@auth0/auth0-spa-js
Version:
Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE
3 lines • 226 kB
JavaScript
function e(e,t){var n={};for(var o in e)Object.prototype.hasOwnProperty.call(e,o)&&t.indexOf(o)<0&&(n[o]=e[o]);if(null!=e&&"function"==typeof Object.getOwnPropertySymbols){var i=0;for(o=Object.getOwnPropertySymbols(e);i<o.length;i++)t.indexOf(o[i])<0&&Object.prototype.propertyIsEnumerable.call(e,o[i])&&(n[o[i]]=e[o[i]])}return n}function t(e,t,n,o){if("a"===n&&!o)throw new TypeError("Private accessor was defined without a getter");if("function"==typeof t?e!==t||!o:!t.has(e))throw new TypeError("Cannot read private member from an object whose class did not declare it");return"m"===n?o:"a"===n?o.call(e):o?o.value:t.get(e)}function n(e,t,n,o,i){if("m"===o)throw new TypeError("Private method is not writable");if("a"===o&&!i)throw new TypeError("Private accessor was defined without a setter");if("function"==typeof t?e!==t||!i:!t.has(e))throw new TypeError("Cannot write private member to an object whose class did not declare it");return"a"===o?i.call(e,n):i?i.value=n:t.set(e,n),n}function o(e,t){this.v=e,this.k=t}function i(e,t){(null==t||t>e.length)&&(t=e.length);for(var n=0,o=Array(t);n<t;n++)o[n]=e[n];return o}function r(e,t,n){if("function"==typeof e?e===t:e.has(t))return arguments.length<3?t:n;throw new TypeError("Private element is not present on this object")}function s(e){return new o(e,0)}function a(e,t){if(t.has(e))throw new TypeError("Cannot initialize the same private elements twice on an object")}function c(e,t){return e.get(r(e,t))}function u(e,t,n){a(e,t),t.set(e,n)}function l(e,t,n){return e.set(r(e,t),n),n}function d(e,t){a(e,t),t.add(e)}function h(e,t,n){return(t=function(e){var t=function(e,t){if("object"!=typeof e||!e)return e;var n=e[Symbol.toPrimitive];if(void 0!==n){var o=n.call(e,t||"default");if("object"!=typeof o)return o;throw new TypeError("@@toPrimitive must return a primitive value.")}return("string"===t?String:Number)(e)}(e,"string");return"symbol"==typeof t?t:t+""}(t))in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function p(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);t&&(o=o.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,o)}return n}function f(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?p(Object(n),!0).forEach(function(t){h(e,t,n[t])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):p(Object(n)).forEach(function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))})}return e}function m(e,t){if(null==e)return{};var n,o,i=function(e,t){if(null==e)return{};var n={};for(var o in e)if({}.hasOwnProperty.call(e,o)){if(-1!==t.indexOf(o))continue;n[o]=e[o]}return n}(e,t);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);for(o=0;o<r.length;o++)n=r[o],-1===t.indexOf(n)&&{}.propertyIsEnumerable.call(e,n)&&(i[n]=e[n])}return i}function y(e,t){return function(e){if(Array.isArray(e))return e}(e)||function(e,t){var n=null==e?null:"undefined"!=typeof Symbol&&e[Symbol.iterator]||e["@@iterator"];if(null!=n){var o,i,r,s,a=[],c=!0,u=!1;try{if(r=(n=n.call(e)).next,0===t){if(Object(n)!==n)return;c=!1}else for(;!(c=(o=r.call(n)).done)&&(a.push(o.value),a.length!==t);c=!0);}catch(e){u=!0,i=e}finally{try{if(!c&&null!=n.return&&(s=n.return(),Object(s)!==s))return}finally{if(u)throw i}}return a}}(e,t)||function(e,t){if(e){if("string"==typeof e)return i(e,t);var n={}.toString.call(e).slice(8,-1);return"Object"===n&&e.constructor&&(n=e.constructor.name),"Map"===n||"Set"===n?Array.from(e):"Arguments"===n||/^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(n)?i(e,t):void 0}}(e,t)||function(){throw new TypeError("Invalid attempt to destructure non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method.")}()}function w(e){return function(){return new g(e.apply(this,arguments))}}function g(e){var t,n;function i(t,n){try{var s=e[t](n),a=s.value,c=a instanceof o;Promise.resolve(c?a.v:a).then(function(n){if(c){var o="return"===t&&a.k?t:"next";if(!a.k||n.done)return i(o,n);n=e[o](n).value}r(!!s.done,n)},function(e){i("throw",e)})}catch(e){r(2,e)}}function r(e,o){2===e?t.reject(o):t.resolve({value:o,done:e}),(t=t.next)?i(t.key,t.arg):n=null}this._invoke=function(e,o){return new Promise(function(r,s){var a={key:e,arg:o,resolve:r,reject:s,next:null};n?n=n.next=a:(t=n=a,i(e,o))})},"function"!=typeof e.return&&(this.return=void 0)}"function"==typeof SuppressedError&&SuppressedError,g.prototype["function"==typeof Symbol&&Symbol.asyncIterator||"@@asyncIterator"]=function(){return this},g.prototype.next=function(e){return this._invoke("next",e)},g.prototype.throw=function(e){return this._invoke("throw",e)},g.prototype.return=function(e){return this._invoke("return",e)};const v={timeoutInSeconds:60},b=1e4,_="memory",k="online_access",S={name:"auth0-spa-js",version:"2.26.0"},T=()=>Date.now(),P="default";class E extends Error{constructor(e,t){super(t),this.error=e,this.error_description=t,Object.setPrototypeOf(this,E.prototype)}static fromPayload(e){let t=e.error,n=e.error_description;return new E(t,n)}}class C extends E{constructor(e,t){super("invalid_configuration","".concat(e," ").concat(t)),this.suggestion=t,Object.setPrototypeOf(this,C.prototype)}}class R extends E{constructor(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:null;super(e,t),this.state=n,this.appState=o,Object.setPrototypeOf(this,R.prototype)}}class A extends E{constructor(e,t,n,o){let i=arguments.length>4&&void 0!==arguments[4]?arguments[4]:null;super(e,t),this.connection=n,this.state=o,this.appState=i,Object.setPrototypeOf(this,A.prototype)}}class x extends E{constructor(){super("timeout","Timeout"),Object.setPrototypeOf(this,x.prototype)}}class I extends x{constructor(e){super(),this.popup=e,Object.setPrototypeOf(this,I.prototype)}}class O extends E{constructor(e){super("cancelled","Popup closed"),this.popup=e,Object.setPrototypeOf(this,O.prototype)}}class j extends E{constructor(){super("popup_open","Unable to open a popup for loginWithPopup - window.open returned `null`"),Object.setPrototypeOf(this,j.prototype)}}class W extends E{constructor(e,t,n,o){super(e,t),this.mfa_token=n,this.mfa_requirements=o,Object.setPrototypeOf(this,W.prototype)}}class N extends E{constructor(e,t){super("missing_refresh_token","Missing Refresh Token (audience: '".concat(U(e,["default"]),"', scope: '").concat(U(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,N.prototype)}}class K extends E{constructor(e,t){super("missing_scopes","Missing requested scopes after refresh (audience: '".concat(U(e,["default"]),"', missing scope: '").concat(U(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,K.prototype)}}class M extends E{constructor(e){super("use_dpop_nonce","Server rejected DPoP proof: wrong nonce"),this.newDpopNonce=e,Object.setPrototypeOf(this,M.prototype)}}function U(e){return e&&!(arguments.length>1&&void 0!==arguments[1]?arguments[1]:[]).includes(e)?e:""}const L=()=>window.crypto,z=()=>{const e="0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-_~.";let t="";for(;t.length<43;){const n=L().getRandomValues(new Uint8Array(43-t.length));for(const o of n)t.length<43&&o<198&&(t+=e[o%66])}return t},J=e=>btoa(e),D=[{key:"name",type:["string"]},{key:"version",type:["string","number"]},{key:"env",type:["object"]}],Z=function(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return Object.keys(e).reduce((n,o)=>{if(t&&"env"===o)return n;const i=D.find(e=>e.key===o);return i&&i.type.includes(typeof e[o])&&(n[o]=e[o]),n},{})},H=t=>{var n=t.clientId,o=e(t,["clientId"]);return new URLSearchParams((e=>Object.keys(e).filter(t=>void 0!==e[t]).reduce((t,n)=>Object.assign(Object.assign({},t),{[n]:e[n]}),{}))(Object.assign({client_id:n},o))).toString()},F=async e=>{const t=L().subtle.digest({name:"SHA-256"},(new TextEncoder).encode(e));return await t},V=e=>(e=>decodeURIComponent(atob(e).split("").map(e=>"%"+("00"+e.charCodeAt(0).toString(16)).slice(-2)).join("")))(e.replace(/_/g,"/").replace(/-/g,"+")),X=e=>{const t=new Uint8Array(e);return(e=>{const t={"+":"-","/":"_","=":""};return e.replace(/[+/=]/g,e=>t[e])})(window.btoa(String.fromCharCode(...Array.from(t))))};var G="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{},Y={},q={};Object.defineProperty(q,"__esModule",{value:!0});var B=function(){function e(){var e=this;this.locked=new Map,this.addToLocked=function(t,n){var o=e.locked.get(t);void 0===o?void 0===n?e.locked.set(t,[]):e.locked.set(t,[n]):void 0!==n&&(o.unshift(n),e.locked.set(t,o))},this.isLocked=function(t){return e.locked.has(t)},this.lock=function(t){return new Promise(function(n,o){e.isLocked(t)?e.addToLocked(t,n):(e.addToLocked(t),n())})},this.unlock=function(t){var n=e.locked.get(t);if(void 0!==n&&0!==n.length){var o=n.pop();e.locked.set(t,n),void 0!==o&&setTimeout(o,0)}else e.locked.delete(t)}}return e.getInstance=function(){return void 0===e.instance&&(e.instance=new e),e.instance},e}();q.default=function(){return B.getInstance()};var Q=G&&G.__awaiter||function(e,t,n,o){return new(n||(n=Promise))(function(i,r){function s(e){try{c(o.next(e))}catch(e){r(e)}}function a(e){try{c(o.throw(e))}catch(e){r(e)}}function c(e){e.done?i(e.value):new n(function(t){t(e.value)}).then(s,a)}c((o=o.apply(e,t||[])).next())})},$=G&&G.__generator||function(e,t){var n,o,i,r,s={label:0,sent:function(){if(1&i[0])throw i[1];return i[1]},trys:[],ops:[]};return r={next:a(0),throw:a(1),return:a(2)},"function"==typeof Symbol&&(r[Symbol.iterator]=function(){return this}),r;function a(r){return function(a){return function(r){if(n)throw new TypeError("Generator is already executing.");for(;s;)try{if(n=1,o&&(i=2&r[0]?o.return:r[0]?o.throw||((i=o.return)&&i.call(o),0):o.next)&&!(i=i.call(o,r[1])).done)return i;switch(o=0,i&&(r=[2&r[0],i.value]),r[0]){case 0:case 1:i=r;break;case 4:return s.label++,{value:r[1],done:!1};case 5:s.label++,o=r[1],r=[0];continue;case 7:r=s.ops.pop(),s.trys.pop();continue;default:if(!(i=s.trys,(i=i.length>0&&i[i.length-1])||6!==r[0]&&2!==r[0])){s=0;continue}if(3===r[0]&&(!i||r[1]>i[0]&&r[1]<i[3])){s.label=r[1];break}if(6===r[0]&&s.label<i[1]){s.label=i[1],i=r;break}if(i&&s.label<i[2]){s.label=i[2],s.ops.push(r);break}i[2]&&s.ops.pop(),s.trys.pop();continue}r=t.call(e,s)}catch(e){r=[6,e],o=0}finally{n=i=0}if(5&r[0])throw r[1];return{value:r[0]?r[1]:void 0,done:!0}}([r,a])}}},ee=G;Object.defineProperty(Y,"__esModule",{value:!0});var te=q,ne="browser-tabs-lock-key",oe={key:function(e){return Q(ee,void 0,void 0,function(){return $(this,function(e){throw new Error("Unsupported")})})},getItem:function(e){return Q(ee,void 0,void 0,function(){return $(this,function(e){throw new Error("Unsupported")})})},clear:function(){return Q(ee,void 0,void 0,function(){return $(this,function(e){return[2,window.localStorage.clear()]})})},removeItem:function(e){return Q(ee,void 0,void 0,function(){return $(this,function(e){throw new Error("Unsupported")})})},setItem:function(e,t){return Q(ee,void 0,void 0,function(){return $(this,function(e){throw new Error("Unsupported")})})},keySync:function(e){return window.localStorage.key(e)},getItemSync:function(e){return window.localStorage.getItem(e)},clearSync:function(){return window.localStorage.clear()},removeItemSync:function(e){return window.localStorage.removeItem(e)},setItemSync:function(e,t){return window.localStorage.setItem(e,t)}};function ie(e){return new Promise(function(t){return setTimeout(t,e)})}function re(e){for(var t="0123456789ABCDEFGHIJKLMNOPQRSTUVWXTZabcdefghiklmnopqrstuvwxyz",n="",o=0;o<e;o++){n+=t[Math.floor(61*Math.random())]}return n}var se=function(){function e(t){this.acquiredIatSet=new Set,this.storageHandler=void 0,this.id=Date.now().toString()+re(15),this.acquireLock=this.acquireLock.bind(this),this.releaseLock=this.releaseLock.bind(this),this.releaseLock__private__=this.releaseLock__private__.bind(this),this.waitForSomethingToChange=this.waitForSomethingToChange.bind(this),this.refreshLockWhileAcquired=this.refreshLockWhileAcquired.bind(this),this.storageHandler=t,void 0===e.waiters&&(e.waiters=[])}return e.prototype.acquireLock=function(t,n){return void 0===n&&(n=5e3),Q(this,void 0,void 0,function(){var o,i,r,s,a,c,u;return $(this,function(l){switch(l.label){case 0:o=Date.now()+re(4),i=Date.now()+n,r=ne+"-"+t,s=void 0===this.storageHandler?oe:this.storageHandler,l.label=1;case 1:return Date.now()<i?[4,ie(30)]:[3,8];case 2:return l.sent(),null!==s.getItemSync(r)?[3,5]:(a=this.id+"-"+t+"-"+o,[4,ie(Math.floor(25*Math.random()))]);case 3:return l.sent(),s.setItemSync(r,JSON.stringify({id:this.id,iat:o,timeoutKey:a,timeAcquired:Date.now(),timeRefreshed:Date.now()})),[4,ie(30)];case 4:return l.sent(),null!==(c=s.getItemSync(r))&&(u=JSON.parse(c)).id===this.id&&u.iat===o?(this.acquiredIatSet.add(o),this.refreshLockWhileAcquired(r,o),[2,!0]):[3,7];case 5:return e.lockCorrector(void 0===this.storageHandler?oe:this.storageHandler),[4,this.waitForSomethingToChange(i)];case 6:l.sent(),l.label=7;case 7:return o=Date.now()+re(4),[3,1];case 8:return[2,!1]}})})},e.prototype.refreshLockWhileAcquired=function(e,t){return Q(this,void 0,void 0,function(){var n=this;return $(this,function(o){return setTimeout(function(){return Q(n,void 0,void 0,function(){var n,o,i;return $(this,function(r){switch(r.label){case 0:return[4,te.default().lock(t)];case 1:return r.sent(),this.acquiredIatSet.has(t)?(n=void 0===this.storageHandler?oe:this.storageHandler,null===(o=n.getItemSync(e))?(te.default().unlock(t),[2]):((i=JSON.parse(o)).timeRefreshed=Date.now(),n.setItemSync(e,JSON.stringify(i)),te.default().unlock(t),this.refreshLockWhileAcquired(e,t),[2])):(te.default().unlock(t),[2])}})})},1e3),[2]})})},e.prototype.waitForSomethingToChange=function(t){return Q(this,void 0,void 0,function(){return $(this,function(n){switch(n.label){case 0:return[4,new Promise(function(n){var o=!1,i=Date.now(),r=!1;function s(){if(r||(window.removeEventListener("storage",s),e.removeFromWaiting(s),clearTimeout(a),r=!0),!o){o=!0;var t=50-(Date.now()-i);t>0?setTimeout(n,t):n(null)}}window.addEventListener("storage",s),e.addToWaiting(s);var a=setTimeout(s,Math.max(0,t-Date.now()))})];case 1:return n.sent(),[2]}})})},e.addToWaiting=function(t){this.removeFromWaiting(t),void 0!==e.waiters&&e.waiters.push(t)},e.removeFromWaiting=function(t){void 0!==e.waiters&&(e.waiters=e.waiters.filter(function(e){return e!==t}))},e.notifyWaiters=function(){void 0!==e.waiters&&e.waiters.slice().forEach(function(e){return e()})},e.prototype.releaseLock=function(e){return Q(this,void 0,void 0,function(){return $(this,function(t){switch(t.label){case 0:return[4,this.releaseLock__private__(e)];case 1:return[2,t.sent()]}})})},e.prototype.releaseLock__private__=function(t){return Q(this,void 0,void 0,function(){var n,o,i,r;return $(this,function(s){switch(s.label){case 0:return n=void 0===this.storageHandler?oe:this.storageHandler,o=ne+"-"+t,null===(i=n.getItemSync(o))?[2]:(r=JSON.parse(i)).id!==this.id?[3,2]:[4,te.default().lock(r.iat)];case 1:s.sent(),this.acquiredIatSet.delete(r.iat),n.removeItemSync(o),te.default().unlock(r.iat),e.notifyWaiters(),s.label=2;case 2:return[2]}})})},e.lockCorrector=function(t){for(var n=Date.now()-5e3,o=t,i=[],r=0;;){var s=o.keySync(r);if(null===s)break;i.push(s),r++}for(var a=!1,c=0;c<i.length;c++){var u=i[c];if(u.includes(ne)){var l=o.getItemSync(u);if(null!==l){var d=JSON.parse(l);(void 0===d.timeRefreshed&&d.timeAcquired<n||void 0!==d.timeRefreshed&&d.timeRefreshed<n)&&(o.removeItemSync(u),a=!0)}}}a&&e.notifyWaiters()},e.waiters=void 0,e}(),ae=Y.default=se;class ce{async runWithLock(e,t,n){const o=new AbortController,i=setTimeout(()=>o.abort(),t);try{return await navigator.locks.request(e,{mode:"exclusive",signal:o.signal},async e=>{if(clearTimeout(i),!e)throw new Error("Lock not available");return await n()})}catch(e){if(clearTimeout(i),"AbortError"===(null==e?void 0:e.name))throw new x;throw e}}}class ue{constructor(){this.activeLocks=new Set,this.lock=new ae,this.pagehideHandler=()=>{this.activeLocks.forEach(e=>this.lock.releaseLock(e)),this.activeLocks.clear()}}async runWithLock(e,t,n){let o=!1;for(let n=0;n<10&&!o;n++)o=await this.lock.acquireLock(e,t);if(!o)throw new x;this.activeLocks.add(e),1===this.activeLocks.size&&"undefined"!=typeof window&&window.addEventListener("pagehide",this.pagehideHandler);try{return await n()}finally{this.activeLocks.delete(e),await this.lock.releaseLock(e),0===this.activeLocks.size&&"undefined"!=typeof window&&window.removeEventListener("pagehide",this.pagehideHandler)}}}function le(){return"undefined"!=typeof navigator&&"function"==typeof(null===(e=navigator.locks)||void 0===e?void 0:e.request)?new ce:new ue;var e}let de=null;const he=new TextEncoder,pe=new TextDecoder;function fe(e){return"string"==typeof e?he.encode(e):pe.decode(e)}function me(e){if("number"!=typeof e.modulusLength||e.modulusLength<2048)throw new be(`${e.name} modulusLength must be at least 2048 bits`)}async function ye(e,t,n){if(!1===n.usages.includes("sign"))throw new TypeError('private CryptoKey instances used for signing assertions must include "sign" in their "usages"');const o=`${ge(fe(JSON.stringify(e)))}.${ge(fe(JSON.stringify(t)))}`;return`${o}.${ge(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:"SHA-256"};case"RSA-PSS":return me(e.algorithm),{name:e.algorithm.name,saltLength:32};case"RSASSA-PKCS1-v1_5":return me(e.algorithm),{name:e.algorithm.name};case"Ed25519":return{name:e.algorithm.name}}throw new ve}(n),n,fe(o)))}`}let we;if(Uint8Array.prototype.toBase64)we=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;we=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function ge(e){return we(e)}class ve extends Error{constructor(e){var t;super(null!=e?e:"operation not supported"),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}class be extends Error{constructor(e){var t;super(e),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}function _e(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){if("SHA-256"===e.algorithm.hash.name)return"PS256";throw new ve("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"RSASSA-PKCS1-v1_5":return function(e){if("SHA-256"===e.algorithm.hash.name)return"RS256";throw new ve("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"ECDSA":return function(e){if("P-256"===e.algorithm.namedCurve)return"ES256";throw new ve("unsupported EcKeyAlgorithm namedCurve")}(e);case"Ed25519":return"Ed25519";default:throw new ve("unsupported CryptoKey algorithm name")}}function ke(e){return e instanceof CryptoKey}function Se(e){return ke(e)&&"public"===e.type}async function Te(e,t,n,o,i,r){const s=null==e?void 0:e.privateKey,a=null==e?void 0:e.publicKey;if(!ke(c=s)||"private"!==c.type)throw new TypeError('"keypair.privateKey" must be a private CryptoKey');var c;if(!Se(a))throw new TypeError('"keypair.publicKey" must be a public CryptoKey');if(!0!==a.extractable)throw new TypeError('"keypair.publicKey.extractable" must be true');if("string"!=typeof t)throw new TypeError('"htu" must be a string');if("string"!=typeof n)throw new TypeError('"htm" must be a string');if(void 0!==o&&"string"!=typeof o)throw new TypeError('"nonce" must be a string or undefined');if(void 0!==i&&"string"!=typeof i)throw new TypeError('"accessToken" must be a string or undefined');if(void 0!==r&&("object"!=typeof r||null===r||Array.isArray(r)))throw new TypeError('"additional" must be an object');const u=Object.assign(Object.create(null),r,{iat:Math.floor(Date.now()/1e3),jti:crypto.randomUUID(),htm:n,nonce:o,htu:t,ath:i?ge(await crypto.subtle.digest("SHA-256",fe(i))):void 0});return ye({alg:_e(s),typ:"dpop+jwt",jwk:await Pe(a)},u,s)}async function Pe(e){const{kty:t,e:n,n:o,x:i,y:r,crv:s}=await crypto.subtle.exportKey("jwk",e);return{kty:t,crv:s,e:n,n:o,x:i,y:r}}const Ee="dpop-nonce",Ce=["authorization_code","refresh_token","urn:ietf:params:oauth:grant-type:token-exchange","urn:okta:params:oauth:grant-type:webauthn","http://auth0.com/oauth/grant-type/mfa-oob","http://auth0.com/oauth/grant-type/mfa-otp","http://auth0.com/oauth/grant-type/mfa-recovery-code"];function Re(){return async function(e,t){var n;let o;if("string"!=typeof e||0===e.length)throw new TypeError('"alg" must be a non-empty string');switch(e){case"PS256":o={name:"RSA-PSS",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"RS256":o={name:"RSASSA-PKCS1-v1_5",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"ES256":o={name:"ECDSA",namedCurve:"P-256"};break;case"Ed25519":o={name:"Ed25519"};break;default:throw new ve}return crypto.subtle.generateKey(o,null!==(n=null==t?void 0:t.extractable)&&void 0!==n&&n,["sign","verify"])}("ES256",{extractable:!1})}function Ae(e){return async function(e){if(!Se(e))throw new TypeError('"publicKey" must be a public CryptoKey');if(!0!==e.extractable)throw new TypeError('"publicKey.extractable" must be true');const t=await Pe(e);let n;switch(t.kty){case"EC":n={crv:t.crv,kty:t.kty,x:t.x,y:t.y};break;case"OKP":n={crv:t.crv,kty:t.kty,x:t.x};break;case"RSA":n={e:t.e,kty:t.kty,n:t.n};break;default:throw new ve("unsupported JWK kty")}return ge(await crypto.subtle.digest({name:"SHA-256"},fe(JSON.stringify(n))))}(e.publicKey)}function xe(e){let t=e.keyPair,n=e.url,o=e.method,i=e.nonce,r=e.accessToken;const s=function(e){const t=new URL(e);return t.search="",t.hash="",t.href}(n);return Te(t,s,o,i,r)}const Ie=(e,t)=>new Promise(function(n,o){const i=new MessageChannel;i.port1.onmessage=function(e){e.data.error?o(new Error(e.data.error)):n(e.data),i.port1.close()},t.postMessage(e,[i.port2])}),Oe=(e,t,n)=>{const o=new AbortController;let i;return t.signal=o.signal,Promise.race([fetch(e,t),new Promise((e,t)=>{i=setTimeout(()=>{o.abort(),t(new Error("Timeout when executing 'fetch'"))},n)})]).finally(()=>{clearTimeout(i)})},je=async function(e,t,n,o,i,r){let s=arguments.length>6&&void 0!==arguments[6]?arguments[6]:b;return i?(async(e,t,n,o,i,r,s,a,c,u)=>Ie({type:"refresh",auth:{audience:t,scope:n},timeout:i,fetchUrl:e,fetchOptions:o,useFormData:s,useMrrt:a,skipTokenStorage:c,preserveRefreshToken:u},r))(e,t,n,o,s,i,r,arguments.length>7?arguments[7]:void 0,arguments.length>8?arguments[8]:void 0,arguments.length>9?arguments[9]:void 0):(async(e,t,n)=>{const o=await Oe(e,t,n);return{ok:o.ok,json:await o.json(),headers:(i=o.headers,[...i].reduce((e,t)=>{let n=y(t,2),o=n[0],i=n[1];return e[o]=i,e},{}))};var i})(e,o,s)};async function We(t,n,o,i,r,s,a,c,u,l,d,h){if(u){const e=await u.generateProof({url:t,method:r.method||"GET",nonce:await u.getNonce()});r.headers=Object.assign(Object.assign({},r.headers),{dpop:e})}let p,f=null;for(let e=0;e<3;e++)try{p=await je(t,o,i,r,s,a,n,c,d,h),f=null;break}catch(e){f=e}if(f)throw f;const m=p.json,y=m.error,w=m.error_description,g=e(m,["error","error_description"]),v=p,b=v.headers,_=v.ok;let k;if(u&&(k=b[Ee],k&&await u.setNonce(k)),!_){const e=w||"HTTP error. Unable to fetch ".concat(t);if("mfa_required"===y)throw new W(y,e,g.mfa_token,g.mfa_requirements);if("missing_refresh_token"===y)throw new N(o,i);if("use_dpop_nonce"===y){if(!u||!k||l)throw new M(k);return We(t,n,o,i,r,s,a,c,u,!0,d,h)}throw new E(y||"request_error",e)}return g}async function Ne(t,n,o){var i=t.baseUrl,r=t.timeout,s=t.audience,a=t.scope,c=t.auth0Client,u=t.useFormData,l=t.useMrrt,d=t.dpop,h=t.preserveRefreshToken,p=e(t,["baseUrl","timeout","audience","scope","auth0Client","useFormData","useMrrt","dpop","preserveRefreshToken"]);const f="urn:ietf:params:oauth:grant-type:token-exchange"===p.grant_type,m="urn:okta:params:oauth:grant-type:webauthn"===p.grant_type,y="refresh_token"===p.grant_type&&l,w=f||m||y,g=Object.assign(Object.assign(Object.assign({},p),w&&s&&{audience:s}),w&&a&&{scope:a}),v=m||!u,b=v?JSON.stringify(g):H(g),_=(k=p.grant_type,Ce.includes(k));var k;return await We("".concat(i,"/oauth/token"),r,s||P,a,{method:"POST",body:b,headers:{"Content-Type":v?"application/json":"application/x-www-form-urlencoded","Auth0-Client":btoa(JSON.stringify(Z(c||S)))}},n,u,l,_?d:void 0,void 0,o,h)}const Ke=function(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];return(o=t.filter(Boolean).join(" ").trim().split(/\s+/),Array.from(new Set(o))).join(" ");var o},Me=(e,t,n)=>{let o;return n&&(o=e[n]),o||(o=e[P]),Ke(o,t)},Ue="@@auth0spajs@@",Le="@@user@@";class ze{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:Ue,n=arguments.length>2?arguments[2]:void 0;this.prefix=t,this.suffix=n,this.clientId=e.clientId,this.scope=e.scope,this.audience=e.audience}toKey(){return[this.prefix,this.clientId,this.audience,this.scope,this.suffix].filter(Boolean).join("::")}static fromKey(e){const t=y(e.split("::"),4),n=t[0],o=t[1],i=t[2],r=t[3];return new ze({clientId:o,scope:r,audience:i},n)}static fromCacheEntry(e){const t=e.scope,n=e.audience,o=e.client_id;return new ze({scope:t,audience:n,clientId:o})}}class Je{set(e,t){localStorage.setItem(e,JSON.stringify(t))}get(e){const t=window.localStorage.getItem(e);if(t)try{return JSON.parse(t)}catch(e){return}}remove(e){localStorage.removeItem(e)}allKeys(){return Object.keys(window.localStorage).filter(e=>e.startsWith(Ue))}}class De{constructor(){this.enclosedCache=function(){let e={};return{set(t,n){e[t]=n},get(t){const n=e[t];if(n)return n},remove(t){delete e[t]},allKeys:()=>Object.keys(e)}}()}}class Ze{constructor(e,t,n){this.cache=e,this.keyManifest=t,this.nowProvider=n||T}async setIdToken(e,t,n){var o;const i=this.getIdTokenCacheKey(e);await this.cache.set(i,{id_token:t,decodedToken:n}),await(null===(o=this.keyManifest)||void 0===o?void 0:o.add(i))}async getIdToken(e){const t=await this.cache.get(this.getIdTokenCacheKey(e.clientId));if(!t&&e.scope&&e.audience){const t=await this.get(e);if(!t)return;if(!t.id_token||!t.decodedToken)return;return{id_token:t.id_token,decodedToken:t.decodedToken}}if(t)return{id_token:t.id_token,decodedToken:t.decodedToken}}async get(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:0,n=arguments.length>2&&void 0!