpopNonceError:()=>this.internalFetchWithAuth(e,t,Object.assign(Object.assign({},r),{onUseDpopNonceError:void 0}),n)};return this.internalFetchWithAuth(e,t,r,n)}},sn=class{constructor(e,t){this.myAccountFetcher=e,this.apiBase=t}async connectAccount(e){let t=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/connected-accounts/connect`,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(e)},{scope:[`create:me:connected_accounts`]});return this._handleResponse(t)}async completeAccount(e){let t=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/connected-accounts/complete`,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(e)},{scope:[`create:me:connected_accounts`]});return this._handleResponse(t)}async getFactors(){let e=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/factors`,{method:`GET`},{scope:[`read:me:factors`]});return(await this._handleResponse(e)).factors}async getAuthenticationMethods(e){let t=e?`?${new URLSearchParams({type:e})}`:``,n=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/authentication-methods${t}`,{method:`GET`},{scope:[`read:me:authentication_methods`]});return(await this._handleResponse(n)).authentication_methods}async getAuthenticationMethod(e){let t=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/authentication-methods/${encodeURIComponent(e)}`,{method:`GET`},{scope:[`read:me:authentication_methods`]});return this._handleResponse(t)}async deleteAuthenticationMethod(e){let t=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/authentication-methods/${encodeURIComponent(e)}`,{method:`DELETE`},{scope:[`delete:me:authentication_methods`]});t.ok||await this._handleResponse(t)}async updateAuthenticationMethod(e,t){let n=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/authentication-methods/${encodeURIComponent(e)}`,{method:`PATCH`,headers:{"Content-Type":`application/json`},body:JSON.stringify(t)},{scope:[`update:me:authentication_methods`]});return this._handleResponse(n)}async enrollmentChallenge(e){let t=await this.myAccountFetcher.fetchWithAuth(`${this.apiBase}v1/authentication-methods`,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(e)},{scope:[`create:me:authentication_methods`]}),n=await this._handleResponse(t),r=t.headers.get(`location`)??``,i=decodeURIComponent(r.split(`/`).pop()||``);return Object.assign(Object.assign({},n),{id:i,location:r})}async enrollmentVerify(e){let t=e,n=t.location;t.type;let r=f(t,[`location`,`type`]),i=await this.myAccountFetcher.fetchWithAuth(`${n}/verify`,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(r)},{scope:[`create:me:authentication_methods`]});return this._handleResponse(i)}async _handleResponse(e){let t;try{t=await e.text(),t=JSON.parse(t)}catch(n){throw new cn({type:`invalid_json`,status:e.status,title:`Invalid JSON response`,detail:t||String(n)})}if(e.ok)return t;throw new cn(t)}},cn=class e extends Error{constructor(t){let n=t.type,r=t.status,i=t.title,a=t.detail,o=t.validation_errors;super(a),this.name=`MyAccountApiError`,this.type=n,this.status=r,this.title=i,this.detail=a,this.validation_errors=o,Object.setPrototypeOf(this,e.prototype)}},ln={otp:{authenticatorTypes:[`otp`]},sms:{authenticatorTypes:[`oob`],oobChannels:[`sms`]},email:{authenticatorTypes:[`oob`],oobChannels:[`email`]},push:{authenticatorTypes:[`oob`],oobChannels:[`auth0`]},voice:{authenticatorTypes:[`oob`],oobChannels:[`voice`]}},un=`http://auth0.com/oauth/grant-type/mfa-otp`,dn=`http://auth0.com/oauth/grant-type/mfa-oob`,fn=`http://auth0.com/oauth/grant-type/mfa-recovery-code`,pn,mn,hn;(typeof navigator>`u`||(pn=navigator.userAgent)==null||(mn=pn.startsWith)==null||!mn.call(pn,`Mozilla/5.0 `))&&(hn=`oauth4webapi/v3.8.6`);function gn(e,t){if(e==null)return!1;try{return e instanceof t||Object.getPrototypeOf(e)[Symbol.toStringTag]===t.prototype[Symbol.toStringTag]}catch{return!1}}var k=`ERR_INVALID_ARG_VALUE`,A=`ERR_INVALID_ARG_TYPE`;function j(e,t,n){let r=TypeError(e,{cause:n});return Object.assign(r,{code:t}),r}var M=Symbol(),_n=Symbol(),vn=Symbol(),N=Symbol(),yn=Symbol(),bn=Symbol(),xn=new TextEncoder,Sn=new TextDecoder;function Cn(e){return typeof e==`string`?xn.encode(e):Sn.decode(e)}var wn,Tn;if(Uint8Array.prototype.toBase64)wn=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:`base64url`,omitPadding:!0}));else{let e=32768;wn=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));let n=[];for(let r=0;r<t.byteLength;r+=e)n.push(String.fromCharCode.apply(null,t.subarray(r,r+e)));return btoa(n.join(``)).replace(/=/g,``).replace(/\+/g,`-`).replace(/\//g,`_`)}}function En(e){return typeof e==`string`?Tn(e):wn(e)}Tn=Uint8Array.fromBase64?e=>{try{return Uint8Array.fromBase64(e,{alphabet:`base64url`})}catch(e){throw j(`The input to be decoded is not correctly encoded.`,k,e)}}:e=>{try{let t=atob(e.replace(/-/g,`+`).replace(/_/g,`/`).replace(/\s/g,``)),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}catch(e){throw j(`The input to be decoded is not correctly encoded.`,k,e)}};var P=class extends Error{constructor(e,t){var n;super(e,t),C(this,`code`,void 0),this.name=this.constructor.name,this.code=br,(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}},Dn=class extends Error{constructor(e,t){var n;super(e,t),C(this,`code`,void 0),this.name=this.constructor.name,t!=null&&t.code&&(this.code=t?.code),(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}};function F(e,t,n){return new Dn(e,{code:t,cause:n})}function On(e,t){if(function(e,t){if(!(e instanceof CryptoKey))throw j(`${t} must be a CryptoKey`,A)}(e,t),e.type!==`private`)throw j(`${t} must be a private CryptoKey`,k)}function kn(e){return typeof e==`object`&&!!e&&!Array.isArray(e)}function An(e){gn(e,Headers)&&(e=Object.fromEntries(e.entries()));let t=new Headers(e??{});if(hn&&!t.has(`user-agent`)&&t.set(`user-agent`,hn),t.has(`authorization`))throw j(`"options.headers" must not include the "authorization" header name`,k);return t}function jn(e,t){if(t!==void 0){if(typeof t==`function`&&(t=t(e.href)),!(t instanceof AbortSignal))throw j(`"options.signal" must return or be an instance of AbortSignal`,A);return t}}function Mn(e){return e.includes(`//`)?e.replace(`//`,`/`):e}async function Nn(e,t){return async function(e,t,n,r){if(!(e instanceof URL))throw j(`"${t}" must be an instance of URL`,A);Wn(e,!0!==r?.[M]);let i=n(new URL(e.href)),a=An(r?.headers);return a.set(`accept`,`application/json`),(r?.[N]||fetch)(i.href,{body:void 0,headers:Object.fromEntries(a.entries()),method:`GET`,redirect:`manual`,signal:jn(i,r?.signal)})}(e,`issuerIdentifier`,e=>{switch(t?.algorithm){case void 0:case`oidc`:(function(e,t){e.pathname=Mn(`${e.pathname}/${t}`)})(e,`.well-known/openid-configuration`);break;case`oauth2`:(function(e,t){let n=arguments.length>2&&arguments[2]!==void 0&&arguments[2];e.pathname=e.pathname===`/`?t:Mn(`${t}/${n?e.pathname:e.pathname.replace(/(\/)$/,``)}`)})(e,`.well-known/oauth-authorization-server`);break;default:throw j(`"options.algorithm" must be "oidc" (default), or "oauth2"`,k)}return e},t)}function Pn(e,t,n,r,i){try{if(typeof e!=`number`||!Number.isFinite(e))throw j(`${n} must be a number`,A,i);if(e>0)return;if(t){if(e!==0)throw j(`${n} must be a non-negative number`,k,i);return}throw j(`${n} must be a positive number`,k,i)}catch(e){throw r?F(e.message,r,i):e}}function I(e,t,n,r){try{if(typeof e!=`string`)throw j(`${t} must be a string`,A,r);if(e.length===0)throw j(`${t} must not be empty`,k,r)}catch(e){throw n?F(e.message,n,r):e}}function Fn(e){(function(e,t){if(nr(e)!==t)throw function(e){let t=`"response" content-type must be `;var n=[...arguments].slice(1);if(n.length>2){let e=n.pop();t+=`${n.join(`, `)}, or ${e}`}else n.length===2?t+=`${n[0]} or ${n[1]}`:t+=n[0];return F(t,Cr,e)}(e,t)})(e,`application/json`)}function In(){return En(crypto.getRandomValues(new Uint8Array(32)))}function Ln(e){switch(e.algorithm.name){case`RSA-PSS`:return function(e){switch(e.algorithm.hash.name){case`SHA-256`:return`PS256`;case`SHA-384`:return`PS384`;case`SHA-512`:return`PS512`;default:throw new P(`unsupported RsaHashedKeyAlgorithm hash name`,{cause:e})}}(e);case`RSASSA-PKCS1-v1_5`:return function(e){switch(e.algorithm.hash.name){case`SHA-256`:return`RS256`;case`SHA-384`:return`RS384`;case`SHA-512`:return`RS512`;default:throw new P(`unsupported RsaHashedKeyAlgorithm hash name`,{cause:e})}}(e);case`ECDSA`:return function(e){switch(e.algorithm.namedCurve){case`P-256`:return`ES256`;case`P-384`:return`ES384`;case`P-521`:return`ES512`;default:throw new P(`unsupported EcKeyAlgorithm namedCurve`,{cause:e})}}(e);case`Ed25519`:case`ML-DSA-44`:case`ML-DSA-65`:case`ML-DSA-87`:return e.algorithm.name;case`EdDSA`:return`Ed25519`;default:throw new P(`unsupported CryptoKey algorithm name`,{cause:e})}}function Rn(e){let t=e?.[_n];return typeof t==`number`&&Number.isFinite(t)?t:0}function zn(e){let t=e?.[vn];return typeof t==`number`&&Number.isFinite(t)&&Math.sign(t)!==-1?t:30}function Bn(){return Math.floor(Date.now()/1e3)}function L(e){if(typeof e!=`object`||!e)throw j(`"as" must be an object`,A);I(e.issuer,`"as.issuer"`)}function R(e){if(typeof e!=`object`||!e)throw j(`"client" must be an object`,A);I(e.client_id,`"client.client_id"`)}function Vn(e){return I(e,`"clientSecret"`),(t,n,r,i)=>{r.set(`client_id`,n.client_id),r.set(`client_secret`,e)}}function Hn(e,t){let n=(a=e)instanceof CryptoKey?{key:a}:a?.key instanceof CryptoKey?(a.kid!==void 0&&I(a.kid,`"kid"`),{key:a.key,kid:a.kid}):{},r=n.key,i=n.kid;var a;return On(r,`"clientPrivateKey.key"`),async(e,n,a,o)=>{var s;let c={alg:Ln(r),kid:i},l=function(e,t){let n=Bn()+Rn(t);return{jti:In(),aud:e.issuer,exp:n+60,iat:n,nbf:n,iss:t.client_id,sub:t.client_id}}(e,n);t==null||(s=t[yn])==null||s.call(t,c,l),a.set(`client_id`,n.client_id),a.set(`client_assertion_type`,`urn:ietf:params:oauth:client-assertion-type:jwt-bearer`),a.set(`client_assertion`,await async function(e,t,n){if(!n.usages.includes(`sign`))throw j(`CryptoKey instances used for signing assertions must include "sign" in their "usages"`,k);let r=`${En(Cn(JSON.stringify(e)))}.${En(Cn(JSON.stringify(t)))}`;return`${r}.${En(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case`ECDSA`:return{name:e.algorithm.name,hash:Fr(e)};case`RSA-PSS`:switch(Pr(e),e.algorithm.hash.name){case`SHA-256`:case`SHA-384`:case`SHA-512`:return{name:e.algorithm.name,saltLength:parseInt(e.algorithm.hash.name.slice(-3),10)>>3};default:throw new P(`unsupported RSA-PSS hash name`,{cause:e})}case`RSASSA-PKCS1-v1_5`:return Pr(e),e.algorithm.name;case`ML-DSA-44`:case`ML-DSA-65`:case`ML-DSA-87`:case`Ed25519`:return e.algorithm.name}throw new P(`unsupported CryptoKey algorithm name`,{cause:e})}(n),n,Cn(r)))}`}(c,l,r))}}var Un=URL.parse?(e,t)=>URL.parse(e,t):(e,t)=>{try{return new URL(e,t)}catch{return null}};function Wn(e,t){if(t&&e.protocol!==`https:`)throw F(`only requests to HTTPS are allowed`,Tr,e);if(e.protocol!==`https:`&&e.protocol!==`http:`)throw F(`only HTTP and HTTPS requests are allowed`,Er,e)}function Gn(e,t,n,r){let i;if(typeof e!=`string`||!(i=Un(e)))throw F(`authorization server metadata does not contain a valid ${n?`"as.mtls_endpoint_aliases.${t}"`:`"as.${t}"`}`,e===void 0?Ar:jr,{attribute:n?`mtls_endpoint_aliases.${t}`:t});return Wn(i,r),i}function Kn(e,t,n,r){return n&&e.mtls_endpoint_aliases&&t in e.mtls_endpoint_aliases?Gn(e.mtls_endpoint_aliases[t],t,n,r):Gn(e[t],t,n,r)}var qn=class extends Error{constructor(e,t){var n;super(e,t),C(this,`cause`,void 0),C(this,`code`,void 0),C(this,`error`,void 0),C(this,`status`,void 0),C(this,`error_description`,void 0),C(this,`response`,void 0),this.name=this.constructor.name,this.code=yr,this.cause=t.cause,this.error=t.cause.error,this.status=t.response.status,this.error_description=t.cause.error_description,Object.defineProperty(this,"response",{enumerable:!1,value:t.response}),(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}},Jn=class extends Error{constructor(e,t){var n;super(e,t),C(this,`cause`,void 0),C(this,`code`,void 0),C(this,`error`,void 0),C(this,`error_description`,void 0),this.name=this.constructor.name,this.code=xr,this.cause=t.cause,this.error=t.cause.get(`error`),this.error_description=t.cause.get(`error_description`)??void 0,(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}},Yn=class extends Error{constructor(e,t){var n;super(e,t),C(this,`cause`,void 0),C(this,`code`,void 0),C(this,`response`,void 0),C(this,`status`,void 0),this.name=this.constructor.name,this.code=vr,this.cause=t.cause,this.status=t.response.status,this.response=t.response,Object.defineProperty(this,"response",{enumerable:!1}),(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}},Xn=RegExp("^[,\\s]*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+)"),Zn=RegExp(`^[,\\s]*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_\`\\|~]+)\\s*=\\s*"((?:[^"\\\\]|\\\\[\\s\\S])*)"[,\\s]*(.*)`),Qn=RegExp("^[,\\s]*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+)\\s*=\\s*([a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+)[,\\s]*(.*)"),$n=RegExp(`^([a-zA-Z0-9\\-\\._\\~\\+\\/]+={0,2})(?:$|[,\\s])(.*)`);async function er(e,t,n){if(e.status!==t){let t;throw function(e){let t;if(t=function(e){if(!gn(e,Response))throw j(`"response" must be an instance of Response`,A);let t=e.headers.get(`www-authenticate`);if(t===null)return;let n=[],r=t;for(;r;){let e=r.match(Xn),t=e?.[1].toLowerCase();if(!t)return;let s=r.substring(e[0].length);if(s&&!s.match(/^[\s,]/))return;let c=s.match(/^\s+(.*)$/),l=!!c;r=c?c[1]:void 0;let u={},d;if(l)for(;r;){let t,n;if(e=r.match(Zn)){var i=T(e,4);if(t=i[1],n=i[2],r=i[3],n.includes(`\\`))try{n=JSON.parse(`"${n}"`)}catch{}u[t.toLowerCase()]=n}else{if(!(e=r.match(Qn))){if(e=r.match($n)){if(Object.keys(u).length)break;var a=T(e,3);d=a[1],r=a[2];break}return}var o=T(e,4);t=o[1],n=o[2],r=o[3],u[t.toLowerCase()]=n}}else r=s||void 0;let f={scheme:t,parameters:u};d&&(f.token68=d),n.push(f)}return n.length?n:void 0}(e))throw new Yn(`server responded with a challenge in the WWW-Authenticate HTTP Header`,{cause:t,response:e})}(e),(t=await async function(e){if(e.status>399&&e.status<500){Nr(e),Fn(e);try{let t=await e.clone().json();if(kn(t)&&typeof t.error==`string`&&t.error.length)return t}catch{}}}(e))?(await e.body?.cancel(),new qn(`server responded with an error in the response body`,{cause:t,response:e})):F(`"response" is not a conform ${n} response (unexpected HTTP status code)`,wr,e)}}function tr(e){if(!dr.has(e))throw j(`"options.DPoP" is not a valid DPoPHandle`,k)}function nr(e){return e.headers.get(`content-type`)?.split(`;`)[0]}async function rr(e,t,n,r,i,a,o){return await n(e,t,i,a),a.set(`content-type`,`application/x-www-form-urlencoded;charset=UTF-8`),(o?.[N]||fetch)(r.href,{body:i,headers:Object.fromEntries(a.entries()),method:`POST`,redirect:`manual`,signal:jn(r,o?.signal)})}async function ir(e,t,n,r,i,a){var o;let s=Kn(e,`token_endpoint`,t.use_mtls_endpoint_aliases,!0!==a?.[M]);i.set(`grant_type`,r);let c=An(a?.headers);c.set(`accept`,`application/json`),a?.DPoP!==void 0&&(tr(a.DPoP),await a.DPoP.addProof(s,c,`POST`));let l=await rr(e,t,n,s,i,c,a);return a==null||(o=a.DPoP)==null||o.cacheNonce(l,s),l}var ar=new WeakMap,or=new WeakMap;function sr(e){if(!e.id_token)return;let t=ar.get(e);if(!t)throw j(`"ref" was already garbage collected or did not resolve from the proper sources`,k);return t}async function cr(e,t,n,r,i,a){if(L(e),R(t),!gn(n,Response))throw j(`"response" must be an instance of Response`,A);await er(n,200,`Token Endpoint`),Nr(n);let o=await Hr(n);if(I(o.access_token,`"response" body "access_token" property`,z,{body:o}),I(o.token_type,`"response" body "token_type" property`,z,{body:o}),o.token_type=o.token_type.toLowerCase(),o.expires_in!==void 0){let e=typeof o.expires_in==`number`?o.expires_in:parseFloat(o.expires_in);Pn(e,!0,`"response" body "expires_in" property`,z,{body:o}),o.expires_in=e}if(o.refresh_token!==void 0&&I(o.refresh_token,`"response" body "refresh_token" property`,z,{body:o}),o.scope!==void 0&&typeof o.scope!=`string`)throw F(`"response" body "scope" property must be a string`,z,{body:o});if(o.id_token!==void 0){I(o.id_token,`"response" body "id_token" property`,z,{body:o});let a=[`aud`,`exp`,`iat`,`iss`,`sub`];!0===t.require_auth_time&&a.push(`auth_time`),t.default_max_age!==void 0&&(Pn(t.default_max_age,!0,`"client.default_max_age"`),a.push(`auth_time`)),r!=null&&r.length&&a.push(...r);let s=await async function(e,t,n,r,i){let a,o,s=e.split(`.`),c=s[0],l=s[1],u=s.length;if(u===5){if(i===void 0)throw new P(`JWE decryption is not configured`,{cause:e});var d=(e=await i(e)).split(`.`);c=d[0],l=d[1],u=d.length}if(u!==3)throw F(`Invalid JWT`,z,e);try{a=JSON.parse(Cn(En(c)))}catch(e){throw F(`failed to parse JWT Header body as base64url encoded JSON`,Sr,e)}if(!kn(a))throw F(`JWT Header must be a top level object`,z,e);if(t(a),a.crit!==void 0)throw new P(`no JWT "crit" header parameter extensions are supported`,{cause:{header:a}});try{o=JSON.parse(Cn(En(l)))}catch(e){throw F(`failed to parse JWT Payload body as base64url encoded JSON`,Sr,e)}if(!kn(o))throw F(`JWT Payload must be a top level object`,z,e);let f=Bn()+n;if(o.exp!==void 0){if(typeof o.exp!=`number`)throw F(`unexpected JWT "exp" (expiration time) claim type`,z,{claims:o});if(o.exp<=f-r)throw F(`unexpected JWT "exp" (expiration time) claim value, expiration is past current timestamp`,Dr,{claims:o,now:f,tolerance:r,claim:`exp`})}if(o.iat!==void 0&&typeof o.iat!=`number`)throw F(`unexpected JWT "iat" (issued at) claim type`,z,{claims:o});if(o.iss!==void 0&&typeof o.iss!=`string`)throw F(`unexpected JWT "iss" (issuer) claim type`,z,{claims:o});if(o.nbf!==void 0){if(typeof o.nbf!=`number`)throw F(`unexpected JWT "nbf" (not before) claim type`,z,{claims:o});if(o.nbf>f+r)throw F(`unexpected JWT "nbf" (not before) claim value`,Dr,{claims:o,now:f,tolerance:r,claim:`nbf`})}if(o.aud!==void 0&&typeof o.aud!=`string`&&!Array.isArray(o.aud))throw F(`unexpected JWT "aud" (audience) claim type`,z,{claims:o});return{header:a,claims:o,jwt:e}}(o.id_token,Lr.bind(void 0,t.id_token_signed_response_alg,e.id_token_signing_alg_values_supported,`RS256`),Rn(t),zn(t),i).then(mr.bind(void 0,a)).then(ur.bind(void 0,e)).then(lr.bind(void 0,t.client_id)),c=s.claims,l=s.jwt;if(Array.isArray(c.aud)&&c.aud.length!==1){if(c.azp===void 0)throw F(`ID Token "aud" (audience) claim includes additional untrusted audiences`,Or,{claims:c,claim:`aud`});if(c.azp!==t.client_id)throw F(`unexpected ID Token "azp" (authorized party) claim value`,Or,{expected:t.client_id,claims:c,claim:`azp`})}c.auth_time!==void 0&&Pn(c.auth_time,!0,`ID Token "auth_time" (authentication time)`,z,{claims:c}),or.set(n,l),ar.set(o,c)}if(a?.[o.token_type]!==void 0)a[o.token_type](n,o);else if(o.token_type!==`dpop`&&o.token_type!==`bearer`)throw new P("unsupported `token_type` value",{cause:{body:o}});return o}function lr(e,t){if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e))throw F(`unexpected JWT "aud" (audience) claim value`,Or,{expected:e,claims:t.claims,claim:`aud`})}else if(t.claims.aud!==e)throw F(`unexpected JWT "aud" (audience) claim value`,Or,{expected:e,claims:t.claims,claim:`aud`});return t}function ur(e,t){let n=e[Wr]?.call(e,t)??e.issuer;if(t.claims.iss!