==arguments[2]&&arguments[2],o=arguments.length>3?arguments[3]:void 0;var i;let r=await this.cache.get(e.toKey()),s=e;if(!r){const t=await this.getCacheKeys();if(!t)return;const i=this.matchExistingCacheKey(e,t);if(i&&(r=await this.cache.get(i),s=ze.fromKey(i)),!r&&n&&"cache-only"!==o)return this.getEntryWithRefreshToken(e,t)}if(!r)return;const a=await this.nowProvider(),c=Math.floor(a/1e3);return r.expiresAt-t<c?r.body.refresh_token?this.modifiedCachedEntry(r,s):(await this.cache.remove(s.toKey()),void await(null===(i=this.keyManifest)||void 0===i?void 0:i.remove(s.toKey()))):r.body}async modifiedCachedEntry(e,t){const n={refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope},o={body:n,expiresAt:e.expiresAt};return await this.cache.set(t.toKey(),o),{refresh_token:n.refresh_token,audience:n.audience,scope:n.scope}}async set(e){var t;const n=new ze({clientId:e.client_id,scope:e.scope,audience:e.audience}),o=await this.wrapCacheEntry(e);await this.cache.set(n.toKey(),o),await(null===(t=this.keyManifest)||void 0===t?void 0:t.add(n.toKey()))}async remove(e,t,n){const o=new ze({clientId:e,scope:n,audience:t});await this.cache.remove(o.toKey())}async stripRefreshToken(e){var t;const n=await this.getCacheKeys();if(n)for(const o of n){const n=await this.cache.get(o);(null===(t=null==n?void 0:n.body)||void 0===t?void 0:t.refresh_token)===e&&(delete n.body.refresh_token,await this.cache.set(o,n))}}async clear(e){var t;const n=await this.getCacheKeys();n&&(await n.filter(t=>!e||t.includes(e)).reduce(async(e,t)=>{await e,await this.cache.remove(t)},Promise.resolve()),await(null===(t=this.keyManifest)||void 0===t?void 0:t.clear()))}async wrapCacheEntry(e){const t=await this.nowProvider();return{body:e,expiresAt:Math.floor(t/1e3)+e.expires_in}}async getCacheKeys(){var e;return this.keyManifest?null===(e=await this.keyManifest.get())||void 0===e?void 0:e.keys:this.cache.allKeys?this.cache.allKeys():void 0}getIdTokenCacheKey(e){return new ze({clientId:e},Ue,Le).toKey()}matchExistingCacheKey(e,t){return t.filter(t=>{var n;const o=ze.fromKey(t),i=new Set(o.scope&&o.scope.split(" ")),r=(null===(n=e.scope)||void 0===n?void 0:n.split(" "))||[],s=o.scope&&r.reduce((e,t)=>e&&i.has(t),!0);return o.prefix===Ue&&o.clientId===e.clientId&&o.audience===e.audience&&s})[0]}async getEntryWithRefreshToken(e,t){var n;for(const o of t){const t=ze.fromKey(o);if(t.prefix===Ue&&t.clientId===e.clientId){const e=await this.cache.get(o);if(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)return{refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope}}}}async getRefreshTokensByAudience(e,t){var n;const o=await this.getCacheKeys();if(!o)return[];const i=new Set;for(const r of o){const o=ze.fromKey(r);if(o.prefix===Ue&&o.clientId===t&&o.audience===e){const e=await this.cache.get(r);(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)&&i.add(e.body.refresh_token)}}return Array.from(i)}async updateEntry(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const i=await this.getCacheKeys();if(i)for(const r of i){if(ze.fromKey(r).clientId!==n)continue;const i=await this.cache.get(r);if(!(null==i?void 0:i.body))continue;const s=i.body.refresh_token;s&&(o||s===e)&&(i.body.refresh_token=t,await this.cache.set(r,i))}}}class He{constructor(e,t,n){this.storage=e,this.clientId=t,this.cookieDomain=n,this.storageKey="".concat("a0.spajs.txs",".").concat(this.clientId)}create(e){this.storage.save(this.storageKey,e,{daysUntilExpire:1,cookieDomain:this.cookieDomain})}get(){return this.storage.get(this.storageKey)}remove(){this.storage.remove(this.storageKey,{cookieDomain:this.cookieDomain})}}const Fe=e=>"number"==typeof e,Ve=["iss","aud","exp","nbf","iat","jti","azp","nonce","auth_time","at_hash","c_hash","acr","amr","sub_jwk","cnf","sip_from_tag","sip_date","sip_callid","sip_cseq_num","sip_via_branch","orig","dest","mky","events","toe","txn","rph","sid","vot","vtm"],Xe=e=>{if(!e.id_token)throw new Error("ID token is required but missing");const t=(e=>{const t=e.split("."),n=y(t,3),o=n[0],i=n[1],r=n[2];if(3!==t.length||!o||!i||!r)throw new Error("ID token could not be decoded");const s=JSON.parse(V(i)),a={__raw:e},c={};return Object.keys(s).forEach(e=>{a[e]=s[e],Ve.includes(e)||(c[e]=s[e])}),{encoded:{header:o,payload:i,signature:r},header:JSON.parse(V(o)),claims:a,user:c}})(e.id_token);if(!t.claims.iss)throw new Error("Issuer (iss) claim must be a string present in the ID token");if(t.claims.iss!==e.iss)throw new Error('Issuer (iss) claim mismatch in the ID token; expected "'.concat(e.iss,'", found "').concat(t.claims.iss,'"'));if(!t.user.sub)throw new Error("Subject (sub) claim must be a string present in the ID token");if("RS256"!==t.header.alg)throw new Error('Signature algorithm of "'.concat(t.header.alg,'" is not supported. Expected the ID token to be signed with "RS256".'));if(!t.claims.aud||"string"!=typeof t.claims.aud&&!Array.isArray(t.claims.aud))throw new Error("Audience (aud) claim must be a string or array of strings present in the ID token");if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e.aud))throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but was not one of "').concat(t.claims.aud.join(", "),'"'));if(t.claims.aud.length>1){if(!t.claims.azp)throw new Error("Authorized Party (azp) claim must be a string present in the ID token when Audience (aud) claim has multiple values");if(t.claims.azp!==e.aud)throw new Error('Authorized Party (azp) claim mismatch in the ID token; expected "'.concat(e.aud,'", found "').concat(t.claims.azp,'"'))}}else if(t.claims.aud!==e.aud)throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but found "').concat(t.claims.aud,'"'));if(e.nonce){if(!t.claims.nonce)throw new Error("Nonce (nonce) claim must be a string present in the ID token");if(t.claims.nonce!==e.nonce)throw new Error('Nonce (nonce) claim mismatch in the ID token; expected "'.concat(e.nonce,'", found "').concat(t.claims.nonce,'"'))}if(e.max_age&&!Fe(t.claims.auth_time))throw new Error("Authentication Time (auth_time) claim must be a number present in the ID token when Max Age (max_age) is specified");if(null==t.claims.exp||!Fe(t.claims.exp))throw new Error("Expiration Time (exp) claim must be a number present in the ID token");if(!Fe(t.claims.iat))throw new Error("Issued At (iat) claim must be a number present in the ID token");const n=e.leeway||60,o=new Date(e.now||Date.now()),i=new Date(0);if(i.setUTCSeconds(t.claims.exp+n),o>i)throw new Error("Expiration Time (exp) claim error in the ID token; current time (".concat(o,") is after expiration time (").concat(i,")"));if(null!=t.claims.nbf&&Fe(t.claims.nbf)){const e=new Date(0);if(e.setUTCSeconds(t.claims.nbf-n),o<e)throw new Error("Not Before time (nbf) claim in the ID token indicates that this token can't be used just yet. Current time (".concat(o,") is before ").concat(e))}if(null!=t.claims.auth_time&&Fe(t.claims.auth_time)){const i=new Date(0);if(i.setUTCSeconds(parseInt(t.claims.auth_time)+e.max_age+n),o>i)throw new Error("Authentication Time (auth_time) claim in the ID token indicates that too much time has passed since the last end-user authentication. Current time (".concat(o,") is after last auth at ").concat(i))}if(e.organization){const n=e.organization.trim();if(n.startsWith("org_")){const e=n;if(!t.claims.org_id)throw new Error("Organization ID (org_id) claim must be a string present in the ID token");if(e!==t.claims.org_id)throw new Error('Organization ID (org_id) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_id,'"'))}else{const e=n.toLowerCase();if(!t.claims.org_name)throw new Error("Organization Name (org_name) claim must be a string present in the ID token");if(e!==t.claims.org_name)throw new Error('Organization Name (org_name) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_name,'"'))}}return t};var Ge=G&&G.__assign||function(){return Ge=Object.assign||function(e){for(var t,n=1,o=arguments.length;n<o;n++)for(var i in t=arguments[n])Object.prototype.hasOwnProperty.call(t,i)&&(e[i]=t[i]);return e},Ge.apply(this,arguments)};function Ye(e,t){if(!t)return"";var n="; "+e;return!0===t?n:n+"="+t}function qe(e,t,n){return encodeURIComponent(e).replace(/%(23|24|26|2B|5E|60|7C)/g,decodeURIComponent).replace(/\(/g,"%28").replace(/\)/g,"%29")+"="+encodeURIComponent(t).replace(/%(23|24|26|2B|3A|3C|3E|3D|2F|3F|40|5B|5D|5E|60|7B|7D|7C)/g,decodeURIComponent)+function(e){if("number"==typeof e.expires){var t=new Date;t.setMilliseconds(t.getMilliseconds()+864e5*e.expires),e.expires=t}return Ye("Expires",e.expires?e.expires.toUTCString():"")+Ye("Domain",e.domain)+Ye("Path",e.path)+Ye("Secure",e.secure)+Ye("SameSite",e.sameSite)}(n)}function Be(){return function(e){for(var t={},n=e?e.split("; "):[],o=/(%[\dA-F]{2})+/gi,i=0;i<n.length;i++){var r=n[i].split("="),s=r.slice(1).join("=");'"'===s.charAt(0)&&(s=s.slice(1,-1));try{t[r[0].replace(o,decodeURIComponent)]=s.replace(o,decodeURIComponent)}catch(e){}}return t}(document.cookie)}var Qe=function(e){return Be()[e]};function $e(e,t,n){document.cookie=qe(e,t,Ge({path:"/"},n))}var et=$e;var tt=function(e,t){$e(e,"",Ge(Ge({},t),{expires:-1}))};const nt={get(e){const t=Qe(e);if(void 0!==t)return JSON.parse(t)},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0,sameSite:"none"}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),et(e,JSON.stringify(t),o)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),tt(e,n)}},ot="_legacy_",it={get(e){const t=nt.get(e);return t||nt.get("".concat(ot).concat(e))},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),et("".concat(ot).concat(e),JSON.stringify(t),o),nt.save(e,t,n)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),tt(e,n),nt.remove(e,t),nt.remove("".concat(ot).concat(e),t)}},rt={get(e){if("undefined"==typeof sessionStorage)return;const t=sessionStorage.getItem(e);return null!=t?JSON.parse(t):void 0},save(e,t){sessionStorage.setItem(e,JSON.stringify(t))},remove(e){sessionStorage.removeItem(e)}},st={Offline:"offline",Online:"online"};var at;!function(e){e.Code="code",e.ConnectCode="connect_code"}(at||(at={}));class ct{}function ut(e,t,n){var o=void 0===t?null:t,i=function(e,t){var n=atob(e);if(t){for(var o=new Uint8Array(n.length),i=0,r=n.length;i<r;++i)o[i]=n.charCodeAt(i);return String.fromCharCode.apply(null,new Uint16Array(o.buffer))}return n}(e,void 0!==n&&n),r=i.indexOf("\n",10)+1,s=i.substring(r)+(o?"//# sourceMappingURL="+o:""),a=new Blob([s],{type:"application/javascript"});return URL.createObjectURL(a)}var lt,dt,ht,pt,ft=(lt="Lyogcm9sbHVwLXBsdWdpbi13ZWItd29ya2VyLWxvYWRlciAqLwohZnVuY3Rpb24oKXsidXNlIHN0cmljdCI7ZnVuY3Rpb24gZShlLHQpeyhudWxsPT10fHx0PmUubGVuZ3RoKSYmKHQ9ZS5sZW5ndGgpO2Zvcih2YXIgcj0wLG89QXJyYXkodCk7cjx0O3IrKylvW3JdPWVbcl07cmV0dXJuIG99ZnVuY3Rpb24gdCh0LHIpe3JldHVybiBmdW5jdGlvbihlKXtpZihBcnJheS5pc0FycmF5KGUpKXJldHVybiBlfSh0KXx8ZnVuY3Rpb24oZSx0KXt2YXIgcj1udWxsPT1lP251bGw6InVuZGVmaW5lZCIhPXR5cGVvZiBTeW1ib2wmJmVbU3ltYm9sLml0ZXJhdG9yXXx8ZVsiQEBpdGVyYXRvciJdO2lmKG51bGwhPXIpe3ZhciBvLG4scyxhLGk9W10sYz0hMCxsPSExO3RyeXtpZihzPShyPXIuY2FsbChlKSkubmV4dCwwPT09dCl7aWYoT2JqZWN0KHIpIT09cilyZXR1cm47Yz0hMX1lbHNlIGZvcig7IShjPShvPXMuY2FsbChyKSkuZG9uZSkmJihpLnB1c2goby52YWx1ZSksaS5sZW5ndGghPT10KTtjPSEwKTt9Y2F0Y2goZSl7bD0hMCxuPWV9ZmluYWxseXt0cnl7aWYoIWMmJm51bGwhPXIucmV0dXJuJiYoYT1yLnJldHVybigpLE9iamVjdChhKSE9PWEpKXJldHVybn1maW5hbGx5e2lmKGwpdGhyb3cgbn19cmV0dXJuIGl9fSh0LHIpfHxmdW5jdGlvbih0LHIpe2lmKHQpe2lmKCJzdHJpbmciPT10eXBlb2YgdClyZXR1cm4gZSh0LHIpO3ZhciBvPXt9LnRvU3RyaW5nLmNhbGwodCkuc2xpY2UoOCwtMSk7cmV0dXJuIk9iamVjdCI9PT1vJiZ0LmNvbnN0cnVjdG9yJiYobz10LmNvbnN0cnVjdG9yLm5hbWUpLCJNYXAiPT09b3x8IlNldCI9PT1vP0FycmF5LmZyb20odCk6IkFyZ3VtZW50cyI9PT1vfHwvXig/OlVpfEkpbnQoPzo4fDE2fDMyKSg/OkNsYW1wZWQpP0FycmF5JC8udGVzdChvKT9lKHQscik6dm9pZCAwfX0odCxyKXx8ZnVuY3Rpb24oKXt0aHJvdyBuZXcgVHlwZUVycm9yKCJJbnZhbGlkIGF0dGVtcHQgdG8gZGVzdHJ1Y3R1cmUgbm9uLWl0ZXJhYmxlIGluc3RhbmNlLlxuSW4gb3JkZXIgdG8gYmUgaXRlcmFibGUsIG5vbi1hcnJheSBvYmplY3RzIG11c3QgaGF2ZSBhIFtTeW1ib2wuaXRlcmF0b3JdKCkgbWV0aG9kLiIpfSgpfWNsYXNzIHIgZXh0ZW5kcyBFcnJvcntjb25zdHJ1Y3RvcihlLHQpe3N1cGVyKHQpLHRoaXMuZXJyb3I9ZSx0aGlzLmVycm9yX2Rlc2NyaXB0aW9uPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsci5wcm90b3R5cGUpfXN0YXRpYyBmcm9tUGF5bG9hZChlKXtsZXQgdD1lLmVycm9yLG89ZS5lcnJvcl9kZXNjcmlwdGlvbjtyZXR1cm4gbmV3IHIodCxvKX19Y2xhc3MgbyBleHRlbmRzIHJ7Y29uc3RydWN0b3IoZSx0KXtzdXBlcigibWlzc2luZ19yZWZyZXNoX3Rva2VuIiwiTWlzc2luZyBSZWZyZXNoIFRva2VuIChhdWRpZW5jZTogJyIuY29uY2F0KG4oZSxbImRlZmF1bHQiXSksIicsIHNjb3BlOiAnIikuY29uY2F0KG4odCksIicpIikpLHRoaXMuYXVkaWVuY2U9ZSx0aGlzLnNjb3BlPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsby5wcm90b3R5cGUpfX1mdW5jdGlvbiBuKGUpe3JldHVybiBlJiYhKGFyZ3VtZW50cy5sZW5ndGg+MSYmdm9pZCAwIT09YXJndW1lbnRzWzFdP2FyZ3VtZW50c1sxXTpbXSkuaW5jbHVkZXMoZSk/ZToiIn0iZnVuY3Rpb24iPT10eXBlb2YgU3VwcHJlc3NlZEVycm9yJiZTdXBwcmVzc2VkRXJyb3I7Y29uc3Qgcz1lPT57dmFyIHQ9ZS5jbGllbnRJZCxyPWZ1bmN0aW9uKGUsdCl7dmFyIHI9e307Zm9yKHZhciBvIGluIGUpT2JqZWN0LnByb3RvdHlwZS5oYXNPd25Qcm9wZXJ0eS5jYWxsKGUsbykmJnQuaW5kZXhPZihvKTwwJiYocltvXT1lW29dKTtpZihudWxsIT1lJiYiZnVuY3Rpb24iPT10eXBlb2YgT2JqZWN0LmdldE93blByb3BlcnR5U3ltYm9scyl7dmFyIG49MDtmb3Iobz1PYmplY3QuZ2V0T3duUHJvcGVydHlTeW1ib2xzKGUpO248by5sZW5ndGg7bisrKXQuaW5kZXhPZihvW25dKTwwJiZPYmplY3QucHJvdG90eXBlLnByb3BlcnR5SXNFbnVtZXJhYmxlLmNhbGwoZSxvW25dKSYmKHJbb1tuXV09ZVtvW25dXSl9cmV0dXJuIHJ9KGUsWyJjbGllbnRJZCJdKTtyZXR1cm4gbmV3IFVSTFNlYXJjaFBhcmFtcygoZT0+T2JqZWN0LmtleXMoZSkuZmlsdGVyKHQ9PnZvaWQgMCE9PWVbdF0pLnJlZHVjZSgodCxyKT0+T2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHQpLHtbcl06ZVtyXX0pLHt9KSkoT2JqZWN0LmFzc2lnbih7Y2xpZW50X2lkOnR9LHIpKSkudG9TdHJpbmcoKX07bGV0IGE9e30saT1udWxsO2NvbnN0IGM9KGUsdCk9PiIiLmNvbmNhdChlLCJ8IikuY29uY2F0KHQpLGw9KGUsdCk9PnQuc3RhcnRzV2l0aCgiIi5jb25jYXQoZSwifCIpKSx1PShlLHQpPT5hW2MoZSx0KV0sZj1lPT57T2JqZWN0LmVudHJpZXMoYSkuZm9yRWFjaChyPT57bGV0IG89dChyLDIpLG49b1swXTtvWzFdPT09ZSYmZGVsZXRlIGFbbl19KX0saD1lPT57Y29uc3QgdD1uZXcgVVJMU2VhcmNoUGFyYW1zKGUpLHI9e307cmV0dXJuIHQuZm9yRWFjaCgoZSx0KT0+e3JbdF09ZX0pLHJ9LGQ9YXN5bmMgZT0+e2xldCByLG4saT1lLmRhdGEsZj1pLnRpbWVvdXQsZD1pLmF1dGgscD1pLmZldGNoVXJsLHk9aS5mZXRjaE9wdGlvbnMsZz1pLnVzZUZvcm1EYXRhLGI9aS51c2VNcnJ0LE89aS5za2lwVG9rZW5TdG9yYWdlLGs9aS5wcmVzZXJ2ZVJlZnJlc2hUb2tlbixtPXQoZS5wb3J0cywxKVswXSxqPXt9O2NvbnN0IHY9ZHx8e30sXz12LmF1ZGllbmNlLHc9di5zY29wZTt0cnl7Y29uc3QgZT1nP2goeS5ib2R5KTpKU09OLnBhcnNlKHkuYm9keSk7aWYoZS5yZWZyZXNoX3Rva2VufHwicmVmcmVzaF90b2tlbiIhPT1lLmdyYW50X3R5cGUpZS5tZmFfdG9rZW4mJihuPXUoXyx3KSwhbiYmYiYmKG49YS5sYXRlc3RfcmVmcmVzaF90b2tlbikpO2Vsc2V7aWYobj11KF8sdyksIW4mJmIpe2NvbnN0IGU9YS5sYXRlc3RfcmVmcmVzaF90b2tlbix0PSgoZSx0KT0+ISFPYmplY3Qua2V5cyhhKS5maW5kKHI9PntpZigibGF0ZXN0X3JlZnJlc2hfdG9rZW4iIT09cil7Y29uc3Qgbz1sKHQsciksbj1yLnNwbGl0KCJ8IilbMV0uc3BsaXQoIiAiKSxzPWUuc3BsaXQoIiAiKS5ldmVyeShlPT5uLmluY2x1ZGVzKGUpKTtyZXR1cm4gbyYmc319KSkodyxfKTtlJiYhdCYmKG49ZSl9aWYoIW4pdGhyb3cgbmV3IG8oXyx3KTt5LmJvZHk9Zz9zKE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpfWxldCBpLGQ7ImZ1bmN0aW9uIj09dHlwZW9mIEFib3J0Q29udHJvbGxlciYmKGk9bmV3IEFib3J0Q29udHJvbGxlcix5LnNpZ25hbD1pLnNpZ25hbCk7dHJ5e2Q9YXdhaXQgUHJvbWlzZS5yYWNlKFsoUD1mLG5ldyBQcm9taXNlKGU9PnNldFRpbWVvdXQoZSxQKSkpLGZldGNoKHAsT2JqZWN0LmFzc2lnbih7fSx5KSldKX1jYXRjaChlKXtyZXR1cm4gdm9pZCBtLnBvc3RNZXNzYWdlKHtlcnJvcjplLm1lc3NhZ2V9KX1pZighZClyZXR1cm4gaSYmaS5hYm9ydCgpLHZvaWQgbS5wb3N0TWVzc2FnZSh7ZXJyb3I6IlRpbWVvdXQgd2hlbiBleGVjdXRpbmcgJ2ZldGNoJyJ9KTtpZihVPWQuaGVhZGVycyxqPVsuLi5VXS5yZWR1Y2UoKGUscik9PntsZXQgbz10KHIsMiksbj1vWzBdLHM9b1sxXTtyZXR1cm4gZVtuXT1zLGV9LHt9KSxyPWF3YWl0IGQuanNvbigpLE8pcmV0dXJuIGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4sdm9pZCBtLnBvc3RNZXNzYWdlKHtvazpkLm9rLGpzb246cixoZWFkZXJzOmp9KTtyLnJlZnJlc2hfdG9rZW4/KGImJihhLmxhdGVzdF9yZWZyZXNoX3Rva2VuPXIucmVmcmVzaF90b2tlbixTPW4sTT1yLnJlZnJlc2hfdG9rZW4sT2JqZWN0LmVudHJpZXMoYSkuZm9yRWFjaChlPT57bGV0IHI9dChlLDIpLG89clswXTtyWzFdPT09UyYmKGFbb109TSl9KSksKChlLHQscik9PnthW2ModCxyKV09ZX0pKHIucmVmcmVzaF90b2tlbixfLHcpLGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4pOmt8fCgoZSx0KT0+e2RlbGV0ZSBhW2MoZSx0KV19KShfLHcpLG0ucG9zdE1lc3NhZ2Uoe29rOmQub2ssanNvbjpyLGhlYWRlcnM6an0pfWNhdGNoKGUpe20ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOmUuZXJyb3IsZXJyb3JfZGVzY3JpcHRpb246ZS5tZXNzYWdlfSxoZWFkZXJzOmp9KX12YXIgUyxNLFUsUH0scD1hc3luYyBlPT57bGV0IHI9ZS5kYXRhLG89ci50aW1lb3V0LG49ci5hdXRoLGk9ci5mZXRjaFVybCxjPXIuZmV0Y2hPcHRpb25zLHU9ci51c2VGb3JtRGF0YSxkPXQoZS5wb3J0cywxKVswXTtjb25zdCBwPShufHx7fSkuYXVkaWVuY2U7dHJ5e2NvbnN0IGU9KGU9Pntjb25zdCByPW5ldyBTZXQ7cmV0dXJuIE9iamVjdC5lbnRyaWVzKGEpLmZvckVhY2gobz0+e2xldCBuPXQobywyKSxzPW5bMF0sYT1uWzFdO2woZSxzKSYmci5hZGQoYSl9KSxBcnJheS5mcm9tKHIpfSkocCk7aWYoMD09PWUubGVuZ3RoKXJldHVybiB2b2lkIGQucG9zdE1lc3NhZ2Uoe29rOiEwfSk7Y29uc3Qgcj11P2goYy5ib2R5KTpKU09OLnBhcnNlKGMuYm9keSk7Zm9yKGNvbnN0IHQgb2YgZSl7Y29uc3QgZT11P3MoT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHIpLHt0b2tlbjp0fSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxyKSx7dG9rZW46dH0pKTtsZXQgbixhLGwsaDsiZnVuY3Rpb24iPT10eXBlb2YgQWJvcnRDb250cm9sbGVyJiYobj1uZXcgQWJvcnRDb250cm9sbGVyLGE9bi5zaWduYWwpO3RyeXtoPWF3YWl0IFByb21pc2UucmFjZShbbmV3IFByb21pc2UoZT0+e2w9c2V0VGltZW91dChlLG8pfSksZmV0Y2goaSxPYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30sYykse2JvZHk6ZSxzaWduYWw6YX0pKV0pLmZpbmFsbHkoKCk9PmNsZWFyVGltZW91dChsKSl9Y2F0Y2goZSl7cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZS5tZXNzYWdlfSl9aWYoIWgpcmV0dXJuIG4mJm4uYWJvcnQoKSx2b2lkIGQucG9zdE1lc3NhZ2Uoe2Vycm9yOiJUaW1lb3V0IHdoZW4gZXhlY3V0aW5nICdmZXRjaCcifSk7aWYoIWgub2spe2xldCBlO3RyeXtjb25zdCB0PUpTT04ucGFyc2UoYXdhaXQgaC50ZXh0KCkpO2U9dC5lcnJvcl9kZXNjcmlwdGlvbn1jYXRjaChlKXt9cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZXx8IkhUVFAgZXJyb3IgIi5jb25jYXQoaC5zdGF0dXMpfSl9Zih0KX1kLnBvc3RNZXNzYWdlKHtvazohMH0pfWNhdGNoKGUpe2QucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZXx8IlVua25vd24gZXJyb3IgZHVyaW5nIHRva2VuIHJldm9jYXRpb24ifSl9fSx5PShlLHQpPT57aWYoIWkpcmV0dXJuITE7dHJ5e2NvbnN0IHI9bmV3IFVSTChpKS5vcmlnaW4sbz1uZXcgVVJMKGUuZmV0Y2hVcmwpO3JldHVybiBvLm9yaWdpbj09PXImJm8ucGF0aG5hbWU9PT10fWNhdGNoKGUpe3JldHVybiExfX07YWRkRXZlbnRMaXN0ZW5lcigibWVzc2FnZSIsZT0+e2NvbnN0IHI9ZS5kYXRhLG89dChlLnBvcnRzLDEpWzBdO2lmKCEoInR5cGUiaW4gcil8fCJpbml0IiE9PXIudHlwZSlyZXR1cm4idHlwZSJpbiByJiYiY2xlYXIiPT09ci50eXBlPyhhPXt9LHZvaWQobnVsbD09b3x8by5wb3N0TWVzc2FnZSh7b2s6ITB9KSkpOiJ0eXBlImluIHImJiJyZXZva2UiPT09ci50eXBlP3kociwiL29hdXRoL3Jldm9rZSIpP3ZvaWQgcChlKTp2b2lkKG51bGw9PW98fG8ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOiJpbnZhbGlkX2ZldGNoX3VybCIsZXJyb3JfZGVzY3JpcHRpb246IlVuYXV0aG9yaXplZCBmZXRjaCBVUkwifSxoZWFkZXJzOnt9fSkpOnZvaWQoImZldGNoVXJsImluIHImJnkociwiL29hdXRoL3Rva2VuIik/ZChlKTpudWxsPT1vfHxvLnBvc3RNZXNzYWdlKHtvazohMSxqc29uOntlcnJvcjoiaW52YWxpZF9mZXRjaF91cmwiLGVycm9yX2Rlc2NyaXB0aW9uOiJVbmF1dGhvcml6ZWQgZmV0Y2ggVVJMIn0saGVhZGVyczp7fX0pKTtpZihudWxsPT09aSl0cnl7bmV3IFVSTChyLmFsbG93ZWRCYXNlVXJsKSxpPXIuYWxsb3dlZEJhc2VVcmx9Y2F0Y2goZSl7cmV0dXJufX0pfSgpOwoK",dt=null,ht=!1,function(e){return pt=pt||ut(lt,dt,ht),new Worker(pt,e)});class mt{constructor(e,t){this.cache=e,this.clientId=t,this.manifestKey=this.createManifestKeyFrom(this.clientId)}async add(e){var t;const n=new Set((null===(t=await this.cache.get(this.manifestKey))||void 0===t?void 0:t.keys)||[]);n.add(e),await this.cache.set(this.manifestKey,{keys:[...n]})}async remove(e){const t=await this.cache.get(this.manifestKey);if(t){const n=new Set(t.keys);return n.delete(e),n.size>0?await this.cache.set(this.manifestKey,{keys:[...n]}):await this.cache.remove(this.manifestKey)}}get(){return this.cache.get(this.manifestKey)}clear(){return this.cache.remove(this.manifestKey)}createManifestKeyFrom(e){return"".concat(Ue,"::").concat(e)}}const yt="auth0.is.authenticated",wt={memory:()=>(new De).enclosedCache,localstorage:()=>new Je},gt=e=>wt[e],vt=t=>{const n=t.openUrl,o=t.onRedirect,i=e(t,["openUrl","onRedirect"]);return Object.assign(Object.assign({},i),{openUrl:!1===n||n?n:o})},bt=(e,t,n)=>{const o=(null==e?void 0:e.split(" "))||[],i=n?o.filter(e=>e!==k):o;const r=(null==t?void 0:t.split(" "))||[];return i.filter(e=>-1==r.indexOf(e)).join(",")},_t={NONCE:"nonce",KEYPAIR:"keypair"};class kt{constructor(e){this.clientId=e}getVersion(){return 1}createDbHandle(){const e=window.indexedDB.open("auth0-spa-js",this.getVersion());return new Promise((t,n)=>{e.onupgradeneeded=()=>Object.values(_t).forEach(t=>e.result.createObjectStore(t)),e.onerror=()=>n(e.error),e.onsuccess=()=>t(e.result)})}async getDbHandle(){return this.dbHandle||(this.dbHandle=await this.createDbHandle()),this.dbHandle}async executeDbRequest(e,t,n){const o=n((await this.getDbHandle()).transaction(e,t).objectStore(e));return new Promise((e,t)=>{o.onsuccess=()=>e(o.result),o.onerror=()=>t(o.error)})}buildKey(e){const t=e?"_".concat(e):"auth0";return"".concat(this.clientId,"::").concat(t)}setNonce(e,t){return this.save(_t.NONCE,this.buildKey(t),e)}setKeyPair(e){return this.save(_t.KEYPAIR,this.buildKey(),e)}async save(e,t,n){await this.executeDbRequest(e,"readwrite",e=>e.put(n,t))}findNonce(e){return this.find(_t.NONCE,this.buildKey(e))}findKeyPair(){return this.find(_t.KEYPAIR,this.buildKey())}find(e,t){return this.executeDbRequest(e,"readonly",e=>e.get(t))}async deleteBy(e,t){const n=await this.executeDbRequest(e,"readonly",e=>e.getAllKeys());await Promise.all((null==n?void 0:n.filter(t).map(t=>this.executeDbRequest(e,"readwrite",e=>e.delete(t))))||[])}deleteByClientId(e,t){return this.deleteBy(e,e=>"string"==typeof e&&e.startsWith("".concat(t,"::")))}clearNonces(){return this.deleteByClientId(_t.NONCE,this.clientId)}clearKeyPairs(){return this.deleteByClientId(_t.KEYPAIR,this.clientId)}}class St{constructor(e){this.storage=new kt(e)}getNonce(e){return this.storage.findNonce(e)}setNonce(e,t){return this.storage.setNonce(e,t)}async getOrGenerateKeyPair(){let e=await this.storage.findKeyPair();return e||(e=await Re(),await this.storage.setKeyPair(e)),e}async generateProof(e){const t=await this.getOrGenerateKeyPair();return xe(Object.assign({keyPair:t},e))}async calculateThumbprint(){return Ae(await this.getOrGenerateKeyPair())}async clear(){await Promise.all([this.storage.clearNonces(),this.storage.clearKeyPairs()])}}var Tt;!function(e){e.Bearer="Bearer",e.DPoP="DPoP"}(Tt||(Tt={}));class Pt{constructor(e,t){this.hooks=t,this.config=Object.assign(Object.assign({},e),{fetch:e.fetch||("undefined"==typeof window?fetch:window.fetch.bind(window))})}isAbsoluteUrl(e){return/^(https?:)?\/\//i.test(e)}buildUrl(e,t){if(t){if(this.isAbsoluteUrl(t))return t;if(e)return"".concat(e.replace(/\/?\/$/,""),"/").concat(t.replace(/^\/+/,""))}throw new TypeError("`url` must be absolute or `baseUrl` non-empty.")}getAccessToken(e){return this.config.getAccessToken?this.config.getAccessToken(e):this.hooks.getAccessToken(e)}extractUrl(e){return"string"==typeof e?e:e instanceof URL?e.href:e.url}buildBaseRequest(e,t){if(!this.config.baseUrl)return new Request(e,t);const n=this.buildUrl(this.config.baseUrl,this.extractUrl(e)),o=e instanceof Request?new Request(n,e):n;return new Request(o,t)}setAuthorizationHeader(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:Tt.Bearer;e.headers.set("authorization","".concat(n," ").concat(t))}async setDpopProofHeader(e,t){if(!this.config.dpopNonceId)return;const n=await this.hooks.getDpopNonce(),o=await this.hooks.generateDpopProof({accessToken:t,method:e.method,nonce:n,url:e.url});e.headers.set("dpop",o)}async prepareRequest(e,t){const n=await this.getAccessToken(t);if(void 0===n)throw new E("missing_access_token","No access token available");let o,i;"string"==typeof n?(o=this.config.dpopNonceId?Tt.DPoP:Tt.Bearer,i=n):(o=n.token_type,i=n.access_token),this.setAuthorizationHeader(e,i,o),o===Tt.DPoP&&await this.setDpopProofHeader(e,i)}getHeader(e,t){return Array.isArray(e)?new Headers(e).get(t)||"":"function"==typeof e.get?e.get(t)||"":e[t]||""}hasUseDpopNonceError(e){if(401!==e.status)return!1;const t=this.getHeader(e.headers,"www-authenticate");return t.includes("invalid_dpop_nonce")||t.includes("use_dpop_nonce")}async handleResponse(e,t){const n=this.getHeader(e.headers,Ee);if(n&&await this.hooks.setDpopNonce(n),!this.hasUseDpopNonceError(e))return e;if(!n||!t.onUseDpopNonceError)throw new M(n);return t.onUseDpopNonceError()}async internalFetchWithAuth(e,t,n,o){const i=this.buildBaseRequest(e,t);await this.prepareRequest(i,o);const r=await this.config.fetch(i);return this.handleResponse(r,n)}fetchWithAuth(e,t,n){const o={onUseDpopNonceError:()=>this.internalFetchWithAuth(e,t,Object.assign(Object.assign({},o),{onUseDpopNonceError:void 0}),n)};return this.internalFetchWithAuth(e,t,o,n)}}class Et{constructor(e,t){this.myAccountFetcher=e,this.apiBase=t}async connectAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/connect"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:connected_accounts"]});return this._handleResponse(t)}async completeAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/complete"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:connected_accounts"]});return this._handleResponse(t)}async getFactors(){const e=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/factors"),{method:"GET"},{scope:["read:me:factors"]});return(await this._handleResponse(e)).factors}async getAuthenticationMethods(e){const t=e?"?".concat(new URLSearchParams({type:e})):"",n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods").concat(t),{method:"GET"},{scope:["read:me:authentication_methods"]});return(await this._handleResponse(n)).authentication_methods}async getAuthenticationMethod(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"GET"},{scope:["read:me:authentication_methods"]});return this._handleResponse(t)}async deleteAuthenticationMethod(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"DELETE"},{scope:["delete:me:authentication_methods"]});t.ok||await this._handleResponse(t)}async updateAuthenticationMethod(e,t){const n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"PATCH",headers:{"Content-Type":"application/json"},body:JSON.stringify(t)},{scope:["update:me:authentication_methods"]});return this._handleResponse(n)}async enrollmentChallenge(e){var t;const n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:authentication_methods"]}),o=await this._handleResponse(n),i=null!==(t=n.headers.get("location"))&&void 0!==t?t:"",r=decodeURIComponent(i.split("/").pop()||"");return Object.assign(Object.assign({},o),{id:r,location:i})}async enrollmentVerify(t){const n=t,o=n.location;n.type;const i=e(n,["location","type"]),r=await this.myAccountFetcher.fetchWithAuth("".concat(o,"/verify"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(i)},{scope:["create:me:authentication_methods"]});return this._handleResponse(r)}async _handleResponse(e){let t;try{t=await e.text(),t=JSON.parse(t)}catch(n){throw new Ct({type:"invalid_json",status:e.status,title:"Invalid JSON response",detail:t||String(n)})}if(e.ok)return t;throw new Ct(t)}}class Ct extends Error{constructor(e){let t=e.type,n=e.status,o=e.title,i=e.detail,r=e.validation_errors;super(i),this.name="MyAccountApiError",this.type=t,this.status=n,this.title=o,this.detail=i,this.validation_errors=r,Object.setPrototypeOf(this,Ct.prototype)}}const Rt={otp:{authenticatorTypes:["otp"]},sms:{authenticatorTypes:["oob"],oobChannels:["sms"]},email:{authenticatorTypes:["oob"],oobChannels:["email"]},push:{authenticatorTypes:["oob"],oobChannels:["auth0"]},voice:{authenticatorTypes:["oob"],oobChannels:["voice"]}},At="http://auth0.com/oauth/grant-type/mfa-otp",xt="http://auth0.com/oauth/grant-type/mfa-oob",It="http://auth0.com/oauth/grant-type/mfa-recovery-code";var Ot,jt;let Wt;if("undefined"==typeof navigator||null===(Ot=navigator.userAgent)||void 0===Ot||null===(jt=Ot.startsWith)||void 0===jt||!jt.call(Ot,"Mozilla/5.0 ")){const e="v3.8.6";Wt="".concat("oauth4webapi","/").concat(e)}function Nt(e,t){if(null==e)return!1;try{return e instanceof t||Object.getPrototypeOf(e)[Symbol.toStringTag]===t.prototype[Symbol.toStringTag]}catch(e){return!1}}const Kt="ERR_INVALID_ARG_VALUE",Mt="ERR_INVALID_ARG_TYPE";function Ut(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}const Lt=Symbol(),zt=Symbol(),Jt=Symbol(),Dt=Symbol(),Zt=Symbol(),Ht=Symbol(),Ft=new TextEncoder,Vt=new TextDecoder;function Xt(e){return"string"==typeof e?Ft.encode(e):Vt.decode(e)}let Gt,Yt;if(Uint8Array.prototype.toBase64)Gt=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;Gt=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function qt(e){return"string"==typeof e?Yt(e):Gt(e)}Yt=Uint8Array.fromBase64?e=>{try{return Uint8Array.fromBase64(e,{alphabet:"base64url"})}catch(e){throw Ut("The input to be decoded is not correctly encoded.",Kt,e)}}:e=>{try{const t=atob(e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"")),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}catch(e){throw Ut("The input to be decoded is not correctly encoded.",Kt,e)}};class Bt extends Error{constructor(e,t){var n;super(e,t),h(this,"code",void 0),this.name=this.constructor.name,this.code=ro,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class Qt extends Error{constructor(e,t){var n;super(e,t),h(this,"code",void 0),this.name=this.constructor.name,null!=t&&t.code&&(this.code=null==t?void 0:t.code),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function $t(e,t,n){return new Qt(e,{code:t,cause:n})}function en(e,t){if(function(e,t){if(!(e instanceof CryptoKey))throw Ut("".concat(t," must be a CryptoKey"),Mt)}(e,t),"private"!==e.type)throw Ut("".concat(t," must be a private CryptoKey"),Kt)}function tn(e){return null!==e&&"object"==typeof e&&!Array.isArray(e)}function nn(e){Nt(e,Headers)&&(e=Object.fromEntries(e.entries()));const t=new Headers(null!=e?e:{});if(Wt&&!t.has("user-agent")&&t.set("user-agent",Wt),t.has("authorization"))throw Ut('"options.headers" must not include the "authorization" header name',Kt);return t}function on(e,t){if(void 0!==t){if("function"==typeof t&&(t=t(e.href)),!(t instanceof AbortSignal))throw Ut('"options.signal" must return or be an instance of AbortSignal',Mt);return t}}function rn(e){return e.includes("//")?e.replace("//","/"):e}async function sn(e,t){return async function(e,t,n,o){if(!(e instanceof URL))throw Ut('"'.concat(t,'" must be an instance of URL'),Mt);bn(e,!0!==(null==o?void 0:o[Lt]));const i=n(new URL(e.href)),r=nn(null==o?void 0:o.headers);return r.set("accept","application/json"),((null==o?void 0:o[Dt])||fetch)(i.href,{body:void 0,headers:Object.fromEntries(r.entries()),method:"GET",redirect:"manual",signal:on(i,null==o?void 0:o.signal)})}(e,"issuerIdentifier",e=>{switch(null==t?void 0:t.algorithm){case void 0:case"oidc":!function(e,t){e.pathname=rn("".concat(e.pathname,"/").concat(t))}(e,".well-known/openid-configuration");break;case"oauth2":!function(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];"/"===e.pathname?e.pathname=t:e.pathname=rn("".concat(t,"/").concat(n?e.pathname:e.pathname.replace(/(\/)$/,"")))}(e,".well-known/oauth-authorization-server");break;default:throw Ut('"options.algorithm" must be "oidc" (default), or "oauth2"',Kt)}return e},t)}function an(e,t,n,o,i){try{if("number"!=typeof e||!Number.isFinite(e))throw Ut("".concat(n," must be a number"),Mt,i);if(e>0)return;if(t){if(0!==e)throw Ut("".concat(n," must be a non-negative number"),Kt,i);return}throw Ut("".concat(n," must be a positive number"),Kt,i)}catch(e){if(o)throw $t(e.message,o,i);throw e}}function cn(e,t,n,o){try{if("string"!=typeof e)throw Ut("".concat(t," must be a string"),Mt,o);if(0===e.length)throw Ut("".concat(t," must not be empty"),Kt,o)}catch(e){if(n)throw $t(e.message,n,o);throw e}}function un(e){!function(e,t){if(Mn(e)!==t)throw function(e){let t='"response" content-type must be ';for(var n=arguments.length,o=new Array(n>1?n-1:0),i=1;i<n;i++)o[i-1]=arguments[i];if(o.length>2){const e=o.pop();t+="".concat(o.join(", "),", or ").concat(e)}else 2===o.length?t+="".concat(o[0]," or ").concat(o[1]):t+=o[0];return $t(t,lo,e)}(e,t)}(e,"application/json")}function ln(){return qt(crypto.getRandomValues(new Uint8Array(32)))}function dn(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"PS256";case"SHA-384":return"PS384";case"SHA-512":return"PS512";default:throw new Bt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"RSASSA-PKCS1-v1_5":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"RS256";case"SHA-384":return"RS384";case"SHA-512":return"RS512";default:throw new Bt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"ECDSA":return function(e){switch(e.algorithm.namedCurve){case"P-256":return"ES256";case"P-384":return"ES384";case"P-521":return"ES512";default:throw new Bt("unsupported EcKeyAlgorithm namedCurve",{cause:e})}}(e);case"Ed25519":case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return e.algorithm.name;case"EdDSA":return"Ed25519";default:throw new Bt("unsupported CryptoKey algorithm name",{cause:e})}}function hn(e){const t=null==e?void 0:e[zt];return"number"==typeof t&&Number.isFinite(t)?t:0}function pn(e){const t=null==e?void 0:e[Jt];return"number"==typeof t&&Number.isFinite(t)&&-1!==Math.sign(t)?t:30}function fn(){return Math.floor(Date.now()/1e3)}function mn(e){if("object"!=typeof e||null===e)throw Ut('"as" must be an object',Mt);cn(e.issuer,'"as.issuer"')}function yn(e){if("object"!=typeof e||null===e)throw Ut('"client" must be an object',Mt);cn(e.client_id,'"client.client_id"')}function wn(e){return cn(e,'"clientSecret"'),(t,n,o,i)=>{o.set("client_id",n.client_id),o.set("client_secret",e)}}function gn(e,t){const n=(r=e)instanceof CryptoKey?{key:r}:(null==r?void 0:r.key)instanceof CryptoKey?(void 0!==r.kid&&cn(r.kid,'"kid"'),{key:r.key,kid:r.kid}):{},o=n.key,i=n.kid;var r;return en(o,'"clientPrivateKey.key"'),async(e,n,r,s)=>{var a;const c={alg:dn(o),kid:i},u=function(e,t){const n=fn()+hn(t);return{jti:ln(),aud:e.issuer,exp:n+60,iat:n,nbf:n,iss:t.client_id,sub:t.client_id}}(e,n);null==t||null===(a=t[Zt])||void 0===a||a.call(t,c,u),r.set("client_id",n.client_id),r.set("client_assertion_type","urn:ietf:params:oauth:client-assertion-type:jwt-bearer"),r.set("client_assertion",await async function(e,t,n){if(!n.usages.includes("sign"))throw Ut('CryptoKey instances used for signing assertions must include "sign" in their "usages"',Kt);const o="".concat(qt(Xt(JSON.stringify(e))),".").concat(qt(Xt(JSON.stringify(t)))),i=qt(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:So(e)};case"RSA-PSS":switch(ko(e),e.algorithm.hash.name){case"SHA-256":case"SHA-384":case"SHA-512":return{name:e.algorithm.name,saltLength:parseInt(e.algorithm.hash.name.slice(-3),10)>>3};default:throw new Bt("unsupported RSA-PSS hash name",{cause:e})}case"RSASSA-PKCS1-v1_5":return ko(e),e.algorithm.name;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":case"Ed25519":return e.algorithm.name}throw new Bt("unsupported CryptoKey algorithm name",{cause:e})}(n),n,Xt(o)));return"".concat(o,".").concat(i)}(c,u,o))}}const vn=URL.parse?(e,t)=>URL.parse(e,t):(e,t)=>{try{return new URL(e,t)}catch(e){return null}};function bn(e,t){if(t&&"https:"!==e.protocol)throw $t("only requests to HTTPS are allowed",po,e);if("https:"!==e.protocol&&"http:"!==e.protocol)throw $t("only HTTP and HTTPS requests are allowed",fo,e)}function _n(e,t,n,o){let i;if("string"!=typeof e||!(i=vn(e)))throw $t("authorization server metadata does not contain a valid ".concat(n?'"as.mtls_endpoint_aliases.'.concat(t,'"'):'"as.'.concat(t,'"')),void 0===e?go:vo,{attribute:n?"mtls_endpoint_aliases.".concat(t):t});return bn(i,o),i}function kn(e,t,n,o){return n&&e.mtls_endpoint_aliases&&t in e.mtls_endpoint_aliases?_n(e.mtls_endpoint_aliases[t],t,n,o):_n(e[t],t,n,o)}class Sn extends Error{constructor(e,t){var n;super(e,t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"error",void 0),h(this,"status",void 0),h(this,"error_description",void 0),h(this,"response",void 0),this.name=this.constructor.name,this.code=io,this.cause=t.cause,this.error=t.cause.error,this.status=t.response.status,this.error_description=t.cause.error_description,Object.defineProperty(this,"response",{enumerable:!1,value:t.response}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class Tn extends Error{constructor(e,t){var n,o;super(e,t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"error",void 0),h(this,"error_description",void 0),this.name=this.constructor.name,this.code=so,this.cause=t.cause,this.error=t.cause.get("error"),this.error_description=null!==(n=t.cause.get("error_description"))&&void 0!==n?n:void 0,null===(o=Error.captureStackTrace)||void 0===o||o.call(Error,this,this.constructor)}}class Pn extends Error{constructor(e,t){var n;super(e,t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"response",void 0),h(this,"status",void 0),this.name=this.constructor.name,this.code=oo,this.cause=t.cause,this.status=t.response.status,this.response=t.response,Object.defineProperty(this,"response",{enumerable:!1}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}const En="[a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+",Cn="("+En+')\\s*=\\s*"((?:[^"\\\\]|\\\\[\\s\\S])*)"',Rn="("+En+")\\s*=\\s*("+En+")",An=new RegExp("^[,\\s]*("+En+")"),xn=new RegExp("^[,\\s]*"+Cn+"[,\\s]*(.*)"),In=new RegExp("^[,\\s]*"+Rn+"[,\\s]*(.*)"),On=new RegExp("^([a-zA-Z0-9\\-\\._\\~\\+\\/]+={0,2})(?:$|[,\\s])(.*)");async function jn(e,t,n){if(e.status!==t){let t;var o;if(Fn(e),t=await async function(e){if(e.status>399&&e.status<500){_o(e),un(e);try{const t=await e.clone().json();if(tn(t)&&"string"==typeof t.error&&t.error.length)return t}catch(e){}}}(e))throw await(null===(o=e.body)||void 0===o?void 0:o.cancel()),new Sn("server responded with an error in the response body",{cause:t,response:e});throw $t('"response" is not a conform '.concat(n," response (unexpected HTTP status code)"),ho,e)}}function Wn(e){if(!qn.has(e))throw Ut('"options.DPoP" is not a valid DPoPHandle',Kt)}async function Nn(e,t,n,o){mn(e),yn(t);const i=kn(e,"userinfo_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==o?void 0:o[Lt])),r=nn(null==o?void 0:o.headers);return t.userinfo_signed_response_alg?r.set("accept","application/jwt"):(r.set("accept","application/json"),r.append("accept","application/jwt")),async function(e,t,n,o,i,r){var s;if(cn(e,'"accessToken"'),!(n instanceof URL))throw Ut('"url" must be an instance of URL',Mt);bn(n,!0!==(null==r?void 0:r[Lt])),o=nn(o),null!=r&&r.DPoP&&(Wn(r.DPoP),await r.DPoP.addProof(n,o,t.toUpperCase(),e)),o.set("authorization","".concat(o.has("dpop")?"DPoP":"Bearer"," ").concat(e));const a=await((null==r?void 0:r[Dt])||fetch)(n.href,{duplex:Nt(i,ReadableStream)?"half":void 0,body:i,headers:Object.fromEntries(o.entries()),method:t,redirect:"manual",signal:on(n,null==r?void 0:r.signal)});return null==r||null===(s=r.DPoP)||void 0===s||s.cacheNonce(a,n),a}(n,"GET",i,r,null,f(f({},o),{},{[zt]:hn(t)}))}const Kn=Symbol();function Mn(e){var t;return null===(t=e.headers.get("content-type"))||void 0===t?void 0:t.split(";")[0]}async function Un(e,t,n,o,i){if(mn(e),yn(t),!Nt(o,Response))throw Ut('"response" must be an instance of Response',Mt);if(Fn(o),200!==o.status)throw $t('"response" is not a conform UserInfo Endpoint response (unexpected HTTP status code)',ho,o);let r;if(_o(o),"application/jwt"===Mn(o)){const n=await To(await o.text(),Eo.bind(void 0,t.userinfo_signed_response_alg,e.userinfo_signing_alg_values_supported,void 0),hn(t),pn(t),null==i?void 0:i[Ht]).then(Vn.bind(void 0,t.client_id)).then(Gn.bind(void 0,e)),s=n.claims,a=n.jwt;Dn.set(o,a),r=s}else{if(t.userinfo_signed_response_alg)throw $t("JWT UserInfo Response expected",ao,o);r=await Io(o)}if(cn(r.sub,'"response" body "sub" property',uo,{body:r}),n===Kn);else if(cn(n,'"expectedSubject"'),r.sub!==n)throw $t('unexpected "response" body "sub" property value',wo,{expected:n,body:r,attribute:"sub"});return r}async function Ln(e,t,n,o,i,r,s){return await n(e,t,i,r),r.set("content-type","application/x-www-form-urlencoded;charset=UTF-8"),((null==s?void 0:s[Dt])||fetch)(o.href,{body:i,headers:Object.fromEntries(r.entries()),method:"POST",redirect:"manual",signal:on(o,null==s?void 0:s.signal)})}async function zn(e,t,n,o,i,r){var s;const a=kn(e,"token_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==r?void 0:r[Lt]));i.set("grant_type",o);const c=nn(null==r?void 0:r.headers);c.set("accept","application/json"),void 0!==(null==r?void 0:r.DPoP)&&(Wn(r.DPoP),await r.DPoP.addProof(a,c,"POST"));const u=await Ln(e,t,n,a,i,c,r);return null==r||null===(s=r.DPoP)||void 0===s||s.cacheNonce(u,a),u}const Jn=new WeakMap,Dn=new WeakMap;function Zn(e){if(!e.id_token)return;const t=Jn.get(e);if(!t)throw Ut('"ref" was already garbage collected or did not resolve from the proper sources',Kt);return t}async function Hn(e,t,n,o,i,r){if(mn(e),yn(t),!Nt(n,Response))throw Ut('"response" must be an instance of Response',Mt);await jn(n,200,"Token Endpoint"),_o(n);const s=await Io(n);if(cn(s.access_token,'"response" body "access_token" property',uo,{body:s}),cn(s.token_type,'"response" body "token_type" property',uo,{body:s}),s.token_type=s.token_type.toLowerCase(),void 0!==s.expires_in){let e="number"!=typeof s.expires_in?parseFloat(s.expires_in):s.expires_in;an(e,!0,'"response" body "expires_in" property',uo,{body:s}),s.expires_in=e}if(void 0!==s.refresh_token&&cn(s.refresh_token,'"response" body "refresh_token" property',uo,{body:s}),void 0!==s.scope&&"string"!=typeof s.scope)throw $t('"response" body "scope" property must be a string',uo,{body:s});if(void 0!==s.id_token){cn(s.id_token,'"response" body "id_token" property',uo,{body:s});const r=["aud","exp","iat","iss","sub"];!0===t.require_auth_time&&r.push("auth_time"),void 0!==t.default_max_age&&(an(t.default_max_age,!0,'"client.default_max_age"'),r.push("auth_time")),null!=o&&o.length&&r.push(...o);const a=await To(s.id_token,Eo.bind(void 0,t.id_token_signed_response_alg,e.id_token_signing_alg_values_supported,"RS256"),hn(t),pn(t),i).then($n.bind(void 0,r)).then(Yn.bind(void 0,e)).then(Xn.bind(void 0,t.client_id)),c=a.claims,u=a.jwt;if(Array.isArray(c.aud)&&1!==c.aud.length){if(void 0===c.azp)throw $t('ID Token "aud" (audience) claim includes additional untrusted audiences',yo,{claims:c,claim:"aud"});if(c.azp!==t.client_id)throw $t('unexpected ID Token "azp" (authorized party) claim value',yo,{expected:t.client_id,claims:c,claim:"azp"})}void 0!==c.auth_time&&an(c.auth_time,!0,'ID Token "auth_time" (authentication time)',uo,{claims:c}),Dn.set(n,u),Jn.set(s,c)}if(void 0!==(null==r?void 0:r[s.token_type]))r[s.token_type](n,s);else if("dpop"!==s.token_type&&"bearer"!==s.token_type)throw new Bt("unsupported `token_type` value",{cause:{body:s}});return s}function Fn(e){let t;if(t=function(e){if(!Nt(e,Response))throw Ut('"response" must be an instance of Response',Mt);const t=e.headers.get("www-authenticate");if(null===t)return;const n=[];let o=t;for(;o;){var i;let e=o.match(An);const t=null===(i=e)||void 0===i?void 0:i[1].toLowerCase();if(!t)return;const c=o.substring(e[0].length);if(c&&!c.match(/^[\s,]/))return;const u=c.match(/^\s+(.*)$/),l=!!u;o=u?u[1]:void 0;const d={};let h;if(l)for(;o;){let t,n;if(e=o.match(xn)){var r=y(e,4);if(t=r[1],n=r[2],o=r[3],n.includes("\\"))try{n=JSON.parse('"'.concat(n,'"'))}catch(e){}d[t.toLowerCase()]=n}else{if(!(e=o.match(In))){if(e=o.match(On)){if(Object.keys(d).length)break;var s=y(e,3);h=s[1],o=s[2];break}return}var a=y(e,4);t=a[1],n=a[2],o=a[3],d[t.toLowerCase()]=n}}else o=c||void 0;const p={scheme:t,parameters:d};h&&(p.token68=h),n.push(p)}return n.length?n:void 0}(e))throw new Pn("server responded with a challenge in the WWW-Authenticate HTTP Header",{cause:t,response:e})}function Vn(e,t){return void 0!==t.claims.aud?Xn(e,t):t}function Xn(e,t){if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e))throw $t('unexpected JWT "aud" (audience) claim value',yo,{expected:e,claims:t.claims,claim:"aud"})}else if(t.claims.aud!==e)throw $t('unexpected JWT "aud" (audience) claim value',yo,{expected:e,claims:t.claims,claim:"aud"});return t}function Gn(e,t){return void 0!==t.claims.iss?Yn(e,t):t}function Yn(e,t){var n,o;const i=null!==(n=null===(o=e[jo])||void 0===o?void 0:o.call(e,t))&&void 0!==n?n:e.issuer;if(t.claims.iss!==i)throw $t('unexpected JWT "iss" (issuer) claim value',yo,{expected:i,claims:t.claims,claim:"iss"});return t}const qn=new WeakSet;const Bn=Symbol();const Qn={aud:"audience",c_hash:"code hash",client_id:"client id",exp:"expiration time",iat:"issued at",iss:"issuer",jti:"jwt id",nonce:"nonce",s_hash:"state hash",sub:"subject",ath:"access token hash",htm:"http method",htu:"http uri",cnf:"confirmation",auth_time:"authentication time"};function $n(e,t){for(const n of e)if(void 0===t.claims[n])throw $t('JWT "'.concat(n,'" (').concat(Qn[n],") claim missing"),uo,{claims:t.claims});return t}const eo=Symbol(),to=Symbol();async function no(e,t,n,o){return"string"==typeof(null==o?void 0:o.expectedNonce)||"number"==typeof(null==o?void 0:o.maxAge)||null!=o&&o.requireIdToken?async function(e,t,n,o,i,r,s){const a=[];switch(o){case void 0:o=eo;break;case eo:break;default:cn(o,'"expectedNonce" argument'),a.push("nonce")}switch(null!=i||(i=t.default_max_age),i){case void 0:i=to;break;case to:break;default:an(i,!0,'"maxAge" argument'),a.push("auth_time")}const c=await Hn(e,t,n,a,r,s);cn(c.id_token,'"response" body "id_token" property',uo,{body:c});const u=Zn(c);if(i!==to){const e=fn()+hn(t),n=pn(t);if(u.auth_time+i<e-n)throw $t("too much time has elapsed since the last End-User authentication",mo,{claims:u,now:e,tolerance:n,claim:"auth_time"})}if(o===eo){if(void 0!==u.nonce)throw $t('unexpected ID Token "nonce" claim value',yo,{expected:void 0,claims:u,claim:"nonce"})}else if(u.nonce!==o)throw $t('unexpected ID Token "nonce" claim value',yo,{expected:o,claims:u,claim:"nonce"});return c}(e,t,n,o.expectedNonce,o.maxAge,o[Ht],o.recognizedTokenTypes):async function(e,t,n,o,i){const r=await Hn(e,t,n,void 0,o,i),s=Zn(r);if(s){if(void 0!==t.default_max_age){an(t.default_max_age,!0,'"client.default_max_age"');const e=fn()+hn(t),n=pn(t);if(s.auth_time+t.default_max_age<e-n)throw $t("too much time has elapsed since the last End-User authentication",mo,{claims:s,now:e,tolerance:n,claim:"auth_time"})}if(void 0!==s.nonce)throw $t('unexpected ID Token "nonce" claim value',yo,{expected:void 0,claims:s,claim:"nonce"})}return r}(e,t,n,null==o?void 0:o[Ht],null==o?void 0:o.recognizedTokenTypes)}const oo="OAUTH_WWW_AUTHENTICATE_CHALLENGE",io="OAUTH_RESPONSE_BODY_ERROR",ro="OAUTH_UNSUPPORTED_OPERATION",so="OAUTH_AUTHORIZATION_RESPONSE_ERROR",ao="OAUTH_JWT_USERINFO_EXPECTED",co="OAUTH_PARSE_ERROR",uo="OAUTH_INVALID_RESPONSE",lo="OAUTH_RESPONSE_IS_NOT_JSON",ho="OAUTH_RESPONSE_IS_NOT_CONFORM",po="OAUTH_HTTP_REQUEST_FORBIDDEN",fo="OAUTH_REQUEST_PROTOCOL_FORBIDDEN",mo="OAUTH_JWT_TIMESTAMP_CHECK_FAILED",yo="OAUTH_JWT_CLAIM_COMPARISON_FAILED",wo="OAUTH_JSON_ATTRIBUTE_COMPARISON_FAILED",go="OAUTH_MISSING_SERVER_METADATA",vo="OAUTH_INVALID_SERVER_METADATA";async function bo(e){if(!Nt(e,Response))throw Ut('"response" must be an instance of Response',Mt);await jn(e,200,"Revocation Endpoint")}function _o(e){if(e.bodyUsed)throw Ut('"response" body has been used already',Kt)}function ko(e){const t=e.algorithm;if("number"!=typeof t.modulusLength||t.modulusLength<2048)throw new Bt("unsupported ".concat(t.name," modulusLength"),{cause:e})}function So(e){switch(e.algorithm.namedCurve){case"P-256":return"SHA-256";case"P-384":return"SHA-384";case"P-521":return"SHA-512";default:throw new Bt("unsupported ECDSA namedCurve",{cause:e})}}async function To(e,t,n,o,i){let r,s,a=e.split("."),c=a[0],u=a[1],l=a.length;if(5===l){if(void 0===i)throw new Bt("JWE decryption is not configured",{cause:e});var d=(e=await i(e)).split(".");c=d[0],u=d[1],l=d.length}if(3!==l)throw $t("Invalid JWT",uo,e);try{r=JSON.parse(Xt(qt(c)))}catch(e){throw $t("failed to parse JWT Header body as base64url encoded JSON",co,e)}if(!tn(r))throw $t("JWT Header must be a top level object",uo,e);if(t(r),void 0!==r.crit)throw new Bt('no JWT "crit" header parameter extensions are supported',{cause:{header:r}});try{s=JSON.parse(Xt(qt(u)))}catch(e){throw $t("failed to parse JWT Payload body as base64url encoded JSON",co,e)}if(!tn(s))throw $t("JWT Payload must be a top level object",uo,e);const h=fn()+n;if(void 0!==s.exp){if("number"!=typeof s.exp)throw $t('unexpected JWT "exp" (expiration time) claim type',uo,{claims:s});if(s.exp<=h-o)throw $t('unexpected JWT "exp" (expiration time) claim value, expiration is past current timestamp',mo,{claims:s,now:h,tolerance:o,claim:"exp"})}if(void 0!==s.iat&&"number"!=typeof s.iat)throw $t('unexpected JWT "iat" (issued at) claim type',uo,{claims:s});if(void 0!==s.iss&&"string"!=typeof s.iss)throw $t('unexpected JWT "iss" (issuer) claim type',uo,{claims:s});if(void 0!==s.nbf){if("number"!=typeof s.nbf)throw $t('unexpected JWT "nbf" (not before) claim type',uo,{claims:s});if(s.nbf>h+o)throw $t('unexpected JWT "nbf" (not before) claim value',mo,{claims:s,now:h,tolerance:o,claim:"nbf"})}if(void 0!==s.aud&&"string"!=typeof s.aud&&!Array.isArray(s.aud))throw $t('unexpected JWT "aud" (audience) claim type',uo,{claims:s});return{header:r,claims:s,jwt:e}}async function Po(e){if("POST"!==e.method)throw Ut("form_post responses are expected to use the POST method",Kt,{cause:e});if("application/x-www-form-urlencoded"!==Mn(e))throw Ut("form_post responses are expected to use the application/x-www-form-urlencoded content-type",Kt,{cause:e});return async function(e){if(e.bodyUsed)throw Ut("form_post Request instances must contain a readable body",Kt,{cause:e});return e.text()}(e)}function Eo(e,t,n,o){if(void 0===e)if(Array.isArray(t)){if(!t.includes(o.alg))throw $t('unexpected JWT "alg" header parameter',uo,{header:o,expected:t,reason:"authorization server metadata"})}else{if(void 0===n)throw $t('missing client or server configuration to verify used JWT "alg" header parameter',void 0,{client:e,issuer:t,fallback:n});if("string"==typeof n?o.alg!