==n)throw F(`unexpected JWT "iss" (issuer) claim value`,Or,{expected:n,claims:t.claims,claim:`iss`});return t}var dr=new WeakSet,fr=Symbol(),pr={aud:`audience`,c_hash:`code hash`,client_id:`client id`,exp:`expiration time`,iat:`issued at`,iss:`issuer`,jti:`jwt id`,nonce:`nonce`,s_hash:`state hash`,sub:`subject`,ath:`access token hash`,htm:`http method`,htu:`http uri`,cnf:`confirmation`,auth_time:`authentication time`};function mr(e,t){for(let n of e)if(t.claims[n]===void 0)throw F(`JWT "${n}" (${pr[n]}) claim missing`,z,{claims:t.claims});return t}var hr=Symbol(),gr=Symbol();async function _r(e,t,n,r){return typeof r?.expectedNonce==`string`||typeof r?.maxAge==`number`||r!=null&&r.requireIdToken?async function(e,t,n,r,i,a,o){let s=[];switch(r){case void 0:r=hr;break;case hr:break;default:I(r,`"expectedNonce" argument`),s.push(`nonce`)}switch(i??=t.default_max_age,i){case void 0:i=gr;break;case gr:break;default:Pn(i,!0,`"maxAge" argument`),s.push(`auth_time`)}let c=await cr(e,t,n,s,a,o);I(c.id_token,`"response" body "id_token" property`,z,{body:c});let l=sr(c);if(i!==gr){let e=Bn()+Rn(t),n=zn(t);if(l.auth_time+i<e-n)throw F(`too much time has elapsed since the last End-User authentication`,Dr,{claims:l,now:e,tolerance:n,claim:`auth_time`})}if(r===hr){if(l.nonce!==void 0)throw F(`unexpected ID Token "nonce" claim value`,Or,{expected:void 0,claims:l,claim:`nonce`})}else if(l.nonce!==r)throw F(`unexpected ID Token "nonce" claim value`,Or,{expected:r,claims:l,claim:`nonce`});return c}(e,t,n,r.expectedNonce,r.maxAge,r[bn],r.recognizedTokenTypes):async function(e,t,n,r,i){let a=await cr(e,t,n,void 0,r,i),o=sr(a);if(o){if(t.default_max_age!==void 0){Pn(t.default_max_age,!0,`"client.default_max_age"`);let e=Bn()+Rn(t),n=zn(t);if(o.auth_time+t.default_max_age<e-n)throw F(`too much time has elapsed since the last End-User authentication`,Dr,{claims:o,now:e,tolerance:n,claim:`auth_time`})}if(o.nonce!==void 0)throw F(`unexpected ID Token "nonce" claim value`,Or,{expected:void 0,claims:o,claim:`nonce`})}return a}(e,t,n,r?.[bn],r?.recognizedTokenTypes)}var vr=`OAUTH_WWW_AUTHENTICATE_CHALLENGE`,yr=`OAUTH_RESPONSE_BODY_ERROR`,br=`OAUTH_UNSUPPORTED_OPERATION`,xr=`OAUTH_AUTHORIZATION_RESPONSE_ERROR`,Sr=`OAUTH_PARSE_ERROR`,z=`OAUTH_INVALID_RESPONSE`,Cr=`OAUTH_RESPONSE_IS_NOT_JSON`,wr=`OAUTH_RESPONSE_IS_NOT_CONFORM`,Tr=`OAUTH_HTTP_REQUEST_FORBIDDEN`,Er=`OAUTH_REQUEST_PROTOCOL_FORBIDDEN`,Dr=`OAUTH_JWT_TIMESTAMP_CHECK_FAILED`,Or=`OAUTH_JWT_CLAIM_COMPARISON_FAILED`,kr=`OAUTH_JSON_ATTRIBUTE_COMPARISON_FAILED`,Ar=`OAUTH_MISSING_SERVER_METADATA`,jr=`OAUTH_INVALID_SERVER_METADATA`;async function Mr(e){if(!gn(e,Response))throw j(`"response" must be an instance of Response`,A);await er(e,200,`Revocation Endpoint`)}function Nr(e){if(e.bodyUsed)throw j(`"response" body has been used already`,k)}function Pr(e){let t=e.algorithm;if(typeof t.modulusLength!=`number`||t.modulusLength<2048)throw new P(`unsupported ${t.name} modulusLength`,{cause:e})}function Fr(e){switch(e.algorithm.namedCurve){case`P-256`:return`SHA-256`;case`P-384`:return`SHA-384`;case`P-521`:return`SHA-512`;default:throw new P(`unsupported ECDSA namedCurve`,{cause:e})}}async function Ir(e){if(e.method!==`POST`)throw j(`form_post responses are expected to use the POST method`,k,{cause:e});if(nr(e)!==`application/x-www-form-urlencoded`)throw j(`form_post responses are expected to use the application/x-www-form-urlencoded content-type`,k,{cause:e});return async function(e){if(e.bodyUsed)throw j(`form_post Request instances must contain a readable body`,k,{cause:e});return e.text()}(e)}function Lr(e,t,n,r){if(e===void 0){if(Array.isArray(t)){if(!t.includes(r.alg))throw F(`unexpected JWT "alg" header parameter`,z,{header:r,expected:t,reason:`authorization server metadata`})}else{if(n===void 0)throw F(`missing client or server configuration to verify used JWT "alg" header parameter`,void 0,{client:e,issuer:t,fallback:n});if(typeof n==`string`?r.alg!==n:typeof n==`function`?!n(r.alg):!n.includes(r.alg))throw F(`unexpected JWT "alg" header parameter`,z,{header:r,expected:n,reason:`default value`})}}else if(typeof e==`string`?r.alg!==e:!e.includes(r.alg))throw F(`unexpected JWT "alg" header parameter`,z,{header:r,expected:e,reason:`client configuration`})}function Rr(e,t){let n=e.getAll(t),r=n[0];if(n.length>1)throw F(`"${t}" parameter must be provided only once`,z);return r}var zr=Symbol(),Br=Symbol();function Vr(e,t,n,r){if(L(e),R(t),n instanceof URL&&(n=n.searchParams),!(n instanceof URLSearchParams))throw j(`"parameters" must be an instance of URLSearchParams, or URL`,A);if(Rr(n,`response`))throw F(`"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()`,z,{parameters:n});let i=Rr(n,`iss`),a=Rr(n,`state`);if(!i&&e.authorization_response_iss_parameter_supported)throw F(`response parameter "iss" (issuer) missing`,z,{parameters:n});if(i&&i!==e.issuer)throw F(`unexpected "iss" (issuer) response parameter value`,z,{expected:e.issuer,parameters:n});switch(r){case void 0:case Br:if(a!==void 0)throw F(`unexpected "state" response parameter encountered`,z,{expected:void 0,parameters:n});break;case zr:break;default:if(I(r,`"expectedState" argument`),a!==r)throw F(a===void 0?`response parameter "state" missing`:`unexpected "state" response parameter value`,z,{expected:r,parameters:n})}if(Rr(n,`error`))throw new Jn(`authorization response from the server is an error`,{cause:n});let o=Rr(n,`id_token`),s=Rr(n,`token`);if(o!==void 0||s!==void 0)throw new P(`implicit and hybrid flows are not supported`);return c=new URLSearchParams(n),dr.add(c),c;var c}async function Hr(e){let t,n=arguments.length>1&&arguments[1]!==void 0?arguments[1]:Fn;try{t=await e.json()}catch(t){throw n(e),F(`failed to parse "response" body as JSON`,Sr,t)}if(!kn(t))throw F(`"response" body must be a top level object`,z,{body:t});return t}var Ur=Symbol(),Wr=Symbol(),Gr=new TextEncoder,Kr=new TextDecoder;function qr(){var e=[...arguments];let t=e.reduce((e,t)=>e+t.length,0),n=new Uint8Array(t),r=0;for(let t of e)n.set(t,r),r+=t.length;return n}function Jr(e){let t=new Uint8Array(e.length);for(let n=0;n<e.length;n++){let r=e.charCodeAt(n);if(r>127)throw TypeError(`non-ASCII string encountered in encode()`);t[n]=r}return t}function Yr(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);let t=atob(e),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}function Xr(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(typeof e==`string`?e:Kr.decode(e),{alphabet:`base64url`});let t=e;t instanceof Uint8Array&&(t=Kr.decode(t)),t=t.replace(/-/g,`+`).replace(/_/g,`/`);try{return Yr(t)}catch{throw TypeError(`The input to be decoded is not correctly encoded.`)}}function Zr(e){let t=e;return typeof t==`string`&&(t=Gr.encode(t)),Uint8Array.prototype.toBase64?t.toBase64({alphabet:`base64url`,omitPadding:!0}):function(e){if(Uint8Array.prototype.toBase64)return e.toBase64();let t=[];for(let n=0;n<e.length;n+=32768)t.push(String.fromCharCode.apply(null,e.subarray(n,n+32768)));return btoa(t.join(``))}(t).replace(/=/g,``).replace(/\+/g,`-`).replace(/\//g,`_`)}var Qr=function(e){return TypeError(`CryptoKey does not support this operation, its ${arguments.length>1&&arguments[1]!==void 0?arguments[1]:`algorithm.name`} must be ${e}`)},$r=(e,t)=>e.name===t;function ei(e,t){var n;if(n=e.hash,parseInt(n.name.slice(4),10)!==t)throw Qr(`SHA-${t}`,`algorithm.hash`)}function ti(e,t,n){switch(t){case`HS256`:case`HS384`:case`HS512`:if(!$r(e.algorithm,`HMAC`))throw Qr(`HMAC`);ei(e.algorithm,parseInt(t.slice(2),10));break;case`RS256`:case`RS384`:case`RS512`:if(!$r(e.algorithm,`RSASSA-PKCS1-v1_5`))throw Qr(`RSASSA-PKCS1-v1_5`);ei(e.algorithm,parseInt(t.slice(2),10));break;case`PS256`:case`PS384`:case`PS512`:if(!$r(e.algorithm,`RSA-PSS`))throw Qr(`RSA-PSS`);ei(e.algorithm,parseInt(t.slice(2),10));break;case`Ed25519`:case`EdDSA`:if(!$r(e.algorithm,`Ed25519`))throw Qr(`Ed25519`);break;case`ML-DSA-44`:case`ML-DSA-65`:case`ML-DSA-87`:if(!$r(e.algorithm,t))throw Qr(t);break;case`ES256`:case`ES384`:case`ES512`:{if(!$r(e.algorithm,`ECDSA`))throw Qr(`ECDSA`);let n=function(e){switch(e){case`ES256`:return`P-256`;case`ES384`:return`P-384`;case`ES512`:return`P-521`;default:throw Error(`unreachable`)}}(t);if(e.algorithm.namedCurve!==n)throw Qr(n,`algorithm.namedCurve`);break}default:throw TypeError(`CryptoKey does not support this operation`)}(function(e,t){if(t&&!e.usages.includes(t))throw TypeError(`CryptoKey does not support this operation, its usages must include ${t}.`)})(e,n)}function ni(e,t){var n=[...arguments].slice(2);if((n=n.filter(Boolean)).length>2){let t=n.pop();e+=`one of type ${n.join(`, `)}, or ${t}.`}else n.length===2?e+=`one of type ${n[0]} or ${n[1]}.`:e+=`of type ${n[0]}.`;if(t==null)e+=` Received ${t}`;else if(typeof t==`function`&&t.name)e+=` Received function ${t.name}`;else if(typeof t==`object`&&t){var r;(r=t.constructor)!=null&&r.name&&(e+=` Received an instance of ${t.constructor.name}`)}return e}var ri=function(e,t){var n=[...arguments].slice(2);return ni(`Key for the ${e} algorithm must be `,t,...n)},B=class extends Error{constructor(e,t){var n;super(e,t),C(this,`code`,`ERR_JOSE_GENERIC`),this.name=this.constructor.name,(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}};C(B,`code`,`ERR_JOSE_GENERIC`);var ii=class extends B{constructor(e,t){let n=arguments.length>2&&arguments[2]!==void 0?arguments[2]:`unspecified`,r=arguments.length>3&&arguments[3]!==void 0?arguments[3]:`unspecified`;super(e,{cause:{claim:n,reason:r,payload:t}}),C(this,`code`,`ERR_JWT_CLAIM_VALIDATION_FAILED`),C(this,`claim`,void 0),C(this,`reason`,void 0),C(this,`payload`,void 0),this.claim=n,this.reason=r,this.payload=t}};C(ii,`code`,`ERR_JWT_CLAIM_VALIDATION_FAILED`);var ai=class extends B{constructor(e,t){let n=arguments.length>2&&arguments[2]!==void 0?arguments[2]:`unspecified`,r=arguments.length>3&&arguments[3]!==void 0?arguments[3]:`unspecified`;super(e,{cause:{claim:n,reason:r,payload:t}}),C(this,`code`,`ERR_JWT_EXPIRED`),C(this,`claim`,void 0),C(this,`reason`,void 0),C(this,`payload`,void 0),this.claim=n,this.reason=r,this.payload=t}};C(ai,`code`,`ERR_JWT_EXPIRED`);var oi=class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JOSE_ALG_NOT_ALLOWED`)}};C(oi,`code`,`ERR_JOSE_ALG_NOT_ALLOWED`);var V=class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JOSE_NOT_SUPPORTED`)}};C(V,`code`,`ERR_JOSE_NOT_SUPPORTED`),C(class extends B{constructor(){super(arguments.length>0&&arguments[0]!==void 0?arguments[0]:`decryption operation failed`,arguments.length>1?arguments[1]:void 0),C(this,`code`,`ERR_JWE_DECRYPTION_FAILED`)}},`code`,`ERR_JWE_DECRYPTION_FAILED`),C(class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JWE_INVALID`)}},`code`,`ERR_JWE_INVALID`);var H=class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JWS_INVALID`)}};C(H,`code`,`ERR_JWS_INVALID`);var si=class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JWT_INVALID`)}};C(si,`code`,`ERR_JWT_INVALID`),C(class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JWK_INVALID`)}},`code`,`ERR_JWK_INVALID`);var ci=class extends B{constructor(){super(...arguments),C(this,`code`,`ERR_JWKS_INVALID`)}};C(ci,`code`,`ERR_JWKS_INVALID`);var li=class extends B{constructor(){super(arguments.length>0&&arguments[0]!==void 0?arguments[0]:`no applicable key found in the JSON Web Key Set`,arguments.length>1?arguments[1]:void 0),C(this,`code`,`ERR_JWKS_NO_MATCHING_KEY`)}};C(li,`code`,`ERR_JWKS_NO_MATCHING_KEY`);var ui=class extends B{constructor(){super(arguments.length>0&&arguments[0]!==void 0?arguments[0]:`multiple matching keys found in the JSON Web Key Set`,arguments.length>1?arguments[1]:void 0),C(this,Symbol.asyncIterator,void 0),C(this,`code`,`ERR_JWKS_MULTIPLE_MATCHING_KEYS`)}};C(ui,`code`,`ERR_JWKS_MULTIPLE_MATCHING_KEYS`);var di=class extends B{constructor(){super(arguments.length>0&&arguments[0]!==void 0?arguments[0]:`request timed out`,arguments.length>1?arguments[1]:void 0),C(this,`code`,`ERR_JWKS_TIMEOUT`)}};C(di,`code`,`ERR_JWKS_TIMEOUT`);var fi=class extends B{constructor(){super(arguments.length>0&&arguments[0]!==void 0?arguments[0]:`signature verification failed`,arguments.length>1?arguments[1]:void 0),C(this,`code`,`ERR_JWS_SIGNATURE_VERIFICATION_FAILED`)}};C(fi,`code`,`ERR_JWS_SIGNATURE_VERIFICATION_FAILED`);var pi=e=>{if(e?.[Symbol.toStringTag]===`CryptoKey`)return!0;try{return e instanceof CryptoKey}catch{return!1}},mi=e=>e?.[Symbol.toStringTag]===`KeyObject`,hi=e=>pi(e)||mi(e);function gi(e,t){if(e)throw TypeError(`${t} can only be called once`)}function _i(e,t,n){try{return Xr(e)}catch{throw new n(`Failed to base64url decode the ${t}`)}}function vi(e){if(typeof(t=e)!=`object`||t===null||Object.prototype.toString.call(e)!==`[object Object]`)return!1;var t;if(Object.getPrototypeOf(e)===null)return!0;let n=e;for(;Object.getPrototypeOf(n)!==null;)n=Object.getPrototypeOf(n);return Object.getPrototypeOf(e)===n}function yi(){let e=[...arguments].filter(Boolean);if(e.length===0||e.length===1)return!0;let t;for(let n of e){let e=Object.keys(n);if(t&&t.size!==0)for(let n of e){if(t.has(n))return!1;t.add(n)}else t=new Set(e)}return!0}var bi=e=>vi(e)&&typeof e.kty==`string`;function xi(e,t){if(e.startsWith(`RS`)||e.startsWith(`PS`)){let n=t.algorithm.modulusLength;if(typeof n!=`number`||n<2048)throw TypeError(`${e} requires key modulusLength to be 2048 bits or larger`)}}function Si(e,t){let n=`SHA-${e.slice(-3)}`;switch(e){case`HS256`:case`HS384`:case`HS512`:return{hash:n,name:`HMAC`};case`PS256`:case`PS384`:case`PS512`:return{hash:n,name:`RSA-PSS`,saltLength:parseInt(e.slice(-3),10)>>3};case`RS256`:case`RS384`:case`RS512`:return{hash:n,name:`RSASSA-PKCS1-v1_5`};case`ES256`:case`ES384`:case`ES512`:return{hash:n,name:`ECDSA`,namedCurve:t.namedCurve};case`Ed25519`:case`EdDSA`:return{name:`Ed25519`};case`ML-DSA-44`:case`ML-DSA-65`:case`ML-DSA-87`:return{name:e};default:throw new V(`alg ${e} is not supported either by JOSE or your javascript runtime`)}}async function Ci(e,t,n){if(t instanceof Uint8Array){if(!e.startsWith(`HS`))throw TypeError(function(e){return ni(`Key must be `,e,...[...arguments].slice(1))}(t,`CryptoKey`,`KeyObject`,`JSON Web Key`));return crypto.subtle.importKey(`raw`,t,{hash:`SHA-${e.slice(-3)}`,name:`HMAC`},!1,[n])}return ti(t,e,n),t}var wi=`Invalid or unsupported JWK "alg" (Algorithm) Parameter value`;async function Ti(e){if(!e.alg)throw TypeError(`"alg" argument is required when "jwk.alg" is not present`);let t=function(e){let t,n;switch(e.kty){case`AKP`:switch(e.alg){case`ML-DSA-44`:case`ML-DSA-65`:case`ML-DSA-87`:t={name:e.alg},n=e.priv?[`sign`]:[`verify`];break;default:throw new V(wi)}break;case`RSA`:switch(e.alg){case`PS256`:case`PS384`:case`PS512`:t={name:`RSA-PSS`,hash:`SHA-${e.alg.slice(-3)}`},n=e.d?[`sign`]:[`verify`];break;case`RS256`:case`RS384`:case`RS512`:t={name:`RSASSA-PKCS1-v1_5`,hash:`SHA-${e.alg.slice(-3)}`},n=e.d?[`sign`]:[`verify`];break;case`RSA-OAEP`:case`RSA-OAEP-256`:case`RSA-OAEP-384`:case`RSA-OAEP-512`:t={name:`RSA-OAEP`,hash:`SHA-${parseInt(e.alg.slice(-3),10)||1}`},n=e.d?[`decrypt`,`unwrapKey`]:[`encrypt`,`wrapKey`];break;default:throw new V(wi)}break;case`EC`:switch(e.alg){case`ES256`:case`ES384`:case`ES512`:t={name:`ECDSA`,namedCurve:{ES256:`P-256`,ES384:`P-384`,ES512:`P-521`}[e.alg]},n=e.d?[`sign`]:[`verify`];break;case`ECDH-ES`:case`ECDH-ES+A128KW`:case`ECDH-ES+A192KW`:case`ECDH-ES+A256KW`:t={name:`ECDH`,namedCurve:e.crv},n=e.d?[`deriveBits`]:[];break;default:throw new V(wi)}break;case`OKP`:switch(e.alg){case`Ed25519`:case`EdDSA`:t={name:`Ed25519`},n=e.d?[`sign`]:[`verify`];break;case`ECDH-ES`:case`ECDH-ES+A128KW`:case`ECDH-ES+A192KW`:case`ECDH-ES+A256KW`:t={name:e.crv},n=e.d?[`deriveBits`]:[];break;default:throw new V(wi)}break;default:throw new V(`Invalid or unsupported JWK "kty" (Key Type) Parameter value`)}return{algorithm:t,keyUsages:n}}(e),n=t.algorithm,r=t.keyUsages,i=w({},e);return i.kty!==`AKP`&&delete i.alg,delete i.use,crypto.subtle.importKey(`jwk`,i,n,e.ext??(!e.d&&!e.priv),e.key_ops??r)}var Ei=`given KeyObject instance cannot be used for this algorithm`,Di,Oi=async function(e,t,n){let r=arguments.length>3&&arguments[3]!==void 0&&arguments[3];Di||=new WeakMap;let i=Di.get(e);if(i!=null&&i[n])return i[n];let a=await Ti(w(w({},t),{},{alg:n}));return r&&Object.freeze(e),i?i[n]=a:Di.set(e,{[n]:a}),a};async function ki(e,t){if(e instanceof Uint8Array||pi(e))return e;if(mi(e)){if(e.type===`secret`)return e.export();if(`toCryptoKey`in e&&typeof e.toCryptoKey==`function`)try{return((e,t)=>{Di||=new WeakMap;let n=Di.get(e);if(n!=null&&n[t])return n[t];let r=e.type===`public`,i=!!r,a;if(e.asymmetricKeyType===`x25519`){switch(t){case`ECDH-ES`:case`ECDH-ES+A128KW`:case`ECDH-ES+A192KW`:case`ECDH-ES+A256KW`:break;default:throw TypeError(Ei)}a=e.toCryptoKey(e.asymmetricKeyType,i,r?[]:[`deriveBits`])}if(e.asymmetricKeyType===`ed25519`){if(t!==`EdDSA`&&t!==`Ed25519`)throw TypeError(Ei);a=e.toCryptoKey(e.asymmetricKeyType,i,[r?`verify`:`sign`])}switch(e.asymmetricKeyType){case`ml-dsa-44`:case`ml-dsa-65`:case`ml-dsa-87`:if(t!==e.asymmetricKeyType.toUpperCase())throw TypeError(Ei);a=e.toCryptoKey(e.asymmetricKeyType,i,[r?`verify`:`sign`])}if(e.asymmetricKeyType===`rsa`){let n;switch(t){case`RSA-OAEP`:n=`SHA-1`;break;case`RS256`:case`PS256`:case`RSA-OAEP-256`:n=`SHA-256`;break;case`RS384`:case`PS384`:case`RSA-OAEP-384`:n=`SHA-384`;break;case`RS512`:case`PS512`:case`RSA-OAEP-512`:n=`SHA-512`;break;default:throw TypeError(Ei)}if(t.startsWith(`RSA-OAEP`))return e.toCryptoKey({name:`RSA-OAEP`,hash:n},i,r?[`encrypt`]:[`decrypt`]);a=e.toCryptoKey({name:t.startsWith(`PS`)?`RSA-PSS`:`RSASSA-PKCS1-v1_5`,hash:n},i,[r?`verify`:`sign`])}if(e.asymmetricKeyType===`ec`){let n=new Map([[`prime256v1`,`P-256`],[`secp384r1`,`P-384`],[`secp521r1`,`P-521`]]).get(e.asymmetricKeyDetails?.namedCurve);if(!n)throw TypeError(Ei);let o={ES256:`P-256`,ES384:`P-384`,ES512:`P-521`};o[t]&&n===o[t]&&(a=e.toCryptoKey({name:`ECDSA`,namedCurve:n},i,[r?`verify`:`sign`])),t.startsWith(`ECDH-ES`)&&(a=e.toCryptoKey({name:`ECDH`,namedCurve:n},i,r?[]:[`deriveBits`]))}if(!a)throw TypeError(Ei);return n?n[t]=a:Di.set(e,{[t]:a}),a})(e,t)}catch(e){if(e instanceof TypeError)throw e}return Oi(e,e.export({format:`jwk`}),t)}if(bi(e))return e.k?Xr(e.k):Oi(e,e,t,!0);throw Error(`unreachable`)}var Ai=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let n=0;n<e.byteLength;n++)if(e[n]!==t[n])return!1;return!0},ji=e=>{let t=e.data[e.pos++];if(128&t){let n=127&t,r=0;for(let t=0;t<n;t++)r=r<<8|e.data[e.pos++];return r}return t},Mi=(e,t,n)=>{if(e.data[e.pos++]!==t)throw Error(n)},Ni=(e,t)=>{let n=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,n},Pi=e=>{let t=(e=>(Mi(e,6,`Expected algorithm OID`),Ni(e,ji(e))))(e);if(Ai(t,[43,101,110]))return`X25519`;if(!Ai(t,[42,134,72,206,61,2,1]))throw Error(`Unsupported key algorithm`);Mi(e,6,`Expected curve OID`);let n=Ni(e,ji(e));for(let e of[{name:`P-256`,oid:[42,134,72,206,61,3,1,7]},{name:`P-384`,oid:[43,129,4,0,34]},{name:`P-521`,oid:[43,129,4,0,35]}]){let t=e.name,r=e.oid;if(Ai(n,r))return t}throw Error(`Unsupported named curve`)},Fi=async(e,t,n,r)=>{let i,a,o=e===`spki`,s=()=>o?[`verify`]:[`sign`];switch(n){case`PS256`:case`PS384`:case`PS512`:i={name:`RSA-PSS`,hash:`SHA-${n.slice(-3)}`},a=s();break;case`RS256`:case`RS384`:case`RS512`:i={name:`RSASSA-PKCS1-v1_5`,hash:`SHA-${n.slice(-3)}`},a=s();break;case`RSA-OAEP`:case`RSA-OAEP-256`:case`RSA-OAEP-384`:case`RSA-OAEP-512`:i={name:`RSA-OAEP`,hash:`SHA-${parseInt(n.slice(-3),10)||1}`},a=o?[`encrypt`,`wrapKey`]:[`decrypt`,`unwrapKey`];break;case`ES256`:case`ES384`:case`ES512`:i={name:`ECDSA`,namedCurve:{ES256:`P-256`,ES384:`P-384`,ES512:`P-521`}[n]},a=s();break;case`ECDH-ES`:case`ECDH-ES+A128KW`:case`ECDH-ES+A192KW`:case`ECDH-ES+A256KW`:try{let e=r.getNamedCurve(t);i=e===`X25519`?{name:`X25519`}:{name:`ECDH`,namedCurve:e}}catch{throw new V(`Invalid or unsupported key format`)}a=o?[]:[`deriveBits`];break;case`Ed25519`:case`EdDSA`:i={name:`Ed25519`},a=s();break;case`ML-DSA-44`:case`ML-DSA-65`:case`ML-DSA-87`:i={name:n},a=s();break;default:throw new V(`Invalid or unsupported "alg" (Algorithm) value`)}return crypto.subtle.importKey(e,t,i,r?.extractable??!!o,a)},Ii=(e,t,n)=>{var r;let i=((e,t)=>Yr(e.replace(t,``)))(e,/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g),a=n;return t!=null&&(r=t.startsWith)!=null&&r.call(t,`ECDH-ES`)&&(a||={},a.getNamedCurve=e=>{let t={data:e,pos:0};return function(e){Mi(e,48,`Invalid PKCS#8 structure`),ji(e),Mi(e,2,`Expected version field`);let t=ji(e);e.pos+=t,Mi(e,48,`Expected algorithm identifier`),ji(e),e.pos}(t),Pi(t)}),Fi(`pkcs8`,i,t,a)};async function Li(e,t,n){if(typeof e!=`string`||e.indexOf(`-----BEGIN PRIVATE KEY-----`)!==0)throw TypeError(`"pkcs8" must be PKCS#8 formatted string`);return Ii(e,t,n)}function Ri(e,t,n,r,i){if(i.crit!==void 0&&r?.crit===void 0)throw new e(`"crit" (Critical) Header Parameter MUST be integrity protected`);if(!r||r.crit===void 0)return new Set;if(!Array.isArray(r.crit)||r.crit.length===0||r.crit.some(e=>typeof e!=`string`||e.length===0))throw new e(`"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present`);let a;a=n===void 0?t:new Map([...Object.entries(n),...t.entries()]);for(let t of r.crit){if(!a.has(t))throw new V(`Extension Header Parameter "${t}" is not recognized`);if(i[t]===void 0)throw new e(`Extension Header Parameter "${t}" is missing`);if(a.get(t)&&r[t]===void 0)throw new e(`Extension Header Parameter "${t}" MUST be integrity protected`)}return new Set(r.crit)}var zi=e=>e?.[Symbol.toStringTag],Bi=(e,t,n)=>{if(t.use!==void 0){let e;switch(n){case`sign`:case`verify`:e=`sig`;break;case`encrypt`:case`decrypt`:e=`enc`}if(t.use!==e)throw TypeError(`Invalid key for this operation, its "use" must be "${e}" when present`)}if(t.alg!==void 0&&t.alg!==e)throw TypeError(`Invalid key for this operation, its "alg" must be "${e}" when present`);if(Array.isArray(t.key_ops)){var r,i;let a;switch(!0){case n===`sign`||n===`verify`:case e===`dir`:case e.includes(`CBC-HS`):a=n;break;case e.startsWith(`PBES2`):a=`deriveBits`;break;case/^A\d{3}(?:GCM)?(?:KW)?$/.test(e):a=!e.includes(`GCM`)&&e.endsWith(`KW`)?n===`encrypt`?`wrapKey`:`unwrapKey`:n;break;case n===`encrypt`&&e.startsWith(`RSA`):a=`wrapKey`;break;case n===`decrypt`:a=e.startsWith(`RSA`)?`unwrapKey`:`deriveBits`}if(a&&!1===((r=t.key_ops)==null||(i=r.includes)==null?void 0:i.call(r,a)))throw TypeError(`Invalid key for this operation, its "key_ops" must include "${a}" when present`)}return!0};function Vi(e,t,n){switch(e.substring(0,2)){case`A1`:case`A2`:case`di`:case`HS`:case`PB`:((e,t,n)=>{if(!(t instanceof Uint8Array)){if(bi(t)){if((e=>e.kty===`oct`&&typeof e.k==`string`)(t)&&Bi(e,t,n))return;throw TypeError(`JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present`)}if(!hi(t))throw TypeError(ri(e,t,`CryptoKey`,`KeyObject`,`JSON Web Key`,`Uint8Array`));if(t.type!==`secret`)throw TypeError(`${zi(t)} instances for symmetric algorithms must be of type "secret"`)}})(e,t,n);break;default:((e,t,n)=>{if(bi(t))switch(n){case`decrypt`:case`sign`:if((e=>e.kty!==`oct`&&(e.kty===`AKP`&&typeof e.priv==`string`||typeof e.d==`string`))(t)&&Bi(e,t,n))return;throw TypeError(`JSON Web Key for this operation must be a private JWK`);case`encrypt`:case`verify`:if((e=>e.kty!==`oct`&&e.d===void 0&&e.priv===void 0)(t)&&Bi(e,t,n))return;throw TypeError(`JSON Web Key for this operation must be a public JWK`)}if(!hi(t))throw TypeError(ri(e,t,`CryptoKey`,`KeyObject`,`JSON Web Key`));if(t.type===`secret`)throw TypeError(`${zi(t)} instances for asymmetric algorithms must not be of type "secret"`);if(t.type===`public`)switch(n){case`sign`:throw TypeError(`${zi(t)} instances for asymmetric algorithm signing must be of type "private"`);case`decrypt`:throw TypeError(`${zi(t)} instances for asymmetric algorithm decryption must be of type "private"`)}if(t.type===`private`)switch(n){case`verify`:throw TypeError(`${zi(t)} instances for asymmetric algorithm verifying must be of type "public"`);case`encrypt`:throw TypeError(`${zi(t)} instances for asymmetric algorithm encryption must be of type "public"`)}})(e,t,n)}}var Hi,Ui,Wi,Gi;(typeof navigator>`u`||(Hi=navigator.userAgent)==null||(Ui=Hi.startsWith)==null||!Ui.call(Hi,`Mozilla/5.0 `))&&(Gi=`openid-client/v6.8.4`,Wi={"user-agent":Gi});var U=e=>Ki.get(e),Ki,qi;function Ji(e){return e===void 0?(qi||=new WeakMap,(e,t,n,r)=>{let i;return(i=qi.get(t))||(function(e,t){if(typeof e!=`string`)throw Qi(`${t} must be a string`,Zi);if(e.length===0)throw Qi(`${t} must not be empty`,Xi)}(t.client_secret,`"metadata.client_secret"`),i=Vn(t.client_secret),qi.set(t,i)),i(e,t,n,r)}):Vn(e)}var Yi=N,Xi=`ERR_INVALID_ARG_VALUE`,Zi=`ERR_INVALID_ARG_TYPE`;function Qi(e,t,n){let r=TypeError(e,{cause:n});return Object.assign(r,{code:t}),r}function $i(e){return async function(e){return I(e,`codeVerifier`),En(await crypto.subtle.digest(`SHA-256`,Cn(e)))}(e)}function ea(){return In()}var ta=class extends Error{constructor(e,t){var n;super(e,t),C(this,`code`,void 0),this.name=this.constructor.name,this.code=t?.code,(n=Error.captureStackTrace)==null||n.call(Error,this,this.constructor)}};function W(e,t,n){return new ta(e,{cause:t,code:n})}function G(e){if(e instanceof TypeError||e instanceof ta||e instanceof qn||e instanceof Jn||e instanceof Yn)throw e;if(e instanceof Dn)switch(e.code){case Tr:throw W(`only requests to HTTPS are allowed`,e,e.code);case Er:throw W(`only requests to HTTP or HTTPS are allowed`,e,e.code);case wr:throw W(`unexpected HTTP response status code`,e.cause,e.code);case Cr:throw W(`unexpected response content-type`,e.cause,e.code);case Sr:throw W(`parsing error occured`,e,e.code);case z:throw W(`invalid response encountered`,e,e.code);case Or:throw W(`unexpected JWT claim value encountered`,e,e.code);case kr:throw W(`unexpected JSON attribute value encountered`,e,e.code);case Dr:throw W(`JWT timestamp claim value failed validation`,e,e.code);default:throw W(e.message,e,e.code)}if(e instanceof P)throw W(`unsupported operation`,e,e.code);if(e instanceof DOMException)switch(e.name){case`OperationError`:throw W(`runtime operation error`,e,br);case`NotSupportedError`:throw W(`runtime unsupported operation`,e,br);case`TimeoutError`:throw W(`operation timed out`,e,`OAUTH_TIMEOUT`);case`AbortError`:throw W(`operation aborted`,e,`OAUTH_ABORT`)}throw new ta(`something went wrong`,{cause:e})}async function na(e,t,n,r,i){let a=new ia(await async function(e,t){var n;if(!(e instanceof URL))throw Qi(`"server" must be an instance of URL`,Zi);let r=!e.href.includes(`/.well-known/`),i=t?.timeout??30,a=AbortSignal.timeout(1e3*i),o=await(r?Nn(e,{algorithm:t?.algorithm,[N]:t?.[Yi],[M]:t==null||(n=t.execute)==null?void 0:n.includes(ua),signal:a,headers:new Headers(Wi)}):(t?.[Yi]||fetch)((Wn(e,t==null||(s=t.execute)==null||!s.includes(ua)),e.href),{headers:Object.fromEntries(new Headers(w({accept:`application/json`},Wi)).entries()),body:void 0,method:`GET`,redirect:`manual`,signal:a})).then(e=>async function(e,t){let n=e;if(!(n instanceof URL)&&n!==Ur)throw j(`"expectedIssuerIdentifier" must be an instance of URL`,A);if(!gn(t,Response))throw j(`"response" must be an instance of Response`,A);if(t.status!==200)throw F(`"response" is not a conform Authorization Server Metadata response (unexpected HTTP status code)`,wr,t);Nr(t);let r=await Hr(t);if(I(r.issuer,`"response" body "issuer" property`,z,{body:r}),n!==Ur&&new URL(r.issuer).href!==n.href)throw F(`"response" body "issuer" property does not match the expected value`,kr,{expected:n.href,body:r,attribute:`issuer`});return r}(Ur,e)).catch(G);var s;return r&&new URL(o.issuer).href!==e.href&&(function(e,t,n){return!(e.origin!==`https://login.microsoftonline.com`||n!=null&&n.algorithm&&n.algorithm!==`oidc`||(t[ra]=!0,0))}(e,o,t)||function(e,t){return!(!e.hostname.endsWith(`.b2clogin.com`)||t!=null&&t.algorithm&&t.algorithm!==`oidc`)}(e,t)||(()=>{throw new ta(`discovered metadata issuer does not match the expected issuer`,{code:kr,cause:{expected:e.href,body:o,attribute:`issuer`}})})()),o}(e,i),t,n,r),o=U(a);if(i!=null&&i[Yi]&&(o.fetch=i[Yi]),i!=null&&i.timeout&&(o.timeout=i.timeout),i!=null&&i.execute)for(let e of i.execute)e(a);return a}new TextDecoder;var ra=Symbol(),ia=class{constructor(e,t,n,r){if(typeof t!=`string`||!t.length)throw Qi(`"clientId" must be a non-empty string`,Zi);if(typeof n==`string`&&(n={client_secret:n}),n?.client_id!==void 0&&t!==n.client_id)throw Qi(`"clientId" and "metadata.client_id" must be the same`,Xi);let i=w(w({},structuredClone(n)),{},{client_id:t}),a;i[_n]=n?.[_n]??0,i[vn]=n?.[vn]??30,a=r||(typeof i.client_secret==`string`&&i.client_secret.length?Ji(i.client_secret):(e,t,n,r)=>{n.set(`client_id`,t.client_id)});let o=Object.freeze(i),s=structuredClone(e);ra in e&&(s[Wr]=t=>{let n=t.claims.tid;return e.issuer.replace(`{tenantid}`,n)});let c=Object.freeze(s);Ki||=new WeakMap,Ki.set(this,{__proto__:null,as:c,c:o,auth:a,tlsOnly:!0,jwksCache:{}})}serverMetadata(){let e=structuredClone(U(this).as);return function(e){Object.defineProperties(e,function(e){return{supportsPKCE:{__proto__:null,value(){let t=arguments.length>0&&arguments[0]!==void 0?arguments[0]:`S256`;return!0===e.code_challenge_methods_supported?.includes(t)}}}}(e))}(e),e}clientMetadata(){return structuredClone(U(this).c)}get timeout(){return U(this).timeout}set timeout(e){U(this).timeout=e}get[Yi](){return U(this).fetch}set[Yi](e){U(this).fetch=e}};function aa(e){Object.defineProperties(e,function(e){let t;if(e.expires_in!==void 0){let n=new Date;n.setSeconds(n.getSeconds()+e.expires_in),t=n.getTime()}return{expiresIn:{__proto__:null,value(){if(t){let e=Date.now();return t>e?Math.floor((t-e)/1e3):0}}},claims:{__proto__:null,value(){try{return sr(this)}catch{return}}}}}(e))}async function oa(e,t,n){let r=arguments.length>3&&arguments[3]!==void 0&&arguments[3],i=e.headers.get(`retry-after`)?.trim();if(i===void 0)return;let a;if(/^\d+$/.test(i))a=parseInt(i,10);else{let e=new Date(i);if(Number.isFinite(e.getTime())){let t=new Date,n=e.getTime()-t.getTime();n>0&&(a=Math.ceil(n/1e3))}}if(r&&!Number.isFinite(a))throw new Dn(`invalid Retry-After header value`,{cause:e});a>t&&await sa(a-t,n)}function sa(e,t){return new Promise((n,r)=>{let i=e=>{try{t.throwIfAborted()}catch(e){r(e);return}if(e<=0)return void n();let a=Math.min(e,5);setTimeout(()=>i(e-a),1e3*a)};i(e)})}async function ca(e,t){ga(e);let n=U(e),r=n.as,i=n.c,a=n.auth,o=n.fetch,s=n.tlsOnly,c=n.timeout;return async function(e,t,n,r,i){L(e),R(t);let a=Kn(e,`backchannel_authentication_endpoint`,t.use_mtls_endpoint_aliases,!0!==i?.[M]),o=new URLSearchParams(r);o.set(`client_id`,t.client_id);let s=An(i?.headers);return s.set(`accept`,`application/json`),rr(e,t,n,a,o,s,i)}(r,i,a,t,{[N]:o,[M]:!s,headers:new Headers(Wi),signal:_a(c)}).then(e=>async function(e,t,n){if(L(e),R(t),!gn(n,Response))throw j(`"response" must be an instance of Response`,A);await er(n,200,`Backchannel Authentication Endpoint`),Nr(n);let r=await Hr(n);I(r.auth_req_id,`"response" body "auth_req_id" property`,z,{body:r});let i=typeof r.expires_in==`number`?r.expires_in:parseFloat(r.expires_in);return Pn(i,!0,`"response" body "expires_in" property`,z,{body:r}),r.expires_in=i,r.interval!==void 0&&Pn(r.interval,!1,`"response" body "interval" property`,z,{body:r}),r}(r,i,e)).catch(G)}async function la(e,t,n,r){ga(e),n=new URLSearchParams(n);let i=t.interval??5,a=r?.signal??AbortSignal.timeout(1e3*t.expires_in);try{await sa(i,a)}catch(e){G(e)}let o=U(e),s=o.as,c=o.c,l=o.auth,u=o.fetch,d=o.tlsOnly,f=o.nonRepudiation,p=o.timeout,m=o.decrypt,h=(i,o)=>la(e,w(w({},t),{},{interval:i}),n,w(w({},r),{},{signal:a,flag:o})),g=function(e,t){let n=_a(t);if(!n)return{signal:e,cleanup(){}};let r=new AbortController,i=e=>{let t=e.target;r.abort(t.reason)};return e.aborted?r.abort(e.reason):n.aborted?r.abort(n.reason):(e.addEventListener(`abort`,i,{once:!0}),n.addEventListener(`abort`,i,{once:!0})),{signal:r.signal,cleanup(){e.removeEventListener(`abort`,i),n.removeEventListener(`abort`,i)}}}(a,p),_=await async function(e,t,n,r,i){L(e),R(t),I(r,`"authReqId"`);let a=new URLSearchParams(i?.additionalParameters);return a.set(`auth_req_id`,r),ir(e,t,n,`urn:openid:params:grant-type:ciba`,a,i)}(s,c,l,t.auth_req_id,{[N]:u,[M]:!d,additionalParameters:n,DPoP:r?.DPoP,headers:new Headers(Wi),signal:g.signal}).catch(G).finally(g.cleanup);if(_.status===503&&_.headers.has(`retry-after`))return await oa(_,i,a,!0),await _.body?.cancel(),h(i);let v=async function(e,t,n,r){return cr(e,t,n,void 0,r?.[bn],r?.recognizedTokenTypes)}(s,c,_,{[bn]:m}),y;try{y=await v}catch(e){if(va(e,r))return h(i,ya);if(e instanceof qn)switch(e.error){case`slow_down`:i+=5;case`authorization_pending`:return await oa(e.response,i,a),h(i)}G(e)}return y.id_token&&await f?.(_),aa(y),y}function ua(e){U(e).tlsOnly=!1}async function da(e,t,n,r,i){if(ga(e),!(i?.flag===ya||t instanceof URL||function(e,t){try{return Object.getPrototypeOf(e)[Symbol.toStringTag]===t}catch{return!1}}(t,`Request`)))throw Qi(`"currentUrl" must be an instance of URL, or Request`,Zi);let a,o,s=U(e),c=s.as,l=s.c,u=s.auth,d=s.fetch,f=s.tlsOnly,p=s.jarm,m=s.hybrid,h=s.nonRepudiation,g=s.timeout,_=s.decrypt,v=s.implicit;if(i?.flag===ya)a=i.authResponse,o=i.redirectUri;else{if(!(t instanceof URL)){let e=t;switch(t=new URL(t.url),e.method){case`GET`:break;case`POST`:let n=new URLSearchParams(await Ir(e));if(m)t.hash=n.toString();else for(let e of n.entries()){var y=T(e,2);let n=y[0],r=y[1];t.searchParams.append(n,r)}break;default:throw Qi(`unexpected Request HTTP method`,Xi)}}switch(o=function(e){return(e=new URL(e)).search=``,e.hash=``,e.href}(t),!0){case!!p:a=await p(t,n?.expectedState);break;case!!m:a=await m(t,n?.expectedNonce,n?.expectedState,n?.maxAge);break;case!!v:throw TypeError(`authorizationCodeGrant() cannot be used by response_type=id_token clients`);default:try{a=Vr(c,l,t.searchParams,n?.expectedState)}catch(e){G(e)}}}let b=await async function(e,t,n,r,i,a,o){if(L(e),R(t),!dr.has(r))throw j(`"callbackParameters" must be an instance of URLSearchParams obtained from "validateAuthResponse()", or "validateJwtAuthResponse()`,k);I(i,`"redirectUri"`);let s=Rr(r,`code`);if(!s)throw F(`no authorization code in "callbackParameters"`,z);let c=new URLSearchParams(o?.additionalParameters);return c.set(`redirect_uri`,i),c.set(`code`,s),a!==fr&&(I(a,`"codeVerifier"`),c.set(`code_verifier`,a)),ir(e,t,n,`authorization_code`,c,o)}(c,l,u,a,o,n?.pkceCodeVerifier||fr,{additionalParameters:r,[N]:d,[M]:!f,DPoP:i?.DPoP,headers:new Headers(Wi),signal:_a(g)}).catch(G);typeof n?.expectedNonce!=`string`&&typeof n?.maxAge!=`number`||(n.idTokenExpected=!0);let x=_r(c,l,b,{expectedNonce:n?.expectedNonce,maxAge:n?.maxAge,requireIdToken:n?.idTokenExpected,[bn]:_}),S;try{S=await x}catch(t){if(va(t,i))return da(e,void 0,n,r,w(w({},i),{},{flag:ya,authResponse:a,redirectUri:o}));G(t)}return S.id_token&&await h?.(b),aa(S),S}async function fa(e,t,n,r){ga(e),n=new URLSearchParams(n);let i=U(e),a=i.as,o=i.c,s=i.auth,c=i.fetch,l=i.tlsOnly,u=i.nonRepudiation,d=i.timeout,f=i.decrypt,p=await async function(e,t,n,r,i){L(e),R(t),I(r,`"refreshToken"`);let a=new URLSearchParams(i?.additionalParameters);return a.set(`refresh_token`,r),ir(e,t,n,`refresh_token`,a,i)}(a,o,s,t,{[N]:c,[M]:!l,additionalParameters:n,DPoP:r?.DPoP,headers:new Headers(Wi),signal:_a(d)}).catch(G),m=async function(e,t,n,r){return cr(e,t,n,void 0,r?.[bn],r?.recognizedTokenTypes)}(a,o,p,{[bn]:f}),h;try{h=await m}catch(i){if(va(i,r))return fa(e,t,n,w(w({},r),{},{flag:ya}));G(i)}return h.id_token&&await u?.(p),aa(h),h}async function pa(e,t,n){ga(e),t=new URLSearchParams(t);let r=U(e),i=r.as,a=r.c,o=r.auth,s=r.fetch,c=r.tlsOnly,l=r.timeout,u=async function(e,t,n,r){return cr(e,t,n,void 0,r?.[bn],r?.recognizedTokenTypes)}(i,a,await async function(e,t,n,r,i){return L(e),R(t),ir(e,t,n,`client_credentials`,new URLSearchParams(r),i)}(i,a,o,t,{[N]:s,[M]:!c,DPoP:n?.DPoP,headers:new Headers(Wi),signal:_a(l)}).catch(G)),d;try{d=await u}catch(r){if(va(r,n))return pa(e,t,w(w({},n),{},{flag:ya}));G(r)}return aa(d),d}function ma(e,t){ga(e);let n=U(e),r=n.as,i=n.c,a=n.tlsOnly,o=n.hybrid,s=n.jarm,c=n.implicit,l=Kn(r,`authorization_endpoint`,!1,a);if((t=new URLSearchParams(t)).has(`client_id`)||t.set(`client_id`,i.client_id),!t.has(`request_uri`)&&!t.has(`request`)){if(t.has(`response_type`)||t.set(`response_type`,o?`code id_token`:c?`id_token`:`code`),c&&!t.has(`nonce`))throw Qi(`response_type=id_token clients must provide a nonce parameter in their authorization request parameters`,Xi);s&&t.set(`response_mode`,`jwt`)}for(let e of t.entries()){var u=T(e,2);let t=u[0],n=u[1];l.searchParams.append(t,n)}return l}async function ha(e,t,n){ga(e);let r=ma(e,t),i=U(e),a=i.as,o=i.c,s=i.auth,c=i.fetch,l=i.tlsOnly,u=i.timeout,d=async function(e,t,n){if(L(e),R(t),!gn(n,Response))throw j(`"response" must be an instance of Response`,A);await er(n,201,`Pushed Authorization Request Endpoint`),Nr(n);let r=await Hr(n);I(r.request_uri,`"response" body "request_uri" property`,z,{body:r});let i=typeof r.expires_in==`number`?r.expires_in:parseFloat(r.expires_in);return Pn(i,!0,`"response" body "expires_in" property`,z,{body:r}),r.expires_in=i,r}(a,o,await async function(e,t,n,r,i){var a;L(e),R(t);let o=Kn(e,`pushed_authorization_request_endpoint`,t.use_mtls_endpoint_aliases,!0!==i?.[M]),s=new URLSearchParams(r);s.set(`client_id`,t.client_id);let c=An(i?.headers);c.set(`accept`,`application/json`),i?.DPoP!==void 0&&(tr(i.DPoP),await i.DPoP.addProof(o,c,`POST`));let l=await rr(e,t,n,o,s,c,i);return i==null||(a=i.DPoP)==null||a.cacheNonce(l,o),l}(a,o,s,r.searchParams,{[N]:c,[M]:!l,DPoP:n?.DPoP,headers:new Headers(Wi),signal:_a(u)}).catch(G)),f;try{f=await d}catch(r){if(va(r,n))return ha(e,t,w(w({},n),{},{flag:ya}));G(r)}return ma(e,{request_uri:f.request_uri})}function ga(e){if(!(e instanceof ia))throw Qi(`"config" must be an instance of Configuration`,Zi);if(Object.getPrototypeOf(e)!==ia.prototype)throw Qi(`subclassing Configuration is not allowed`,Xi)}function _a(e){return e?AbortSignal.timeout(1e3*e):void 0}function va(e,t){return!