==n:"function"==typeof n?!n(o.alg):!n.includes(o.alg))throw $t('unexpected JWT "alg" header parameter',uo,{header:o,expected:n,reason:"default value"})}else if("string"==typeof e?o.alg!==e:!e.includes(o.alg))throw $t('unexpected JWT "alg" header parameter',uo,{header:o,expected:e,reason:"client configuration"})}function Co(e,t){const n=e.getAll(t),o=n[0];if(n.length>1)throw $t('"'.concat(t,'" parameter must be provided only once'),uo);return o}const Ro=Symbol(),Ao=Symbol();function xo(e,t,n,o){if(mn(e),yn(t),n instanceof URL&&(n=n.searchParams),!(n instanceof URLSearchParams))throw Ut('"parameters" must be an instance of URLSearchParams, or URL',Mt);if(Co(n,"response"))throw $t('"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()',uo,{parameters:n});const i=Co(n,"iss"),r=Co(n,"state");if(!i&&e.authorization_response_iss_parameter_supported)throw $t('response parameter "iss" (issuer) missing',uo,{parameters:n});if(i&&i!==e.issuer)throw $t('unexpected "iss" (issuer) response parameter value',uo,{expected:e.issuer,parameters:n});switch(o){case void 0:case Ao:if(void 0!==r)throw $t('unexpected "state" response parameter encountered',uo,{expected:void 0,parameters:n});break;case Ro:break;default:if(cn(o,'"expectedState" argument'),r!==o)throw $t(void 0===r?'response parameter "state" missing':'unexpected "state" response parameter value',uo,{expected:o,parameters:n})}if(Co(n,"error"))throw new Tn("authorization response from the server is an error",{cause:n});const s=Co(n,"id_token"),a=Co(n,"token");if(void 0!==s||void 0!==a)throw new Bt("implicit and hybrid flows are not supported");return c=new URLSearchParams(n),qn.add(c),c;var c}async function Io(e){let t,n=arguments.length>1&&void 0!==arguments[1]?arguments[1]:un;try{t=await e.json()}catch(t){throw n(e),$t('failed to parse "response" body as JSON',co,t)}if(!tn(t))throw $t('"response" body must be a top level object',uo,{body:t});return t}const Oo=Symbol(),jo=Symbol(),Wo=new TextEncoder,No=new TextDecoder,Ko=new TextDecoder("utf-8",{fatal:!0});function Mo(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];const o=t.reduce((e,t)=>e+t.length,0),i=new Uint8Array(o);let r=0;for(const e of t)i.set(e,r),r+=e.length;return i}function Uo(e){const t=new Uint8Array(e.length);for(let n=0;n<e.length;n++){const o=e.charCodeAt(n);if(o>127)throw new TypeError("non-ASCII string encountered in encode()");t[n]=o}return t}const Lo=function(e){return new TypeError("CryptoKey does not support this operation, its ".concat(arguments.length>1&&void 0!==arguments[1]?arguments[1]:"algorithm.name"," must be ").concat(e))};function zo(e,t,n){var o;const i=e.algorithm;if(i.name!==t.name)throw Lo(t.name);if(t.hash&&(null===(o=i.hash)||void 0===o?void 0:o.name)!==t.hash)throw Lo(t.hash,"algorithm.hash");if(t.namedCurve&&i.namedCurve!==t.namedCurve)throw Lo(t.namedCurve,"algorithm.namedCurve");if(void 0!==t.length&&i.length!==t.length)throw Lo(t.length,"algorithm.length");!function(e,t){if(t&&!e.usages.includes(t))throw new TypeError("CryptoKey does not support this operation, its usages must include ".concat(t,"."))}(e,n)}const Jo=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];return function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];if(o.length>2){const t=o.pop();e+="one of type ".concat(o.join(", "),", or ").concat(t,".")}else 2===o.length?e+="one of type ".concat(o[0]," or ").concat(o[1],"."):e+="of type ".concat(o[0],".");if(null==t)e+=" Received ".concat(t);else if("function"==typeof t&&t.name)e+=" Received function ".concat(t.name);else if("object"==typeof t&&null!=t){var r;null!==(r=t.constructor)&&void 0!==r&&r.name&&(e+=" Received an instance of ".concat(t.constructor.name))}return e}("Key for the ".concat(e," algorithm must be "),t,...o)};class Do extends Error{constructor(e,t){var n;super(e,t),h(this,"code","ERR_JOSE_GENERIC"),this.name=this.constructor.name,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}h(Do,"code","ERR_JOSE_GENERIC");class Zo extends Do{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),h(this,"code","ERR_JWT_CLAIM_VALIDATION_FAILED"),h(this,"claim",void 0),h(this,"reason",void 0),h(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}h(Zo,"code","ERR_JWT_CLAIM_VALIDATION_FAILED");class Ho extends Do{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),h(this,"code","ERR_JWT_EXPIRED"),h(this,"claim",void 0),h(this,"reason",void 0),h(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}h(Ho,"code","ERR_JWT_EXPIRED");class Fo extends Do{constructor(){super(...arguments),h(this,"code","ERR_JOSE_ALG_NOT_ALLOWED")}}h(Fo,"code","ERR_JOSE_ALG_NOT_ALLOWED");class Vo extends Do{constructor(){super(...arguments),h(this,"code","ERR_JOSE_NOT_SUPPORTED")}}h(Vo,"code","ERR_JOSE_NOT_SUPPORTED");h(class extends Do{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"decryption operation failed",arguments.length>1?arguments[1]:void 0),h(this,"code","ERR_JWE_DECRYPTION_FAILED")}},"code","ERR_JWE_DECRYPTION_FAILED");h(class extends Do{constructor(){super(...arguments),h(this,"code","ERR_JWE_INVALID")}},"code","ERR_JWE_INVALID");class Xo extends Do{constructor(){super(...arguments),h(this,"code","ERR_JWS_INVALID")}}h(Xo,"code","ERR_JWS_INVALID");class Go extends Do{constructor(){super(...arguments),h(this,"code","ERR_JWT_INVALID")}}h(Go,"code","ERR_JWT_INVALID");h(class extends Do{constructor(){super(...arguments),h(this,"code","ERR_JWK_INVALID")}},"code","ERR_JWK_INVALID");class Yo extends Do{constructor(){super(...arguments),h(this,"code","ERR_JWKS_INVALID")}}h(Yo,"code","ERR_JWKS_INVALID");class qo extends Do{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"no applicable key found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),h(this,"code","ERR_JWKS_NO_MATCHING_KEY")}}h(qo,"code","ERR_JWKS_NO_MATCHING_KEY");class Bo extends Do{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"multiple matching keys found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),h(this,Symbol.asyncIterator,w(function*(){})),h(this,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS")}}h(Bo,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS");class Qo extends Do{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"request timed out",arguments.length>1?arguments[1]:void 0),h(this,"code","ERR_JWKS_TIMEOUT")}}h(Qo,"code","ERR_JWKS_TIMEOUT");class $o extends Do{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"signature verification failed",arguments.length>1?arguments[1]:void 0),h(this,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED")}}h($o,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED");const ei=e=>{if("CryptoKey"===(null==e?void 0:e[Symbol.toStringTag]))return!0;try{return e instanceof CryptoKey}catch(e){return!1}},ti=e=>ei(e)||(e=>"KeyObject"===(null==e?void 0:e[Symbol.toStringTag]))(e);function ni(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);const t=atob(e),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}const oi="The input to be decoded is not correctly encoded.";function ii(e){if(Uint8Array.fromBase64)try{return Uint8Array.fromBase64("string"==typeof e?e:No.decode(e),{alphabet:"base64url"})}catch(e){throw new TypeError(oi,{cause:e})}let t=e;if(t instanceof Uint8Array&&(t=No.decode(t)),t.includes("+")||t.includes("/"))throw new TypeError(oi);t=t.replace(/-/g,"+").replace(/_/g,"/");try{return ni(t)}catch(e){throw new TypeError(oi)}}function ri(e){let t=e;return"string"==typeof t&&(t=Wo.encode(t)),Uint8Array.prototype.toBase64?t.toBase64({alphabet:"base64url",omitPadding:!0}):function(e){if(Uint8Array.prototype.toBase64)return e.toBase64();const t=[];for(let n=0;n<e.length;n+=32768)t.push(String.fromCharCode.apply(null,e.subarray(n,n+32768)));return btoa(t.join(""))}(t).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}function si(e){if("object"!=typeof e||null===e||"[object Object]"!==Object.prototype.toString.call(e))return!1;const t=Object.getPrototypeOf(e);return null===t||null===Object.getPrototypeOf(t)}function ai(e){return si(e)&&Array.isArray(e.keys)&&Array.from(e.keys).every(si)}function ci(e,t,n){try{return ii(e)}catch(e){throw new n("Failed to base64url decode the ".concat(t))}}async function ui(e,t){var n,o,i,r;if("RSA"===t.kty&&"oth"in t&&void 0!==t.oth)throw new Vo('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');if(!e.kty.includes(t.kty))throw new Vo('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');const s=null!==(n=null===(o=e.resolve)||void 0===o?void 0:o.call(e,{kty:t.kty,crv:t.crv}))&&void 0!==n?n:e.subtle,a=!(!t.d&&!t.priv),c=f({},t);return"AKP"!==c.kty&&delete c.alg,delete c.use,crypto.subtle.importKey("jwk",c,s,null!==(i=t.ext)&&void 0!==i?i:!a,null!==(r=t.key_ops)&&void 0!==r?r:e.usages[a?1:0])}function li(e){return f({__proto__:null},e)}const di=e=>e[Symbol.toStringTag];function hi(e,t,n){const o=e.alg,i=e.secret,r="decrypt"===n||"sign"===n;if(i&&t instanceof Uint8Array)return[pi,t];if(si(t)){const s=function(e){const t=li(e);if(void 0!==t.ext&&"boolean"!=typeof t.ext)throw new TypeError('"ext" (Extractable) Parameter must be a boolean');if(void 0!==t.key_ops){const e=t.key_ops,n=Array.isArray(e)?[...e]:void 0;if(!n||n.some(e=>"string"!=typeof e)||new Set(n).size!==n.length)throw new TypeError('"key_ops" (Key Operations) Parameter must be an array of unique strings');t.key_ops=n}return t}(t);if("string"!=typeof s.kty)throw new TypeError(i?Jo(o,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"):Jo(o,t,"CryptoKey","KeyObject","JSON Web Key"));if(!(i?"oct"===s.kty&&"string"==typeof s.k:"oct"!==s.kty&&(r?"AKP"===s.kty&&"string"==typeof s.priv||"string"==typeof s.d:void 0===s.d&&void 0===s.priv)))throw new TypeError(i?'JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present':"JSON Web Key for this operation must be a ".concat(r?"private":"public"," JWK"));return((e,t,n)=>{const o=e.alg;if(void 0!==t.use){const e="sign"===n||"verify"===n?"sig":"enc";if(t.use!==e)throw new TypeError('Invalid key for this operation, its "use" must be "'.concat(e,'" when present'))}if(void 0!==t.alg&&t.alg!==o)throw new TypeError('Invalid key for this operation, its "alg" must be "'.concat(o,'" when present'));if(Array.isArray(t.key_ops)){var i;const o="encrypt"===n||"decrypt"===n?null===(i=e.ops)||void 0===i?void 0:i["encrypt"===n?0:1]:n;if(o&&!t.key_ops.includes(o))throw new TypeError('Invalid key for this operation, its "key_ops" must include "'.concat(o,'" when present'))}})(e,s,n),[yi,t,s]}if(!ti(t))throw new TypeError(i?Jo(o,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"):Jo(o,t,"CryptoKey","KeyObject","JSON Web Key"));if(i){if("secret"!==t.type)throw new TypeError("".concat(di(t),' instances for symmetric algorithms must be of type "secret"'))}else{if("secret"===t.type)throw new TypeError("".concat(di(t),' instances for asymmetric algorithms must not be of type "secret"'));const e=r?"private":"public";if(("public"===t.type||"private"===t.type)&&t.type!==e){const o="sign"===n?"signing":"verify"===n?"verifying":"".concat(n.slice(0,-1),"tion");throw new TypeError("".concat(di(t)," instances for asymmetric algorithm ").concat(o,' must be of type "').concat(e,'"'))}}return ei(t)?[fi,t]:[mi,t]}const pi=0,fi=1,mi=2,yi=3;let wi;const gi={__proto__:null,prime256v1:"P-256",secp384r1:"P-384",secp521r1:"P-521"};function vi(e,t,n){wi||(wi=new WeakMap);const o=wi.get(e);return n&&(o?o[t]=n:wi.set(e,{[t]:n})),null!=n?n:null==o?void 0:o[t]}const bi=async(e,t,n)=>{var o;return null!==(o=vi(e,n.alg))&&void 0!==o?o:vi(e,n.alg,await ui(n,f(f({},t),{},{alg:n.alg})))};async function _i(e,t,n){const o=hi(e,t,n);switch(o[0]){case pi:case fi:return o[1];case yi:{const t=o[1],n=o[2];if("oct"===n.kty)return ii(n.k);if(!Object.isFrozen(t)){const e=t.key_ops;Array.isArray(e)&&Object.freeze(e),Object.freeze(t)}return bi(t,n,e)}case mi:{const t=o[1];return"secret"===t.type?t.export():"toCryptoKey"in t&&"function"==typeof t.toCryptoKey?((e,t)=>{var n,o,i;const r=vi(e,t.alg);if(r)return r;const s="public"===e.type,a=t.usages[s?0:1],c=e.asymmetricKeyType,u=gi[null===(n=e.asymmetricKeyDetails)||void 0===n?void 0:n.namedCurve],l=null!==(o=null===(i=t.resolve)||void 0===i?void 0:i.call(t,{crv:u,asymmetricKeyType:c}))&&void 0!==o?o:t.subtle;return vi(e,t.alg,e.toCryptoKey(l,s,a))})(t,e):bi(t,t.export({format:"jwk"}),e)}}}function ki(e){const t={__proto__:null};for(const n in e)t[n]=f(f({},e[n]),{},{alg:n});return t}const Si=[["encrypt","wrapKey"],["decrypt","unwrapKey"]],Ti=[[],["deriveBits"]],Pi=[[],[]];function Ei(e){return{kty:["RSA"],subtle:{name:"RSA-OAEP",hash:"SHA-".concat(e)},usages:Si,ops:["wrapKey","unwrapKey"]}}function Ci(){return{kty:["EC","OKP"],subtle:{name:"ECDH"},resolve:e=>{let t=e.kty,n=e.crv,o=e.asymmetricKeyType;if("X25519"===n||"x25519"===o)return{name:"X25519"};if("OKP"===t)throw new Vo('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');return{name:"ECDH",namedCurve:n}},usages:Ti,ops:[void 0,"deriveBits"]}}function Ri(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return{kty:["oct"],secret:!0,subtle:{name:t?"AES-GCM":"AES-KW",length:e},usages:Pi,ops:t?["encrypt","decrypt"]:["wrapKey","unwrapKey"]}}function Ai(){return{kty:["oct"],secret:!0,subtle:{name:"PBKDF2"},usages:Pi,ops:["deriveBits","deriveBits"]}}const xi=ki({dir:{kty:["oct"],secret:!0,subtle:{name:"AES-GCM"},usages:Pi,ops:["encrypt","decrypt"]},"RSA-OAEP":Ei(1),"RSA-OAEP-256":Ei(256),"RSA-OAEP-384":Ei(384),"RSA-OAEP-512":Ei(512),"ECDH-ES":Ci(),"ECDH-ES+A128KW":Ci(),"ECDH-ES+A192KW":Ci(),"ECDH-ES+A256KW":Ci(),A128KW:Ri(128),A192KW:Ri(192),A256KW:Ri(256),A128GCMKW:Ri(128,!0),A192GCMKW:Ri(192,!0),A256GCMKW:Ri(256,!0),"PBES2-HS256+A128KW":Ai(),"PBES2-HS384+A192KW":Ai(),"PBES2-HS512+A256KW":Ai()}),Ii=["encrypt","decrypt"];function Oi(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return{kty:["oct"],secret:!0,subtle:{name:t?"AES-CBC":"AES-GCM",length:e},usages:Pi,ops:Ii,cekBits:e,ivBits:t?128:96,cbc:t}}ki({A128GCM:Oi(128),A192GCM:Oi(192),A256GCM:Oi(256),"A128CBC-HS256":Oi(256,!0),"A192CBC-HS384":Oi(384,!0),"A256CBC-HS512":Oi(512,!0)});const ji={__proto__:null,b64:!0};function Wi(e,t){if(void 0!==t&&(!Array.isArray(t)||t.some(e=>"string"!=typeof e)))throw new TypeError('"'.concat(e,'" option must be an array of strings'));if(t)return new Set(t)}function Ni(e,t,n,o,i){if(void 0!==i.crit&&void 0===(null==o?void 0:o.crit))throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!o||void 0===o.crit)return[];if(!Array.isArray(o.crit)||0===o.crit.length||o.crit.some(e=>"string"!=typeof e||0===e.length))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');const r=void 0===n?t:f(f({__proto__:null},n),t);for(const t of o.crit){if(!(t in r))throw new Vo('Extension Header Parameter "'.concat(t,'" is not recognized'));if(!Object.hasOwn(i,t)||void 0===i[t])throw new e('Extension Header Parameter "'.concat(t,'" is missing'));if(r[t]&&(!Object.hasOwn(o,t)||void 0===o[t]))throw new e('Extension Header Parameter "'.concat(t,'" MUST be integrity protected'))}return o.crit}function Ki(e,t){if(t.includes("b64")){const t=e.b64;if("boolean"!=typeof t)throw new Xo('The "b64" (base64url-encode payload) Header Parameter must be a boolean');return t}return!0}var Mi,Ui;let Li,zi;if("undefined"==typeof navigator||null===(Mi=navigator.userAgent)||void 0===Mi||null===(Ui=Mi.startsWith)||void 0===Ui||!Ui.call(Mi,"Mozilla/5.0 ")){const e="v6.8.4";zi="".concat("openid-client","/").concat(e),Li={"user-agent":zi}}const Ji=e=>Di.get(e);let Di,Zi;function Hi(e){return void 0!==e?wn(e):(Zi||(Zi=new WeakMap),(e,t,n,o)=>{let i;return(i=Zi.get(t))||(!function(e,t){if("string"!=typeof e)throw Yi("".concat(t," must be a string"),Gi);if(0===e.length)throw Yi("".concat(t," must not be empty"),Xi)}(t.client_secret,'"metadata.client_secret"'),i=wn(t.client_secret),Zi.set(t,i)),i(e,t,n,o)})}const Fi=Kn,Vi=Dt,Xi="ERR_INVALID_ARG_VALUE",Gi="ERR_INVALID_ARG_TYPE";function Yi(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}function qi(e){return async function(e){return cn(e,"codeVerifier"),qt(await crypto.subtle.digest("SHA-256",Xt(e)))}(e)}function Bi(){return ln()}class Qi extends Error{constructor(e,t){var n;super(e,t),h(this,"code",void 0),this.name=this.constructor.name,this.code=null==t?void 0:t.code,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function $i(e,t,n){return new Qi(e,{cause:t,code:n})}function er(e){if(e instanceof TypeError||e instanceof Qi||e instanceof Sn||e instanceof Tn||e instanceof Pn)throw e;if(e instanceof Qt)switch(e.code){case po:throw $i("only requests to HTTPS are allowed",e,e.code);case fo:throw $i("only requests to HTTP or HTTPS are allowed",e,e.code);case ho:throw $i("unexpected HTTP response status code",e.cause,e.code);case lo:throw $i("unexpected response content-type",e.cause,e.code);case co:throw $i("parsing error occured",e,e.code);case uo:throw $i("invalid response encountered",e,e.code);case yo:throw $i("unexpected JWT claim value encountered",e,e.code);case wo:throw $i("unexpected JSON attribute value encountered",e,e.code);case mo:throw $i("JWT timestamp claim value failed validation",e,e.code);default:throw $i(e.message,e,e.code)}if(e instanceof Bt)throw $i("unsupported operation",e,e.code);if(e instanceof DOMException)switch(e.name){case"OperationError":throw $i("runtime operation error",e,ro);case"NotSupportedError":throw $i("runtime unsupported operation",e,ro);case"TimeoutError":throw $i("operation timed out",e,"OAUTH_TIMEOUT");case"AbortError":throw $i("operation aborted",e,"OAUTH_ABORT")}throw new Qi("something went wrong",{cause:e})}async function tr(e,t,n,o,i){const r=await async function(e,t){var n,o;if(!(e instanceof URL))throw Yi('"server" must be an instance of URL',Gi);const i=!e.href.includes("/.well-known/"),r=null!==(n=null==t?void 0:t.timeout)&&void 0!==n?n:30,s=AbortSignal.timeout(1e3*r),a=await(i?sn(e,{algorithm:null==t?void 0:t.algorithm,[Dt]:null==t?void 0:t[Vi],[Lt]:null==t||null===(o=t.execute)||void 0===o?void 0:o.includes(ur),signal:s,headers:new Headers(Li)}):((null==t?void 0:t[Vi])||fetch)((bn(e,null==t||null===(c=t.execute)||void 0===c||!c.includes(ur)),e.href),{headers:Object.fromEntries(new Headers(f({accept:"application/json"},Li)).entries()),body:void 0,method:"GET",redirect:"manual",signal:s})).then(e=>async function(e,t){const n=e;if(!(n instanceof URL)&&n!==Oo)throw Ut('"expectedIssuerIdentifier" must be an instance of URL',Mt);if(!Nt(t,Response))throw Ut('"response" must be an instance of Response',Mt);if(200!==t.status)throw $t('"response" is not a conform Authorization Server Metadata response (unexpected HTTP status code)',ho,t);_o(t);const o=await Io(t);if(cn(o.issuer,'"response" body "issuer" property',uo,{body:o}),n!==Oo&&new URL(o.issuer).href!==n.href)throw $t('"response" body "issuer" property does not match the expected value',wo,{expected:n.href,body:o,attribute:"issuer"});return o}(Oo,e)).catch(er);var c;i&&new URL(a.issuer).href!==e.href&&(function(e,t,n){return!("https://login.microsoftonline.com"!==e.origin||null!=n&&n.algorithm&&"oidc"!==n.algorithm||(t[nr]=!0,0))}(e,a,t)||function(e,t){return!(!e.hostname.endsWith(".b2clogin.com")||null!=t&&t.algorithm&&"oidc"!==t.algorithm)}(e,t)||(()=>{throw new Qi("discovered metadata issuer does not match the expected issuer",{code:wo,cause:{expected:e.href,body:a,attribute:"issuer"}})})());return a}(e,i),s=new or(r,t,n,o);let a=Ji(s);if(null!=i&&i[Vi]&&(a.fetch=i[Vi]),null!=i&&i.timeout&&(a.timeout=i.timeout),null!=i&&i.execute)for(const e of i.execute)e(s);return s}new TextDecoder;const nr=Symbol();class or{constructor(e,t,n,o){var i,r,s,a,c;if("string"!=typeof t||!t.length)throw Yi('"clientId" must be a non-empty string',Gi);if("string"==typeof n&&(n={client_secret:n}),void 0!==(null===(i=n)||void 0===i?void 0:i.client_id)&&t!==n.client_id)throw Yi('"clientId" and "metadata.client_id" must be the same',Xi);const u=f(f({},structuredClone(n)),{},{client_id:t});let l;u[zt]=null!==(r=null===(s=n)||void 0===s?void 0:s[zt])&&void 0!==r?r:0,u[Jt]=null!==(a=null===(c=n)||void 0===c?void 0:c[Jt])&&void 0!==a?a:30,l=o||("string"==typeof u.client_secret&&u.client_secret.length?Hi(u.client_secret):(e,t,n,o)=>{n.set("client_id",t.client_id)});let d=Object.freeze(u);const h=structuredClone(e);nr in e&&(h[jo]=t=>{let n=t.claims.tid;return e.issuer.replace("{tenantid}",n)});let p=Object.freeze(h);Di||(Di=new WeakMap),Di.set(this,{__proto__:null,as:p,c:d,auth:l,tlsOnly:!0,jwksCache:{}})}serverMetadata(){const e=structuredClone(Ji(this).as);return function(e){Object.defineProperties(e,function(e){return{supportsPKCE:{__proto__:null,value(){var t;let n=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"S256";return!0===(null===(t=e.code_challenge_methods_supported)||void 0===t?void 0:t.includes(n))}}}}(e))}(e),e}clientMetadata(){return structuredClone(Ji(this).c)}get timeout(){return Ji(this).timeout}set timeout(e){Ji(this).timeout=e}get[Vi](){return Ji(this).fetch}set[Vi](e){Ji(this).fetch=e}}function ir(e){Object.defineProperties(e,function(e){let t;if(void 0!==e.expires_in){const n=new Date;n.setSeconds(n.getSeconds()+e.expires_in),t=n.getTime()}return{expiresIn:{__proto__:null,value(){if(t){const e=Date.now();return t>e?Math.floor((t-e)/1e3):0}}},claims:{__proto__:null,value(){try{return Zn(this)}catch(e){return}}}}}(e))}async function rr(e,t,n){var o;let i=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const r=null===(o=e.headers.get("retry-after"))||void 0===o?void 0:o.trim();if(void 0===r)return;let s;if(/^\d+$/.test(r))s=parseInt(r,10);else{const e=new Date(r);if(Number.isFinite(e.getTime())){const t=new Date,n=e.getTime()-t.getTime();n>0&&(s=Math.ceil(n/1e3))}}if(i&&!Number.isFinite(s))throw new Qt("invalid Retry-After header value",{cause:e});s>t&&await sr(s-t,n)}function sr(e,t){return new Promise((n,o)=>{const i=e=>{try{t.throwIfAborted()}catch(e){return void o(e)}if(e<=0)return void n();const r=Math.min(e,5);setTimeout(()=>i(e-r),1e3*r)};i(e)})}async function ar(e,t){mr(e);const n=Ji(e),o=n.as,i=n.c,r=n.auth,s=n.fetch,a=n.tlsOnly,c=n.timeout;return async function(e,t,n,o,i){mn(e),yn(t);const r=kn(e,"backchannel_authentication_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[Lt])),s=new URLSearchParams(o);s.set("client_id",t.client_id);const a=nn(null==i?void 0:i.headers);return a.set("accept","application/json"),Ln(e,t,n,r,s,a,i)}(o,i,r,t,{[Dt]:s,[Lt]:!a,headers:new Headers(Li),signal:yr(c)}).then(e=>async function(e,t,n){if(mn(e),yn(t),!Nt(n,Response))throw Ut('"response" must be an instance of Response',Mt);await jn(n,200,"Backchannel Authentication Endpoint"),_o(n);const o=await Io(n);cn(o.auth_req_id,'"response" body "auth_req_id" property',uo,{body:o});let i="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return an(i,!0,'"response" body "expires_in" property',uo,{body:o}),o.expires_in=i,void 0!==o.interval&&an(o.interval,!1,'"response" body "interval" property',uo,{body:o}),o}(o,i,e)).catch(er)}async function cr(e,t,n,o){var i,r;mr(e),n=new URLSearchParams(n);let s=null!==(i=t.interval)&&void 0!==i?i:5;const a=null!==(r=null==o?void 0:o.signal)&&void 0!==r?r:AbortSignal.timeout(1e3*t.expires_in);try{await sr(s,a)}catch(e){er(e)}const c=Ji(e),u=c.as,l=c.c,d=c.auth,h=c.fetch,p=c.tlsOnly,m=c.nonRepudiation,y=c.timeout,w=c.decrypt,g=(i,r)=>cr(e,f(f({},t),{},{interval:i}),n,f(f({},o),{},{signal:a,flag:r})),v=function(e,t){const n=yr(t);if(!n)return{signal:e,cleanup(){}};const o=new AbortController,i=e=>{const t=e.target;o.abort(t.reason)};return e.aborted?o.abort(e.reason):n.aborted?o.abort(n.reason):(e.addEventListener("abort",i,{once:!0}),n.addEventListener("abort",i,{once:!0})),{signal:o.signal,cleanup(){e.removeEventListener("abort",i),n.removeEventListener("abort",i)}}}(a,y),b=await async function(e,t,n,o,i){mn(e),yn(t),cn(o,'"authReqId"');const r=new URLSearchParams(null==i?void 0:i.additionalParameters);return r.set("auth_req_id",o),zn(e,t,n,"urn:openid:params:grant-type:ciba",r,i)}(u,l,d,t.auth_req_id,{[Dt]:h,[Lt]:!p,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Li),signal:v.signal}).catch(er).finally(v.cleanup);var _;if(503===b.status&&b.headers.has("retry-after"))return await rr(b,s,a,!0),await(null===(_=b.body)||void 0===_?void 0:_.cancel()),g(s);const k=async function(e,t,n,o){return Hn(e,t,n,void 0,null==o?void 0:o[Ht],null==o?void 0:o.recognizedTokenTypes)}(u,l,b,{[Ht]:w});let S;try{S=await k}catch(e){if(gr(e,o))return g(s,vr);if(e instanceof Sn)switch(e.error){case"slow_down":s+=5;case"authorization_pending":return await rr(e.response,s,a),g(s)}er(e)}return S.id_token&&await(null==m?void 0:m(b)),ir(S),S}function ur(e){Ji(e).tlsOnly=!1}async function lr(e,t,n,o,i){if(mr(e),!((null==i?void 0:i.flag)===vr||t instanceof URL||function(e,t){try{return Object.getPrototypeOf(e)[Symbol.toStringTag]===t}catch(e){return!1}}(t,"Request")))throw Yi('"currentUrl" must be an instance of URL, or Request',Gi);let r,s;const a=Ji(e),c=a.as,u=a.c,l=a.auth,d=a.fetch,h=a.tlsOnly,p=a.jarm,m=a.hybrid,w=a.nonRepudiation,g=a.timeout,v=a.decrypt,b=a.implicit;if((null==i?void 0:i.flag)===vr)r=i.authResponse,s=i.redirectUri;else{if(!(t instanceof URL)){const e=t;switch(t=new URL(t.url),e.method){case"GET":break;case"POST":const n=new URLSearchParams(await Po(e));if(m)t.hash=n.toString();else for(const e of n.entries()){var _=y(e,2);const n=_[0],o=_[1];t.searchParams.append(n,o)}break;default:throw Yi("unexpected Request HTTP method",Xi)}}switch(s=function(e){return(e=new URL(e)).search="",e.hash="",e.href}(t),!0){case!!p:r=await p(t,null==n?void 0:n.expectedState);break;case!!m:r=await m(t,null==n?void 0:n.expectedNonce,null==n?void 0:n.expectedState,null==n?void 0:n.maxAge);break;case!!b:throw new TypeError("authorizationCodeGrant() cannot be used by response_type=id_token clients");default:try{r=xo(c,u,t.searchParams,null==n?void 0:n.expectedState)}catch(e){er(e)}}}const k=await async function(e,t,n,o,i,r,s){if(mn(e),yn(t),!qn.has(o))throw Ut('"callbackParameters" must be an instance of URLSearchParams obtained from "validateAuthResponse()", or "validateJwtAuthResponse()',Kt);cn(i,'"redirectUri"');const a=Co(o,"code");if(!a)throw $t('no authorization code in "callbackParameters"',uo);const c=new URLSearchParams(null==s?void 0:s.additionalParameters);return c.set("redirect_uri",i),c.set("code",a),r!==Bn&&(cn(r,'"codeVerifier"'),c.set("code_verifier",r)),zn(e,t,n,"authorization_code",c,s)}(c,u,l,r,s,(null==n?void 0:n.pkceCodeVerifier)||Bn,{additionalParameters:o,[Dt]:d,[Lt]:!h,DPoP:null==i?void 0:i.DPoP,headers:new Headers(Li),signal:yr(g)}).catch(er);"string"!=typeof(null==n?void 0:n.expectedNonce)&&"number"!=typeof(null==n?void 0:n.maxAge)||(n.idTokenExpected=!0);const S=no(c,u,k,{expectedNonce:null==n?void 0:n.expectedNonce,maxAge:null==n?void 0:n.maxAge,requireIdToken:null==n?void 0:n.idTokenExpected,[Ht]:v});let T;try{T=await S}catch(t){if(gr(t,i))return lr(e,void 0,n,o,f(f({},i),{},{flag:vr,authResponse:r,redirectUri:s}));er(t)}return T.id_token&&await(null==w?void 0:w(k)),ir(T),T}async function dr(e,t,n,o){mr(e),n=new URLSearchParams(n);const i=Ji(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.nonRepudiation,d=i.timeout,h=i.decrypt,p=await async function(e,t,n,o,i){mn(e),yn(t),cn(o,'"refreshToken"');const r=new URLSearchParams(null==i?void 0:i.additionalParameters);return r.set("refresh_token",o),zn(e,t,n,"refresh_token",r,i)}(r,s,a,t,{[Dt]:c,[Lt]:!u,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Li),signal:yr(d)}).catch(er),m=async function(e,t,n,o){return Hn(e,t,n,void 0,null==o?void 0:o[Ht],null==o?void 0:o.recognizedTokenTypes)}(r,s,p,{[Ht]:h});let y;try{y=await m}catch(i){if(gr(i,o))return dr(e,t,n,f(f({},o),{},{flag:vr}));er(i)}return y.id_token&&await(null==l?void 0:l(p)),ir(y),y}async function hr(e,t,n){mr(e),t=new URLSearchParams(t);const o=Ji(e),i=o.as,r=o.c,s=o.auth,a=o.fetch,c=o.tlsOnly,u=o.timeout,l=await async function(e,t,n,o,i){return mn(e),yn(t),zn(e,t,n,"client_credentials",new URLSearchParams(o),i)}(i,r,s,t,{[Dt]:a,[Lt]:!c,DPoP:null==n?void 0:n.DPoP,headers:new Headers(Li),signal:yr(u)}).catch(er),d=async function(e,t,n,o){return Hn(e,t,n,void 0,null==o?void 0:o[Ht],null==o?void 0:o.recognizedTokenTypes)}(i,r,l);let h;try{h=await d}catch(o){if(gr(o,n))return hr(e,t,f(f({},n),{},{flag:vr}));er(o)}return ir(h),h}function pr(e,t){mr(e);const n=Ji(e),o=n.as,i=n.c,r=n.tlsOnly,s=n.hybrid,a=n.jarm,c=n.implicit,u=kn(o,"authorization_endpoint",!1,r);if((t=new URLSearchParams(t)).has("client_id")||t.set("client_id",i.client_id),!t.has("request_uri")&&!t.has("request")){if(t.has("response_type")||t.set("response_type",s?"code id_token":c?"id_token":"code"),c&&!t.has("nonce"))throw Yi("response_type=id_token clients must provide a nonce parameter in their authorization request parameters",Xi);a&&t.set("response_mode","jwt")}for(const e of t.entries()){var l=y(e,2);const t=l[0],n=l[1];u.searchParams.append(t,n)}return u}async function fr(e,t,n){mr(e);const o=pr(e,t),i=Ji(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.timeout,d=await async function(e,t,n,o,i){var r;mn(e),yn(t);const s=kn(e,"pushed_authorization_request_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[Lt])),a=new URLSearchParams(o);a.set("client_id",t.client_id);const c=nn(null==i?void 0:i.headers);c.set("accept","application/json"),void 0!==(null==i?void 0:i.DPoP)&&(Wn(i.DPoP),await i.DPoP.addProof(s,c,"POST"));const u=await Ln(e,t,n,s,a,c,i);return null==i||null===(r=i.DPoP)||void 0===r||r.cacheNonce(u,s),u}(r,s,a,o.searchParams,{[Dt]:c,[Lt]:!u,DPoP:null==n?void 0:n.DPoP,headers:new Headers(Li),signal:yr(l)}).catch(er),h=async function(e,t,n){if(mn(e),yn(t),!Nt(n,Response))throw Ut('"response" must be an instance of Response',Mt);await jn(n,201,"Pushed Authorization Request Endpoint"),_o(n);const o=await Io(n);cn(o.request_uri,'"response" body "request_uri" property',uo,{body:o});let i="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return an(i,!0,'"response" body "expires_in" property',uo,{body:o}),o.expires_in=i,o}(r,s,d);let p;try{p=await h}catch(o){if(gr(o,n))return fr(e,t,f(f({},n),{},{flag:vr}));er(o)}return pr(e,{request_uri:p.request_uri})}function mr(e){if(!(e instanceof or))throw Yi('"config" must be an instance of Configuration',Gi);if(Object.getPrototypeOf(e)!==or.prototype)throw Yi("subclassing Configuration is not allowed",Xi)}function yr(e){return e?AbortSignal.timeout(1e3*e):void 0}async function wr(e,t,n,o){mr(e);const i=Ji(e),r=i.as,s=i.c,a=i.fetch,c=i.tlsOnly,u=i.nonRepudiation,l=i.timeout,d=i.decrypt,h=await Nn(r,s,t,{[Dt]:a,[Lt]:!c,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Li),signal:yr(l)}).catch(er);let p,m=Un(r,s,n,h,{[Ht]:d});try{p=await m}catch(i){if(gr(i,o))return wr(e,t,n,f(f({},o),{},{flag:vr}));er(i)}return"application/jwt"===Mn(h)&&await(null==u?void 0:u(h)),p}function gr(e,t){return!(null==t||!t.DPoP||t.flag===vr)&&function(e){if(e instanceof Pn){const t=e.cause,n=t[0];return 1===t.length&&"dpop"===n.scheme&&"use_dpop_nonce"===n.parameters.error}return e instanceof Sn&&"use_dpop_nonce"===e.error}(e)}Object.freeze(or.prototype);const vr=Symbol();async function br(e,t,n,o){mr(e);const i=Ji(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.timeout,d=i.decrypt,h=i.nonRepudiation,p=await async function(e,t,n,o,i,r){return mn(e),yn(t),cn(o,'"grantType"'),zn(e,t,n,o,new URLSearchParams(i),r)}(r,s,a,t,new URLSearchParams(n),{[Dt]:c,[Lt]:!u,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Li),signal:yr(l)}).catch(er);let m;"urn:ietf:params:oauth:grant-type:token-exchange"===t&&(m={n_a:()=>{}});const y=async function(e,t,n,o){return Hn(e,t,n,void 0,null==o?void 0:o[Ht],null==o?void 0:o.recognizedTokenTypes)}(r,s,p,{[Ht]:d,recognizedTokenTypes:m});let w;try{w=await y}catch(i){if(gr(i,o))return br(e,t,n,f(f({},o),{},{flag:vr}));er(i)}return w.id_token&&await(null==h?void 0:h(p)),ir(w),w}async function _r(e,t,n){mr(e);const o=Ji(e),i=o.as,r=o.c,s=o.auth,a=o.fetch,c=o.tlsOnly,u=o.timeout;return async function(e,t,n,o,i){mn(e),yn(t),cn(o,'"token"');const r=kn(e,"revocation_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[Lt])),s=new URLSearchParams(null==i?void 0:i.additionalParameters);s.set("token",o);const a=nn(null==i?void 0:i.headers);return a.delete("accept"),Ln(e,t,n,r,s,a,i)}(i,r,s,t,{[Dt]:a,[Lt]:!c,additionalParameters:new URLSearchParams(n),headers:new Headers(Li),signal:yr(u)}).then(bo).catch(er)}async function kr(e,t,n){return t instanceof Uint8Array?crypto.subtle.importKey("raw",t,e.subtle,!1,[n]):(zo(t,e.subtle,n),e.minRsaBits&&function(e,t){const n=t.algorithm.modulusLength;if("number"!=typeof n||n<2048)throw new TypeError("".concat(e," requires key modulusLength to be 2048 bits or larger"))}(e.alg,t),t)}const Sr=[["verify"],["sign"]];function Tr(e){const t={name:"HMAC",hash:"SHA-".concat(e)};return{kty:["oct"],secret:!0,subtle:t,signing:t,usages:Sr}}function Pr(e,t){const n={name:t?"RSA-PSS":"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(e)};return{kty:["RSA"],subtle:n,signing:t?f(f({},n),{},{saltLength:t}):n,usages:Sr,minRsaBits:2048}}function Er(e,t){return{kty:["EC"],crv:e,subtle:{name:"ECDSA",namedCurve:e},signing:{name:"ECDSA",hash:"SHA-".concat(t)},usages:Sr}}function Cr(){const e={name:"Ed25519"};return{kty:["OKP"],crv:"Ed25519",subtle:e,signing:e,usages:Sr}}function Rr(e){const t={name:"ML-DSA-".concat(e)};return{kty:["AKP"],subtle:t,signing:t,usages:Sr}}const Ar=ki({HS256:Tr(256),HS384:Tr(384),HS512:Tr(512),RS256:Pr(256),RS384:Pr(384),RS512:Pr(512),PS256:Pr(256,32),PS384:Pr(384,48),PS512:Pr(512,64),ES256:Er("P-256",256),ES384:Er("P-384",384),ES512:Er("P-521",512),EdDSA:Cr(),Ed25519:Cr(),"ML-DSA-44":Rr(44),"ML-DSA-65":Rr(65),"ML-DSA-87":Rr(87)});function xr(e){const t="string"==typeof e?Ar[e]:void 0;if(!t)throw new Vo("alg ".concat(e," is not supported either by JOSE or your javascript runtime"));return t}function Ir(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:void 0===e?{}:function(e,t,n){let o;try{o=JSON.parse(Ko.decode(ii(e)))}catch(e){throw new t(n)}if(!si(o))throw new t(n);return o}(e,Xo,"JWS Protected Header is invalid");return t}async function Or(e,t,n,o,i,r,s){var a;let c=!1;"function"==typeof n&&(n=await n(i,e),c=!0);const u="string"==typeof s,l=xr(r),d=Mo(void 0!==o?Uo(o):new Uint8Array,Uo("."),u?null!==(a=t[2])&&void 0!==a?a:t[2]=function(e,t,n){try{return Uo(e)}catch(e){throw new n("The ".concat(t," is not a valid base64url string"))}}(s,"payload",Xo):s),h=ci(e.signature,"signature",Xo),p=await _i(l,n,"verify");if(!await async function(e,t,n,o){const i=await kr(e,t,"verify");try{return await crypto.subtle.verify(e.signing,i,n,o)}catch(e){return!1}}(l,p,h,d))throw new $o;return[u?ci(s,"payload",Xo):s,i,u,p,c]}async function jr(e,t,n){if(e instanceof Uint8Array&&(e=No.decode(e)),"string"!=typeof e)throw new Xo("Compact JWS must be a string or Uint8Array");const o=e.split("."),i=o[0],r=o[1],s=o[2];if(3!==o.length)throw new Xo("Invalid Compact JWS");const a={payload:r,protected:i,signature:s},c=Ir(i),u=function(e,t,n){const o=Ki(e,Ni(Xo,ji,n[1],e,t)),i=t.alg;if("string"!=typeof i||!i)throw new Xo('JWS "alg" (Algorithm) Header Parameter missing or invalid');if(n[0]&&!n[0].has(i))throw new Fo('"alg" (Algorithm) Header Parameter value not allowed');return[o,i]}(c,c,t),l=y(u,2),d=l[0],h=l[1],p=d?r:function(e){try{return Uo(e)}catch(e){throw new Xo("JWS Compact Serialization payload must use only ASCII characters")}}(r);return Or(a,t,n,i,c,h,p)}const Wr=e=>Math.floor(e.getTime()/1e3),Nr={s:1,m:60,h:3600,d:86400,w:604800,y:31557600},Kr=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i,Mr="check_failed";function Ur(){throw new TypeError("Invalid time period format")}function Lr(e){"string"!=typeof e&&Ur();const t=Kr.exec(e);(!t||t[4]&&t[1])&&Ur();const n=parseFloat(t[2]),o=Math.round(n*Nr[t[3][0].toLowerCase()]);return Number.isFinite(o)||Ur(),"-"===t[1]||"ago"===t[4]?-o:o}function zr(e,t){if(!Number.isFinite(t))throw new TypeError("Invalid ".concat(e," input"));return t}function Jr(e,t){if("string"!=typeof t)throw new TypeError('"'.concat(e,'" claim must be a string'))}function Dr(e,t){return"number"==typeof e?zr(t,e):e instanceof Date?zr(t,Wr(e)):Wr(new Date)+Lr(e)}const Zr=e=>{const t=e.toLowerCase();return e.includes("/")?t:"application/".concat(t)};function Hr(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];const o=e[t];if(void 0!==o||n){if("number"!=typeof o)throw new Zo('"'.concat(t,'" claim must be a number'),e,t,"invalid");return o}}function Fr(e,t){throw new Zo('unexpected "'.concat(t,'" claim value'),e,t,Mr)}function Vr(e,t){let n,o=arguments.length>2&&void 0!==arguments[2]?arguments[2]:{};try{n=JSON.parse(Ko.decode(t))}catch(e){}if(!si(n))throw new Go("JWT Claims Set must be a top-level JSON object");const i=o.typ;if(void 0!==i&&("string"!=typeof e.typ||Zr(e.typ)!==Zr(i)))throw new Zo('unexpected "typ" JWT header value',n,"typ",Mr);const r=o.requiredClaims,s=void 0===r?[]:r,a=o.issuer,c=o.subject,u=o.audience,l=o.maxTokenAge,d=[...s];void 0!==l&&d.push("iat"),void 0!==u&&d.push("aud"),void 0!==c&&d.push("sub"),void 0!==a&&d.push("iss");for(const e of new Set(d.reverse()))if(!Object.hasOwn(n,e))throw new Zo('missing required "'.concat(e,'" claim'),n,e,"missing");var h,p;void 0===a||(Array.isArray(a)?a:[a]).includes(n.iss)||Fr(n,"iss"),void 0!==c&&n.sub!==c&&Fr(n,"sub"),void 0===u||(h=n.aud,p="string"==typeof u?[u]:u,"string"==typeof h?p.includes(h):Array.isArray(h)&&p.some(e=>h.includes(e)))||Fr(n,"aud");const f=o.clockTolerance;let m=0;if("string"==typeof f)m=Lr(f);else if(void 0!==f){if("number"!=typeof f)throw new TypeError("Invalid clockTolerance option type");m=f}zr("clockTolerance option",m);const y=o.currentDate,w=zr("currentDate option",Wr(void 0===y?new Date:y)),g=Hr(n,"iat",void 0!==l),v=Hr(n,"nbf");if(void 0!==v&&v>w+m)throw new Zo('"nbf" claim timestamp check failed',n,"nbf",Mr);const b=Hr(n,"exp");if(void 0!==b&&b<=w-m)throw new Ho('"exp" claim timestamp check failed',n,"exp",Mr);if(void 0!==l){const e=w-g;if(e-m>zr("maxTokenAge option","number"==typeof l?l:Lr(l)))throw new Ho('"iat" claim timestamp check failed (too far in the past)',n,"iat",Mr);if(e<-m)throw new Zo('"iat" claim timestamp check failed (it should be in the past)',n,"iat",Mr)}return n}let Xr;function Gr(e){return Xr.get(e)}async function Yr(e,t,n){const o=await jr(e,function(e){return[e&&Wi("algorithms",e.algorithms),null==e?void 0:e.crit]}(n),t);if(!o[2])throw new Go("JWTs MUST NOT use unencoded payload");const i={payload:Vr(o[1],o[0],n),protectedHeader:o[1]};return"function"==typeof t?f(f({},i),{},{key:o[3]}):i}function qr(e){if(void 0===e)return[void 0,""];const t=function(e,t){let n,o;try{n=JSON.stringify(t),o=JSON.parse(n)}catch(t){throw new e("JOSE Header is not valid JSON",{cause:t})}if(!si(o))throw new e("JOSE Header is not a JSON object");return[o,n]}(Xo,e);return[t[0],ri(t[1])]}function Br(e,t,n){return function(e,t){const n=(null!=t?t:{}).crit;if(Array.isArray(n)&&new Set(n).size!==n.length)throw new e('"crit" (Critical) Header Parameter MUST NOT contain duplicate values')}(Xo,e),Ki(e,Ni(Xo,ji,n,e,t))}async function Qr(e,t,n,o){const i=Mo(Uo(e),Uo("."),t),r=await _i(n,o,"sign");return ri(await async function(e,t,n){const o=await kr(e,t,"sign"),i=await crypto.subtle.sign(e.signing,o,n);return new Uint8Array(i)}(n,r,i))}async function $r(e,t,n,o,i){const r=y(qr(t),2),s=r[0],a=r[1];if(!s)throw new Xo("either setProtectedHeader or setUnprotectedHeader must be called before #sign()");Br(s,s,n)||i();const c=function(e){const t=e.alg;if("string"!=typeof t||!t)throw new Xo('JWS "alg" (Algorithm) Header Parameter missing or invalid');return xr(t)}(s),u=ri(e),l=await Qr(a,Uo(u),c,o);return"".concat(a,".").concat(u,".").concat(l)}const es=class{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!si(e))throw new TypeError("JWT Claims Set MUST be an object");(Xr||(Xr=new WeakMap)).set(this,structuredClone(e))}setIssuer(e){return Jr("iss",e),Gr(this).iss=e,this}setSubject(e){return Jr("sub",e),Gr(this).sub=e,this}setAudience(e){return function(e){if("string"!=typeof e&&(!Array.isArray(e)||Array.from(e).some(e=>"string"!=typeof e)))throw new TypeError('"aud" claim must be a string or an array of strings')}(e),Gr(this).aud=e,this}setJti(e){return Jr("jti",e),Gr(this).jti=e,this}setNotBefore(e){return Gr(this).nbf=Dr(e,"setNotBefore"),this}setExpirationTime(e){return Gr(this).exp=Dr(e,"setExpirationTime"),this}setIssuedAt(e){const t=Gr(this);return t.iat=void 0===e?Wr(new Date):"string"==typeof e?zr("setIssuedAt",Wr(new Date)+Lr(e)):Dr(e,"setIssuedAt"),this}};var ts=new WeakMap;class ns extends es{constructor(){super(...arguments),u(this,ts,void 0)}setProtectedHeader(e){return function(e,t){if(void 0!==e)throw new TypeError("".concat(t," can only be called once"))}(c(ts,this),"setProtectedHeader"),l(ts,this,e),this}async sign(e,t){return $r(function(e){const t=Gr(e);for(const e of["iat","nbf","exp"]){const n=t[e];if("number"==typeof n&&!Number.isFinite(n))throw new TypeError('"'.concat(e,'" claim must be a finite number'))}return Wo.encode(JSON.stringify(t))}(this),c(ts,this),null==t?void 0:t.crit,e,()=>{throw new Go("JWTs MUST NOT use unencoded payload")})}}const os='"alg" (Algorithm)';function is(){throw new Vo("Invalid or unsupported ".concat(arguments.length>0&&void 0!==arguments[0]?arguments[0]:'JWK "alg" (Algorithm) Parameter'," value"))}const rs=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let n=0;n<e.byteLength;n++)if(e[n]!==t[n])return!1;return!0},ss=e=>{const t=e.data[e.pos++];if(void 0===t)throw new Error("Unexpected end of ASN.1 input");return t},as=e=>{const t=ss(e);if(128&t){const n=127&t;let o=0;for(let t=0;t<n;t++)o=o<<8|ss(e);return o}return t},cs=(e,t,n)=>{if(ss(e)!==t)throw new Error(n)},us=(e,t)=>{if(t<0||e.pos+t>e.data.length)throw new Error("Unexpected end of ASN.1 input");const n=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,n};const ls=e=>{const t=(e=>{cs(e,6,"Expected algorithm OID");const t=as(e);return us(e,t)})(e);if(rs(t,[43,101,110]))return"X25519";if(!rs(t,[42,134,72,206,61,2,1]))throw new Error("Unsupported key algorithm");cs(e,6,"Expected curve OID");const n=as(e),o=us(e,n);if(rs(o,[42,134,72,206,61,3,1,7]))return"P-256";if(rs(o,[43,129,4,0,34]))return"P-384";if(rs(o,[43,129,4,0,35]))return"P-521";throw new Error("Unsupported named curve")},ds=async(e,t,n,o)=>{const i=function(e){if(void 0!==e&&"boolean"!=typeof e)throw new TypeError('"extractable" option must be a boolean');return e}(null==o?void 0:o.extractable),r=function(e,t){var n,o;return null!==(n="string"==typeof e?null!==(o=Ar[e])&&void 0!==o?o:xi[e]:void 0)&&void 0!==n?n:is(t)}(n,os);r.secret&&is(os);const s="spki"===e;let a;if(r.resolve)try{const n={data:t,pos:0};!function(e,t){if(cs(e,48,"Invalid ".concat("spki"===t?"SPKI":"PKCS#8"," structure")),as(e),"pkcs8"===t){cs(e,2,"Expected version field");const t=as(e);e.pos+=t}cs(e,48,"Expected algorithm identifier"),as(e)}(n,e),a=r.resolve({crv:ls(n)})}catch(e){throw new Vo("Invalid or unsupported key format")}else a=r.subtle;return crypto.subtle.importKey(e,t,a,null!=i?i:s,r.usages[s?0:1])},hs=(e,t,n)=>{const o=((e,t)=>ni(e.replace(t,"")))(e,/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g);return ds("pkcs8",o,t,n)};async function ps(e,t,n){const o=e.get(t)||e.set(t,{}).get(t),i=n.alg;if(void 0===o[i]){const e=await ui(n,f(f({},t),{},{alg:i,ext:!0}));if("public"!==e.type)throw new Yo("JSON Web Key Set members must be public keys");o[i]=e}return o[i]}function fs(e){let t;try{t=structuredClone(e)}catch(e){}if(!ai(t))throw new Yo("JSON Web Key Set malformed");const n=new WeakMap;return Object.defineProperty(async(e,o)=>{const i=f(f({},e),null==o?void 0:o.header),r=i.alg,a=i.kid,c="string"==typeof r?Ar[r]:void 0;if(!c||c.secret)throw new Vo('Unsupported "alg" value for a JSON Web Key Set');const u=t.keys.filter(e=>function(e,t,n,o){const i=li(e),r=i.kty,s=i.key_ops,a=i.ext,c=i.kid,u=i.alg,l=i.use,d=i.crv,h=Array.isArray(s)?[...s]:s;return(void 0===a||"boolean"==typeof a)&&(void 0===h||Array.isArray(h)&&h.every((e,t)=>"string"==typeof e&&h.indexOf(e)===t)&&h.includes("verify"))&&t.kty.includes(r)&&(void 0===o||"string"==typeof o&&o===c)&&(void 0===u?"AKP"!==r:n===u)&&(void 0===l||"sig"===l)&&(!t.crv||d===t.crv)}(e,c,r,a)),l=u[0],d=u.length;if(!d)throw new qo;if(1!==d){const e=new Bo;throw e[Symbol.asyncIterator]=w(function*(){for(const e of u)try{yield yield s(ps(n,e,c))}catch(e){}}),e}return ps(n,l,c)},"jwks",{value:()=>structuredClone(t)})}var ms,ys;let ws;if("undefined"==typeof navigator||null===(ms=navigator.userAgent)||void 0===ms||null===(ys=ms.startsWith)||void 0===ys||!ys.call(ms,"Mozilla/5.0 ")){const e="v6.2.10";ws="".concat("jose","/").concat(e)}const gs=Symbol();const vs=Symbol();function bs(e,t){return Number.isFinite(e)&&Date.now()<e+t}function _s(e,t,n){if(Number.isNaN(e))throw new TypeError('"'.concat(n,'" option must not be NaN'));return"number"==typeof e?e:t}function ks(e,t){if(!(e instanceof URL))throw new TypeError("url must be an instance of URL");const n=new URL(e.href).href,o=null!=t?t:{},i=o.timeoutDuration;if("number"==typeof i&&(!Number.isInteger(i)||i<0))throw new TypeError('"timeoutDuration" option must be a non-negative integer');const r="number"==typeof i?i:5e3,s=_s(o.cooldownDuration,3e4,"cooldownDuration"),a=_s(o.cacheMaxAge,6e5,"cacheMaxAge"),c=new Headers(o.headers);ws&&!c.has("User-Agent")&&c.set("User-Agent",ws),c.has("accept")||c.set("accept","application/json, application/jwk-set+json");const u=o[gs],l=o[vs];let d,h,p,f=0,m=0;if(l&&"object"==typeof l){const e=l.uat,t=l.jwks;bs(e,a)&&ai(t)&&(d=e,p=fs(t))}const y=async()=>{if(h&&("undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime)&&(h=void 0),!h){const e=++f,t=h=async function(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:fetch;const i=await o(e,{method:"GET",signal:n,redirect:"manual",headers:t}).catch(e=>{if("TimeoutError"===e.name)throw new Qo;throw e});if(200!==i.status)throw new Do("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await i.json()}catch(e){throw new Do("Failed to parse the JSON Web Key Set HTTP response as JSON")}}(n,c,AbortSignal.timeout(r),u).then(t=>{const n=fs(t);if(e<=m)return;p=n;const o=Date.now();l&&(l.uat=o,l.jwks=t),d=o,m=e}).finally(()=>{h===t&&(h=void 0)})}await h};return Object.defineProperties(async(e,t)=>{p&&bs(d,a)||await y();try{return await p(e,t)}catch(n){if(n instanceof qo&&!bs(d,s))return await y(),p(e,t);throw n}},{coolingDown:{get:()=>bs(d,s),enumerable:!0},fresh:{get:()=>bs(d,a),enumerable:!0},reload:{value:y,enumerable:!0},reloading:{get:()=>!!h,enumerable:!0},jwks:{value:()=>{var e;return null===(e=p)||void 0===e?void 0:e.jwks()},enumerable:!0}})}async function Ss(e,t,n){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw new TypeError('"pkcs8" must be PKCS#8 formatted string');return hs(e,t,n)}const Ts=["mfaToken"],Ps=["mfaToken"];var Es,Cs,Rs,As,xs,Is,Os,js,Ws,Ns,Ks,Ms,Us,Ls,zs,Js,Ds,Zs,Hs,Fs,Vs,Xs,Gs,Ys,qs,Bs,Qs,$s,ea,ta,na,oa,ia,ra,sa,aa,ca,ua,la,da,ha,pa,fa,ma,ya,wa,ga,va,ba,_a,ka,Sa;function Ta(e){if("object"!=typeof e||null===e)return{};const t=e;return{statusCode:"number"==typeof t.statusCode?t.statusCode:void 0,headers:t.headers instanceof Headers?t.headers:void 0,body:"string"==typeof t.body?t.body:void 0}}function Pa(e){var t,n;if("object"!=typeof e||null===e)return{error:"unknown_error",error_description:String(e)};const o=e;let i;if(o.response instanceof Response)try{i=new Headers(o.response.headers),i.delete("set-cookie")}catch(e){i=void 0}const r={error:null!==(t=o.error)&&void 0!==t?t:"",error_description:null!==(n=o.error_description)&&void 0!==n?n:"",message:o.message,statusCode:"number"==typeof o.status?o.status:void 0,headers:i};if("mfa_required"===o.error&&o.cause){r.mfa_token="string"==typeof o.cause.mfa_token?o.cause.mfa_token:void 0;const e=o.cause.mfa_requirements;"object"==typeof e&&null!==e&&(r.mfa_requirements=e)}return r}var Ea=class extends Error{constructor(e,t){super(t),h(this,"code",void 0),this.name="NotSupportedError",this.code=e}},Ca=class extends Error{constructor(e,t,n){super(t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"statusCode",void 0),h(this,"headers",void 0),h(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements};const o=Ta(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},Ra=class extends Ca{constructor(e,t){super("token_by_code_error",e,t),this.name="TokenByCodeError"}},Aa=class extends Ca{constructor(e,t){super("token_by_client_credentials_error",e,t),this.name="TokenByClientCredentialsError"}},xa=class extends Ca{constructor(e,t){super("token_by_refresh_token_error",e,t),this.name="TokenByRefreshTokenError"}},Ia=class extends Ca{constructor(e,t){super("token_by_password_error",e,t),this.name="TokenByPasswordError"}},Oa=class extends Ca{constructor(e,t){super("token_for_connection_error",e,t),this.name="TokenForConnectionErrorCode"}},ja=class extends Ca{constructor(e,t){super("token_exchange_error",e,t),this.name="TokenExchangeError"}},Wa=class extends Ca{constructor(e,t){super("token_revocation_error",e,t),this.name="TokenRevocationError"}},Na=class extends Ca{constructor(e,t){super("user_info_error",e,t),this.name="UserInfoError"}},Ka=class extends Error{constructor(e){super(e),h(this,"code","verify_logout_token_error"),this.name="VerifyLogoutTokenError"}},Ma=class extends Ca{constructor(e){super("backchannel_authentication_error","There was an error when trying to use Client-Initiated Backchannel Authentication.",e),h(this,"code","backchannel_authentication_error"),this.name="BackchannelAuthenticationError"}},Ua=class extends Ca{constructor(e){super("build_authorization_url_error","There was an error when trying to build the authorization URL.",e),this.name="BuildAuthorizationUrlError"}},La=class extends Ca{constructor(e){super("build_link_user_url_error","There was an error when trying to build the Link User URL.",e),this.name="BuildLinkUserUrlError"}},za=class extends Ca{constructor(e){super("build_unlink_user_url_error","There was an error when trying to build the Unlink User URL.",e),this.name="BuildUnlinkUserUrlError"}},Ja=class extends Error{constructor(){super("The client secret or client assertion signing key must be provided."),h(this,"code","missing_client_auth_error"),this.name="MissingClientAuthError"}},Da=class extends Error{constructor(e){super(e),h(this,"code","organization_validation_error"),this.name="OrganizationValidationError"}},Za=class extends Error{constructor(e){super(e||"fullResponse: true requested but no HTTP Response was captured. This is a bug in CapturingFetch."),h(this,"code","missing_captured_response_error"),this.name="MissingCapturedResponseError"}};function Ha(e){try{const t=new Headers(e);return t.delete("set-cookie"),t}catch(e){return new Headers}}function Fa(e,t,n){var o;const i="object"==typeof t&&null!