(t==null||!t.DPoP||t.flag===ya)&&function(e){if(e instanceof Yn){let t=e.cause,n=t[0];return t.length===1&&n.scheme===`dpop`&&n.parameters.error===`use_dpop_nonce`}return e instanceof qn&&e.error===`use_dpop_nonce`}(e)}Object.freeze(ia.prototype);var ya=Symbol();async function ba(e,t,n,r){ga(e);let i=U(e),a=i.as,o=i.c,s=i.auth,c=i.fetch,l=i.tlsOnly,u=i.timeout,d=i.decrypt,f=i.nonRepudiation,p=await async function(e,t,n,r,i,a){return L(e),R(t),I(r,`"grantType"`),ir(e,t,n,r,new URLSearchParams(i),a)}(a,o,s,t,new URLSearchParams(n),{[N]:c,[M]:!l,DPoP:r?.DPoP,headers:new Headers(Wi),signal:_a(u)}).catch(G),m;t===`urn:ietf:params:oauth:grant-type:token-exchange`&&(m={n_a:()=>{}});let h=async function(e,t,n,r){return cr(e,t,n,void 0,r?.[bn],r?.recognizedTokenTypes)}(a,o,p,{[bn]:d,recognizedTokenTypes:m}),g;try{g=await h}catch(i){if(va(i,r))return ba(e,t,n,w(w({},r),{},{flag:ya}));G(i)}return g.id_token&&await f?.(p),aa(g),g}async function xa(e,t,n){ga(e);let r=U(e),i=r.as,a=r.c,o=r.auth,s=r.fetch,c=r.tlsOnly,l=r.timeout;return async function(e,t,n,r,i){L(e),R(t),I(r,`"token"`);let a=Kn(e,`revocation_endpoint`,t.use_mtls_endpoint_aliases,!0!==i?.[M]),o=new URLSearchParams(i?.additionalParameters);o.set(`token`,r);let s=An(i?.headers);return s.delete(`accept`),rr(e,t,n,a,o,s,i)}(i,a,o,t,{[N]:s,[M]:!c,additionalParameters:new URLSearchParams(n),headers:new Headers(Wi),signal:_a(l)}).then(Mr).catch(G)}async function Sa(e,t,n){if(!vi(e))throw new H(`Flattened JWS must be an object`);if(e.protected===void 0&&e.header===void 0)throw new H(`Flattened JWS must have either of the "protected" or "header" members`);if(e.protected!==void 0&&typeof e.protected!=`string`)throw new H(`JWS Protected Header incorrect type`);if(e.payload===void 0)throw new H(`JWS Payload missing`);if(typeof e.signature!=`string`)throw new H(`JWS Signature missing or incorrect type`);if(e.header!==void 0&&!vi(e.header))throw new H(`JWS Unprotected Header incorrect type`);let r={};if(e.protected)try{let t=Xr(e.protected);r=JSON.parse(Kr.decode(t))}catch{throw new H(`JWS Protected Header is invalid`)}if(!yi(r,e.header))throw new H(`JWS Protected and JWS Unprotected Header Parameter names must be disjoint`);let i=w(w({},r),e.header),a=!0;if(Ri(H,new Map([[`b64`,!0]]),n?.crit,r,i).has(`b64`)&&(a=r.b64,typeof a!=`boolean`))throw new H(`The "b64" (base64url-encode payload) Header Parameter must be a boolean`);let o=i.alg;if(typeof o!=`string`||!o)throw new H(`JWS "alg" (Algorithm) Header Parameter missing or invalid`);let s=n&&function(e,t){if(t!==void 0&&(!Array.isArray(t)||t.some(e=>typeof e!=`string`)))throw TypeError(`"${e}" option must be an array of strings`);if(t)return new Set(t)}(`algorithms`,n.algorithms);if(s&&!s.has(o))throw new oi(`"alg" (Algorithm) Header Parameter value not allowed`);if(a){if(typeof e.payload!=`string`)throw new H(`JWS Payload must be a string`)}else if(typeof e.payload!=`string`&&!(e.payload instanceof Uint8Array))throw new H(`JWS Payload must be a string or an Uint8Array instance`);let c=!1;typeof t==`function`&&(t=await t(r,e),c=!0),Vi(o,t,`verify`);let l=qr(e.protected===void 0?new Uint8Array:Jr(e.protected),Jr(`.`),typeof e.payload==`string`?a?Jr(e.payload):Gr.encode(e.payload):e.payload),u=_i(e.signature,`signature`,H),d=await ki(t,o);if(!await async function(e,t,n,r){let i=await Ci(e,t,`verify`);xi(e,i);let a=Si(e,i.algorithm);try{return await crypto.subtle.verify(a,i,n,r)}catch{return!1}}(o,d,u,l))throw new fi;let f;f=a?_i(e.payload,`payload`,H):typeof e.payload==`string`?Gr.encode(e.payload):e.payload;let p={payload:f};return e.protected!==void 0&&(p.protectedHeader=r),e.header!==void 0&&(p.unprotectedHeader=e.header),c?w(w({},p),{},{key:d}):p}var Ca=e=>Math.floor(e.getTime()/1e3),wa=86400,Ta=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i;function Ea(e){let t=Ta.exec(e);if(!t||t[4]&&t[1])throw TypeError(`Invalid time period format`);let n=parseFloat(t[2]),r;switch(t[3].toLowerCase()){case`sec`:case`secs`:case`second`:case`seconds`:case`s`:r=Math.round(n);break;case`minute`:case`minutes`:case`min`:case`mins`:case`m`:r=Math.round(60*n);break;case`hour`:case`hours`:case`hr`:case`hrs`:case`h`:r=Math.round(3600*n);break;case`day`:case`days`:case`d`:r=Math.round(n*wa);break;case`week`:case`weeks`:case`w`:r=Math.round(604800*n);break;default:r=Math.round(31557600*n)}return t[1]===`-`||t[4]===`ago`?-r:r}function Da(e,t){if(!Number.isFinite(t))throw TypeError(`Invalid ${e} input`);return t}var Oa=e=>e.includes(`/`)?e.toLowerCase():`application/${e.toLowerCase()}`;function ka(e,t){let n,r=arguments.length>2&&arguments[2]!==void 0?arguments[2]:{};try{n=JSON.parse(Kr.decode(t))}catch{}if(!vi(n))throw new si(`JWT Claims Set must be a top-level JSON object`);let i=r.typ;if(i&&(typeof e.typ!=`string`||Oa(e.typ)!==Oa(i)))throw new ii(`unexpected "typ" JWT header value`,n,`typ`,`check_failed`);let a=r.requiredClaims,o=a===void 0?[]:a,s=r.issuer,c=r.subject,l=r.audience,u=r.maxTokenAge,d=[...o];u!==void 0&&d.push(`iat`),l!==void 0&&d.push(`aud`),c!==void 0&&d.push(`sub`),s!==void 0&&d.push(`iss`);for(let e of new Set(d.reverse()))if(!(e in n))throw new ii(`missing required "${e}" claim`,n,e,`missing`);if(s&&!(Array.isArray(s)?s:[s]).includes(n.iss))throw new ii(`unexpected "iss" claim value`,n,`iss`,`check_failed`);if(c&&n.sub!==c)throw new ii(`unexpected "sub" claim value`,n,`sub`,`check_failed`);if(l&&(f=n.aud,p=typeof l==`string`?[l]:l,!(typeof f==`string`?p.includes(f):Array.isArray(f)&&p.some(Set.prototype.has.bind(new Set(f))))))throw new ii(`unexpected "aud" claim value`,n,`aud`,`check_failed`);var f,p;let m;switch(typeof r.clockTolerance){case`string`:m=Ea(r.clockTolerance);break;case`number`:m=r.clockTolerance;break;case`undefined`:m=0;break;default:throw TypeError(`Invalid clockTolerance option type`)}let h=r.currentDate,g=Ca(h||new Date);if((n.iat!==void 0||u)&&typeof n.iat!=`number`)throw new ii(`"iat" claim must be a number`,n,`iat`,`invalid`);if(n.nbf!==void 0){if(typeof n.nbf!=`number`)throw new ii(`"nbf" claim must be a number`,n,`nbf`,`invalid`);if(n.nbf>g+m)throw new ii(`"nbf" claim timestamp check failed`,n,`nbf`,`check_failed`)}if(n.exp!==void 0){if(typeof n.exp!=`number`)throw new ii(`"exp" claim must be a number`,n,`exp`,`invalid`);if(n.exp<=g-m)throw new ai(`"exp" claim timestamp check failed`,n,`exp`,`check_failed`)}if(u){let e=g-n.iat;if(e-m>(typeof u==`number`?u:Ea(u)))throw new ai(`"iat" claim timestamp check failed (too far in the past)`,n,`iat`,`check_failed`);if(e<0-m)throw new ii(`"iat" claim timestamp check failed (it should be in the past)`,n,`iat`,`check_failed`)}return n}var K=new WeakMap,Aa=class{constructor(e){if(x(this,K,void 0),!vi(e))throw TypeError(`JWT Claims Set MUST be an object`);S(K,this,structuredClone(e))}data(){return Gr.encode(JSON.stringify(b(K,this)))}get iss(){return b(K,this).iss}set iss(e){b(K,this).iss=e}get sub(){return b(K,this).sub}set sub(e){b(K,this).sub=e}get aud(){return b(K,this).aud}set aud(e){b(K,this).aud=e}set jti(e){b(K,this).jti=e}set nbf(e){typeof e==`number`?b(K,this).nbf=Da(`setNotBefore`,e):e instanceof Date?b(K,this).nbf=Da(`setNotBefore`,Ca(e)):b(K,this).nbf=Ca(new Date)+Ea(e)}set exp(e){typeof e==`number`?b(K,this).exp=Da(`setExpirationTime`,e):e instanceof Date?b(K,this).exp=Da(`setExpirationTime`,Ca(e)):b(K,this).exp=Ca(new Date)+Ea(e)}set iat(e){e===void 0?b(K,this).iat=Ca(new Date):e instanceof Date?b(K,this).iat=Da(`setIssuedAt`,Ca(e)):b(K,this).iat=Da(`setIssuedAt`,typeof e==`string`?Ca(new Date)+Ea(e):e)}};async function ja(e,t,n){var r;let i=await async function(e,t,n){if(e instanceof Uint8Array&&(e=Kr.decode(e)),typeof e!=`string`)throw new H(`Compact JWS must be a string or Uint8Array`);let r=e.split(`.`),i=r[0],a=r[1],o=r[2];if(r.length!==3)throw new H(`Invalid Compact JWS`);let s=await Sa({payload:a,protected:i,signature:o},t,n),c={payload:s.payload,protectedHeader:s.protectedHeader};return typeof t==`function`?w(w({},c),{},{key:s.key}):c}(e,t,n);if((r=i.protectedHeader.crit)!=null&&r.includes(`b64`)&&!1===i.protectedHeader.b64)throw new si(`JWTs MUST NOT use unencoded payload`);let a={payload:ka(i.protectedHeader,i.payload,n),protectedHeader:i.protectedHeader};return typeof t==`function`?w(w({},a),{},{key:i.key}):a}var Ma=new WeakMap,Na=new WeakMap,Pa=new WeakMap,Fa=class{constructor(e){if(x(this,Ma,void 0),x(this,Na,void 0),x(this,Pa,void 0),!(e instanceof Uint8Array))throw TypeError(`payload must be an instance of Uint8Array`);S(Ma,this,e)}setProtectedHeader(e){return gi(b(Na,this),`setProtectedHeader`),S(Na,this,e),this}setUnprotectedHeader(e){return gi(b(Pa,this),`setUnprotectedHeader`),S(Pa,this,e),this}async sign(e,t){if(!b(Na,this)&&!b(Pa,this))throw new H(`either setProtectedHeader or setUnprotectedHeader must be called before #sign()`);if(!yi(b(Na,this),b(Pa,this)))throw new H(`JWS Protected and JWS Unprotected Header Parameter names must be disjoint`);let n=w(w({},b(Na,this)),b(Pa,this)),r=!0;if(Ri(H,new Map([[`b64`,!0]]),t?.crit,b(Na,this),n).has(`b64`)&&(r=b(Na,this).b64,typeof r!=`boolean`))throw new H(`The "b64" (base64url-encode payload) Header Parameter must be a boolean`);let i=n.alg;if(typeof i!=`string`||!i)throw new H(`JWS "alg" (Algorithm) Header Parameter missing or invalid`);let a,o,s,c;Vi(i,e,`sign`),r?(a=Zr(b(Ma,this)),o=Jr(a)):(o=b(Ma,this),a=``),b(Na,this)?(s=Zr(JSON.stringify(b(Na,this))),c=Jr(s)):(s=``,c=new Uint8Array);let l=qr(c,Jr(`.`),o),u={signature:Zr(await async function(e,t,n){let r=await Ci(e,t,`sign`);xi(e,r);let i=await crypto.subtle.sign(Si(e,r.algorithm),r,n);return new Uint8Array(i)}(i,await ki(e,i),l)),payload:a};return b(Pa,this)&&(u.header=b(Pa,this)),b(Na,this)&&(u.protected=s),u}},Ia=new WeakMap,La=class{constructor(e){x(this,Ia,void 0),S(Ia,this,new Fa(e))}setProtectedHeader(e){return b(Ia,this).setProtectedHeader(e),this}async sign(e,t){let n=await b(Ia,this).sign(e,t);if(n.payload===void 0)throw TypeError(`use the flattened module for creating JWS with b64: false`);return`${n.protected}.${n.payload}.${n.signature}`}},Ra=new WeakMap,za=new WeakMap,Ba=class{constructor(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{};x(this,Ra,void 0),x(this,za,void 0),S(za,this,new Aa(e))}setIssuer(e){return b(za,this).iss=e,this}setSubject(e){return b(za,this).sub=e,this}setAudience(e){return b(za,this).aud=e,this}setJti(e){return b(za,this).jti=e,this}setNotBefore(e){return b(za,this).nbf=e,this}setExpirationTime(e){return b(za,this).exp=e,this}setIssuedAt(e){return b(za,this).iat=e,this}setProtectedHeader(e){return S(Ra,this,e),this}async sign(e,t){let n=new La(b(za,this).data());if(n.setProtectedHeader(b(Ra,this)),Array.isArray(b(Ra,this)?.crit)&&b(Ra,this).crit.includes(`b64`)&&!1===b(Ra,this).b64)throw new si(`JWTs MUST NOT use unencoded payload`);return n.sign(e,t)}};function Va(e){return vi(e)}var Ha,Ua,Wa=new WeakMap,Ga=new WeakMap,Ka=class{constructor(e){if(x(this,Wa,void 0),x(this,Ga,new WeakMap),!function(e){return e&&typeof e==`object`&&Array.isArray(e.keys)&&e.keys.every(Va)}(e))throw new ci(`JSON Web Key Set malformed`);S(Wa,this,structuredClone(e))}jwks(){return b(Wa,this)}async getKey(e,t){let n=w(w({},e),t?.header),r=n.alg,i=n.kid,a=function(e){switch(typeof e==`string`&&e.slice(0,2)){case`RS`:case`PS`:return`RSA`;case`ES`:return`EC`;case`Ed`:return`OKP`;case`ML`:return`AKP`;default:throw new V(`Unsupported "alg" value for a JSON Web Key Set`)}}(r),o=b(Wa,this).keys.filter(e=>{let t=a===e.kty;if(t&&typeof i==`string`&&(t=i===e.kid),!t||typeof e.alg!=`string`&&a!==`AKP`||(t=r===e.alg),t&&typeof e.use==`string`&&(t=e.use===`sig`),t&&Array.isArray(e.key_ops)&&(t=e.key_ops.includes(`verify`)),t)switch(r){case`ES256`:t=e.crv===`P-256`;break;case`ES384`:t=e.crv===`P-384`;break;case`ES512`:t=e.crv===`P-521`;break;case`Ed25519`:case`EdDSA`:t=e.crv===`Ed25519`}return t}),s=o[0],c=o.length;if(c===0)throw new li;if(c!==1){let e=new ui,t=b(Ga,this);throw e[Symbol.asyncIterator]=re(function*(){for(let e of o)try{yield yield v(qa(t,e,r))}catch{}}),e}return qa(b(Ga,this),s,r)}};async function qa(e,t,n){let r=e.get(t)||e.set(t,{}).get(t);if(r[n]===void 0){let e=await async function(e,t,n){if(!vi(e))throw TypeError(`JWK must be an object`);let r;switch(t??=e.alg,r??=n?.extractable??e.ext,e.kty){case`oct`:if(typeof e.k!=`string`||!e.k)throw TypeError(`missing "k" (Key Value) Parameter value`);return Xr(e.k);case`RSA`:if(`oth`in e&&e.oth!==void 0)throw new V(`RSA JWK "oth" (Other Primes Info) Parameter value is not supported`);return Ti(w(w({},e),{},{alg:t,ext:r}));case`AKP`:if(typeof e.alg!=`string`||!e.alg)throw TypeError(`missing "alg" (Algorithm) Parameter value`);if(t!==void 0&&t!==e.alg)throw TypeError(`JWK alg and alg option value mismatch`);return Ti(w(w({},e),{},{ext:r}));case`EC`:case`OKP`:return Ti(w(w({},e),{},{alg:t,ext:r}));default:throw new V(`Unsupported "kty" (Key Type) Parameter value`)}}(w(w({},t),{},{ext:!0}),n);if(e instanceof Uint8Array||e.type!==`public`)throw new ci(`JSON Web Key Set members must be public keys`);r[n]=e}return r[n]}function Ja(e){let t=new Ka(e),n=async(e,n)=>t.getKey(e,n);return Object.defineProperties(n,{jwks:{value:()=>structuredClone(t.jwks()),enumerable:!1,configurable:!1,writable:!1}}),n}var Ya;(typeof navigator>`u`||(Ha=navigator.userAgent)==null||(Ua=Ha.startsWith)==null||!Ua.call(Ha,`Mozilla/5.0 `))&&(Ya=`jose/v6.2.3`);var Xa=Symbol(),Za=Symbol(),Qa=new WeakMap,$a=new WeakMap,eo=new WeakMap,to=new WeakMap,no=new WeakMap,ro=new WeakMap,io=new WeakMap,ao=new WeakMap,oo=new WeakMap,so=new WeakMap,co=class{constructor(e,t){if(x(this,Qa,void 0),x(this,$a,void 0),x(this,eo,void 0),x(this,to,void 0),x(this,no,void 0),x(this,ro,void 0),x(this,io,void 0),x(this,ao,void 0),x(this,oo,void 0),x(this,so,void 0),!(e instanceof URL))throw TypeError(`url must be an instance of URL`);var n,r;S(Qa,this,new URL(e.href)),S($a,this,typeof t?.timeoutDuration==`number`?t?.timeoutDuration:5e3),S(eo,this,typeof t?.cooldownDuration==`number`?t?.cooldownDuration:3e4),S(to,this,typeof t?.cacheMaxAge==`number`?t?.cacheMaxAge:6e5),S(io,this,new Headers(t?.headers)),Ya&&!b(io,this).has(`User-Agent`)&&b(io,this).set(`User-Agent`,Ya),b(io,this).has(`accept`)||(b(io,this).set(`accept`,`application/json`),b(io,this).append(`accept`,`application/jwk-set+json`)),S(ao,this,t?.[Xa]),t?.[Za]!==void 0&&(S(so,this,t?.[Za]),n=t?.[Za],r=b(to,this),typeof n==`object`&&n&&`uat`in n&&typeof n.uat==`number`&&!(Date.now()-n.uat>=r)&&`jwks`in n&&vi(n.jwks)&&Array.isArray(n.jwks.keys)&&Array.prototype.every.call(n.jwks.keys,vi)&&(S(no,this,b(so,this).uat),S(oo,this,Ja(b(so,this).jwks))))}pendingFetch(){return!!b(ro,this)}coolingDown(){return typeof b(no,this)==`number`&&Date.now()<b(no,this)+b(eo,this)}fresh(){return typeof b(no,this)==`number`&&Date.now()<b(no,this)+b(to,this)}jwks(){return b(oo,this)?.jwks()}async getKey(e,t){b(oo,this)&&this.fresh()||await this.reload();try{return await b(oo,this).call(this,e,t)}catch(n){if(n instanceof li&&!1===this.coolingDown())return await this.reload(),b(oo,this).call(this,e,t);throw n}}async reload(){b(ro,this)&&(typeof WebSocketPair<`u`||typeof navigator<`u`&&navigator.userAgent===`Cloudflare-Workers`||typeof EdgeRuntime<`u`&&EdgeRuntime===`vercel`)&&S(ro,this,void 0),b(ro,this)||S(ro,this,async function(e,t,n){let r=await(arguments.length>3&&arguments[3]!==void 0?arguments[3]:fetch)(e,{method:`GET`,signal:n,redirect:`manual`,headers:t}).catch(e=>{throw e.name===`TimeoutError`?new di:e});if(r.status!==200)throw new B(`Expected 200 OK from the JSON Web Key Set HTTP response`);try{return await r.json()}catch{throw new B(`Failed to parse the JSON Web Key Set HTTP response as JSON`)}}(b(Qa,this).href,b(io,this),AbortSignal.timeout(b($a,this)),b(ao,this)).then(e=>{S(oo,this,Ja(e)),b(so,this)&&(b(so,this).uat=Date.now(),b(so,this).jwks=e),S(no,this,Date.now()),S(ro,this,void 0)}).catch(e=>{throw S(ro,this,void 0),e})),await b(ro,this)}},lo=[`mfaToken`],uo=[`mfaToken`],fo,po,mo,ho,go,_o,vo,yo,bo,xo,So,Co,wo,To,Eo,Do,Oo,ko,Ao,jo,Mo,q,No,Po,Fo,Io,Lo,J,Y,Ro,zo,Bo,Vo,X;function Ho(e){if(typeof e!=`object`||!e)return{error:`unknown_error`,error_description:String(e)};let t=e,n={error:t.error??``,error_description:t.error_description??``,message:t.message};if(t.error===`mfa_required`&&t.cause){n.mfa_token=typeof t.cause.mfa_token==`string`?t.cause.mfa_token:void 0;let e=t.cause.mfa_requirements;typeof e==`object`&&e&&(n.mfa_requirements=e)}return n}var Uo=class extends Error{constructor(e,t){super(t),C(this,`code`,void 0),this.name=`NotSupportedError`,this.code=e}},Wo=class extends Error{constructor(e,t,n){super(t),C(this,`cause`,void 0),C(this,`code`,void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements}}},Go=class extends Wo{constructor(e,t){super(`token_by_code_error`,e,t),this.name=`TokenByCodeError`}},Ko=class extends Wo{constructor(e,t){super(`token_by_client_credentials_error`,e,t),this.name=`TokenByClientCredentialsError`}},qo=class extends Wo{constructor(e,t){super(`token_by_refresh_token_error`,e,t),this.name=`TokenByRefreshTokenError`}},Jo=class extends Wo{constructor(e,t){super(`token_by_password_error`,e,t),this.name=`TokenByPasswordError`}},Yo=class extends Wo{constructor(e,t){super(`token_for_connection_error`,e,t),this.name=`TokenForConnectionErrorCode`}},Xo=class extends Wo{constructor(e,t){super(`token_exchange_error`,e,t),this.name=`TokenExchangeError`}},Zo=class extends Wo{constructor(e,t){super(`token_revocation_error`,e,t),this.name=`TokenRevocationError`}},Qo=class extends Error{constructor(e){super(e),C(this,`code`,`verify_logout_token_error`),this.name=`VerifyLogoutTokenError`}},$o=class extends Wo{constructor(e){super(`backchannel_authentication_error`,`There was an error when trying to use Client-Initiated Backchannel Authentication.`,e),C(this,`code`,`backchannel_authentication_error`),this.name=`BackchannelAuthenticationError`}},es=class extends Wo{constructor(e){super(`build_authorization_url_error`,`There was an error when trying to build the authorization URL.`,e),this.name=`BuildAuthorizationUrlError`}},ts=class extends Wo{constructor(e){super(`build_link_user_url_error`,`There was an error when trying to build the Link User URL.`,e),this.name=`BuildLinkUserUrlError`}},ns=class extends Wo{constructor(e){super(`build_unlink_user_url_error`,`There was an error when trying to build the Unlink User URL.`,e),this.name=`BuildUnlinkUserUrlError`}},rs=class extends Error{constructor(){super(`The client secret or client assertion signing key must be provided.`),C(this,`code`,`missing_client_auth_error`),this.name=`MissingClientAuthError`}},is=class extends Error{constructor(e){super(e),C(this,`code`,`organization_validation_error`),this.name=`OrganizationValidationError`}};function as(e){return Object.entries(e).filter(e=>T(e,2)[1]!==void 0).reduce((e,t)=>w(w({},e),{},{[t[0]]:t[1]}),{})}function os(e){if(!e.trim())throw new is(`organization must not be blank`)}function ss(e,t){if(!e)return;let n=t.trim();if(n.startsWith(`org_`)){let t=e.org_id;if(typeof t!=`string`)throw new is(`Organization Id (org_id) claim must be a string present in the ID token`);if(t!==n)throw new is(`Organization Id (org_id) claim value mismatch in the ID token; expected "${n}", found "${t}"`)}else{let t=e.org_name;if(typeof t!=`string`)throw new is(`Organization Name (org_name) claim must be a string present in the ID token`);if(t.toLowerCase()!