==t?t:void 0,r=null!==(o=null==i?void 0:i.response)&&void 0!==o?o:n,s="number"==typeof(null==i?void 0:i.status)?i.status:null==r?void 0:r.status;"number"==typeof s&&(e.statusCode=s),null!=r&&r.headers&&(e.headers=Ha(r.headers))}function Va(e){return Object.entries(e).filter(e=>void 0!==y(e,2)[1]).reduce((e,t)=>f(f({},e),{},{[t[0]]:t[1]}),{})}function Xa(e){if(!e.trim())throw new Da("organization must not be blank")}function Ga(e,t){if(!e)return;const n=t.trim();if(n.startsWith("org_")){const t=e.org_id;if("string"!=typeof t)throw new Da("Organization Id (org_id) claim must be a string present in the ID token");if(t!==n)throw new Da('Organization Id (org_id) claim value mismatch in the ID token; expected "'.concat(n,'", found "').concat(t,'"'))}else{const t=e.org_name;if("string"!=typeof t)throw new Da("Organization Name (org_name) claim must be a string present in the ID token");if(t.toLowerCase()!==n.toLowerCase())throw new Da('Organization Name (org_name) claim value mismatch in the ID token; expected "'.concat(n,'", found "').concat(t,'"'))}}var Ya=class extends Error{constructor(e,t,n){super(t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"statusCode",void 0),h(this,"headers",void 0),h(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Ta(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},qa=class extends Ya{constructor(e,t){super("mfa_list_authenticators_error",e,t),this.name="MfaListAuthenticatorsError"}},Ba=class extends Ya{constructor(e,t){super("mfa_enrollment_error",e,t),this.name="MfaEnrollmentError"}},Qa=class extends Ya{constructor(e,t){super("mfa_delete_authenticator_error",e,t),this.name="MfaDeleteAuthenticatorError"}},$a=class extends Ya{constructor(e,t){super("mfa_challenge_error",e,t),this.name="MfaChallengeError"}},ec=class extends Ya{constructor(e,t){super("mfa_verify_error",e,t),this.name="MfaVerifyError"}};function tc(e){return{id:e.id,authenticatorType:e.authenticator_type,active:e.active,name:e.name,oobChannels:e.oob_channels,type:e.type}}var nc=class e{constructor(e,t,n,o,i,r,s){h(this,"accessToken",void 0),h(this,"idToken",void 0),h(this,"refreshToken",void 0),h(this,"expiresAt",void 0),h(this,"scope",void 0),h(this,"claims",void 0),h(this,"authorizationDetails",void 0),h(this,"tokenType",void 0),h(this,"issuedTokenType",void 0),h(this,"recoveryCode",void 0),h(this,"act",void 0),this.accessToken=e,this.idToken=n,this.refreshToken=o,this.expiresAt=t,this.scope=i,this.claims=r,this.authorizationDetails=s}static fromTokenEndpointResponse(t){const n=t.id_token?t.claims():void 0,o=new e(t.access_token,Math.floor(Date.now()/1e3)+Number(t.expires_in),t.id_token,t.refresh_token,t.scope,n,t.authorization_details);return o.tokenType=t.token_type,o.issuedTokenType=t.issued_token_type,o}};function oc(e,t){if(!1===t.enabled)return e;const n={name:t.name,version:t.version},o=btoa(JSON.stringify(n));return async(t,n)=>{const i=t instanceof Request?new Headers(t.headers):new Headers;if(null!=n&&n.headers){new Headers(n.headers).forEach((e,t)=>{i.set(t,e)})}return i.set("Auth0-Client",o),e(t,f(f({},n),{},{headers:i}))}}function ic(e){var t,n;return!1===(null==e?void 0:e.enabled)?e:{enabled:!0,name:null!==(t=null==e?void 0:e.name)&&void 0!==t?t:"@auth0/auth0-auth-js",version:null!==(n=null==e?void 0:e.version)&&void 0!==n?n:"1.15.0"}}function rc(e){let t;const n=async(n,o)=>{const i=await e(n,o);return t=i.clone(),i};return n.getCapturedResponse=()=>t,n}function sc(e,t,n){if(!t)return e;const o=t.signal,i=t.headers,r=t.customFetch,s=r?oc(r,n):e;return o||i?async(e,t)=>{const n=i?new Headers(e instanceof Request?e.headers:void 0):void 0;if(n&&null!=t&&t.headers&&new Headers(t.headers).forEach((e,t)=>n.set(t,e)),i)for(const e of Object.entries(i)){var r=y(e,2);const t=r[0],o=r[1],i=t.toLowerCase();"authorization"!==i&&"auth0-client"!==i&&n.set(t,o)}const a=function(e,t){if(!e)return{signal:null!=t?t:void 0};if(!t)return{signal:e};if("undefined"!=typeof AbortSignal&&"function"==typeof AbortSignal.any)return{signal:AbortSignal.any([e,t])};const n=new AbortController,o=[e,t],i=o.find(e=>e.aborted);if(i)return n.abort(i.reason),{signal:n.signal};const r=[],s=()=>{o.forEach((e,t)=>{const n=r[t];n&&e.removeEventListener("abort",n)})};return o.forEach((e,t)=>{const o=()=>{s(),n.abort(e.reason)};r[t]=o,e.addEventListener("abort",o,{once:!0})}),{signal:n.signal,cleanup:s}}(o,null==t?void 0:t.signal);try{return await s(e,f(f(f({},t),n&&{headers:n}),{},{signal:a.signal}))}finally{var c;null===(c=a.cleanup)||void 0===c||c.call(a)}}:s}var ac={otp:"http://auth0.com/oauth/grant-type/mfa-otp",oob:"http://auth0.com/oauth/grant-type/mfa-oob","recovery-code":"http://auth0.com/oauth/grant-type/mfa-recovery-code"},cc=(Es=new WeakMap,Cs=new WeakMap,Rs=new WeakMap,As=new WeakMap,xs=new WeakMap,Is=new WeakMap,Os=new WeakMap,js=new WeakSet,class{constructor(e){var t,n;d(this,js),u(this,Es,void 0),u(this,Cs,void 0),u(this,Rs,void 0),u(this,As,void 0),u(this,xs,void 0),u(this,Is,void 0),u(this,Os,void 0),l(Es,this,"https://".concat(e.domain)),l(Cs,this,e.clientId),l(Rs,this,e.clientSecret),l(As,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),l(xs,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:ic()),l(Is,this,e.getConfiguration),l(Os,this,e.createCaptureConfiguration)}async listAuthenticators(e,t){const n="".concat(c(Es,this),"/mfa/authenticators"),o=e.mfaToken,i=await r(js,this,uc).call(this,t)(n,{method:"GET",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"}});if(!i.ok){const e=await i.clone().text(),t=i.status,n=Ha(i.headers);let o;try{o=JSON.parse(e)}catch(o){throw new qa("Failed to list authenticators",{error:"unknown_error",error_description:"Failed to list authenticators",statusCode:t,headers:n,body:e})}throw new qa(o.error_description||"Failed to list authenticators",f(f({},o),{},{statusCode:t,headers:n,body:e}))}return(await i.json()).map(tc)}async enrollAuthenticator(e,t){const n="".concat(c(Es,this),"/mfa/associate"),o=e.mfaToken,i=m(e,Ts),s={authenticator_types:i.authenticatorTypes};"oobChannels"in i&&(s.oob_channels=i.oobChannels),"phoneNumber"in i&&i.phoneNumber&&(s.phone_number=i.phoneNumber),"email"in i&&i.email&&(s.email=i.email);const a=await r(js,this,uc).call(this,t)(n,{method:"POST",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"},body:JSON.stringify(s)});if(!a.ok){const e=await a.clone().text(),t=a.status,n=Ha(a.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Ba("Failed to enroll authenticator",{error:"unknown_error",error_description:"Failed to enroll authenticator",statusCode:t,headers:n,body:e})}throw new Ba(o.error_description||"Failed to enroll authenticator",f(f({},o),{},{statusCode:t,headers:n,body:e}))}return function(e){if("otp"===e.authenticator_type)return{authenticatorType:"otp",secret:e.secret,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes,id:e.id};if("oob"===e.authenticator_type)return{authenticatorType:"oob",oobChannel:e.oob_channel,oobCode:e.oob_code,bindingMethod:e.binding_method,id:e.id,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes};throw new Error("Unexpected authenticator type: ".concat(e.authenticator_type))}(await a.json())}async deleteAuthenticator(e,t){const n=e.authenticatorId,o=e.mfaToken,i="".concat(c(Es,this),"/mfa/authenticators/").concat(encodeURIComponent(n)),s=await r(js,this,uc).call(this,t)(i,{method:"DELETE",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"}});if(!s.ok){const e=await s.clone().text(),t=s.status,n=Ha(s.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Qa("Failed to delete authenticator",{error:"unknown_error",error_description:"Failed to delete authenticator",statusCode:t,headers:n,body:e})}throw new Qa(o.error_description||"Failed to delete authenticator",f(f({},o),{},{statusCode:t,headers:n,body:e}))}}async challengeAuthenticator(e,t){const n="".concat(c(Es,this),"/mfa/challenge"),o=e.mfaToken,i=m(e,Ps),s={mfa_token:o,client_id:c(Cs,this),challenge_type:i.challengeType};c(Rs,this)&&(s.client_secret=c(Rs,this)),i.authenticatorId&&(s.authenticator_id=i.authenticatorId);const a=await r(js,this,uc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(s)});if(!a.ok){const e=await a.clone().text(),t=a.status,n=Ha(a.headers);let o;try{o=JSON.parse(e)}catch(o){throw new $a("Failed to challenge authenticator",{error:"unknown_error",error_description:"Failed to challenge authenticator",statusCode:t,headers:n,body:e})}throw new $a(o.error_description||"Failed to challenge authenticator",f(f({},o),{},{statusCode:t,headers:n,body:e}))}return function(e){const t={challengeType:e.challenge_type};return void 0!==e.oob_code&&(t.oobCode=e.oob_code),void 0!==e.binding_method&&(t.bindingMethod=e.binding_method),t}(await a.json())}async verify(e,t){if(!c(Is,this))throw new Error("MFA verify requires a configuration provider (getConfiguration was not set)");const n={mfa_token:e.mfaToken};if(e.audience&&(n.audience=e.audience),"otp"===e.factorType?n.otp=e.otp:"oob"===e.factorType?(n.oob_code=e.oobCode,e.bindingCode&&(n.binding_code=e.bindingCode)):"recovery-code"===e.factorType&&(n.recovery_code=e.recoveryCode),e.fullResponse){var o;if(!c(Os,this))throw new Error("MFA verify fullResponse requires a capture-config factory (createCaptureConfiguration was not set)");const a=rc(null!==(o=(await c(Is,this).call(this,t))[Vi])&&void 0!==o?o:fetch),u=await c(Os,this).call(this,a);try{const t=await br(u,ac[e.factorType],n),o=nc.fromTokenEndpointResponse(t);t.recovery_code&&(o.recoveryCode=t.recovery_code);const i=a.getCapturedResponse();if(!i)throw new Za;return{data:o,response:i}}catch(e){var i,r,s;if(e instanceof Za)throw e;if(e instanceof ec)throw e;const t=e,n=new ec(t.error_description||t.message||"Failed to verify MFA challenge",{error:null!==(i=t.error)&&void 0!==i?i:"mfa_verify_error",error_description:null!==(r=null!==(s=t.error_description)&&void 0!==s?s:t.message)&&void 0!==r?r:"Failed to verify MFA challenge"});throw Fa(n,e,a.getCapturedResponse()),n}}const a=await c(Is,this).call(this,t);try{const t=await br(a,ac[e.factorType],n),o=nc.fromTokenEndpointResponse(t);return t.recovery_code&&(o.recoveryCode=t.recovery_code),o}catch(e){var u,l,d;if(e instanceof ec)throw e;const t=e,n=new ec(t.error_description||t.message||"Failed to verify MFA challenge",{error:null!==(u=t.error)&&void 0!==u?u:"mfa_verify_error",error_description:null!==(l=null!==(d=t.error_description)&&void 0!==d?d:t.message)&&void 0!==l?l:"Failed to verify MFA challenge"});throw Fa(n,e),n}}});function uc(e){return sc(c(As,this),e,c(xs,this))}var lc=class extends Error{constructor(e,t,n){super(t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"statusCode",void 0),h(this,"headers",void 0),h(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Ta(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},dc=class extends lc{constructor(e,t){super("passkey_register_error",e,t),this.name="PasskeyRegisterError"}},hc=class extends lc{constructor(e,t){super("passkey_challenge_error",e,t),this.name="PasskeyChallengeError"}},pc=class extends lc{constructor(e,t){super("passkey_get_token_error",e,t),this.name="PasskeyGetTokenError",this.cause=t&&{error:t.error,error_description:t.error_description,message:t.message,mfa_token:t.mfa_token,mfa_requirements:t.mfa_requirements}}};function fc(e){return e.useMtls?{}:e.clientSecret?{client_secret:e.clientSecret}:{}}var mc="urn:okta:params:oauth:grant-type:webauthn",yc=(Ws=new WeakMap,Ns=new WeakMap,Ks=new WeakMap,Ms=new WeakMap,Us=new WeakMap,Ls=new WeakMap,zs=new WeakSet,class{constructor(e){var t,n;d(this,zs),u(this,Ws,void 0),u(this,Ns,void 0),u(this,Ks,void 0),u(this,Ms,void 0),u(this,Us,void 0),u(this,Ls,void 0),l(Ws,this,"https://".concat(e.domain)),l(Ns,this,e.clientId),l(Ks,this,{clientSecret:e.clientSecret,useMtls:e.useMtls}),l(Ms,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),l(Us,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:ic()),l(Ls,this,e.grantRequest)}async register(e,t){const n="".concat(c(Ws,this),"/passkey/register"),o=f(f(f(f(f(f(f(f({},e.email&&{email:e.email}),e.name&&{name:e.name}),e.phoneNumber&&{phone_number:e.phoneNumber}),e.username&&{username:e.username}),e.givenName&&{given_name:e.givenName}),e.familyName&&{family_name:e.familyName}),e.nickname&&{nickname:e.nickname}),e.picture&&{picture:e.picture}),i=f(f({client_id:c(Ns,this)},fc(c(Ks,this))),{},{user_profile:o});e.realm&&(i.realm=e.realm),e.organization&&(i.organization=e.organization),e.userMetadata&&(i.user_metadata=e.userMetadata);const s=await r(zs,this,wc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(i)});if(!s.ok){const e=await r(zs,this,gc).call(this,s),t=new dc(e.error_description||"Failed to request signup challenge",e);throw t.statusCode=s.status,t.headers=Ha(s.headers),t}const a=await s.json();return{authSession:(u=a).auth_session,authnParamsPublicKey:f({},u.authn_params_public_key)};var u}async challenge(e,t){const n="".concat(c(Ws,this),"/passkey/challenge"),o=f({client_id:c(Ns,this)},fc(c(Ks,this)));null!=e&&e.realm&&(o.realm=e.realm),null!=e&&e.organization&&(o.organization=e.organization);const i=await r(zs,this,wc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(o)});if(!i.ok){const e=await r(zs,this,gc).call(this,i),t=new hc(e.error_description||"Failed to request login challenge",e);throw t.statusCode=i.status,t.headers=Ha(i.headers),t}const s=await i.json();return{authSession:(a=s).auth_session,authnParamsPublicKey:f({},a.authn_params_public_key)};var a}async getTokenByPasskey(e,t){void 0!==e.organization&&Xa(e.organization);const n=new URLSearchParams({auth_session:e.authSession,authn_response:JSON.stringify(e.credential)});let o;e.realm&&n.append("realm",e.realm),e.scope&&n.append("scope",e.scope),e.audience&&n.append("audience",e.audience),e.organization&&n.append("organization",e.organization);try{o=await c(Ls,this).call(this,mc,n,t,e.fullResponse)}catch(e){if(e instanceof Za)throw e;const t=Pa(e),n=new pc(t.error_description||"Failed to exchange passkey credential for tokens.",t);throw Fa(n,e),n}if(e.fullResponse){const t=o;return e.organization&&Ga(t.data.claims,e.organization),t}const i=o;return e.organization&&Ga(i.claims,e.organization),i}});function wc(e){return sc(c(Ms,this),e,c(Us,this))}async function gc(e){const t=await e.clone().text();try{return f(f({},JSON.parse(t)),{},{statusCode:e.status,headers:e.headers,body:t})}catch(n){return{error:"unknown_error",error_description:"HTTP ".concat(e.status," ").concat(e.statusText),statusCode:e.status,headers:e.headers,body:t}}}var vc=class extends Error{constructor(e,t,n){super(t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"statusCode",void 0),h(this,"headers",void 0),h(this,"body",void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&(n.error||n.error_description)?{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements}:void 0;const o=Ta(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},bc=class extends vc{constructor(e,t){super("passwordless_start_error",e,t),this.name="PasswordlessStartError"}},_c=class extends vc{constructor(e,t){super("passwordless_verify_error",e,t),this.name="PasswordlessVerifyError"}},kc=class extends vc{constructor(e,t){super("passwordless_db_get_token_error",e,t),this.name="PasswordlessDbGetTokenError"}},Sc=class extends vc{constructor(e,t,n,o,i){super("passwordless_challenge_error",e,n),h(this,"statusCode",void 0),h(this,"validationErrors",void 0),this.name="PasswordlessChallengeError",this.statusCode=t,this.validationErrors=o,this.headers=null!=i?i:this.headers}};function Tc(e){return/^\+[1-9]\d{1,14}$/.test(e)}async function Pc(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){var o;const i=null!==(o=e.clientAssertionSigningAlg)&&void 0!==o?o:"RS256",r=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await Ss(e.clientAssertionSigningKey,i);return{client_assertion:await new ns({}).setProtectedHeader({alg:i}).setIssuer(t).setSubject(t).setAudience("https://".concat(n,"/")).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime("".concat(120,"s")).sign(r),client_assertion_type:"urn:ietf:params:oauth:client-assertion-type:jwt-bearer"}}if(e.clientSecret)return{client_secret:e.clientSecret};throw new Ja}var Ec=(Js=new WeakMap,Ds=new WeakMap,Zs=new WeakMap,Hs=new WeakMap,Fs=new WeakMap,Vs=new WeakMap,Xs=new WeakMap,Gs=new WeakSet,class{constructor(e){var t,n;d(this,Gs),u(this,Js,void 0),u(this,Ds,void 0),u(this,Zs,void 0),u(this,Hs,void 0),u(this,Fs,void 0),u(this,Vs,void 0),u(this,Xs,void 0),l(Ds,this,e.domain),l(Js,this,"https://".concat(e.domain)),l(Zs,this,e.clientId),l(Hs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),l(Fs,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:ic()),l(Vs,this,{clientSecret:e.clientSecret,clientAssertionSigningKey:e.clientAssertionSigningKey,clientAssertionSigningAlg:e.clientAssertionSigningAlg,useMtls:e.useMtls}),l(Xs,this,e.grantRequest)}async sendEmail(e,t){const n=await r(Gs,this,Rc).call(this,function(e){var t;const n=null!==(t=e.send)&&void 0!==t?t:"code",o={email:e.email,connection:"email",send:n};return"link"===n&&e.authParams&&(o.authParams=e.authParams),o}(e),"Failed to send passwordless email",e.language,t);if(e.fullResponse)return{data:void 0,response:n}}async sendSms(e,t){if(!Tc(e.phoneNumber))throw new bc("Phone number must be in E.164 format (e.g. +14155550100).");const n=await r(Gs,this,Rc).call(this,function(e){return{phone_number:e.phoneNumber,connection:"sms"}}(e),"Failed to send passwordless SMS",e.language,t);if(e.fullResponse)return{data:void 0,response:n}}async challengeWithEmail(e,t){const n=function(e){var t;return{email:e.email,connection:e.connection,allow_signup:null!==(t=e.allowSignup)&&void 0!==t&&t}}(e);return r(Gs,this,Ac).call(this,n,"Failed to request email OTP challenge",t)}async challengeWithPhoneNumber(e,t){if(!Tc(e.phoneNumber))throw new Sc("Phone number must be in E.164 format (e.g. +14155550100).",0,void 0,void 0);const n=function(e){var t;const n={phone_number:e.phoneNumber,connection:e.connection,allow_signup:null!==(t=e.allowSignup)&&void 0!==t&&t};return e.deliveryMethod&&(n.delivery_method=e.deliveryMethod),n}(e);return r(Gs,this,Ac).call(this,n,"Failed to request phone OTP challenge",t)}async getTokenByPasswordlessDbConnection(e,t){const n=new URLSearchParams({auth_session:e.authSession,otp:e.otp});if(e.scope&&n.append("scope",e.scope),e.audience&&n.append("audience",e.audience),!c(Xs,this))throw new kc("Missing grant request delegate.",Pa(new Error("missing grantRequest")));try{return await c(Xs,this).call(this,"http://auth0.com/oauth/grant-type/passwordless/otp",n,t,e.fullResponse)}catch(e){if(e instanceof Za)throw e;const t=new kc("There was an error while trying to request a token.",Pa(e)),n=e;throw t.statusCode=n._statusCode,t.headers=n._headers,t}}});function Cc(e){return sc(c(Hs,this),e,c(Fs,this))}async function Rc(e,t,n,o){var i;const s=await Pc(c(Vs,this),c(Zs,this),c(Ds,this)),a=f(f({client_id:c(Zs,this)},e),s);let u;try{u=await r(Gs,this,Cc).call(this,o)("".concat(c(Js,this),"/passwordless/start"),{method:"POST",headers:f({"Content-Type":"application/json"},n?{"x-request-language":n}:{}),body:JSON.stringify(a)})}catch(e){throw new bc("".concat(t,": a network error occurred."))}if(u.ok)return u;const l=await u.clone().text();let d;if(204!==u.status)try{d=JSON.parse(l)}catch(e){d=void 0}const h=new bc((null===(i=d)||void 0===i?void 0:i.error_description)||t,d);throw h.statusCode=u.status,h.headers=Ha(u.headers),h.body=l,h}async function Ac(e,t,n){var o,i;const s=await Pc(c(Vs,this),c(Zs,this),c(Ds,this)),a=f(f({client_id:c(Zs,this)},e),s);let u;try{u=await r(Gs,this,Cc).call(this,n)("".concat(c(Js,this),"/otp/challenge"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(a)})}catch(e){throw new Sc("challenge error: a network error occurred.",0,void 0,void 0)}if(u.ok){let e;try{e=await u.json()}catch(e){throw new Sc("".concat(t,": could not parse the response body."),u.status,void 0,void 0,Ha(u.headers))}return{authSession:e.auth_session}}const l=await u.clone().text();let d;try{d=JSON.parse(l)}catch(e){d=void 0}const h=d?f(f({},d),{},{statusCode:u.status,headers:u.headers,body:l}):{error:"",error_description:"",statusCode:u.status,headers:u.headers,body:l};throw new Sc((null===(o=d)||void 0===o?void 0:o.error_description)||t,u.status,h,null===(i=d)||void 0===i?void 0:i.validation_errors,Ha(u.headers))}var xc=class extends Error{constructor(e,t,n){super(t),h(this,"cause",void 0),h(this,"code",void 0),h(this,"statusCode",void 0),h(this,"headers",void 0),h(this,"body",void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Ta(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},Ic=class extends xc{constructor(e,t){super("signup_error",e,t),this.name="SignUpError"}},Oc=class extends xc{constructor(e,t){super("change_password_error",e,t),this.name="ChangePasswordError"}};function jc(e,t,n){for(const o of t)if(null===e[o]||void 0===e[o]||""===e[o])throw new n('Required parameter "'.concat(String(o),'" was null, undefined, or empty.'))}function Wc(e){var t,n;return{id:null!==(t=null!==(n=e._id)&&void 0!==n?n:e.user_id)&&void 0!==t?t:e.id,email:"string"==typeof e.email?e.email:"",emailVerified:Boolean(e.email_verified),username:e.username,givenName:e.given_name,familyName:e.family_name,name:e.name,nickname:e.nickname,picture:e.picture,userMetadata:e.user_metadata}}var Nc=(Ys=new WeakMap,qs=new WeakMap,Bs=new WeakMap,Qs=new WeakMap,$s=new WeakSet,class{constructor(e){var t,n;d(this,$s),u(this,Ys,void 0),u(this,qs,void 0),u(this,Bs,void 0),u(this,Qs,void 0),l(Ys,this,"https://".concat(e.domain)),l(qs,this,e.clientId),l(Bs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),l(Qs,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:ic())}async signUp(e,t){var n;jc(e,["email","password","connection"],Ic);const o=f({client_id:null!==(n=e.clientId)&&void 0!==n?n:c(qs,this)},function(e){const t={email:e.email,password:e.password,connection:e.connection};return void 0!==e.username&&(t.username=e.username),void 0!==e.givenName&&(t.given_name=e.givenName),void 0!==e.familyName&&(t.family_name=e.familyName),void 0!==e.name&&(t.name=e.name),void 0!==e.nickname&&(t.nickname=e.nickname),void 0!==e.picture&&(t.picture=e.picture),void 0!==e.userMetadata&&(t.user_metadata=e.userMetadata),t}(e)),i=await r($s,this,Kc).call(this,"/dbconnections/signup",o,Ic,"Failed to sign up",t);if(e.fullResponse){const e=i.clone();return{data:Wc(await i.json()),response:e}}return Wc(await i.json())}async changePassword(e,t){var n;if(jc(e,["connection"],Oc),!e.email&&!e.username)throw new Oc('Either "email" or "username" is required.');const o=f({client_id:null!==(n=e.clientId)&&void 0!==n?n:c(qs,this)},function(e){const t={connection:e.connection};return void 0!==e.email&&(t.email=e.email),void 0!==e.username&&(t.username=e.username),void 0!==e.organization&&(t.organization=e.organization),t}(e)),i=await r($s,this,Kc).call(this,"/dbconnections/change_password",o,Oc,"Failed to request a password change",t);if(e.fullResponse){const e=i.clone();return{data:await i.text(),response:e}}return i.text()}});async function Kc(e,t,n,o,i){const r=sc(c(Bs,this),i,c(Qs,this));let s;try{s=await r("".concat(c(Ys,this)).concat(e),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(t)})}catch(e){throw new n("".concat(o,": a network error occurred."))}if(s.ok)return s;const a=await s.clone().text(),u=await async function(e){let t;try{t=await e.json()}catch(e){return}return"string"==typeof t.error?t:"string"==typeof t.code?{error:t.code,error_description:"string"==typeof t.description?t.description:""}:void 0}(s.clone()),l=new n((null==u?void 0:u.error_description)||o,null!=u?u:{error:"unknown_error",error_description:o});throw l.statusCode=s.status,l.headers=Ha(s.headers),l.body=a,l}var Mc=class extends Error{constructor(e,t,n){super(t),h(this,"code",void 0),h(this,"cause",void 0),this.name="AnonymousSessionError",this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}};var Uc=new Set(["session_expired","invalid_session_token"]);async function Lc(e){const t="Request failed with status ".concat(e.status);let n={};try{n=await e.json()}catch(e){}return{error:"string"==typeof n.error?n.error:"server_error",error_description:"string"==typeof n.error_description?n.error_description:t}}var zc=(ea=new WeakMap,ta=new WeakMap,na=new WeakMap,oa=new WeakMap,ia=new WeakMap,ra=new WeakMap,sa=new WeakMap,aa=new WeakMap,ca=new WeakSet,class{constructor(e){var t;d(this,ca),u(this,ea,void 0),u(this,ta,void 0),u(this,na,void 0),u(this,oa,void 0),u(this,ia,void 0),u(this,ra,void 0),u(this,sa,void 0),u(this,aa,void 0),l(ea,this,e.domain),l(ta,this,"https://".concat(e.domain)),l(na,this,e.clientId),l(oa,this,e.clientSecret),l(ia,this,e.clientAssertionSigningKey),l(ra,this,e.clientAssertionSigningAlg),l(sa,this,e.useMtls),l(aa,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)})}async createSession(e){const t={client_id:c(na,this)};null!=e&&e.audience&&(t.audience=e.audience),null!=e&&e.scope&&(t.scope=e.scope),null!=e&&e.metadata&&(t.metadata=e.metadata);const n=await r(ca,this,Dc).call(this,t);if(!n.sessionToken)throw new Mc("server_error","session_token missing from create session response");return{sessionToken:n.sessionToken,accessToken:n.accessToken,expiresAt:n.expiresAt,sessionTokenExpiresAt:n.sessionTokenExpiresAt,scope:n.scope}}async getAccessToken(e){if(null==e||!e.sessionToken)return this.createSession({audience:null==e?void 0:e.audience,scope:null==e?void 0:e.scope});try{return await r(ca,this,Jc).call(this,e.sessionToken,e)}catch(t){if(t instanceof Mc&&Uc.has(t.code)){return f(f({},await this.createSession({audience:null==e?void 0:e.audience,scope:null==e?void 0:e.scope})),{},{sessionReplaced:!0})}throw t}}async logout(){const e="".concat(c(ta,this),"/anonymous/logout"),t={client_id:c(na,this)},n=await c(aa,this).call(this,e,{method:"POST",headers:{"Content-Type":"application/json"},credentials:"include",redirect:"error",body:JSON.stringify(t)});if(!n.ok){const e=await Lc(n);throw new Mc(e.error,e.error_description||"Failed to end anonymous session",e)}}});async function Jc(e,t){const n={client_id:c(na,this),session_token:e};null!=t&&t.audience&&(n.audience=t.audience),null!=t&&t.scope&&(n.scope=t.scope);const o=await r(ca,this,Dc).call(this,n);return{sessionToken:e,accessToken:o.accessToken,expiresAt:o.expiresAt,sessionTokenExpiresAt:o.sessionTokenExpiresAt,scope:o.scope,sessionReplaced:!1}}async function Dc(e){const t="".concat(c(ta,this),"/anonymous/token"),n=await async function(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){var o;const i=null!==(o=e.clientAssertionSigningAlg)&&void 0!==o?o:"RS256",r=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await Ss(e.clientAssertionSigningKey,i);return{client_assertion:await new ns({}).setProtectedHeader({alg:i}).setIssuer(t).setSubject(t).setAudience("https://".concat(n,"/")).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime("".concat(120,"s")).sign(r),client_assertion_type:"urn:ietf:params:oauth:client-assertion-type:jwt-bearer"}}return e.clientSecret?{client_secret:e.clientSecret}:{}}({clientSecret:c(oa,this),clientAssertionSigningKey:c(ia,this),clientAssertionSigningAlg:c(ra,this),useMtls:c(sa,this)},c(na,this),c(ea,this));Object.assign(e,n);const o=await c(aa,this).call(this,t,{method:"POST",headers:{"Content-Type":"application/json"},credentials:"include",redirect:"error",body:JSON.stringify(e)});if(!o.ok){const e=await Lc(o);throw new Mc(e.error,e.error_description||"Anonymous token request failed",e)}let i;try{i=await o.json()}catch(e){throw new Mc("server_error","Invalid response from anonymous token endpoint")}return function(e){const t=Math.floor(Date.now()/1e3);if("string"!=typeof e.access_token||!e.access_token)throw new Mc("server_error","access_token missing or invalid in anonymous token response");const n=e.expires_in;if("number"!=typeof n||!Number.isFinite(n))throw new Mc("server_error","expires_in missing or invalid in anonymous token response");return{accessToken:e.access_token,expiresAt:t+n,scope:e.scope,sessionToken:e.session_token,sessionTokenExpiresAt:"number"==typeof e.session_expires_in&&Number.isFinite(e.session_expires_in)?t+e.session_expires_in:void 0}}(i)}var Zc=(ua=new WeakMap,la=new WeakMap,da=new WeakMap,class{constructor(e,t){u(this,ua,new Map),u(this,la,void 0),u(this,da,void 0),l(da,this,Math.max(1,Math.floor(e))),l(la,this,Math.max(0,Math.floor(t)))}get(e){const t=c(ua,this).get(e);if(t){if(!(Date.now()>=t.expiresAt))return c(ua,this).delete(e),c(ua,this).set(e,t),t.value;c(ua,this).delete(e)}}set(e,t,n){c(ua,this).has(e)&&c(ua,this).delete(e);const o=null!=n&&Number.isFinite(n)&&n>0?n:c(la,this);for(c(ua,this).set(e,{value:t,expiresAt:Date.now()+o});c(ua,this).size>c(da,this);){const e=c(ua,this).keys().next().value;if(void 0===e)break;c(ua,this).delete(e)}}}),Hc=new Map;function Fc(e){return{ttlMs:1e3*("number"==typeof(null==e?void 0:e.ttl)?e.ttl:600),maxEntries:"number"==typeof(null==e?void 0:e.maxEntries)&&e.maxEntries>0?e.maxEntries:100}}var Vc=class{static createDiscoveryCache(e){const t=(n=e.maxEntries,o=e.ttlMs,"".concat(n,":").concat(o));var n,o;let i=(r=t,Hc.get(r));var r;return i||(i=new Zc(e.maxEntries,e.ttlMs),Hc.set(t,i)),i}static createJwksCache(){return{}}},Xc="openid profile email offline_access",Gc=Object.freeze(new Set(["grant_type","client_id","client_secret","client_assertion","client_assertion_type","subject_token","subject_token_type","requested_token_type","actor_token","actor_token_type","audience","aud","resource","resources","resource_indicator","scope","connection","login_hint","organization","assertion"]));function Yc(e){if(null==e)throw new ja("subject_token is required");if("string"!=typeof e)throw new ja("subject_token must be a string");if(0===e.trim().length)throw new ja("subject_token cannot be blank or whitespace");if(e!==e.trim())throw new ja("subject_token must not include leading or trailing whitespace");if(/^bearer\s+/i.test(e))throw new ja("subject_token must not include the 'Bearer ' prefix")}function qc(e,t){if(t)for(const o of Object.entries(t)){var n=y(o,2);const t=n[0],i=n[1];if(!Gc.has(t))if(Array.isArray(i)){if(i.length>20)throw new ja("Parameter '".concat(t,"' exceeds maximum array size of ").concat(20));i.forEach(n=>{e.append(t,n)})}else e.append(t,i)}}var Bc="urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token",Qc="urn:ietf:params:oauth:grant-type:token-exchange",$c="urn:ietf:params:oauth:token-type:access_token";function eu(e,t){return(n,o)=>{const i=null==o?void 0:o.body;if(t!==mc||!(i instanceof URLSearchParams))return e(n,o);const r={};for(const e of i){var s=y(e,2);const t=s[0],n=s[1];r[t]="authn_response"===t?JSON.parse(n):n}const a=new Headers(null==o?void 0:o.headers);return a.set("Content-Type","application/json"),e(n,f(f({},o),{},{headers:a,body:JSON.stringify(r)}))}}var tu=(ha=new WeakMap,pa=new WeakMap,fa=new WeakMap,ma=new WeakMap,ya=new WeakMap,wa=new WeakMap,ga=new WeakMap,va=new WeakMap,ba=new WeakMap,_a=new WeakMap,ka=new WeakMap,Sa=new WeakSet,class{constructor(e){var t;if(d(this,Sa),u(this,ha,void 0),u(this,pa,void 0),u(this,fa,void 0),u(this,ma,void 0),u(this,ya,void 0),u(this,wa,void 0),u(this,ga,void 0),u(this,va,void 0),u(this,ba,void 0),u(this,_a,void 0),u(this,ka,void 0),h(this,"mfa",void 0),h(this,"passkey",void 0),h(this,"passwordless",void 0),h(this,"database",void 0),h(this,"anonymous",void 0),l(ya,this,e),e.useMtls&&!e.customFetch)throw new Ea("mtls_without_custom_fetch_not_supported","Using mTLS without a custom fetch implementation is not supported");l(ga,this,ic(e.telemetry)),l(wa,this,oc(null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)},c(ga,this)));const n=Fc(e.discoveryCache);l(ba,this,Vc.createDiscoveryCache(n)),l(_a,this,new Map),l(ka,this,Vc.createJwksCache()),this.mfa=new cc({domain:c(ya,this).domain,clientId:c(ya,this).clientId,clientSecret:c(ya,this).clientSecret,customFetch:c(wa,this),telemetryConfig:c(ga,this),getConfiguration:async e=>(await r(Sa,this,ru).call(this,e)).configuration,createCaptureConfiguration:async e=>{const t=(await r(Sa,this,su).call(this)).serverMetadata;return r(Sa,this,ou).call(this,t,e)}}),this.passkey=new yc({domain:c(ya,this).domain,clientId:c(ya,this).clientId,clientSecret:c(ya,this).clientSecret,useMtls:c(ya,this).useMtls,customFetch:c(wa,this),telemetryConfig:c(ga,this),grantRequest:async(e,t,n,o)=>{const i=(await r(Sa,this,su).call(this)).serverMetadata,s=r(Sa,this,iu).call(this,n);if(o){const n=rc(s),o=await r(Sa,this,ou).call(this,i,n);o[Vi]=eu(n,e);const a=await br(o,e,t),c=nc.fromTokenEndpointResponse(a),u=n.getCapturedResponse();if(!u)throw new Za;return{data:c,response:u}}const a=await r(Sa,this,ou).call(this,i);a[Vi]=eu(s,e);const c=await br(a,e,t);return nc.fromTokenEndpointResponse(c)}}),this.passwordless=new Ec({domain:c(ya,this).domain,clientId:c(ya,this).clientId,customFetch:c(wa,this),telemetryConfig:c(ga,this),clientSecret:c(ya,this).clientSecret,clientAssertionSigningKey:c(ya,this).clientAssertionSigningKey,clientAssertionSigningAlg:c(ya,this).clientAssertionSigningAlg,useMtls:c(ya,this).useMtls,grantRequest:async(e,t,n,o)=>{const i=(await r(Sa,this,ru).call(this,n)).configuration;if(o){var s;const n=rc(null!==(s=i[Vi])&&void 0!==s?s:c(wa,this)),o=await r(Sa,this,ou).call(this,i.serverMetadata(),n),a=await br(o,e,t),u=nc.fromTokenEndpointResponse(a),l=n.getCapturedResponse();if(!l)throw new Za;return{data:u,response:l}}try{const n=await br(i,e,t);return nc.fromTokenEndpointResponse(n)}catch(e){const t=e,n={};throw Fa(n,e),t._statusCode=n.statusCode,t._headers=n.headers,e}}}),this.database=new Nc({domain:c(ya,this).domain,clientId:c(ya,this).clientId,customFetch:c(wa,this),telemetryConfig:c(ga,this)}),this.anonymous=new zc({domain:c(ya,this).domain,clientId:c(ya,this).clientId,clientSecret:c(ya,this).clientSecret,clientAssertionSigningKey:c(ya,this).clientAssertionSigningKey,clientAssertionSigningAlg:c(ya,this).clientAssertionSigningAlg,useMtls:c(ya,this).useMtls,customFetch:c(wa,this)})}async getServerMetadata(){return(await r(Sa,this,su).call(this)).serverMetadata}async buildAuthorizationUrl(e){const t=(await r(Sa,this,su).call(this)).serverMetadata;if(null!=e&&e.pushedAuthorizationRequests&&!t.pushed_authorization_request_endpoint)throw new Ea("par_not_supported_error","The Auth0 tenant does not have pushed authorization requests enabled. Learn how to enable it here: https://auth0.com/docs/get-started/applications/configure-par");try{return await r(Sa,this,pu).call(this,e)}catch(e){throw new Ua(e)}}async buildLinkUserUrl(e){try{const t=await r(Sa,this,pu).call(this,{authorizationParams:f(f({},e.authorizationParams),{},{requested_connection:e.connection,requested_connection_scope:e.connectionScope,scope:"openid link_account offline_access",id_token_hint:e.idToken})});return{linkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new La(e)}}async buildUnlinkUserUrl(e){try{const t=await r(Sa,this,pu).call(this,{authorizationParams:f(f({},e.authorizationParams),{},{requested_connection:e.connection,scope:"openid unlink_account",id_token_hint:e.idToken})});return{unlinkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new za(e)}}async backchannelAuthentication(e,t){var n;const o=await r(Sa,this,ru).call(this,t),i=o.configuration,s=o.serverMetadata,a=Va(f(f({},c(ya,this).authorizationParams),null==e?void 0:e.authorizationParams)),u=new URLSearchParams(f(f({scope:Xc},a),{},{client_id:c(ya,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:s.issuer,sub:e.loginHint.sub})}));if(e.requestedExpiry&&u.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&u.append("authorization_details",JSON.stringify(e.authorizationDetails)),e.fullResponse){var l;const e=rc(null!==(l=i[Vi])&&void 0!==l?l:c(wa,this)),t=await r(Sa,this,ou).call(this,i.serverMetadata(),e);try{const n=await ar(i,u),o=await cr(t,n),r=e.getCapturedResponse();if(!r)throw new Za;return{data:nc.fromTokenEndpointResponse(o),response:r}}catch(t){if(t instanceof Za)throw t;const n=new Ma(t);throw Fa(n,t,e.getCapturedResponse()),n}}const d=rc(null!==(n=i[Vi])&&void 0!==n?n:c(wa,this)),h=await r(Sa,this,ou).call(this,i.serverMetadata(),d);try{const e=await ar(i,u),t=await cr(h,e);return nc.fromTokenEndpointResponse(t)}catch(e){const t=new Ma(e);throw Fa(t,e,d.getCapturedResponse()),t}}async initiateBackchannelAuthentication(e,t){var n;const o=await r(Sa,this,ru).call(this,t),i=o.configuration,s=o.serverMetadata,a=Va(f(f({},c(ya,this).authorizationParams),null==e?void 0:e.authorizationParams)),u=new URLSearchParams(f(f({scope:Xc},a),{},{client_id:c(ya,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:s.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&u.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&u.append("authorization_details",JSON.stringify(e.authorizationDetails));const l=rc(null!==(n=i[Vi])&&void 0!==n?n:c(wa,this)),d=await r(Sa,this,ou).call(this,i.serverMetadata(),l);try{const e=await ar(d,u);return{authReqId:e.auth_req_id,expiresIn:e.expires_in,interval:e.interval}}catch(e){const t=new Ma(e),n=l.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async backchannelAuthenticationGrant(e,t){var n;let o=e.authReqId;const i=(await r(Sa,this,ru).call(this,t)).configuration,s=new URLSearchParams({auth_req_id:o}),a=rc(null!==(n=i[Vi])&&void 0!==n?n:c(wa,this)),u=await r(Sa,this,ou).call(this,i.serverMetadata(),a);try{const e=await br(u,"urn:openid:params:grant-type:ciba",s);return nc.fromTokenEndpointResponse(e)}catch(e){const t=new Ma(e),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async getTokenForConnection(e,t){var n;if(e.refreshToken&&e.accessToken)throw new Oa("Either a refresh or access token should be specified, but not both.");const o=null!==(n=e.accessToken)&&void 0!==n?n:e.refreshToken;if(!o)throw new Oa("Either a refresh or access token must be specified.");try{return await this.exchangeToken(f({connection:e.connection,subjectToken:o,subjectTokenType:e.accessToken?$c:"urn:ietf:params:oauth:token-type:refresh_token",loginHint:e.loginHint},e.fullResponse?{fullResponse:!0}:{}),t)}catch(e){if(e instanceof ja){const t=new Oa(e.message,e.cause);throw t.statusCode=e.statusCode,t.headers=e.headers,t}throw e}}async exchangeToken(e,t){return e.fullResponse?"connection"in e?r(Sa,this,cu).call(this,e,t,!0):r(Sa,this,lu).call(this,e,t,!0):"connection"in e?r(Sa,this,cu).call(this,e,t):r(Sa,this,lu).call(this,e,t)}async getTokenByCode(e,t,n){var o;const i=(await r(Sa,this,ru).call(this,n)).configuration;if(void 0!==t.organization&&Xa(t.organization),t.fullResponse){var s;const n=rc(null!==(s=i[Vi])&&void 0!==s?s:c(wa,this)),o=await r(Sa,this,ou).call(this,i.serverMetadata(),n);let a,u;try{const i=await lr(o,e,{pkceCodeVerifier:t.codeVerifier});if(a=nc.fromTokenEndpointResponse(i),u=n.getCapturedResponse(),!u)throw new Za}catch(e){if(e instanceof Za)throw e;const t=new Ra("There was an error while trying to request a token.",Pa(e)),o=n.getCapturedResponse();throw t.statusCode=null==o?void 0:o.status,t.headers=o?Ha(o.headers):void 0,t}return t.organization&&Ga(a.claims,t.organization),{data:a,response:u}}const a=rc(null!==(o=i[Vi])&&void 0!==o?o:c(wa,this)),u=await r(Sa,this,ou).call(this,i.serverMetadata(),a);let l;try{const n=await lr(u,e,{pkceCodeVerifier:t.codeVerifier});l=nc.fromTokenEndpointResponse(n)}catch(e){const t=new Ra("There was an error while trying to request a token.",Pa(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}return t.organization&&Ga(l.claims,t.organization),l}async getTokenByMagicLinkCode(e,t,n){var o;const i=(await r(Sa,this,ru).call(this,n)).configuration;if(null!=t&&t.fullResponse){var s;const n=rc(null!==(s=i[Vi])&&void 0!==s?s:c(wa,this)),o=await r(Sa,this,ou).call(this,i.serverMetadata(),n);try{const i=await lr(o,e,{expectedState:null==t?void 0:t.expectedState}),r=nc.fromTokenEndpointResponse(i),s=n.getCapturedResponse();if(!s)throw new Za;return{data:r,response:s}}catch(e){if(e instanceof Za)throw e;const t=e instanceof Error&&e.message?e.message:"There was an error while trying to request a token.",o=new Ra(t,e),i=n.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Ha(i.headers):void 0,o}}const a=rc(null!==(o=i[Vi])&&void 0!==o?o:c(wa,this)),u=await r(Sa,this,ou).call(this,i.serverMetadata(),a);try{const n=await lr(u,e,{expectedState:null==t?void 0:t.expectedState});return nc.fromTokenEndpointResponse(n)}catch(e){const t=e instanceof Error&&e.message?e.message:"There was an error while trying to request a token.",n=new Ra(t,e),o=a.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}}async getTokenByRefreshToken(e,t){var n;const o=(await r(Sa,this,ru).call(this,t)).configuration,i=new URLSearchParams;if(e.audience&&i.append("audience",e.audience),e.scope&&i.append("scope",e.scope),e.fullResponse){var s;const t=rc(null!==(s=o[Vi])&&void 0!==s?s:c(wa,this)),n=await r(Sa,this,ou).call(this,o.serverMetadata(),t);try{const o=await dr(n,e.refreshToken,i),r=nc.fromTokenEndpointResponse(o),s=t.getCapturedResponse();if(!s)throw new Za;return{data:r,response:s}}catch(e){if(e instanceof Za)throw e;const n=new xa("The access token has expired and there was an error while trying to refresh it.",Pa(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}}const a=rc(null!==(n=o[Vi])&&void 0!==n?n:c(wa,this)),u=await r(Sa,this,ou).call(this,o.serverMetadata(),a);try{const t=await dr(u,e.refreshToken,i);return nc.fromTokenEndpointResponse(t)}catch(e){const t=new xa("The access token has expired and there was an error while trying to refresh it.",Pa(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async revokeToken(e,t){var n;const o=(await r(Sa,this,ru).call(this,t)).configuration,i={};e.tokenTypeHint&&(i.token_type_hint=e.tokenTypeHint);const s=rc(null!==(n=o[Vi])&&void 0!==n?n:c(wa,this)),a=await r(Sa,this,ou).call(this,o.serverMetadata(),s);try{await _r(a,e.token,i)}catch(e){const t=new Wa("An error occurred while trying to revoke the token.",Pa(e)),n=s.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async getUserInfo(e,t){const n=(await r(Sa,this,ru).call(this,t,!0)).configuration;try{var o;return await wr(n,e.accessToken,null!==(o=e.expectedSubject)&&void 0!==o?o:Fi)}catch(e){throw new Na("There was an error while trying to retrieve the user info.",Pa(e))}}async getTokenByPassword(e,t){var n;const o=(await r(Sa,this,ru).call(this,t)).configuration,i=new URLSearchParams({username:e.username,password:e.password});e.audience&&i.append("audience",e.audience),e.scope&&i.append("scope",e.scope),e.realm&&i.append("realm",e.realm);let s=o;if(e.auth0ForwardedFor){const t=await r(Sa,this,hu).call(this);s=new or(o.serverMetadata(),c(ya,this).clientId,{client_secret:c(ya,this).clientSecret,use_mtls_endpoint_aliases:c(ya,this).useMtls},t);const n=o[Vi];s[Vi]=(t,o)=>n(t,f(f({},o),{},{headers:f(f({},o.headers),{},{"auth0-forwarded-for":e.auth0ForwardedFor})}))}if(e.fullResponse){var a;const e=rc(null!==(a=s[Vi])&&void 0!==a?a:c(wa,this)),t=await r(Sa,this,ou).call(this,s.serverMetadata(),e);try{const n=await br(t,"password",i),o=nc.fromTokenEndpointResponse(n),r=e.getCapturedResponse();if(!r)throw new Za;return{data:o,response:r}}catch(t){if(t instanceof Za)throw t;const n=new Ia("There was an error while trying to request a token.",Pa(t)),o=e.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}}const u=rc(null!==(n=s[Vi])&&void 0!==n?n:c(wa,this)),l=await r(Sa,this,ou).call(this,s.serverMetadata(),u);try{const e=await br(l,"password",i);return nc.fromTokenEndpointResponse(e)}catch(e){const t=new Ia("There was an error while trying to request a token.",Pa(e)),n=u.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async getTokenByPasswordlessEmail(e,t){const n=new URLSearchParams({username:e.email,otp:e.code,realm:"email"});return e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),r(Sa,this,du).call(this,n,t,e.fullResponse)}async getTokenByPasswordlessSms(e,t){if(!Tc(e.phoneNumber))throw new _c("Phone number must be in E.164 format (e.g. +14155550100).");const n=new URLSearchParams({username:e.phoneNumber,otp:e.code,realm:"sms"});return e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),r(Sa,this,du).call(this,n,t,e.fullResponse)}async getTokenByClientCredentials(e,t){var n;const o=(await r(Sa,this,ru).call(this,t)).configuration;if(e.fullResponse){var i;const t=rc(null!==(i=o[Vi])&&void 0!==i?i:c(wa,this)),n=await r(Sa,this,ou).call(this,o.serverMetadata(),t),s=new URLSearchParams({audience:e.audience});e.organization&&s.append("organization",e.organization);try{const e=await hr(n,s),o=nc.fromTokenEndpointResponse(e),i=t.getCapturedResponse();if(!i)throw new Za;return{data:o,response:i}}catch(e){if(e instanceof Za)throw e;const n=new Aa("There was an error while trying to request a token.",Pa(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}}const s=rc(null!==(n=o[Vi])&&void 0!==n?n:c(wa,this)),a=await r(Sa,this,ou).call(this,o.serverMetadata(),s);try{const t=new URLSearchParams({audience:e.audience});e.organization&&t.append("organization",e.organization);const n=await hr(a,t);return nc.fromTokenEndpointResponse(n)}catch(e){const t=new Aa("There was an error while trying to request a token.",Pa(e)),n=s.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async buildLogoutUrl(e){const t=await r(Sa,this,su).call(this),n=t.configuration;if(!t.serverMetadata.end_session_endpoint){const t=new URL("https://".concat(c(ya,this).domain,"/v2/logout"));return t.searchParams.set("returnTo",e.returnTo),t.searchParams.set("client_id",c(ya,this).clientId),e.federated&&t.searchParams.set("federated",""),t}const o={post_logout_redirect_uri:e.returnTo};return e.federated&&(o.federated=""),function(e,t){mr(e);const n=Ji(e),o=n.as,i=n.c,r=kn(o,"end_session_endpoint",!1,n.tlsOnly);(t=new URLSearchParams(t)).has("client_id")||t.set("client_id",i.client_id);for(const e of t.entries()){var s=y(e,2);const t=s[0],n=s[1];r.searchParams.append(t,n)}return r}(n,o)}async verifyLogoutToken(e){const t=(await r(Sa,this,su).call(this)).serverMetadata,n=Fc(c(ya,this).discoveryCache),o=t.jwks_uri;c(va,this)||l(va,this,ks(new URL(o),{cacheMaxAge:n.ttlMs,[gs]:c(wa,this),[vs]:c(ka,this)}));const i=(await Yr(e.logoutToken,c(va,this),{issuer:t.issuer,audience:c(ya,this).clientId,algorithms:["RS256"],requiredClaims:["iat"]})).payload;if(!("sid"in i)&&!("sub"in i))throw new Ka('either "sid" or "sub" (or both) claims must be present');if("sid"in i&&"string"!=typeof i.sid)throw new Ka('"sid" claim must be a string');if("sub"in i&&"string"!=typeof i.sub)throw new Ka('"sub" claim must be a string');if("nonce"in i)throw new Ka('"nonce" claim is prohibited');if(!("events"in i))throw new Ka('"events" claim is missing');if("object"!=typeof i.events||null===i.events)throw new Ka('"events" claim must be an object');if(!("http://schemas.openid.net/event/backchannel-logout"in i.events))throw new Ka('"http://schemas.openid.net/event/backchannel-logout" member is missing in the "events" claim');if("object"!=typeof i.events["http://schemas.openid.net/event/backchannel-logout"])throw new Ka('"http://schemas.openid.net/event/backchannel-logout" member in the "events" claim must be an object');return{sid:i.sid,sub:i.sub}}});function nu(){const e=c(ya,this).domain.toLowerCase();return"".concat(e,"|mtls:").concat(c(ya,this).useMtls?"1":"0")}async function ou(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];const o=await r(Sa,this,hu).call(this,n),i=new or(e,c(ya,this).clientId,{client_secret:c(ya,this).clientSecret,use_mtls_endpoint_aliases:c(ya,this).useMtls},o);return i[Vi]=null!=t?t:c(wa,this),i}function iu(e){return sc(c(wa,this),e,c(ga,this))}async function ru(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];const n=await r(Sa,this,su).call(this,t),o=n.configuration,i=n.serverMetadata;if(!e)return{configuration:o,serverMetadata:i};const s=r(Sa,this,iu).call(this,e);return{configuration:await r(Sa,this,ou).call(this,i,s,t),serverMetadata:i}}async function su(){let e=arguments.length>0&&void 0!==arguments[0]&&arguments[0];const t=c(e?pa:ha,this);if(t&&c(fa,this))return{configuration:t,serverMetadata:c(fa,this)};const n=r(Sa,this,nu).call(this);e||await r(Sa,this,hu).call(this,!1);const o=c(ba,this).get(n);if(o)return r(Sa,this,au).call(this,o.serverMetadata,e);const i=c(_a,this).get(n);if(i){const t=await i;return r(Sa,this,au).call(this,t.serverMetadata,e)}const s=(async()=>{const e=(await tr(new URL("https://".concat(c(ya,this).domain)),c(ya,this).clientId,{use_mtls_endpoint_aliases:c(ya,this).useMtls},(e,t,n,o)=>{n.set("client_id",t.client_id)},{[Vi]:c(wa,this)})).serverMetadata();return c(ba,this).set(n,{serverMetadata:e}),{serverMetadata:e}})();s.catch(()=>{}),c(_a,this).set(n,s);try{const t=(await s).serverMetadata;return r(Sa,this,au).call(this,t,e)}finally{c(_a,this).delete(n)}}async function au(e,t){const n=await r(Sa,this,ou).call(this,e,void 0,t);return l(fa,this,e),l(t?pa:ha,this,n),{configuration:n,serverMetadata:e}}async function cu(e,t,n){var o,i,s;const a=(await r(Sa,this,ru).call(this,t)).configuration;if("audience"in e||"resource"in e)throw new ja("audience and resource parameters are not supported for Token Vault exchanges");Yc(e.subjectToken);const u=new URLSearchParams({connection:e.connection,subject_token:e.subjectToken,subject_token_type:null!==(o=e.subjectTokenType)&&void 0!==o?o:$c,requested_token_type:null!==(i=e.requestedTokenType)&&void 0!==i?i:"http://auth0.com/oauth/token-type/federated-connection-access-token"});if(e.loginHint&&u.append("login_hint",e.loginHint),e.scope&&u.append("scope",e.scope),qc(u,e.extra),n){var l;const t=rc(null!