==n.toLowerCase())throw new is(`Organization Name (org_name) claim value mismatch in the ID token; expected "${n}", found "${t}"`)}}var cs=class extends Error{constructor(e,t,n){super(t),C(this,`cause`,void 0),C(this,`code`,void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},ls=class extends cs{constructor(e,t){super(`mfa_list_authenticators_error`,e,t),this.name=`MfaListAuthenticatorsError`}},us=class extends cs{constructor(e,t){super(`mfa_enrollment_error`,e,t),this.name=`MfaEnrollmentError`}},ds=class extends cs{constructor(e,t){super(`mfa_delete_authenticator_error`,e,t),this.name=`MfaDeleteAuthenticatorError`}},fs=class extends cs{constructor(e,t){super(`mfa_challenge_error`,e,t),this.name=`MfaChallengeError`}},ps=class extends cs{constructor(e,t){super(`mfa_verify_error`,e,t),this.name=`MfaVerifyError`}};function ms(e){return{id:e.id,authenticatorType:e.authenticator_type,active:e.active,name:e.name,oobChannels:e.oob_channels,type:e.type}}var Z=class e{constructor(e,t,n,r,i,a,o){C(this,`accessToken`,void 0),C(this,`idToken`,void 0),C(this,`refreshToken`,void 0),C(this,`expiresAt`,void 0),C(this,`scope`,void 0),C(this,`claims`,void 0),C(this,`authorizationDetails`,void 0),C(this,`tokenType`,void 0),C(this,`issuedTokenType`,void 0),C(this,`recoveryCode`,void 0),C(this,`act`,void 0),this.accessToken=e,this.idToken=n,this.refreshToken=r,this.expiresAt=t,this.scope=i,this.claims=a,this.authorizationDetails=o}static fromTokenEndpointResponse(t){let n=t.id_token?t.claims():void 0,r=new e(t.access_token,Math.floor(Date.now()/1e3)+Number(t.expires_in),t.id_token,t.refresh_token,t.scope,n,t.authorization_details);return r.tokenType=t.token_type,r.issuedTokenType=t.issued_token_type,r}},hs={otp:`http://auth0.com/oauth/grant-type/mfa-otp`,oob:`http://auth0.com/oauth/grant-type/mfa-oob`,"recovery-code":`http://auth0.com/oauth/grant-type/mfa-recovery-code`},gs=(fo=new WeakMap,po=new WeakMap,mo=new WeakMap,ho=new WeakMap,go=new WeakMap,class{constructor(e){x(this,fo,void 0),x(this,po,void 0),x(this,mo,void 0),x(this,ho,void 0),x(this,go,void 0),S(fo,this,`https://${e.domain}`),S(po,this,e.clientId),S(mo,this,e.clientSecret),S(ho,this,e.customFetch??function(){return fetch(...arguments)}),S(go,this,e.getConfiguration)}async listAuthenticators(e){let t=`${b(fo,this)}/mfa/authenticators`,n=e.mfaToken,r=await b(ho,this).call(this,t,{method:`GET`,headers:{Authorization:`Bearer ${n}`,"Content-Type":`application/json`}});if(!r.ok){let e;try{e=await r.json()}catch{throw new ls(`Failed to list authenticators`)}throw new ls(e.error_description||`Failed to list authenticators`,e)}return(await r.json()).map(ms)}async enrollAuthenticator(e){let t=`${b(fo,this)}/mfa/associate`,n=e.mfaToken,r=ne(e,lo),i={authenticator_types:r.authenticatorTypes};`oobChannels`in r&&(i.oob_channels=r.oobChannels),`phoneNumber`in r&&r.phoneNumber&&(i.phone_number=r.phoneNumber),`email`in r&&r.email&&(i.email=r.email);let a=await b(ho,this).call(this,t,{method:`POST`,headers:{Authorization:`Bearer ${n}`,"Content-Type":`application/json`},body:JSON.stringify(i)});if(!a.ok){let e;try{e=await a.json()}catch{throw new us(`Failed to enroll authenticator`)}throw new us(e.error_description||`Failed to enroll authenticator`,e)}return function(e){if(e.authenticator_type===`otp`)return{authenticatorType:`otp`,secret:e.secret,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes,id:e.id};if(e.authenticator_type===`oob`)return{authenticatorType:`oob`,oobChannel:e.oob_channel,oobCode:e.oob_code,bindingMethod:e.binding_method,id:e.id,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes};throw Error(`Unexpected authenticator type: ${e.authenticator_type}`)}(await a.json())}async deleteAuthenticator(e){let t=e.authenticatorId,n=e.mfaToken,r=`${b(fo,this)}/mfa/authenticators/${encodeURIComponent(t)}`,i=await b(ho,this).call(this,r,{method:`DELETE`,headers:{Authorization:`Bearer ${n}`,"Content-Type":`application/json`}});if(!i.ok){let e;try{e=await i.json()}catch{throw new ds(`Failed to delete authenticator`)}throw new ds(e.error_description||`Failed to delete authenticator`,e)}}async challengeAuthenticator(e){let t=`${b(fo,this)}/mfa/challenge`,n=e.mfaToken,r=ne(e,uo),i={mfa_token:n,client_id:b(po,this),challenge_type:r.challengeType};b(mo,this)&&(i.client_secret=b(mo,this)),r.authenticatorId&&(i.authenticator_id=r.authenticatorId);let a=await b(ho,this).call(this,t,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(i)});if(!a.ok){let e;try{e=await a.json()}catch{throw new fs(`Failed to challenge authenticator`)}throw new fs(e.error_description||`Failed to challenge authenticator`,e)}return function(e){let t={challengeType:e.challenge_type};return e.oob_code!==void 0&&(t.oobCode=e.oob_code),e.binding_method!==void 0&&(t.bindingMethod=e.binding_method),t}(await a.json())}async verify(e){if(!b(go,this))throw Error(`MFA verify requires a configuration provider (getConfiguration was not set)`);let t=await b(go,this).call(this),n={mfa_token:e.mfaToken};e.audience&&(n.audience=e.audience),e.factorType===`otp`?n.otp=e.otp:e.factorType===`oob`?(n.oob_code=e.oobCode,e.bindingCode&&(n.binding_code=e.bindingCode)):e.factorType===`recovery-code`&&(n.recovery_code=e.recoveryCode);try{let r=await ba(t,hs[e.factorType],n),i=Z.fromTokenEndpointResponse(r);return r.recovery_code&&(i.recoveryCode=r.recovery_code),i}catch(e){if(e instanceof ps)throw e;let t=e;throw new ps(t.error_description||t.message||`Failed to verify MFA challenge`,{error:t.error??`mfa_verify_error`,error_description:t.error_description??t.message??`Failed to verify MFA challenge`})}}}),_s=class extends Error{constructor(e,t,n){super(t),C(this,`cause`,void 0),C(this,`code`,void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},vs=class extends _s{constructor(e,t){super(`passkey_register_error`,e,t),this.name=`PasskeyRegisterError`}},ys=class extends _s{constructor(e,t){super(`passkey_challenge_error`,e,t),this.name=`PasskeyChallengeError`}},bs=class extends _s{constructor(e,t){super(`passkey_get_token_error`,e,t),this.name=`PasskeyGetTokenError`,this.cause=t&&{error:t.error,error_description:t.error_description,message:t.message,mfa_token:t.mfa_token,mfa_requirements:t.mfa_requirements}}},xs=`urn:okta:params:oauth:grant-type:webauthn`,Ss=(_o=new WeakMap,vo=new WeakMap,yo=new WeakMap,bo=new WeakMap,xo=new WeakSet,class{constructor(e){ee(this,xo),x(this,_o,void 0),x(this,vo,void 0),x(this,yo,void 0),x(this,bo,void 0),S(_o,this,`https://${e.domain}`),S(vo,this,e.clientId),S(yo,this,e.customFetch??function(){return fetch(...arguments)}),S(bo,this,e.grantRequest)}async register(e){let t=`${b(_o,this)}/passkey/register`,n=w(w(w(w(w(w(w(w({},e.email&&{email:e.email}),e.name&&{name:e.name}),e.phoneNumber&&{phone_number:e.phoneNumber}),e.username&&{username:e.username}),e.givenName&&{given_name:e.givenName}),e.familyName&&{family_name:e.familyName}),e.nickname&&{nickname:e.nickname}),e.picture&&{picture:e.picture}),r={client_id:b(vo,this),user_profile:n};e.realm&&(r.realm=e.realm),e.organization&&(r.organization=e.organization),e.userMetadata&&(r.user_metadata=e.userMetadata);let i=await b(yo,this).call(this,t,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(r)});if(!i.ok){let e=await _(xo,this,Cs).call(this,i);throw new vs(e.error_description||`Failed to request signup challenge`,e)}return{authSession:(a=await i.json()).auth_session,authnParamsPublicKey:w({},a.authn_params_public_key)};var a}async challenge(e){let t=`${b(_o,this)}/passkey/challenge`,n={client_id:b(vo,this)};e!=null&&e.realm&&(n.realm=e.realm),e!=null&&e.organization&&(n.organization=e.organization);let r=await b(yo,this).call(this,t,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(n)});if(!r.ok){let e=await _(xo,this,Cs).call(this,r);throw new ys(e.error_description||`Failed to request login challenge`,e)}return{authSession:(i=await r.json()).auth_session,authnParamsPublicKey:w({},i.authn_params_public_key)};var i}async getTokenByPasskey(e){e.organization!==void 0&&os(e.organization);let t=new URLSearchParams({auth_session:e.authSession,authn_response:JSON.stringify(e.credential)}),n;e.realm&&t.append(`realm`,e.realm),e.scope&&t.append(`scope`,e.scope),e.audience&&t.append(`audience`,e.audience),e.organization&&t.append(`organization`,e.organization);try{n=await b(bo,this).call(this,xs,t)}catch(e){let t=Ho(e);throw new bs(t.error_description||`Failed to exchange passkey credential for tokens.`,t)}return e.organization&&ss(n.claims,e.organization),n}});async function Cs(e){try{return await e.json()}catch{return{error:`unknown_error`,error_description:`HTTP ${e.status} ${e.statusText}`}}}var ws=class extends Error{constructor(e,t,n){super(t),C(this,`cause`,void 0),C(this,`code`,void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements}}},Ts=class extends ws{constructor(e,t){super(`passwordless_start_error`,e,t),this.name=`PasswordlessStartError`}},Es=class extends ws{constructor(e,t){super(`passwordless_verify_error`,e,t),this.name=`PasswordlessVerifyError`}},Ds=class extends ws{constructor(e,t){super(`passwordless_db_get_token_error`,e,t),this.name=`PasswordlessDbGetTokenError`}},Os=class extends ws{constructor(e,t,n,r){super(`passwordless_challenge_error`,e,n),C(this,`statusCode`,void 0),C(this,`validationErrors`,void 0),this.name=`PasswordlessChallengeError`,this.statusCode=t,this.validationErrors=r}};function ks(e){return/^\+[1-9]\d{1,14}$/.test(e)}async function As(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){let r=e.clientAssertionSigningAlg??`RS256`,i=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await Li(e.clientAssertionSigningKey,r);return{client_assertion:await new Ba({}).setProtectedHeader({alg:r}).setIssuer(t).setSubject(t).setAudience(`https://${n}/`).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime(`120s`).sign(i),client_assertion_type:`urn:ietf:params:oauth:client-assertion-type:jwt-bearer`}}if(e.clientSecret)return{client_secret:e.clientSecret};throw new rs}var js=(So=new WeakMap,Co=new WeakMap,wo=new WeakMap,To=new WeakMap,Eo=new WeakMap,Do=new WeakMap,Oo=new WeakSet,class{constructor(e){ee(this,Oo),x(this,So,void 0),x(this,Co,void 0),x(this,wo,void 0),x(this,To,void 0),x(this,Eo,void 0),x(this,Do,void 0),S(Co,this,e.domain),S(So,this,`https://${e.domain}`),S(wo,this,e.clientId),S(To,this,e.customFetch??function(){return fetch(...arguments)}),S(Eo,this,{clientSecret:e.clientSecret,clientAssertionSigningKey:e.clientAssertionSigningKey,clientAssertionSigningAlg:e.clientAssertionSigningAlg,useMtls:e.useMtls}),S(Do,this,e.grantRequest)}async sendEmail(e){await _(Oo,this,Ms).call(this,function(e){let t=e.send??`code`,n={email:e.email,connection:`email`,send:t};return t===`link`&&e.authParams&&(n.authParams=e.authParams),n}(e),`Failed to send passwordless email`,e.language)}async sendSms(e){if(!ks(e.phoneNumber))throw new Ts(`Phone number must be in E.164 format (e.g. +14155550100).`);await _(Oo,this,Ms).call(this,function(e){return{phone_number:e.phoneNumber,connection:`sms`}}(e),`Failed to send passwordless SMS`,e.language)}async challengeWithEmail(e){let t=function(e){var t;return{email:e.email,connection:e.connection,allow_signup:(t=e.allowSignup)!=null&&t}}(e);return _(Oo,this,Ns).call(this,t,`Failed to request email OTP challenge`)}async challengeWithPhoneNumber(e){if(!ks(e.phoneNumber))throw new Os(`Phone number must be in E.164 format (e.g. +14155550100).`,0,void 0,void 0);let t=function(e){var t;let n={phone_number:e.phoneNumber,connection:e.connection,allow_signup:(t=e.allowSignup)!=null&&t};return e.deliveryMethod&&(n.delivery_method=e.deliveryMethod),n}(e);return _(Oo,this,Ns).call(this,t,`Failed to request phone OTP challenge`)}async getTokenByPasswordlessDbConnection(e){let t=new URLSearchParams({auth_session:e.authSession,otp:e.otp});if(e.scope&&t.append(`scope`,e.scope),e.audience&&t.append(`audience`,e.audience),!b(Do,this))throw new Ds(`Missing grant request delegate.`,Ho(Error(`missing grantRequest`)));try{return await b(Do,this).call(this,`http://auth0.com/oauth/grant-type/passwordless/otp`,t)}catch(e){throw new Ds(`There was an error while trying to request a token.`,Ho(e))}}});async function Ms(e,t,n){let r=await As(b(Eo,this),b(wo,this),b(Co,this)),i=w(w({client_id:b(wo,this)},e),r),a,o;try{a=await b(To,this).call(this,`${b(So,this)}/passwordless/start`,{method:`POST`,headers:w({"Content-Type":`application/json`},n?{"x-request-language":n}:{}),body:JSON.stringify(i)})}catch{throw new Ts(`${t}: a network error occurred.`)}if(!a.ok){if(a.status!==204)try{o=await a.json()}catch{o=void 0}throw new Ts(o?.error_description||t,o)}}async function Ns(e,t){let n=await As(b(Eo,this),b(wo,this),b(Co,this)),r=w(w({client_id:b(wo,this)},e),n),i,a;try{i=await b(To,this).call(this,`${b(So,this)}/otp/challenge`,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(r)})}catch{throw new Os(`challenge error: a network error occurred.`,0,void 0,void 0)}if(i.ok){let e;try{e=await i.json()}catch{throw new Os(`${t}: could not parse the response body.`,i.status,void 0,void 0)}return{authSession:e.auth_session}}try{a=await i.json()}catch{a=void 0}throw new Os(a?.error_description||t,i.status,a,a?.validation_errors)}var Ps=class extends Error{constructor(e,t,n){super(t),C(this,`cause`,void 0),C(this,`code`,void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}},Fs=class extends Ps{constructor(e,t){super(`signup_error`,e,t),this.name=`SignUpError`}},Is=class extends Ps{constructor(e,t){super(`change_password_error`,e,t),this.name=`ChangePasswordError`}};function Ls(e,t,n){for(let r of t)if(e[r]===null||e[r]===void 0||e[r]===``)throw new n(`Required parameter "${String(r)}" was null, undefined, or empty.`)}var Rs=(ko=new WeakMap,Ao=new WeakMap,jo=new WeakMap,Mo=new WeakSet,class{constructor(e){ee(this,Mo),x(this,ko,void 0),x(this,Ao,void 0),x(this,jo,void 0),S(ko,this,`https://${e.domain}`),S(Ao,this,e.clientId),S(jo,this,e.customFetch??function(){return fetch(...arguments)})}async signUp(e){Ls(e,[`email`,`password`,`connection`],Fs);let t=w({client_id:e.clientId??b(Ao,this)},function(e){let t={email:e.email,password:e.password,connection:e.connection};return e.username!==void 0&&(t.username=e.username),e.givenName!==void 0&&(t.given_name=e.givenName),e.familyName!==void 0&&(t.family_name=e.familyName),e.name!==void 0&&(t.name=e.name),e.nickname!==void 0&&(t.nickname=e.nickname),e.picture!==void 0&&(t.picture=e.picture),e.userMetadata!==void 0&&(t.user_metadata=e.userMetadata),t}(e));return function(e){return{id:e._id??e.user_id??e.id,email:typeof e.email==`string`?e.email:``,emailVerified:!!e.email_verified,username:e.username,givenName:e.given_name,familyName:e.family_name,name:e.name,nickname:e.nickname,picture:e.picture,userMetadata:e.user_metadata}}(await(await _(Mo,this,zs).call(this,`/dbconnections/signup`,t,Fs,`Failed to sign up`)).json())}async changePassword(e){if(Ls(e,[`connection`],Is),!e.email&&!e.username)throw new Is(`Either "email" or "username" is required.`);let t=w({client_id:e.clientId??b(Ao,this)},function(e){let t={connection:e.connection};return e.email!==void 0&&(t.email=e.email),e.username!==void 0&&(t.username=e.username),e.organization!==void 0&&(t.organization=e.organization),t}(e));return(await _(Mo,this,zs).call(this,`/dbconnections/change_password`,t,Is,`Failed to request a password change`)).text()}});async function zs(e,t,n,r){let i;try{i=await b(jo,this).call(this,`${b(ko,this)}${e}`,{method:`POST`,headers:{"Content-Type":`application/json`},body:JSON.stringify(t)})}catch{throw new n(`${r}: a network error occurred.`)}if(i.ok)return i;let a=await async function(e){let t;try{t=await e.json()}catch{return}return typeof t.error==`string`?t:typeof t.code==`string`?{error:t.code,error_description:typeof t.description==`string`?t.description:``}:void 0}(i);throw new n(a?.error_description||r,a)}var Bs=(q=new WeakMap,No=new WeakMap,Po=new WeakMap,class{constructor(e,t){x(this,q,new Map),x(this,No,void 0),x(this,Po,void 0),S(Po,this,Math.max(1,Math.floor(e))),S(No,this,Math.max(0,Math.floor(t)))}get(e){let t=b(q,this).get(e);if(t){if(!(Date.now()>=t.expiresAt))return b(q,this).delete(e),b(q,this).set(e,t),t.value;b(q,this).delete(e)}}set(e,t){for(b(q,this).has(e)&&b(q,this).delete(e),b(q,this).set(e,{value:t,expiresAt:Date.now()+b(No,this)});b(q,this).size>b(Po,this);){let e=b(q,this).keys().next().value;if(e===void 0)break;b(q,this).delete(e)}}}),Vs=new Map;function Hs(e){return{ttlMs:1e3*(typeof e?.ttl==`number`?e.ttl:600),maxEntries:typeof e?.maxEntries==`number`&&e.maxEntries>0?e.maxEntries:100}}var Us=class{static createDiscoveryCache(e){let t=(n=e.maxEntries,r=e.ttlMs,`${n}:${r}`);var n,r;let i=(a=t,Vs.get(a));var a;return i||(i=new Bs(e.maxEntries,e.ttlMs),Vs.set(t,i)),i}static createJwksCache(){return{}}},Ws=`openid profile email offline_access`,Gs=Object.freeze(new Set([`grant_type`,`client_id`,`client_secret`,`client_assertion`,`client_assertion_type`,`subject_token`,`subject_token_type`,`requested_token_type`,`actor_token`,`actor_token_type`,`audience`,`aud`,`resource`,`resources`,`resource_indicator`,`scope`,`connection`,`login_hint`,`organization`,`assertion`]));function Ks(e){if(e==null)throw new Xo(`subject_token is required`);if(typeof e!=`string`)throw new Xo(`subject_token must be a string`);if(e.trim().length===0)throw new Xo(`subject_token cannot be blank or whitespace`);if(e!==e.trim())throw new Xo(`subject_token must not include leading or trailing whitespace`);if(/^bearer\s+/i.test(e))throw new Xo(`subject_token must not include the 'Bearer ' prefix`)}function qs(e,t){if(t)for(let r of Object.entries(t)){var n=T(r,2);let t=n[0],i=n[1];if(!Gs.has(t)){if(Array.isArray(i)){if(i.length>20)throw new Xo(`Parameter '${t}' exceeds maximum array size of 20`);i.forEach(n=>{e.append(t,n)})}else e.append(t,i)}}}var Js=`urn:ietf:params:oauth:token-type:access_token`,Ys=(Fo=new WeakMap,Io=new WeakMap,Lo=new WeakMap,J=new WeakMap,Y=new WeakMap,Ro=new WeakMap,zo=new WeakMap,Bo=new WeakMap,Vo=new WeakMap,X=new WeakSet,class{constructor(e){var t;if(ee(this,X),x(this,Fo,void 0),x(this,Io,void 0),x(this,Lo,void 0),x(this,J,void 0),x(this,Y,void 0),x(this,Ro,void 0),x(this,zo,void 0),x(this,Bo,void 0),x(this,Vo,void 0),C(this,`mfa`,void 0),C(this,`passkey`,void 0),C(this,`passwordless`,void 0),C(this,`database`,void 0),S(J,this,e),e.useMtls&&!e.customFetch)throw new Uo(`mtls_without_custom_fetch_not_supported`,`Using mTLS without a custom fetch implementation is not supported`);S(Y,this,function(e,t){if(!1===t.enabled)return e;let n={name:t.name,version:t.version},r=btoa(JSON.stringify(n));return async(t,n)=>{let i=t instanceof Request?new Headers(t.headers):new Headers;return n!=null&&n.headers&&new Headers(n.headers).forEach((e,t)=>{i.set(t,e)}),i.set(`Auth0-Client`,r),e(t,w(w({},n),{},{headers:i}))}}(e.customFetch??function(){return fetch(...arguments)},!1===(t=e.telemetry)?.enabled?t:{enabled:!0,name:t?.name??`@auth0/auth0-auth-js`,version:t?.version??`1.12.0`}));let n=Hs(e.discoveryCache);S(zo,this,Us.createDiscoveryCache(n)),S(Bo,this,new Map),S(Vo,this,Us.createJwksCache()),this.mfa=new gs({domain:b(J,this).domain,clientId:b(J,this).clientId,clientSecret:b(J,this).clientSecret,customFetch:b(Y,this),getConfiguration:async()=>(await _(X,this,Q).call(this)).configuration}),this.passkey=new Ss({domain:b(J,this).domain,clientId:b(J,this).clientId,customFetch:b(Y,this),grantRequest:async(e,t)=>{let n=(await _(X,this,Q).call(this)).serverMetadata,r=await _(X,this,Zs).call(this,n);r[Yi]=function(e,t){return(n,r)=>{let i=r?.body;if(t!==xs||!(i instanceof URLSearchParams))return e(n,r);let a={};for(let e of i){var o=T(e,2);let t=o[0],n=o[1];a[t]=t===`authn_response`?JSON.parse(n):n}let s=new Headers(r?.headers);return s.set(`Content-Type`,`application/json`),e(n,w(w({},r),{},{headers:s,body:JSON.stringify(a)}))}}(b(Y,this),e);let i=await ba(r,e,t);return Z.fromTokenEndpointResponse(i)}}),this.passwordless=new js({domain:b(J,this).domain,clientId:b(J,this).clientId,customFetch:b(Y,this),clientSecret:b(J,this).clientSecret,clientAssertionSigningKey:b(J,this).clientAssertionSigningKey,clientAssertionSigningAlg:b(J,this).clientAssertionSigningAlg,useMtls:b(J,this).useMtls,grantRequest:async(e,t)=>{let n=(await _(X,this,Q).call(this)).configuration,r=await ba(n,e,t);return Z.fromTokenEndpointResponse(r)}}),this.database=new Rs({domain:b(J,this).domain,clientId:b(J,this).clientId,customFetch:b(Y,this)})}async getServerMetadata(){return(await _(X,this,Q).call(this)).serverMetadata}async buildAuthorizationUrl(e){let t=(await _(X,this,Q).call(this)).serverMetadata;if(e!=null&&e.pushedAuthorizationRequests&&!t.pushed_authorization_request_endpoint)throw new Uo(`par_not_supported_error`,`The Auth0 tenant does not have pushed authorization requests enabled. Learn how to enable it here: https://auth0.com/docs/get-started/applications/configure-par`);try{return await _(X,this,nc).call(this,e)}catch(e){throw new es(e)}}async buildLinkUserUrl(e){try{let t=await _(X,this,nc).call(this,{authorizationParams:w(w({},e.authorizationParams),{},{requested_connection:e.connection,requested_connection_scope:e.connectionScope,scope:`openid link_account offline_access`,id_token_hint:e.idToken})});return{linkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new ts(e)}}async buildUnlinkUserUrl(e){try{let t=await _(X,this,nc).call(this,{authorizationParams:w(w({},e.authorizationParams),{},{requested_connection:e.connection,scope:`openid unlink_account`,id_token_hint:e.idToken})});return{unlinkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new ns(e)}}async backchannelAuthentication(e){let t=await _(X,this,Q).call(this),n=t.configuration,r=t.serverMetadata,i=as(w(w({},b(J,this).authorizationParams),e?.authorizationParams)),a=new URLSearchParams(w(w({scope:Ws},i),{},{client_id:b(J,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:`iss_sub`,iss:r.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&a.append(`requested_expiry`,e.requestedExpiry.toString()),e.authorizationDetails&&a.append(`authorization_details`,JSON.stringify(e.authorizationDetails));try{let e=await la(n,await ca(n,a));return Z.fromTokenEndpointResponse(e)}catch(e){throw new $o(e)}}async initiateBackchannelAuthentication(e){let t=await _(X,this,Q).call(this),n=t.configuration,r=t.serverMetadata,i=as(w(w({},b(J,this).authorizationParams),e?.authorizationParams)),a=new URLSearchParams(w(w({scope:Ws},i),{},{client_id:b(J,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:`iss_sub`,iss:r.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&a.append(`requested_expiry`,e.requestedExpiry.toString()),e.authorizationDetails&&a.append(`authorization_details`,JSON.stringify(e.authorizationDetails));try{let e=await ca(n,a);return{authReqId:e.auth_req_id,expiresIn:e.expires_in,interval:e.interval}}catch(e){throw new $o(e)}}async backchannelAuthenticationGrant(e){let t=e.authReqId,n=(await _(X,this,Q).call(this)).configuration,r=new URLSearchParams({auth_req_id:t});try{let e=await ba(n,`urn:openid:params:grant-type:ciba`,r);return Z.fromTokenEndpointResponse(e)}catch(e){throw new $o(e)}}async getTokenForConnection(e){if(e.refreshToken&&e.accessToken)throw new Yo(`Either a refresh or access token should be specified, but not both.`);let t=e.accessToken??e.refreshToken;if(!t)throw new Yo(`Either a refresh or access token must be specified.`);try{return await this.exchangeToken({connection:e.connection,subjectToken:t,subjectTokenType:e.accessToken?Js:`urn:ietf:params:oauth:token-type:refresh_token`,loginHint:e.loginHint})}catch(e){throw e instanceof Xo?new Yo(e.message,e.cause):e}}async exchangeToken(e){return`connection`in e?_(X,this,Qs).call(this,e):_(X,this,$s).call(this,e)}async getTokenByCode(e,t){let n=(await _(X,this,Q).call(this)).configuration,r;t.organization!==void 0&&os(t.organization);try{let i=await da(n,e,{pkceCodeVerifier:t.codeVerifier});r=Z.fromTokenEndpointResponse(i)}catch(e){throw new Go(`There was an error while trying to request a token.`,Ho(e))}return t.organization&&ss(r.claims,t.organization),r}async getTokenByMagicLinkCode(e,t){let n=(await _(X,this,Q).call(this)).configuration;try{let r=await da(n,e,{expectedState:t?.expectedState});return Z.fromTokenEndpointResponse(r)}catch(e){throw new Go(e instanceof Error&&e.message?e.message:`There was an error while trying to request a token.`,e)}}async getTokenByRefreshToken(e){let t=(await _(X,this,Q).call(this)).configuration,n=new URLSearchParams;e.audience&&n.append(`audience`,e.audience),e.scope&&n.append(`scope`,e.scope);try{let r=await fa(t,e.refreshToken,n);return Z.fromTokenEndpointResponse(r)}catch(e){throw new qo(`The access token has expired and there was an error while trying to refresh it.`,Ho(e))}}async revokeToken(e){let t=(await _(X,this,Q).call(this)).configuration,n={};e.tokenTypeHint&&(n.token_type_hint=e.tokenTypeHint);try{await xa(t,e.token,n)}catch(e){throw new Zo(`An error occurred while trying to revoke the token.`,Ho(e))}}async getTokenByPassword(e){let t=(await _(X,this,Q).call(this)).configuration,n=new URLSearchParams({username:e.username,password:e.password});e.audience&&n.append(`audience`,e.audience),e.scope&&n.append(`scope`,e.scope),e.realm&&n.append(`realm`,e.realm);let r=t;if(e.auth0ForwardedFor){let n=await _(X,this,tc).call(this);r=new ia(t.serverMetadata(),b(J,this).clientId,b(J,this).clientSecret,n),r[Yi]=(t,n)=>b(Y,this).call(this,t,w(w({},n),{},{headers:w(w({},n.headers),{},{"auth0-forwarded-for":e.auth0ForwardedFor})}))}try{let e=await ba(r,`password`,n);return Z.fromTokenEndpointResponse(e)}catch(e){throw new Jo(`There was an error while trying to request a token.`,Ho(e))}}async getTokenByPasswordlessEmail(e){let t=new URLSearchParams({username:e.email,otp:e.code,realm:`email`});return e.audience&&t.append(`audience`,e.audience),e.scope&&t.append(`scope`,e.scope),_(X,this,ec).call(this,t)}async getTokenByPasswordlessSms(e){if(!ks(e.phoneNumber))throw new Es(`Phone number must be in E.164 format (e.g. +14155550100).`);let t=new URLSearchParams({username:e.phoneNumber,otp:e.code,realm:`sms`});return e.audience&&t.append(`audience`,e.audience),e.scope&&t.append(`scope`,e.scope),_(X,this,ec).call(this,t)}async getTokenByClientCredentials(e){let t=(await _(X,this,Q).call(this)).configuration;try{let n=new URLSearchParams({audience:e.audience});e.organization&&n.append(`organization`,e.organization);let r=await pa(t,n);return Z.fromTokenEndpointResponse(r)}catch(e){throw new Ko(`There was an error while trying to request a token.`,Ho(e))}}async buildLogoutUrl(e){let t=await _(X,this,Q).call(this),n=t.configuration;if(!t.serverMetadata.end_session_endpoint){let t=new URL(`https://${b(J,this).domain}/v2/logout`);return t.searchParams.set(`returnTo`,e.returnTo),t.searchParams.set(`client_id`,b(J,this).clientId),t}return function(e,t){ga(e);let n=U(e),r=n.as,i=n.c,a=Kn(r,`end_session_endpoint`,!1,n.tlsOnly);(t=new URLSearchParams(t)).has(`client_id`)||t.set(`client_id`,i.client_id);for(let e of t.entries()){var o=T(e,2);let t=o[0],n=o[1];a.searchParams.append(t,n)}return a}(n,{post_logout_redirect_uri:e.returnTo})}async verifyLogoutToken(e){let t=(await _(X,this,Q).call(this)).serverMetadata,n=Hs(b(J,this).discoveryCache),r=t.jwks_uri;b(Ro,this)||S(Ro,this,function(e,t){let n=new co(e,t),r=async(e,t)=>n.getKey(e,t);return Object.defineProperties(r,{coolingDown:{get:()=>n.coolingDown(),enumerable:!0,configurable:!1},fresh:{get:()=>n.fresh(),enumerable:!0,configurable:!1},reload:{value:()=>n.reload(),enumerable:!0,configurable:!1,writable:!1},reloading:{get:()=>n.pendingFetch(),enumerable:!0,configurable:!1},jwks:{value:()=>n.jwks(),enumerable:!0,configurable:!1,writable:!1}}),r}(new URL(r),{cacheMaxAge:n.ttlMs,[Xa]:b(Y,this),[Za]:b(Vo,this)}));let i=(await ja(e.logoutToken,b(Ro,this),{issuer:t.issuer,audience:b(J,this).clientId,algorithms:[`RS256`],requiredClaims:[`iat`]})).payload;if(!(`sid`in i)&&!(`sub`in i))throw new Qo(`either "sid" or "sub" (or both) claims must be present`);if(`sid`in i&&typeof i.sid!=`string`)throw new Qo(`"sid" claim must be a string`);if(`sub`in i&&typeof i.sub!=`string`)throw new Qo(`"sub" claim must be a string`);if(`nonce`in i)throw new Qo(`"nonce" claim is prohibited`);if(!(`events`in i))throw new Qo(`"events" claim is missing`);if(typeof i.events!=`object`||i.events===null)throw new Qo(`"events" claim must be an object`);if(!(`http://schemas.openid.net/event/backchannel-logout`in i.events))throw new Qo(`"http://schemas.openid.net/event/backchannel-logout" member is missing in the "events" claim`);if(typeof i.events[`http://schemas.openid.net/event/backchannel-logout`]!=`object`)throw new Qo(`"http://schemas.openid.net/event/backchannel-logout" member in the "events" claim must be an object`);return{sid:i.sid,sub:i.sub}}});function Xs(){return`${b(J,this).domain.toLowerCase()}|mtls:${b(J,this).useMtls?`1`:`0`}`}async function Zs(e){let t=await _(X,this,tc).call(this),n=new ia(e,b(J,this).clientId,b(J,this).clientSecret,t);return n[Yi]=b(Y,this),n}async function Q(){if(b(Fo,this)&&b(Io,this))return{configuration:b(Fo,this),serverMetadata:b(Io,this)};let e=_(X,this,Xs).call(this),t=b(zo,this).get(e);if(t)return S(Io,this,t.serverMetadata),S(Fo,this,await _(X,this,Zs).call(this,t.serverMetadata)),{configuration:b(Fo,this),serverMetadata:b(Io,this)};let n=b(Bo,this).get(e);if(n){let e=await n;return S(Io,this,e.serverMetadata),S(Fo,this,await _(X,this,Zs).call(this,e.serverMetadata)),{configuration:b(Fo,this),serverMetadata:b(Io,this)}}let r=(async()=>{let t=await _(X,this,tc).call(this),n=await na(new URL(`https://${b(J,this).domain}`),b(J,this).clientId,{use_mtls_endpoint_aliases:b(J,this).useMtls},t,{[Yi]:b(Y,this)}),r=n.serverMetadata();return b(zo,this).set(e,{serverMetadata:r}),{configuration:n,serverMetadata:r}})(),i=r.then(e=>({serverMetadata:e.serverMetadata}));i.catch(()=>{}),b(Bo,this).set(e,i);try{let e=await r,t=e.configuration,n=e.serverMetadata;S(Fo,this,t),S(Io,this,n),b(Fo,this)[Yi]=b(Y,this)}finally{b(Bo,this).delete(e)}return{configuration:b(Fo,this),serverMetadata:b(Io,this)}}async function Qs(e){let t=(await _(X,this,Q).call(this)).configuration;if(`audience`in e||`resource`in e)throw new Xo(`audience and resource parameters are not supported for Token Vault exchanges`);Ks(e.subjectToken);let n=new URLSearchParams({connection:e.connection,subject_token:e.subjectToken,subject_token_type:e.subjectTokenType??Js,requested_token_type:e.requestedTokenType??`http://auth0.com/oauth/token-type/federated-connection-access-token`});e.loginHint&&n.append(`login_hint`,e.loginHint),e.scope&&n.append(`scope`,e.scope),qs(n,e.extra);try{let e=await ba(t,`urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token`,n);return Z.fromTokenEndpointResponse(e)}catch(t){throw new Xo(`Failed to exchange token for connection '${e.connection}'.`,Ho(t))}}async function $s(e){let t=(await _(X,this,Q).call(this)).configuration;if(Ks(e.subjectToken),e.organization!==void 0&&os(e.organization),e.actorToken!==void 0&&e.actorTokenType===void 0)throw new Xo(`actorTokenType is required when actorToken is provided`);let n=new URLSearchParams({subject_token_type:e.subjectTokenType,subject_token:e.subjectToken}),r,i;e.audience&&n.append(`audience`,e.audience),e.scope&&n.append(`scope`,e.scope),e.requestedTokenType&&n.append(`requested_token_type`,e.requestedTokenType),e.organization&&n.append(`organization`,e.organization),e.actorToken&&n.append(`actor_token`,e.actorToken),e.actorTokenType&&n.append(`actor_token_type`,e.actorTokenType),qs(n,e.extra);try{i=await ba(t,`urn:ietf:params:oauth:grant-type:token-exchange`,n),r=Z.fromTokenEndpointResponse(i)}catch(t){throw new Xo(`Failed to exchange token of type '${e.subjectTokenType}'${e.audience?` for audience '${e.audience}'`:``}.`,Ho(t))}var a;if(e.organization&&ss(r.claims,e.organization),e.actorToken){if((a=r.claims)!=null&&a.act)r.act=r.claims.act;else try{r.act=function(e){if(typeof e!=`string`)throw new si(`JWTs must use Compact JWS serialization, JWT must be a string`);let t=e.split(`.`),n=t[1],r=t.length;if(r===5)throw new si(`Only JWTs using Compact JWS serialization can be decoded`);if(r!==3)throw new si(`Invalid JWT`);if(!n)throw new si(`JWTs must contain a payload`);let i,a;try{i=Xr(n)}catch{throw new si(`Failed to base64url decode the payload`)}try{a=JSON.parse(Kr.decode(i))}catch{throw new si(`Failed to parse the decoded payload as JSON`)}if(!vi(a))throw new si(`Invalid JWT Claims Set`);return a}(i.access_token).act}catch{}}return r}async function ec(e){let t=(await _(X,this,Q).call(this)).configuration;try{let n=await ba(t,`http://auth0.com/oauth/grant-type/passwordless/otp`,e);return Z.fromTokenEndpointResponse(n)}catch(e){throw new Es(`There was an error while trying to request a token.`,Ho(e))}}async function tc(){return b(Lo,this)||S(Lo,this,(async()=>{if(!b(J,this).clientSecret&&!b(J,this).clientAssertionSigningKey&&!b(J,this).useMtls)throw new rs;if(b(J,this).useMtls)return(e,t,n,r)=>{n.set(`client_id`,t.client_id)};let e=b(J,this).clientAssertionSigningKey;return!e||e instanceof CryptoKey||(e=await Li(e,b(J,this).clientAssertionSigningAlg||`RS256`)),e?function(e,t){return Hn(e,t)}(e):Ji(b(J,this).clientSecret)})().catch(e=>{throw S(Lo,this,void 0),e})),b(Lo,this)}async function nc(e){let t=(await _(X,this,Q).call(this)).configuration,n=ea(),r=await $i(n),i=as(w(w({},b(J,this).authorizationParams),e?.authorizationParams)),a=new URLSearchParams(w(w({scope:Ws},i),{},{client_id:b(J,this).clientId,code_challenge:r,code_challenge_method:`S256`}));return{authorizationUrl:e!=null&&e.pushedAuthorizationRequests?await ha(t,a):await ma(t,a),codeVerifier:n}}var rc=class e extends D{constructor(t,n){super(t,n),Object.setPrototypeOf(this,e.prototype)}static fromPayload(t){let n=t.error,r=t.error_description;return new e(n,r)}},ic=class e extends rc{constructor(t,n){super(t,n),Object.setPrototypeOf(this,e.prototype)}},ac=class e extends rc{constructor(t,n){super(t,n),Object.setPrototypeOf(this,e.prototype)}},oc=class e extends rc{constructor(t,n){super(t,n),Object.setPrototypeOf(this,e.prototype)}},sc=class e extends rc{constructor(t,n){super(t,n),Object.setPrototypeOf(this,e.prototype)}},cc=class e extends rc{constructor(t,n){super(t,n),Object.setPrototypeOf(this,e.prototype)}},lc=class{constructor(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:6e5;this.contexts=new Map,this.ttlMs=e}set(e,t){this.cleanup(),this.contexts.set(e,Object.assign(Object.assign({},t),{createdAt:Date.now()}))}get(e){let t=this.contexts.get(e);if(t){if(!(Date.now()-t.createdAt>this.ttlMs))return t;this.contexts.delete(e)}}remove(e){this.contexts.delete(e)}cleanup(){let e=Date.now();for(let n of this.contexts){var t=T(n,2);let r=t[0];e-t[1].createdAt>this.ttlMs&&this.contexts.delete(r)}}get size(){return this.contexts.size}},uc=class{constructor(e,t){this.authJsMfaClient=e,this.auth0Client=t,this.contextManager=new lc}setMFAAuthDetails(e,t,n,r){this.contextManager.set(e,{scope:t,audience:n,mfaRequirements:r})}async getAuthenticators(e){let t=this.contextManager.get(e);if(!t)throw new ic(`invalid_request`,`MFA context not found for this MFA token`);let n=(t.mfaRequirements?.challenge)?.map(e=>e.type);try{let t=await this.authJsMfaClient.listAuthenticators({mfaToken:e});return n&&n.length!==0?t.filter(e=>!!e.type&&n.includes(e.type)):t}catch(e){throw e instanceof ls?new ic(e.cause?.error,e.message):e}}async enroll(e){let t=function(e){let t=ln[e.factorType];return Object.assign(Object.assign(Object.assign({mfaToken:e.mfaToken,authenticatorTypes:t.authenticatorTypes},t.oobChannels&&{oobChannels:t.oobChannels}),`phoneNumber`in e&&{phoneNumber:e.phoneNumber}),`email`in e&&{email:e.email})}(e);try{return await this.authJsMfaClient.enrollAuthenticator(t)}catch(e){throw e instanceof us?new ac(e.cause?.error,e.message):e}}async challenge(e){try{let t={challengeType:e.challengeType,mfaToken:e.mfaToken};return e.authenticatorId&&(t.authenticatorId=e.authenticatorId),await this.authJsMfaClient.challengeAuthenticator(t)}catch(e){throw e instanceof fs?new oc(e.cause?.error,e.message):e}}async getEnrollmentFactors(e){let t=this.contextManager.get(e);if(!t||!t.mfaRequirements)throw new cc(`mfa_context_not_found`,`MFA context not found for this MFA token. Please retry the original request to get a new MFA token.`);return t.mfaRequirements.enroll&&t.mfaRequirements.enroll.length!==0?t.mfaRequirements.enroll:[]}async verify(e){let t=this.contextManager.get(e.mfaToken);if(!t)throw new sc(`mfa_context_not_found`,`MFA context not found for this MFA token. Please retry the original request to get a new MFA token.`);let n=function(e){return`otp`in e&&e.otp?un:`oobCode`in e&&e.oobCode?dn:`recoveryCode`in e&&e.recoveryCode?fn:void 0}(e);if(!n)throw new sc(`invalid_request`,`Unable to determine grant type. Provide one of: otp, oobCode, or recoveryCode.`);let r=t.scope,i=t.audience;try{let t=await this.auth0Client._requestTokenForMfa({grant_type:n,mfaToken:e.mfaToken,scope:r,audience:i,otp:e.otp,oob_code:e.oobCode,binding_code:e.bindingCode,recovery_code:e.recoveryCode});return this.contextManager.remove(e.mfaToken),t}catch(e){throw e instanceof sc?new sc(e.error,e.error_description):e}}},dc=class e extends Error{constructor(t,n,r){super(n),this.name=`PasskeyError`,this.code=t,this.cause=r,Object.setPrototypeOf(this,e.prototype)}},fc,pc,mc=class{constructor(e,t){fc.set(this,void 0),pc.set(this,void 0),m(this,fc,e,`f`),m(this,pc,t,`f`)}async signup(e){if(!window.PublicKeyCredential)throw new dc(`passkey_not_supported`,`WebAuthn is not supported in this browser.`);let t=e.scope,n=e.audience,r=f(e,[`scope`,`audience`]),i=await p(this,fc,`f`).register(r),a=_c(i.authnParamsPublicKey),o=await navigator.credentials.create({publicKey:a});if(!o)throw new dc(`passkey_cancelled`,`Passkey creation was cancelled or no credential was returned.`);let s=yc(o);return p(this,pc,`f`)._requestTokenForPasskey({authSession:i.authSession,credential:s,realm:r.realm,organization:r.organization,scope:t,audience:n})}async login(e){if(!window.PublicKeyCredential)throw new dc(`passkey_not_supported`,`WebAuthn is not supported in this browser.`);let t=e||{},n=t.scope,r=t.audience,i=f(t,[`scope`,`audience`]),a=await p(this,fc,`f`).challenge(Object.keys(i).length>0?i:void 0),o=vc(a.authnParamsPublicKey),s=await navigator.credentials.get({publicKey:o});if(!s)throw new dc(`passkey_cancelled`,`Passkey authentication was cancelled or no credential was returned.`);let c=bc(s);return p(this,pc,`f`)._requestTokenForPasskey({authSession:a.authSession,credential:c,realm:i.realm,organization:i.organization,scope:n,audience:r})}async getSignupChallenge(e){if(!window.PublicKeyCredential)throw new dc(`passkey_not_supported`,`WebAuthn is not supported in this browser.`);let t=await p(this,fc,`f`).register(e);return{authSession:t.authSession,publicKey:_c(t.authnParamsPublicKey)}}async getLoginChallenge(e){if(!window.PublicKeyCredential)throw new dc(`passkey_not_supported`,`WebAuthn is not supported in this browser.`);let t=await p(this,fc,`f`).challenge(e);return{authSession:t.authSession,publicKey:vc(t.authnParamsPublicKey)}}async getTokenWithPasskey(e){if(!window.PublicKeyCredential)throw new dc(`passkey_not_supported`,`WebAuthn is not supported in this browser.`);let t=e.authSession,n=e.credential,r=e.realm,i=e.organization,a=e.scope,o=e.audience,s=n.response,c;if(s instanceof AuthenticatorAttestationResponse)c=yc(n);else{if(!(s instanceof AuthenticatorAssertionResponse))throw new dc(`passkey_invalid_credential`,`The provided credential is not a valid attestation or assertion response.`);c=bc(n)}return p(this,pc,`f`)._requestTokenForPasskey({authSession:t,credential:c,realm:r,organization:i,scope:a,audience:o})}};function hc(e){let t=new Uint8Array(e),n=Array.from(t,e=>String.fromCharCode(e)).join(``);return btoa(n).replace(/\+/g,`-`).replace(/\//g,`_`).replace(/=+$/,``)}function gc(e){let t=e.replace(/-/g,`+`).replace(/_/g,`/`),n=t+`=`.repeat((4-t.length%4)%4),r=atob(n),i=new Uint8Array(r.length);for(let e=0;e<r.length;e++)i[e]=r.charCodeAt(e);return i.buffer}function _c(e){return Object.assign(Object.assign({},e),{challenge:gc(e.challenge),user:Object.assign(Object.assign({},e.user),{id:gc(e.user.id)}),pubKeyCredParams:e.pubKeyCredParams,authenticatorSelection:e.authenticatorSelection})}function vc(e){return Object.assign(Object.assign({},e),{challenge:gc(e.challenge)})}function yc(e){let t=e.response;return{id:e.id,rawId:hc(e.rawId),type:e.type,authenticatorAttachment:e.authenticatorAttachment??void 0,response:{clientDataJSON:hc(t.clientDataJSON),attestationObject:hc(t.attestationObject)},clientExtensionResults:e.getClientExtensionResults()}}function bc(e){let t=e.response;return{id:e.id,rawId:hc(e.rawId),type:e.type,authenticatorAttachment:e.authenticatorAttachment??void 0,response:{clientDataJSON:hc(t.clientDataJSON),authenticatorData:hc(t.authenticatorData),signature:hc(t.signature),userHandle:t.userHandle?hc(t.userHandle):void 0},clientExtensionResults:e.getClientExtensionResults()}}fc=new WeakMap,pc=new WeakMap;var xc=class{resolveOnlineAccess(e){if(e.refreshTokenMode!==`online`)return!1;if(!0!==e.useRefreshTokens)throw new de('`refreshTokenMode: "online"` requires the refresh-token grant.',"Set `useRefreshTokens: true`.");if(!0!==e.useDpop)throw new de('`refreshTokenMode: "online"` requires DPoP, which is missing or disabled.',"Set `useDpop: true` (DPoP is mandatory for online access).");return!0}constructor(e){let t,n;if(this.userCache=new wt().enclosedCache,this.defaultOptions={authorizationParams:{scope:`openid profile email`},useRefreshTokensFallback:!1,useFormData:!0,refreshTokenMode:`offline`},this.onlineAccess=this.resolveOnlineAccess(e),this.options=Object.assign(Object.assign(Object.assign({},this.defaultOptions),e),{authorizationParams:Object.assign(Object.assign({},this.defaultOptions.authorizationParams),e.authorizationParams)}),typeof window<`u`&&(()=>{if(!Ce())throw Error("For security reasons, `window.crypto` is required to run `auth0-spa-js`.");if(Ce().subtle===void 0)throw Error(`
      auth0-spa-js must run on a secure origin. See https://github.com/auth0/auth0-spa-js/blob/main/FAQ.md#why-do-i-get-auth0-spa-js-must-run-on-a-secure-origin for more information.
    `)})(),this.lockManager=(Je||=qe(),Je),e.cache&&e.cacheLocation&&console.warn("Both `cache` and `cacheLocation` options have been specified in the Auth0Client configuration; ignoring `cacheLocation` and using `cache`."),e.cache)n=e.cache;else{if(t=e.cacheLocation||se,!Qt(t))throw Error(`Invalid cache location "${t}"`);n=Qt(t)()}var r;this.httpTimeoutMs=e.httpTimeoutInSeconds?1e3*e.httpTimeoutInSeconds:oe,this.cookieStorage=!1===e.legacySameSiteCookie?Rt:Bt,this.orgHintCookieName=(r=this.options.clientId,`auth0.${r}.organization_hint`),this.isAuthenticatedCookieName=(e=>`auth0.${e}.is.authenticated`)(this.options.clientId),this.sessionCheckExpiryDays=e.sessionCheckExpiryDays||1;let i=e.useCookiesForTransactions?this.cookieStorage:Vt,a=``;var o;this.onlineAccess?a=ce:this.options.useRefreshTokens&&(a=`offline_access`),this.scope=function(e,t){var n=[...arguments].slice(2);if(typeof e!=`object`)return{[E]:yt(t,e,...n)};let r={[E]:yt(t,...n)};return Object.keys(e).forEach(i=>{let a=e[i];r[i]=yt(t,a,...n)}),r}(this.options.authorizationParams.scope,`openid`,a),this.transactionManager=new Et(i,this.options.clientId,this.options.cookieDomain),this.nowProvider=this.options.nowProvider||ue,this.cacheManager=new Tt(n,n.allKeys?void 0:new Yt(n,this.options.clientId),this.nowProvider),this.dpop=this.options.useDpop?new rn(this.options.clientId):void 0,this.domainUrl=(o=this.options.domain,/^https?:\/\//.test(o)?o:`https://${o}`),this.tokenIssuer=((e,t)=>e?e.startsWith(`https://`)?e:`https://${e}/`:`${t}/`)(this.options.issuer,this.domainUrl);let s=`${this.domainUrl}/me/`,c=this.createFetcher(Object.assign(Object.assign({},this.options.useDpop&&{dpopNonceId:`__auth0_my_account_api__`}),{getAccessToken:e=>this.getTokenSilently({authorizationParams:{scope:(e?.scope)?.join(` `),audience:s},detailedResponse:!0})}));this.myAccount=new sn(c,s),this.authJsClient=new Ys({domain:this.options.domain,clientId:this.options.clientId}),this.mfa=new uc(this.authJsClient.mfa,this),this.passkey=new mc(this.authJsClient.passkey,this),typeof window<`u`&&window.Worker&&this.options.useRefreshTokens&&t===se&&(this.worker=this.options.workerUrl?new Worker(this.options.workerUrl):new Jt,this.worker.postMessage({type:`init`,allowedBaseUrl:this.domainUrl}))}getConfiguration(){return Object.freeze({domain:this.options.domain,clientId:this.options.clientId})}_url(e){let t=De(this.options.auth0Client||le,!0),n=encodeURIComponent(btoa(JSON.stringify(t)));return`${this.domainUrl}${e}&auth0Client=${n}`}_authorizeUrl(e){return this._url(`/authorize?${Oe(e)}`)}async _verifyIdToken(e,t,n){let r=await this.nowProvider();return kt({iss:this.tokenIssuer,aud:this.options.clientId,id_token:e,nonce:t,organization:n,leeway:this.options.leeway,max_age:(i=this.options.authorizationParams.max_age,typeof i==`string`?parseInt(i,10)||void 0:i),now:r});var i}_processOrgHint(e){e?this.cookieStorage.save(this.orgHintCookieName,e,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}):this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain})}_extractSessionTransferToken(e){return new URLSearchParams(window.location.search).get(e)||void 0}_clearSessionTransferTokenFromUrl(e){try{let t=new URL(window.location.href);t.searchParams.has(e)&&(t.searchParams.delete(e),window.history.replaceState({},``,t.toString()))}catch{}}_applySessionTransferToken(e){let t=this.options.sessionTransferTokenQueryParamName;if(!t||e.session_transfer_token)return e;let n=this._extractSessionTransferToken(t);return n?(this._clearSessionTransferTokenFromUrl(t),Object.assign(Object.assign({},e),{session_transfer_token:n})):e}async _prepareAuthorizeUrl(e,t,n){let r=Te(we()),i=Te(we()),a=we(),o=je(await ke(a)),s=await this.dpop?.calculateThumbprint(),c=((e,t,n,r,i,a,o,s,c)=>Object.assign(Object.assign(Object.assign({client_id:e.clientId},e.authorizationParams),n),{scope:bt(t,n.scope,n.audience),response_type:`code`,response_mode:s||`query`,state:r,nonce:i,redirect_uri:o||e.authorizationParams.redirect_uri,code_challenge:a,code_challenge_method:`S256`,dpop_jkt:c}))(this.options,this.scope,e,r,i,o,e.redirect_uri||this.options.authorizationParams.redirect_uri||n,t?.response_mode,s),l=this._authorizeUrl(c);return{nonce:i,code_verifier:a,scope:c.scope,audience:c.audience||E,redirect_uri:c.redirect_uri,state:r,url:l}}async loginWithPopup(e,t){if(e||={},!(t||={}).popup&&(t.popup=(e=>{let t=window.screenX+(window.innerWidth-400)/2,n=window.screenY+(window.innerHeight-600)/2;return window.open(e,`auth0:authorize:popup`,`left=${t},top=${n},width=400,height=600,resizable,scrollbars=yes,status=1`)})(``),!t.popup))throw new _e;let n=this._applySessionTransferToken(e.authorizationParams||{}),r=await this._prepareAuthorizeUrl(n,{response_mode:`web_message`},window.location.origin);t.popup.location.href=r.url;let i=await((e,t)=>new Promise((n,r)=>{let i,a=setInterval(()=>{e.popup&&e.popup.closed&&(clearInterval(a),clearTimeout(o),window.removeEventListener(`message`,i,!1),r(new ge(e.popup)))},1e3),o=setTimeout(()=>{clearInterval(a),r(new he(e.popup)),window.removeEventListener(`message`,i,!1)},1e3*(e.timeoutInSeconds||60));i=function(s){if(s.origin===t&&s.data&&s.data.type===`authorization_response`){if(clearTimeout(o),clearInterval(a),window.removeEventListener(`message`,i,!1),!1!==e.closePopup&&e.popup.close(),s.data.response.error)return r(D.fromPayload(s.data.response));n(s.data.response)}},window.addEventListener(`message`,i)}))(Object.assign(Object.assign({},t),{timeoutInSeconds:t.timeoutInSeconds||this.options.authorizeTimeoutInSeconds||60}),new URL(r.url).origin);if(r.state!==i.state)throw new D(`state_mismatch`,`Invalid state`);let a=e.authorizationParams?.organization||this.options.authorizationParams.organization;await this._requestToken({audience:r.audience,scope:r.scope,code_verifier:r.code_verifier,grant_type:`authorization_code`,code:i.code,redirect_uri:r.redirect_uri},{nonceIn:r.nonce,organization:a})}async getUser(){return await this._isSessionCeilingReached()?void 0:(await this._getIdTokenFromCache())?.decodedToken?.user}async getIdTokenClaims(){return await this._isSessionCeilingReached()?void 0:(await this._getIdTokenFromCache())?.decodedToken?.claims}async loginWithRedirect(){let e=$t(arguments.length>0&&arguments[0]!==void 0?arguments[0]:{}),t=e.openUrl,n=e.fragment,r=e.appState,i=f(e,[`openUrl`,`fragment`,`appState`]),a=i.authorizationParams?.organization||this.options.authorizationParams.organization,o=this._applySessionTransferToken(i.authorizationParams||{}),s=await this._prepareAuthorizeUrl(o),c=s.url,l=f(s,[`url`]);this.transactionManager.create(Object.assign(Object.assign(Object.assign({},l),{appState:r,response_type:Ht.Code}),a&&{organization:a}));let u=n?`${c}#${n}`:c;t?await t(u):window.location.assign(u)}async handleRedirectCallback(){let e=(arguments.length>0&&arguments[0]!==void 0?arguments[0]:window.location.href).split(`?`).slice(1);if(e.length===0)throw Error(`There are no query params available for parsing.`);let t=this.transactionManager.get();if(!t)throw new D(`missing_transaction`,`Invalid state`);this.transactionManager.remove();let n=(e=>{e.indexOf(`#`)>-1&&(e=e.substring(0,e.indexOf(`#`)));let t=new URLSearchParams(e);return{state:t.get(`state`),code:t.get(`code`)||void 0,connect_code:t.get(`connect_code`)||void 0,error:t.get(`error`)||void 0,error_description:t.get(`error_description`)||void 0}})(e.join(``));return t.response_type===Ht.ConnectCode?this._handleConnectAccountRedirectCallback(n,t):this._handleLoginRedirectCallback(n,t)}async _handleLoginRedirectCallback(e,t){let n=e.code,r=e.state,i=e.error,a=e.error_description;if(i)throw new fe(i,a||i,r,t.appState);if(!t.code_verifier||t.state&&t.state!==r)throw new D(`state_mismatch`,`Invalid state`);let o=t.organization,s=t.nonce,c=t.redirect_uri;return await this._requestToken(Object.assign({audience:t.audience,scope:t.scope,code_verifier:t.code_verifier,grant_type:`authorization_code`,code:n},c?{redirect_uri:c}:{}),{nonceIn:s,organization:o}),{appState:t.appState,response_type:Ht.Code}}async _handleConnectAccountRedirectCallback(e,t){let n=e.connect_code,r=e.state,i=e.error,a=e.error_description;if(i)throw new pe(i,a||i,t.connection,r,t.appState);if(!n)throw new D(`missing_connect_code`,`Missing connect code`);if(!(t.code_verifier&&t.state&&t.auth_session&&t.redirect_uri&&t.state===r))throw new D(`state_mismatch`,`Invalid state`);let o=await this.myAccount.completeAccount({auth_session:t.auth_session,connect_code:n,redirect_uri:t.redirect_uri,code_verifier:t.code_verifier});return Object.assign(Object.assign({},o),{appState:t.appState,response_type:Ht.ConnectCode})}async checkSession(e){if(!this.cookieStorage.get(this.isAuthenticatedCookieName)){if(!this.cookieStorage.get(Xt))return;this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(Xt)}try{await this.getTokenSilently(e)}catch{}}async getTokenSilently(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{},t=Object.assign(Object.assign({cacheMode:`on`},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:bt(this.scope,e.authorizationParams?.scope,e.authorizationParams?.audience||this.options.authorizationParams.audience)})}),n=await this._getTokenSilently(t);return e.detailedResponse?n:n?.access_token}async _getTokenSilently(e){let t=e.cacheMode,n=f(e,[`cacheMode`]);if(await this._isSessionCeilingReached())return;if(t!==`off`){let e=await this._getEntryFromCache({scope:n.authorizationParams.scope,audience:n.authorizationParams.audience||E,clientId:this.options.clientId,cacheMode:t});if(e)return e}if(t===`cache-only`)return;let r=(i=this.options.clientId,a=n.authorizationParams.audience||`default`,`auth0.lock.getTokenSilently.${i}.${a}`);var i,a;try{return await this.lockManager.runWithLock(r,5e3,async()=>{if(t!==`off`){let e=await this._getEntryFromCache({scope:n.authorizationParams.scope,audience:n.authorizationParams.audience||E,clientId:this.options.clientId});if(e)return e}let e=this.options.useRefreshTokens?await this._getTokenUsingRefreshToken(n):await this._getTokenFromIFrame(n),r=e.id_token,i=e.token_type,a=e.access_token,o=e.oauthTokenScope,s=e.expires_in;return Object.assign(Object.assign({id_token:r,token_type:i,access_token:a},o?{scope:o}:null),{expires_in:s})})}catch(e){if(this._isInteractiveError(e)&&this.options.interactiveErrorHandler===`popup`)return await this._handleInteractiveErrorWithPopup(n);throw e}}_isInteractiveError(e){return e instanceof ve||e instanceof D&&this._isIframeMfaError(e)}_isIframeMfaError(e){return e.error===`login_required`&&e.error_description===`Multifactor authentication required`}async _handleInteractiveErrorWithPopup(e){try{await this.loginWithPopup({authorizationParams:e.authorizationParams});let t=await this._getEntryFromCache({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||E,clientId:this.options.clientId});if(!t)throw new D(`interactive_handler_cache_miss`,`Token not found in cache after interactive authentication`);return t}catch(e){throw e}}async getTokenWithPopup(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{},t=arguments.length>1&&arguments[1]!==void 0?arguments[1]:{},n=Object.assign(Object.assign({},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:bt(this.scope,e.authorizationParams?.scope,e.authorizationParams?.audience||this.options.authorizationParams.audience)})});return t=Object.assign(Object.assign({},ae),t),await this.loginWithPopup(n,t),(await this.cacheManager.get(new O({scope:n.authorizationParams.scope,audience:n.authorizationParams.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt)).access_token}async isAuthenticated(){return!!await this.getUser()}_buildLogoutUrl(e){e.clientId===null?delete e.clientId:e.clientId=e.clientId||this.options.clientId;let t=e.logoutParams||{},n=t.federated,r=f(t,[`federated`]),i=n?`&federated`:``;return this._url(`/v2/logout?${Oe(Object.assign({clientId:e.clientId},r))}`)+i}async revokeRefreshToken(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{};if(!this.options.useRefreshTokens)return;let t=e.audience||this.options.authorizationParams.audience||E,n=await this.cacheManager.getRefreshTokensByAudience(t,this.options.clientId);await async function(e,t){let n=e.baseUrl,r=e.timeout,i=e.auth0Client,a=e.useFormData,o=e.refreshTokens,s=e.audience,c=e.client_id,l=e.onRefreshTokenRevoked,u=r||oe,d=`refresh_token`,f=`${n}/oauth/revoke`,p={"Content-Type":a?`application/x-www-form-urlencoded`:`application/json`,"Auth0-Client":btoa(JSON.stringify(De(i||le)))};if(t){let e={client_id:c,token_type_hint:d},n=a?Oe(e):JSON.stringify(e);try{return await mt({type:`revoke`,timeout:u,fetchUrl:f,fetchOptions:{method:`POST`,body:n,headers:p},useFormData:a,auth:{audience:s??E}},t)}catch(e){throw new D(`revoke_error`,e.message)}}for(let e of o){let t={client_id:c,token_type_hint:d,token:e},n=await ht(f,{method:`POST`,body:a?Oe(t):JSON.stringify(t),headers:p},u);if(!n.ok){let e,t;try{var m=JSON.parse(await n.text());e=m.error,t=m.error_description}catch{}throw new D(e||`revoke_error`,t||`HTTP error ${n.status}`)}await l?.(e)}}({baseUrl:this.domainUrl,timeout:this.httpTimeoutMs,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,client_id:this.options.clientId,refreshTokens:n,audience:t,onRefreshTokenRevoked:e=>this.cacheManager.stripRefreshToken(e)},this.worker),this.onlineAccess&&await this._clearLocalSession()}async logout(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{},t=$t(e),n=t.openUrl,r=f(t,[`openUrl`]);await this._clearLocalSession(e.clientId);let i=this._buildLogoutUrl(r);n?await n(i):!1!==n&&window.location.assign(i)}async _getTokenFromIFrame(e){let t=(n=this.options.clientId,`auth0.lock.getTokenFromIFrame.${n}`);var n;try{return await this.lockManager.runWithLock(t,5e3,async()=>{let t=Object.assign(Object.assign({},e.authorizationParams),{prompt:`none`}),n=this.cookieStorage.get(this.orgHintCookieName);n&&!t.organization&&(t.organization=n);let r=await this._prepareAuthorizeUrl(t,{response_mode:`web_message`},window.location.origin),i=r.url,a=r.state,o=r.nonce,s=r.code_verifier,c=r.redirect_uri,l=r.scope,u=r.audience;if(window.crossOriginIsolated)throw new D(`login_required`,`The application is running in a Cross-Origin Isolated context, silently retrieving a token without refresh token is not possible.`);let d=e.timeoutInSeconds||this.options.authorizeTimeoutInSeconds,f;try{f=new URL(this.domainUrl).origin}catch{f=this.domainUrl}let p=await function(e,t){let n=arguments.length>2&&arguments[2]!==void 0?arguments[2]:60;return new Promise((r,i)=>{let a=window.document.createElement(`iframe`);a.setAttribute(`width`,`0`),a.setAttribute(`height`,`0`),a.style.display=`none`;let o=()=>{window.document.body.contains(a)&&(window.document.body.removeChild(a),window.removeEventListener(`message`,s,!1))},s,c=setTimeout(()=>{i(new me),o()},1e3*n);s=function(e){if(e.origin!=t||!e.data||e.data.type!==`authorization_response`)return;let n=e.source;n&&n.close(),e.data.response.error?i(D.fromPayload(e.data.response)):r(e.data.response),clearTimeout(c),window.removeEventListener(`message`,s,!1),setTimeout(o,2e3)},window.addEventListener(`message`,s,!1),window.document.body.appendChild(a),a.setAttribute(`src`,e)})}(i,f,d);if(a!==p.state)throw new D(`state_mismatch`,`Invalid state`);let m=await this._requestToken(Object.assign(Object.assign({},e.authorizationParams),{code_verifier:s,code:p.code,grant_type:`authorization_code`,redirect_uri:c,timeout:e.authorizationParams.timeout||this.httpTimeoutMs}),{nonceIn:o,organization:t.organization});return Object.assign(Object.assign({},m),{scope:l,oauthTokenScope:m.scope,audience:u})})}catch(e){throw e.error===`login_required`&&(e instanceof D&&this._isIframeMfaError(e)&&this.options.interactiveErrorHandler===`popup`||this.logout({openUrl:!1})),e}}async _getTokenUsingRefreshToken(e){let t=await this.cacheManager.get(new O({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt);if(!(t&&t.refresh_token||this.worker)){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw new ye(e.authorizationParams.audience||E,e.authorizationParams.scope)}let n=e.authorizationParams.redirect_uri||this.options.authorizationParams.redirect_uri||window.location.origin,r=typeof e.timeoutInSeconds==`number`?1e3*e.timeoutInSeconds:null,i=((e,t,n,r)=>{if(e&&n&&r){if(t.audience!==n)return t.scope;let e=r.split(` `),i=t.scope?.split(` `)||[],a=i.every(t=>e.includes(t));return e.length>=i.length&&a?r:t.scope}return t.scope})(this.options.useMrrt,e.authorizationParams,t?.audience,t?.scope);try{let l=await this._requestToken(Object.assign(Object.assign(Object.assign({},e.authorizationParams),{grant_type:`refresh_token`,refresh_token:t&&t.refresh_token,redirect_uri:n}),r&&{timeout:r}),{scopesToRequest:i});if(!this.onlineAccess&&l.refresh_token&&t!=null&&t.refresh_token&&await this.cacheManager.updateEntry(t.refresh_token,l.refresh_token,this.options.clientId,this.options.useMrrt),this.options.useMrrt&&(a=t?.audience,o=t?.scope,s=e.authorizationParams.audience,c=e.authorizationParams.scope,a!==s||!((e,t)=>{let n=t?.split(` `)||[];return(e?.split(` `)||[]).every(e=>n.includes(e))})(c,o))){let t=en(i,l.scope,this.onlineAccess);if(t){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw await this.cacheManager.remove(this.options.clientId,e.authorizationParams.audience,e.authorizationParams.scope),new be(e.authorizationParams.audience||`default`,t)}}return Object.assign(Object.assign({},l),{scope:e.authorizationParams.scope,oauthTokenScope:l.scope,audience:e.authorizationParams.audience||E})}catch(t){if(t.message){if(t.message.includes(`user is blocked`))throw await this.logout({openUrl:!1}),t;if((t.message.includes(`Missing Refresh Token`)||t.message.includes(`invalid refresh token`))&&this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e)}throw t}var a,o,s,c}async _saveEntryInCache(e){let t=e.decodedToken.claims,n=t.session_expiry,r=t.iat;if(n!==void 0){if(typeof n!=`number`)throw new D(`invalid_token`,`Invalid session_expiry: value must be a number.`);if(n>=1e10)throw new D(`invalid_token`,`Invalid session_expiry: value appears to be in milliseconds; expected a Unix timestamp in seconds.`);if(r===void 0||n<=r)throw new D(`invalid_token`,`Invalid session_expiry: session ceiling is before or at the token issue time.`)}let i=e.id_token,a=e.decodedToken,o=f(e,[`id_token`,`decodedToken`]);this.userCache.set(St,{id_token:i,decodedToken:a}),await this.cacheManager.setIdToken(this.options.clientId,e.id_token,e.decodedToken),await this.cacheManager.set(o)}async _clearLocalSession(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:this.options.clientId;e===null?await this.cacheManager.clear():await this.cacheManager.clear(e),this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(this.isAuthenticatedCookieName,{cookieDomain:this.options.cookieDomain}),this.userCache.remove(St);try{await this.dpop?.clear()}catch{}if(this.worker)try{await mt({type:`clear`},this.worker)}catch{}}async _isSessionCeilingReached(){let e=(this.userCache.get(St)??await this.cacheManager.getIdToken(new O({clientId:this.options.clientId})))?.decodedToken?.claims?.session_expiry;if(e===void 0)return!1;let t=await this.nowProvider();return Math.floor(t/1e3)>=e-30&&(await this._clearLocalSession(),!0)}async _getIdTokenFromCache(){let e=this.options.authorizationParams.audience||E,t=this.scope[e],n=await this.cacheManager.getIdToken(new O({clientId:this.options.clientId,audience:e,scope:t})),r=this.userCache.get(St);return n&&n.id_token===r?.id_token?r:(this.userCache.set(St,n),n)}async _getEntryFromCache(e){let t=e.scope,n=e.audience,r=e.clientId,i=e.cacheMode,a=await this.cacheManager.get(new O({scope:t,audience:n,clientId:r}),60,this.options.useMrrt,i);if(a&&a.access_token){let e=a.token_type,t=a.access_token,n=a.oauthTokenScope,r=a.expires_in,i=await this._getIdTokenFromCache();return i&&Object.assign(Object.assign({id_token:i.id_token,token_type:e||`Bearer`,access_token:t},n?{scope:n}:null),{expires_in:r})}}_storeMfaContext(e,t,n){e instanceof ve&&this.mfa.setMFAAuthDetails(e.mfa_token,t,n,e.mfa_requirements)}async _requestToken(e,t){var n;let r=t||{},i=r.nonceIn,a=r.organization,o=r.scopesToRequest;try{let t=await vt(Object.assign(Object.assign({baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,useMrrt:this.options.useMrrt,dpop:this.dpop,preserveRefreshToken:this.onlineAccess},e),{scope:o||e.scope}),this.worker),r=await this._verifyIdToken(t.id_token,i,a);if(e.grant_type===`authorization_code`){let e=await this._getIdTokenFromCache();(n=e?.decodedToken?.claims)!=null&&n.sub&&e.decodedToken.claims.sub!==r.claims.sub&&(await this.cacheManager.clear(this.options.clientId),this.userCache.remove(St))}if(e.grant_type!==`authorization_code`){let e=(await this._getIdTokenFromCache())?.decodedToken?.claims?.session_expiry;e!==void 0&&(r=Object.assign(Object.assign({},r),{claims:Object.assign(Object.assign({},r.claims),{session_expiry:e})}))}return!t.refresh_token&&this.onlineAccess&&(t.refresh_token=e.refresh_token??(await this.cacheManager.get(new O({scope:o||e.scope,audience:e.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt))?.refresh_token),await this._saveEntryInCache(Object.assign(Object.assign(Object.assign(Object.assign({},t),{decodedToken:r,scope:e.scope,audience:e.audience||E}),t.scope?{oauthTokenScope:t.scope}:null),{client_id:this.options.clientId})),this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this._processOrgHint(a||r.claims.org_id),Object.assign(Object.assign({},t),{decodedToken:r})}catch(t){throw e.grant_type!==`authorization_code`&&this._storeMfaContext(t,o||e.scope,e.audience),t}}_buildTokenExchangeParams(e){return Object.assign(Object.assign(Object.assign(Object.assign(Object.assign({},e),{grant_type:`urn:ietf:params:oauth:grant-type:token-exchange`,subject_token:e.subject_token,subject_token_type:e.subject_token_type}),e.actor_token&&{actor_token:e.actor_token}),e.actor_token_type&&{actor_token_type:e.actor_token_type}),{scope:bt(this.scope,e.scope,e.audience||this.options.authorizationParams.audience),audience:e.audience||this.options.authorizationParams.audience,organization:e.organization||this.options.authorizationParams.organization})}async loginWithCustomTokenExchange(e){return this._requestToken(this._buildTokenExchangeParams(e))}async customTokenExchange(e){let t=this._buildTokenExchangeParams(e);try{let n=await vt(Object.assign(Object.assign({},t),{baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,dpop:this.dpop}),this.worker,!0);return n.id_token&&await this._verifyIdToken(n.id_token,void 0,e.organization),n}catch(e){throw this._storeMfaContext(e,t.scope,t.audience),e}}async exchangeToken(e){return this.loginWithCustomTokenExchange(e)}_assertDpop(e){if(!e)throw Error("`useDpop` option must be enabled before using DPoP.")}getDpopNonce(e){return this._assertDpop(this.dpop),this.dpop.getNonce(e)}setDpopNonce(e,t){return this._assertDpop(this.dpop),this.dpop.setNonce(e,t)}generateDpopProof(e){return this._assertDpop(this.dpop),this.dpop.generateProof(e)}createFetcher(){let e=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{};return new on(e,{isDpopEnabled:()=>!!this.options.useDpop,getAccessToken:e=>this.getTokenSilently({authorizationParams:{scope:(e?.scope)?.join(` `),audience:e?.audience},detailedResponse:!0}),getDpopNonce:()=>this.getDpopNonce(e.dpopNonceId),setDpopNonce:t=>this.setDpopNonce(t,e.dpopNonceId),generateDpopProof:e=>this.generateDpopProof(e)})}async connectAccountWithRedirect(e){let t=e.openUrl,n=e.appState,r=e.connection,i=e.scopes,a=e.authorization_params,o=e.redirectUri,s=o===void 0?this.options.authorizationParams.redirect_uri||window.location.origin:o;if(!r)throw Error(`connection is required`);let c=Te(we()),l=we(),u=je(await ke(l)),d=await this.myAccount.connectAccount({connection:r,scopes:i,redirect_uri:s,state:c,code_challenge:u,code_challenge_method:`S256`,authorization_params:a}),f=d.connect_uri,p=d.connect_params,m=d.auth_session;this.transactionManager.create({state:c,code_verifier:l,auth_session:m,redirect_uri:s,appState:n,connection:r,response_type:Ht.ConnectCode});let h=new URL(f);h.searchParams.set(`ticket`,p.ticket),t?await t(h.toString()):window.location.assign(h)}async _requestTokenForPasskey(e){let t=e.audience||this.options.authorizationParams.audience,n=e.organization||this.options.authorizationParams.organization;return this._requestToken(Object.assign(Object.assign(Object.assign({grant_type:`urn:okta:params:oauth:grant-type:webauthn`,auth_session:e.authSession,authn_response:e.credential},e.realm&&{realm:e.realm}),n&&{organization:n}),{scope:bt(this.scope,e.scope,t),audience:t}))}async _requestTokenForMfa(e,t){let n=e.mfaToken,r=f(e,[`mfaToken`]);return this._requestToken(Object.assign(Object.assign({},r),{mfa_token:n}),t)}},Sc={isAuthenticated:!1,isLoading:!0,error:void 0,user:void 0},$=function(){throw Error(`You forgot to wrap your component in <Auth0Provider>.`)},Cc=s(s({},Sc),{buildAuthorizeUrl:$,buildLogoutUrl:$,getAccessTokenSilently:$,getAccessTokenWithPopup:$,getIdTokenClaims:$,loginWithCustomTokenExchange:$,customTokenExchange:$,exchangeToken:$,loginWithRedirect:$,loginWithPopup:$,connectAccountWithRedirect:$,logout:$,revokeRefreshToken:$,handleRedirectCallback:$,getDpopNonce:$,setDpopNonce:$,generateDpopProof:$,createFetcher:$,getConfiguration:$,mfa:{getAuthenticators:$,enroll:$,challenge:$,verify:$,getEnrollmentFactors:$},passkey:{signup:$,login:$},myAccount:{getFactors:$,getAuthenticationMethods:$,getAuthenticationMethod:$,updateAuthenticationMethod:$,deleteAuthenticationMethod:$,enrollmentChallenge:$,enrollmentVerify:$}}),wc=(0,i.createContext)(Cc),Tc=function(e){o(t,e);function t(n,r){var i=e.call(this,r??n)||this;return i.error=n,i.error_description=r,Object.setPrototypeOf(i,t.prototype),i}return t}(Error),Ec=/[?&](?:connect_)?code=[^&]+/,Dc=/[?&]state=[^&]+/,Oc=/[?&]error=[^&]+/,kc=function(e){return e===void 0&&(e=window.location.search),(Ec.test(e)||Oc.test(e))&&Dc.test(e)},Ac=function(e){return function(t){if(t instanceof Error)return t;if(typeof t==`object`&&t&&`error`in t&&typeof t.error==`string`){if(`error_description`in t&&typeof t.error_description==`string`){var n=t;return new Tc(n.error,n.error_description)}return new Tc(t.error)}return Error(e)}},jc=Ac(`Login failed`),Mc=Ac(`Get access token failed`),Nc=function(e){e?.redirectUri&&(console.warn("Using `redirectUri` has been deprecated, please use `authorizationParams.redirect_uri` instead as `redirectUri` will be no longer supported in a future version"),e.authorizationParams=e.authorizationParams??{},e.authorizationParams.redirect_uri=e.redirectUri,delete e.redirectUri),e?.authorizationParams?.redirectUri&&(console.warn("Using `authorizationParams.redirectUri` has been deprecated, please use `authorizationParams.redirect_uri` instead as `authorizationParams.redirectUri` will be removed in a future version"),e.authorizationParams.redirect_uri=e.authorizationParams.redirectUri,delete e.authorizationParams.redirectUri)},Pc=function(e,t){switch(t.type){case`LOGIN_POPUP_STARTED`:return s(s({},e),{isLoading:!0});case`LOGIN_POPUP_COMPLETE`:case`INITIALISED`:return s(s({},e),{isAuthenticated:!!t.user,user:t.user,isLoading:!1,error:void 0});case`HANDLE_REDIRECT_COMPLETE`:case`GET_ACCESS_TOKEN_COMPLETE`:case`SYNC_USER`:return e.user===t.user?e:s(s({},e),{isAuthenticated:!!t.user,user:t.user});case`LOGOUT`:return s(s({},e),{isAuthenticated:!1,user:void 0});case`ERROR`:return s(s({},e),{isLoading:!1,error:t.error})}},Fc=function(e){return Nc(e),s(s({},e),{auth0Client:{name:`auth0-react`,version:`2.24.0`}})},Ic=function(e){window.history.replaceState({},document.title,e.returnTo??window.location.pathname)},Lc=function(){var e,t,n=new Promise(function(n,r){e=n,t=r});return n.catch(function(){}),{promise:n,resolve:e,reject:t}},Rc=function(e){var t=e,n=t.children,r=t.skipRedirectCallback,a=t.onRedirectCallback,o=a===void 0?Ic:a,f=t.context,p=f===void 0?wc:f,m=t.client,h=c(t,[`children`,`skipRedirectCallback`,`onRedirectCallback`,`context`,`client`]);m&&(h.domain||h.clientId)&&console.warn("Auth0Provider: the `client` prop takes precedence over `domain`/`clientId` and other configuration options. Remove `domain`, `clientId`, and any other Auth0Client configuration props when using the `client` prop.");var g=(0,i.useState)(function(){return m??new xc(Fc(h))})[0],_=(0,i.useReducer)(Pc,Sc),v=_[0],y=_[1],b=(0,i.useState)(Lc),x=b[0],S=b[1],ee=(0,i.useState)(!1),C=ee[0],te=ee[1],w=(0,i.useRef)(!1),ne=(0,i.useRef)(!1),T=(0,i.useCallback)(function(e){return y({type:`ERROR`,error:e}),e},[]),re=(0,i.useCallback)(function(e,t){return l(void 0,void 0,void 0,function(){var n,i,a,s,l,d,f,p;return u(this,function(u){switch(u.label){case 0:return u.trys.push([0,7,,8]),n=void 0,t&&kc()&&!r?[4,g.handleRedirectCallback()]:[3,3];case 1:return i=u.sent(),a=i.appState,s=a===void 0?{}:a,l=i.response_type,d=c(i,[`appState`,`response_type`]),[4,g.getUser()];case 2:return n=u.sent(),s.response_type=l,l===Ht.ConnectCode&&(s.connectedAccount=d),o(s,n),[3,6];case 3:return[4,g.checkSession()];case 4:return u.sent(),[4,g.getUser()];case 5:n=u.sent(),u.label=6;case 6:return y({type:`INITIALISED`,user:n}),e.resolve(),[3,8];case 7:return f=u.sent(),p=jc(f),T(p),te(!0),e.reject(p),[3,8];case 8:return[2]}})})},[g,o,r,T]);(0,i.useEffect)(function(){ne.current||(ne.current=!0,re(x,!0))},[re,x]),(0,i.useEffect)(function(){if(!(!C||w.current||!v.isAuthenticated)){w.current=!0;var e=Lc();S(e),re(e,!1)}},[C,v.isAuthenticated,re]);var ie=(0,i.useCallback)(function(e){return Nc(e),g.loginWithRedirect(e)},[g]),ae=(0,i.useCallback)(function(e,t){return l(void 0,void 0,void 0,function(){var n,r;return u(this,function(i){switch(i.label){case 0:y({type:`LOGIN_POPUP_STARTED`}),i.label=1;case 1:return i.trys.push([1,3,,4]),[4,g.loginWithPopup(e,t)];case 2:return i.sent(),[3,4];case 3:return n=i.sent(),T(jc(n)),[2];case 4:return[4,g.getUser()];case 5:return r=i.sent(),y({type:`LOGIN_POPUP_COMPLETE`,user:r}),[2]}})})},[g,T]),oe=(0,i.useCallback)(function(){return l(void 0,d([],[...arguments],!0),void 0,function(e){return e===void 0&&(e={}),u(this,function(t){switch(t.label){case 0:return[4,g.logout(e)];case 1:return t.sent(),(e.openUrl||e.openUrl===!1)&&y({type:`LOGOUT`}),[2]}})})},[g]),se=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){var t,n;return u(this,function(r){switch(r.label){case 0:return r.trys.push([0,,2,4]),[4,g.revokeRefreshToken(e)];case 1:return r.sent(),[3,4];case 2:return t=y,n={type:`SYNC_USER`},[4,g.getUser()];case 3:return t.apply(void 0,[(n.user=r.sent(),n)]),[7];case 4:return[2]}})})},[g]),ce=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){var t,n,r,i;return u(this,function(a){switch(a.label){case 0:return a.trys.push([0,2,3,5]),[4,g.getTokenSilently(e)];case 1:return t=a.sent(),[3,5];case 2:throw n=a.sent(),Mc(n);case 3:return r=y,i={type:`GET_ACCESS_TOKEN_COMPLETE`},[4,g.getUser()];case 4:return r.apply(void 0,[(i.user=a.sent(),i)]),[7];case 5:return[2,t]}})})},[g]),le=(0,i.useCallback)(function(e,t){return l(void 0,void 0,void 0,function(){var n,r,i,a;return u(this,function(o){switch(o.label){case 0:return o.trys.push([0,2,3,5]),[4,g.getTokenWithPopup(e,t)];case 1:return n=o.sent(),[3,5];case 2:throw r=o.sent(),Mc(r);case 3:return i=y,a={type:`GET_ACCESS_TOKEN_COMPLETE`},[4,g.getUser()];case 4:return i.apply(void 0,[(a.user=o.sent(),a)]),[7];case 5:return[2,n]}})})},[g]),ue=(0,i.useCallback)(function(e){return g.connectAccountWithRedirect(e)},[g]),E=(0,i.useCallback)(function(){return g.getIdTokenClaims()},[g]),D=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){var t,n,r,i;return u(this,function(a){switch(a.label){case 0:return a.trys.push([0,2,3,5]),[4,g.loginWithCustomTokenExchange(e)];case 1:return t=a.sent(),[3,5];case 2:throw n=a.sent(),Mc(n);case 3:return r=y,i={type:`GET_ACCESS_TOKEN_COMPLETE`},[4,g.getUser()];case 4:return r.apply(void 0,[(i.user=a.sent(),i)]),[7];case 5:return[2,t]}})})},[g]),de=(0,i.useCallback)(function(e){return g.customTokenExchange(e)},[g]),fe=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){return u(this,function(t){return[2,D(e)]})})},[D]),pe=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){var t,n,r;return u(this,function(i){switch(i.label){case 0:return i.trys.push([0,2,3,5]),[4,g.handleRedirectCallback(e)];case 1:return[2,i.sent()];case 2:throw t=i.sent(),Mc(t);case 3:return n=y,r={type:`HANDLE_REDIRECT_COMPLETE`},[4,g.getUser()];case 4:return n.apply(void 0,[(r.user=i.sent(),r)]),[7];case 5:return[2]}})})},[g]),me=(0,i.useCallback)(function(e){return g.getDpopNonce(e)},[g]),he=(0,i.useCallback)(function(e,t){return g.setDpopNonce(e,t)},[g]),ge=(0,i.useCallback)(function(e){return g.generateDpopProof(e)},[g]),_e=(0,i.useCallback)(function(e){return g.createFetcher(e)},[g]),ve=(0,i.useCallback)(function(){return g.getConfiguration()},[g]),ye=(0,i.useMemo)(function(){return g.mfa},[g]),be=(0,i.useMemo)(function(){return g.myAccount},[g]),xe=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){var t,n,r,i;return u(this,function(a){switch(a.label){case 0:return a.trys.push([0,2,3,5]),[4,g.passkey.signup(e)];case 1:return t=a.sent(),[3,5];case 2:throw n=a.sent(),Mc(n);case 3:return r=y,i={type:`GET_ACCESS_TOKEN_COMPLETE`},[4,g.getUser()];case 4:return r.apply(void 0,[(i.user=a.sent(),i)]),[7];case 5:return[2,t]}})})},[g]),Se=(0,i.useCallback)(function(e){return l(void 0,void 0,void 0,function(){var t,n,r,i;return u(this,function(a){switch(a.label){case 0:return a.trys.push([0,2,3,5]),[4,g.passkey.login(e)];case 1:return t=a.sent(),[3,5];case 2:throw n=a.sent(),Mc(n);case 3:return r=y,i={type:`GET_ACCESS_TOKEN_COMPLETE`},[4,g.getUser()];case 4:return r.apply(void 0,[(i.user=a.sent(),i)]),[7];case 5:return[2,t]}})})},[g]),Ce=(0,i.useMemo)(function(){return{signup:xe,login:Se}},[xe,Se]),we=(0,i.useMemo)(function(){return s(s({},v),{getAccessTokenSilently:ce,getAccessTokenWithPopup:le,getIdTokenClaims:E,loginWithCustomTokenExchange:D,customTokenExchange:de,exchangeToken:fe,loginWithRedirect:ie,loginWithPopup:ae,connectAccountWithRedirect:ue,logout:oe,revokeRefreshToken:se,handleRedirectCallback:pe,getDpopNonce:me,setDpopNonce:he,generateDpopProof:ge,createFetcher:_e,getConfiguration:ve,mfa:ye,passkey:Ce,myAccount:be,_initPromise:x.promise})},[v,ce,le,E,D,de,fe,ie,ae,ue,oe,se,pe,me,he,ge,_e,ve,ye,Ce,be,x]);return i.createElement(p.Provider,{value:we},n)},zc=function(e){return e===void 0&&(e=wc),(0,i.useContext)(e)};export{zc as n,Rc as t};