==(l=a[Vi])&&void 0!==l?l:c(wa,this)),n=await r(Sa,this,ou).call(this,a.serverMetadata(),t);try{const e=await br(n,Bc,u),o=nc.fromTokenEndpointResponse(e),i=t.getCapturedResponse();if(!i)throw new Za;return{data:o,response:i}}catch(n){if(n instanceof Za)throw n;const o=new ja("Failed to exchange token for connection '".concat(e.connection,"'."),Pa(n)),i=t.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Ha(i.headers):void 0,o}}const d=rc(null!==(s=a[Vi])&&void 0!==s?s:c(wa,this)),h=await r(Sa,this,ou).call(this,a.serverMetadata(),d);try{const e=await br(h,Bc,u);return nc.fromTokenEndpointResponse(e)}catch(t){const n=new ja("Failed to exchange token for connection '".concat(e.connection,"'."),Pa(t)),o=d.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}}function uu(e,t,n){var o;if(n.organization&&Ga(e.claims,n.organization),n.actorToken)if(null!==(o=e.claims)&&void 0!==o&&o.act)e.act=e.claims.act;else try{e.act=function(e){if("string"!=typeof e)throw new Go("JWTs must use Compact JWS serialization, JWT must be a string");const t=e.split("."),n=t[1],o=t.length;if(5===o)throw new Go("Only JWTs using Compact JWS serialization can be decoded");if(3!==o)throw new Go("Invalid JWT");if(!n)throw new Go("JWTs must contain a payload");let i,r;try{i=ii(n)}catch(e){throw new Go("Failed to base64url decode the payload")}try{r=JSON.parse(Ko.decode(i))}catch(e){throw new Go("Failed to parse the decoded payload as JSON")}if(!si(r))throw new Go("Invalid JWT Claims Set");return r}(t.access_token).act}catch(e){}return e}async function lu(e,t,n){var o;const i=(await r(Sa,this,ru).call(this,t)).configuration;if(Yc(e.subjectToken),void 0!==e.organization&&Xa(e.organization),void 0!==e.actorToken&&void 0===e.actorTokenType)throw new ja("actorTokenType is required when actorToken is provided");const s=new URLSearchParams({subject_token_type:e.subjectTokenType,subject_token:e.subjectToken});if(e.audience&&s.append("audience",e.audience),e.scope&&s.append("scope",e.scope),e.requestedTokenType&&s.append("requested_token_type",e.requestedTokenType),e.organization&&s.append("organization",e.organization),e.actorToken&&s.append("actor_token",e.actorToken),e.actorTokenType&&s.append("actor_token_type",e.actorTokenType),qc(s,e.extra),n){var a;const t=rc(null!==(a=i[Vi])&&void 0!==a?a:c(wa,this)),n=await r(Sa,this,ou).call(this,i.serverMetadata(),t);let o,u,l;try{if(u=await br(n,Qc,s),o=nc.fromTokenEndpointResponse(u),l=t.getCapturedResponse(),!l)throw new Za}catch(n){if(n instanceof Za)throw n;const o=new ja("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),Pa(n)),i=t.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Ha(i.headers):void 0,o}return r(Sa,this,uu).call(this,o,u,e),{data:o,response:l}}const u=rc(null!==(o=i[Vi])&&void 0!==o?o:c(wa,this)),l=await r(Sa,this,ou).call(this,i.serverMetadata(),u);let d,h;try{h=await br(l,Qc,s),d=nc.fromTokenEndpointResponse(h)}catch(t){const n=new ja("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),Pa(t)),o=u.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}return r(Sa,this,uu).call(this,d,h,e),d}async function du(e,t,n){var o;const i=(await r(Sa,this,ru).call(this,t)).configuration;if(n){var s;const t=rc(null!==(s=i[Vi])&&void 0!==s?s:c(wa,this)),n=await r(Sa,this,ou).call(this,i.serverMetadata(),t);try{const o=await br(n,"http://auth0.com/oauth/grant-type/passwordless/otp",e),i=nc.fromTokenEndpointResponse(o),r=t.getCapturedResponse();if(!r)throw new Za;return{data:i,response:r}}catch(e){if(e instanceof Za)throw e;const n=new _c("There was an error while trying to request a token.",Pa(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Ha(o.headers):void 0,n}}const a=rc(null!==(o=i[Vi])&&void 0!==o?o:c(wa,this)),u=await r(Sa,this,ou).call(this,i.serverMetadata(),a);try{const t=await br(u,"http://auth0.com/oauth/grant-type/passwordless/otp",e);return nc.fromTokenEndpointResponse(t)}catch(e){const t=new _c("There was an error while trying to request a token.",Pa(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Ha(n.headers):void 0,t}}async function hu(){let e=arguments.length>0&&void 0!==arguments[0]&&arguments[0];const t=!!c(ya,this).clientSecret||!!c(ya,this).clientAssertionSigningKey||!!c(ya,this).useMtls;return e&&!t?(e,t,n,o)=>{n.set("client_id",t.client_id)}:(c(ma,this)||l(ma,this,(async()=>{if(!c(ya,this).clientSecret&&!c(ya,this).clientAssertionSigningKey&&!c(ya,this).useMtls)throw new Ja;if(c(ya,this).useMtls)return(e,t,n,o)=>{n.set("client_id",t.client_id)};let e=c(ya,this).clientAssertionSigningKey;return!e||e instanceof CryptoKey||(e=await Ss(e,c(ya,this).clientAssertionSigningAlg||"RS256")),e?function(e,t){return gn(e,t)}(e):Hi(c(ya,this).clientSecret)})().catch(e=>{throw l(ma,this,void 0),e})),c(ma,this))}async function pu(e){const t=(await r(Sa,this,su).call(this)).configuration,n=Bi(),o=await qi(n),i=Va(f(f({},c(ya,this).authorizationParams),null==e?void 0:e.authorizationParams)),s=new URLSearchParams(f(f({scope:Xc},i),{},{client_id:c(ya,this).clientId,code_challenge:o,code_challenge_method:"S256"}));return{authorizationUrl:null!=e&&e.pushedAuthorizationRequests?await fr(t,s):await pr(t,s),codeVerifier:n}}var fu=new Zc(1e3,6e4);class mu extends E{constructor(e,t){super(e,t),Object.setPrototypeOf(this,mu.prototype)}static fromPayload(e){let t=e.error,n=e.error_description;return new mu(t,n)}}class yu extends mu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,yu.prototype)}}class wu extends mu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,wu.prototype)}}class gu extends mu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,gu.prototype)}}class vu extends mu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,vu.prototype)}}class bu extends mu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,bu.prototype)}}class _u{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:6e5;this.contexts=new Map,this.ttlMs=e}set(e,t){this.cleanup(),this.contexts.set(e,Object.assign(Object.assign({},t),{createdAt:Date.now()}))}get(e){const t=this.contexts.get(e);if(t){if(!(Date.now()-t.createdAt>this.ttlMs))return t;this.contexts.delete(e)}}remove(e){this.contexts.delete(e)}cleanup(){const e=Date.now();for(const n of this.contexts){var t=y(n,2);const o=t[0];e-t[1].createdAt>this.ttlMs&&this.contexts.delete(o)}}get size(){return this.contexts.size}}class ku{constructor(e,t){this.authJsMfaClient=e,this.auth0Client=t,this.contextManager=new _u}setMFAAuthDetails(e,t,n,o){this.contextManager.set(e,{scope:t,audience:n,mfaRequirements:o})}async getAuthenticators(e){var t,n,o;const i=this.contextManager.get(e);if(!i)throw new yu("invalid_request","MFA context not found for this MFA token");const r=null===(n=null===(t=i.mfaRequirements)||void 0===t?void 0:t.challenge)||void 0===n?void 0:n.map(e=>e.type);try{const t=await this.authJsMfaClient.listAuthenticators({mfaToken:e});return r&&0!==r.length?t.filter(e=>!!e.type&&r.includes(e.type)):t}catch(e){if(e instanceof qa)throw new yu(null===(o=e.cause)||void 0===o?void 0:o.error,e.message);throw e}}async enroll(e){var t;const n=function(e){const t=Rt[e.factorType];return Object.assign(Object.assign(Object.assign({mfaToken:e.mfaToken,authenticatorTypes:t.authenticatorTypes},t.oobChannels&&{oobChannels:t.oobChannels}),"phoneNumber"in e&&{phoneNumber:e.phoneNumber}),"email"in e&&{email:e.email})}(e);try{return await this.authJsMfaClient.enrollAuthenticator(n)}catch(e){if(e instanceof Ba)throw new wu(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async challenge(e){var t;try{const t={challengeType:e.challengeType,mfaToken:e.mfaToken};return e.authenticatorId&&(t.authenticatorId=e.authenticatorId),await this.authJsMfaClient.challengeAuthenticator(t)}catch(e){if(e instanceof $a)throw new gu(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async getEnrollmentFactors(e){const t=this.contextManager.get(e);if(!t||!t.mfaRequirements)throw new bu("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");return t.mfaRequirements.enroll&&0!==t.mfaRequirements.enroll.length?t.mfaRequirements.enroll:[]}async verify(e){const t=this.contextManager.get(e.mfaToken);if(!t)throw new vu("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");const n=function(e){return"otp"in e&&e.otp?At:"oobCode"in e&&e.oobCode?xt:"recoveryCode"in e&&e.recoveryCode?It:void 0}(e);if(!n)throw new vu("invalid_request","Unable to determine grant type. Provide one of: otp, oobCode, or recoveryCode.");const o=t.scope,i=t.audience;try{const t=await this.auth0Client._requestTokenForMfa({grant_type:n,mfaToken:e.mfaToken,scope:o,audience:i,otp:e.otp,oob_code:e.oobCode,binding_code:e.bindingCode,recovery_code:e.recoveryCode});return this.contextManager.remove(e.mfaToken),t}catch(e){if(e instanceof vu)throw new vu(e.error,e.error_description);throw e}}}class Su extends Error{constructor(e,t,n){super(t),this.name="PasskeyError",this.code=e,this.cause=n,Object.setPrototypeOf(this,Su.prototype)}}var Tu,Pu;class Eu{constructor(e,t){Tu.set(this,void 0),Pu.set(this,void 0),n(this,Tu,e,"f"),n(this,Pu,t,"f")}async signup(n){if(!window.PublicKeyCredential)throw new Su("passkey_not_supported","WebAuthn is not supported in this browser.");const o=n.scope,i=n.audience,r=e(n,["scope","audience"]),s=await t(this,Tu,"f").register(r),a=Au(s.authnParamsPublicKey),c=await navigator.credentials.create({publicKey:a});if(!c)throw new Su("passkey_cancelled","Passkey creation was cancelled or no credential was returned.");const u=Iu(c);return t(this,Pu,"f")._requestTokenForPasskey({authSession:s.authSession,credential:u,realm:r.realm,organization:r.organization,scope:o,audience:i})}async login(n){if(!window.PublicKeyCredential)throw new Su("passkey_not_supported","WebAuthn is not supported in this browser.");const o=n||{},i=o.scope,r=o.audience,s=e(o,["scope","audience"]),a=await t(this,Tu,"f").challenge(Object.keys(s).length>0?s:void 0),c=xu(a.authnParamsPublicKey),u=await navigator.credentials.get({publicKey:c});if(!u)throw new Su("passkey_cancelled","Passkey authentication was cancelled or no credential was returned.");const l=Ou(u);return t(this,Pu,"f")._requestTokenForPasskey({authSession:a.authSession,credential:l,realm:s.realm,organization:s.organization,scope:i,audience:r})}async getSignupChallenge(e){if(!window.PublicKeyCredential)throw new Su("passkey_not_supported","WebAuthn is not supported in this browser.");const n=await t(this,Tu,"f").register(e);return{authSession:n.authSession,publicKey:Au(n.authnParamsPublicKey)}}async getLoginChallenge(e){if(!window.PublicKeyCredential)throw new Su("passkey_not_supported","WebAuthn is not supported in this browser.");const n=await t(this,Tu,"f").challenge(e);return{authSession:n.authSession,publicKey:xu(n.authnParamsPublicKey)}}async getTokenWithPasskey(e){if(!window.PublicKeyCredential)throw new Su("passkey_not_supported","WebAuthn is not supported in this browser.");const n=e.authSession,o=e.credential,i=e.realm,r=e.organization,s=e.scope,a=e.audience,c=o.response;let u;if(c instanceof AuthenticatorAttestationResponse)u=Iu(o);else{if(!(c instanceof AuthenticatorAssertionResponse))throw new Su("passkey_invalid_credential","The provided credential is not a valid attestation or assertion response.");u=Ou(o)}return t(this,Pu,"f")._requestTokenForPasskey({authSession:n,credential:u,realm:i,organization:r,scope:s,audience:a})}}function Cu(e){const t=new Uint8Array(e),n=Array.from(t,e=>String.fromCharCode(e)).join("");return btoa(n).replace(/\+/g,"-").replace(/\//g,"_").replace(/=+$/,"")}function Ru(e){const t=e.replace(/-/g,"+").replace(/_/g,"/"),n=t+"=".repeat((4-t.length%4)%4),o=atob(n),i=new Uint8Array(o.length);for(let e=0;e<o.length;e++)i[e]=o.charCodeAt(e);return i.buffer}function Au(e){return Object.assign(Object.assign({},e),{challenge:Ru(e.challenge),user:Object.assign(Object.assign({},e.user),{id:Ru(e.user.id)}),pubKeyCredParams:e.pubKeyCredParams,authenticatorSelection:e.authenticatorSelection})}function xu(e){return Object.assign(Object.assign({},e),{challenge:Ru(e.challenge)})}function Iu(e){var t;const n=e.response;return{id:e.id,rawId:Cu(e.rawId),type:e.type,authenticatorAttachment:null!==(t=e.authenticatorAttachment)&&void 0!==t?t:void 0,response:{clientDataJSON:Cu(n.clientDataJSON),attestationObject:Cu(n.attestationObject)},clientExtensionResults:e.getClientExtensionResults()}}function Ou(e){var t;const n=e.response;return{id:e.id,rawId:Cu(e.rawId),type:e.type,authenticatorAttachment:null!==(t=e.authenticatorAttachment)&&void 0!==t?t:void 0,response:{clientDataJSON:Cu(n.clientDataJSON),authenticatorData:Cu(n.authenticatorData),signature:Cu(n.signature),userHandle:n.userHandle?Cu(n.userHandle):void 0},clientExtensionResults:e.getClientExtensionResults()}}Tu=new WeakMap,Pu=new WeakMap;class ju{resolveOnlineAccess(e){if("online"!==e.refreshTokenMode)return!1;if(!0!==e.useRefreshTokens)throw new C('`refreshTokenMode: "online"` requires the refresh-token grant.',"Set `useRefreshTokens: true`.");if(!0!==e.useDpop)throw new C('`refreshTokenMode: "online"` requires DPoP, which is missing or disabled.',"Set `useDpop: true` (DPoP is mandatory for online access).");return!0}warnEnterpriseConnectConfig(e){var t,n;if(!0!==e.enterpriseConnect)return;const o=null===(t=e.authorizationParams)||void 0===t?void 0:t.scope;(!0===e.useRefreshTokens||"string"==typeof o&&o.includes("offline_access"))&&console.warn("Enterprise Connect issues no refresh token; `useRefreshTokens` and `offline_access` in `scope` have no effect."),(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)&&console.warn("Enterprise Connect resolves the organization from the email domain (Home Realm Discovery); a static `organization` breaks multi-customer setups.")}constructor(e){let t,n;if(this.userCache=(new De).enclosedCache,this.defaultOptions={authorizationParams:{scope:"openid profile email"},useRefreshTokensFallback:!1,useFormData:!0,refreshTokenMode:"offline"},this.onlineAccess=this.resolveOnlineAccess(e),this.warnEnterpriseConnectConfig(e),this.options=Object.assign(Object.assign(Object.assign({},this.defaultOptions),e),{authorizationParams:Object.assign(Object.assign({},this.defaultOptions.authorizationParams),e.authorizationParams)}),"undefined"!=typeof window&&(()=>{if(!L())throw new Error("For security reasons, `window.crypto` is required to run `auth0-spa-js`.");if(void 0===L().subtle)throw new Error("\n auth0-spa-js must run on a secure origin. See https://github.com/auth0/auth0-spa-js/blob/main/FAQ.md#why-do-i-get-auth0-spa-js-must-run-on-a-secure-origin for more information.\n ")})(),this.lockManager=(de||(de=le()),de),e.cache&&e.cacheLocation&&console.warn("Both `cache` and `cacheLocation` options have been specified in the Auth0Client configuration; ignoring `cacheLocation` and using `cache`."),e.cache)n=e.cache;else{if(t=e.cacheLocation||_,!gt(t))throw new Error('Invalid cache location "'.concat(t,'"'));n=gt(t)()}var o;this.httpTimeoutMs=e.httpTimeoutInSeconds?1e3*e.httpTimeoutInSeconds:b,this.cookieStorage=!1===e.legacySameSiteCookie?nt:it,this.orgHintCookieName=(o=this.options.clientId,"auth0.".concat(o,".organization_hint")),this.isAuthenticatedCookieName=(e=>"auth0.".concat(e,".is.authenticated"))(this.options.clientId),this.sessionCheckExpiryDays=e.sessionCheckExpiryDays||1;const i=e.useCookiesForTransactions?this.cookieStorage:rt;let r="";var s;this.onlineAccess?r=k:this.options.useRefreshTokens&&(r="offline_access"),this.scope=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];if("object"!=typeof e)return{[P]:Ke(t,e,...o)};let r={[P]:Ke(t,...o)};return Object.keys(e).forEach(n=>{const i=e[n];r[n]=Ke(t,i,...o)}),r}(this.options.authorizationParams.scope,"openid",r),this.transactionManager=new He(i,this.options.clientId,this.options.cookieDomain),this.nowProvider=this.options.nowProvider||T,this.cacheManager=new Ze(n,n.allKeys?void 0:new mt(n,this.options.clientId),this.nowProvider),this.dpop=this.options.useDpop?new St(this.options.clientId):void 0,this.domainUrl=(s=this.options.domain,/^https?:\/\//.test(s)?s:"https://".concat(s)),this.tokenIssuer=((e,t)=>e?e.startsWith("https://")?e:"https://".concat(e,"/"):"".concat(t,"/"))(this.options.issuer,this.domainUrl);const a="".concat(this.domainUrl,"/me/"),c=this.createFetcher(Object.assign(Object.assign({},this.options.useDpop&&{dpopNonceId:"__auth0_my_account_api__"}),{getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:a},detailedResponse:!0})}}));this.myAccount=new Et(c,a),this.authJsClient=new tu({domain:this.options.domain,clientId:this.options.clientId}),this.mfa=new ku(this.authJsClient.mfa,this),this.passkey=new Eu(this.authJsClient.passkey,this),"undefined"!=typeof window&&window.Worker&&this.options.useRefreshTokens&&t===_&&(this.options.workerUrl?this.worker=new Worker(this.options.workerUrl):this.worker=new ft,this.worker.postMessage({type:"init",allowedBaseUrl:this.domainUrl}))}getConfiguration(){return Object.freeze({domain:this.options.domain,clientId:this.options.clientId})}_url(e){const t=this.options.auth0Client||S,n=Z(t,!0),o=encodeURIComponent(btoa(JSON.stringify(n)));return"".concat(this.domainUrl).concat(e,"&auth0Client=").concat(o)}_authorizeUrl(e){return this._url("/authorize?".concat(H(e)))}async _verifyIdToken(e,t,n){const o=await this.nowProvider();return Xe({iss:this.tokenIssuer,aud:this.options.clientId,id_token:e,nonce:t,organization:n,leeway:this.options.leeway,max_age:(i=this.options.authorizationParams.max_age,"string"!=typeof i?i:parseInt(i,10)||void 0),now:o});var i}_processOrgHint(e){e?this.cookieStorage.save(this.orgHintCookieName,e,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}):this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain})}_extractSessionTransferToken(e){return new URLSearchParams(window.location.search).get(e)||void 0}_clearSessionTransferTokenFromUrl(e){try{const t=new URL(window.location.href);t.searchParams.has(e)&&(t.searchParams.delete(e),window.history.replaceState({},"",t.toString()))}catch(e){}}_applySessionTransferToken(e){const t=this.options.sessionTransferTokenQueryParamName;if(!t||e.session_transfer_token)return e;const n=this._extractSessionTransferToken(t);return n?(this._clearSessionTransferTokenFromUrl(t),Object.assign(Object.assign({},e),{session_transfer_token:n})):e}async _prepareAuthorizeUrl(e,t,n){var o;const i=J(z()),r=J(z()),s=z(),a=await F(s),c=X(a),u=await(null===(o=this.dpop)||void 0===o?void 0:o.calculateThumbprint()),l=((e,t,n,o,i,r,s,a,c)=>Object.assign(Object.assign(Object.assign({client_id:e.clientId},e.authorizationParams),n),{scope:Me(t,n.scope,n.audience),response_type:"code",response_mode:a||"query",state:o,nonce:i,redirect_uri:s||e.authorizationParams.redirect_uri,code_challenge:r,code_challenge_method:"S256",dpop_jkt:c}))(this.options,this.scope,e,i,r,c,e.redirect_uri||this.options.authorizationParams.redirect_uri||n,null==t?void 0:t.response_mode,u),d=this._authorizeUrl(l);return{nonce:r,code_verifier:s,scope:l.scope,audience:l.audience||P,redirect_uri:l.redirect_uri,state:i,url:d}}async loginWithPopup(e,t){var n;if(e=e||{},!(t=t||{}).popup&&(t.popup=(e=>{const t=window.screenX+(window.innerWidth-400)/2,n=window.screenY+(window.innerHeight-600)/2;return window.open(e,"auth0:authorize:popup","left=".concat(t,",top=").concat(n,",width=").concat(400,",height=").concat(600,",resizable,scrollbars=yes,status=1"))})(""),!t.popup))throw new j;const o=this._applySessionTransferToken(e.authorizationParams||{}),i=await this._prepareAuthorizeUrl(o,{response_mode:"web_message"},window.location.origin);t.popup.location.href=i.url;const r=await((e,t)=>new Promise((n,o)=>{let i;const r=setInterval(()=>{e.popup&&e.popup.closed&&(clearInterval(r),clearTimeout(s),window.removeEventListener("message",i,!1),o(new O(e.popup)))},1e3),s=setTimeout(()=>{clearInterval(r),o(new I(e.popup)),window.removeEventListener("message",i,!1)},1e3*(e.timeoutInSeconds||60));i=function(a){if(a.origin===t&&a.data&&"authorization_response"===a.data.type){if(clearTimeout(s),clearInterval(r),window.removeEventListener("message",i,!1),!1!==e.closePopup&&e.popup.close(),a.data.response.error)return o(E.fromPayload(a.data.response));n(a.data.response)}},window.addEventListener("message",i)}))(Object.assign(Object.assign({},t),{timeoutInSeconds:t.timeoutInSeconds||this.options.authorizeTimeoutInSeconds||60}),new URL(i.url).origin);if(i.state!==r.state)throw new E("state_mismatch","Invalid state");const s=(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization;await this._requestToken({audience:i.audience,scope:i.scope,code_verifier:i.code_verifier,grant_type:"authorization_code",code:r.code,redirect_uri:i.redirect_uri},{nonceIn:i.nonce,organization:s})}async getUser(){var e;if(await this._isSessionCeilingReached())return;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.user}async getIdTokenClaims(){var e;if(await this._isSessionCeilingReached())return;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.claims}async loginWithRedirect(){var t;const n=vt(arguments.length>0&&void 0!==arguments[0]?arguments[0]:{}),o=n.openUrl,i=n.fragment,r=n.appState,s=e(n,["openUrl","fragment","appState"]),a=(null===(t=s.authorizationParams)||void 0===t?void 0:t.organization)||this.options.authorizationParams.organization,c=this._applySessionTransferToken(s.authorizationParams||{}),u=await this._prepareAuthorizeUrl(c),l=u.url,d=e(u,["url"]);this.transactionManager.create(Object.assign(Object.assign(Object.assign({},d),{appState:r,response_type:at.Code}),a&&{organization:a}));const h=i?"".concat(l,"#").concat(i):l;o?await o(h):window.location.assign(h)}async handleRedirectCallback(){const e=(arguments.length>0&&void 0!==arguments[0]?arguments[0]:window.location.href).split("?").slice(1);if(0===e.length)throw new Error("There are no query params available for parsing.");const t=this.transactionManager.get();if(!t)throw new E("missing_transaction","Invalid state");this.transactionManager.remove();const n=(e=>{e.indexOf("#")>-1&&(e=e.substring(0,e.indexOf("#")));const t=new URLSearchParams(e);return{state:t.get("state"),code:t.get("code")||void 0,connect_code:t.get("connect_code")||void 0,error:t.get("error")||void 0,error_description:t.get("error_description")||void 0}})(e.join(""));return t.response_type===at.ConnectCode?this._handleConnectAccountRedirectCallback(n,t):this._handleLoginRedirectCallback(n,t)}async _handleLoginRedirectCallback(e,t){const n=e.code,o=e.state,i=e.error,r=e.error_description;if(i)throw new R(i,r||i,o,t.appState);if(!t.code_verifier||t.state&&t.state!==o)throw new E("state_mismatch","Invalid state");const s=t.organization,a=t.nonce,c=t.redirect_uri;return await this._requestToken(Object.assign({audience:t.audience,scope:t.scope,code_verifier:t.code_verifier,grant_type:"authorization_code",code:n},c?{redirect_uri:c}:{}),{nonceIn:a,organization:s}),{appState:t.appState,response_type:at.Code}}async _handleConnectAccountRedirectCallback(e,t){const n=e.connect_code,o=e.state,i=e.error,r=e.error_description;if(i)throw new A(i,r||i,t.connection,o,t.appState);if(!n)throw new E("missing_connect_code","Missing connect code");if(!(t.code_verifier&&t.state&&t.auth_session&&t.redirect_uri&&t.state===o))throw new E("state_mismatch","Invalid state");const s=await this.myAccount.completeAccount({auth_session:t.auth_session,connect_code:n,redirect_uri:t.redirect_uri,code_verifier:t.code_verifier});return Object.assign(Object.assign({},s),{appState:t.appState,response_type:at.ConnectCode})}async checkSession(e){if(!this.cookieStorage.get(this.isAuthenticatedCookieName)){if(!this.cookieStorage.get(yt))return;this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(yt)}try{await this.getTokenSilently(e)}catch(e){}}async getTokenSilently(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var t,n;const o=Object.assign(Object.assign({cacheMode:"on"},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:Me(this.scope,null===(t=e.authorizationParams)||void 0===t?void 0:t.scope,(null===(n=e.authorizationParams)||void 0===n?void 0:n.audience)||this.options.authorizationParams.audience)})}),i=await this._getTokenSilently(o);return e.detailedResponse?i:null==i?void 0:i.access_token}async _getTokenSilently(t){const n=t.cacheMode,o=e(t,["cacheMode"]);if(await this._isSessionCeilingReached())return;if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||P,clientId:this.options.clientId,cacheMode:n});if(e)return e}if("cache-only"===n)return;const i=(r=this.options.clientId,s=o.authorizationParams.audience||"default","".concat("auth0.lock.getTokenSilently",".").concat(r,".").concat(s));var r,s;try{return await this.lockManager.runWithLock(i,5e3,async()=>{if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||P,clientId:this.options.clientId});if(e)return e}const e=this.options.useRefreshTokens?await this._getTokenUsingRefreshToken(o):await this._getTokenFromIFrame(o),t=e.id_token,i=e.token_type,r=e.access_token,s=e.oauthTokenScope,a=e.expires_in;return Object.assign(Object.assign({id_token:t,token_type:i,access_token:r},s?{scope:s}:null),{expires_in:a})})}catch(e){if(this._isInteractiveError(e)&&"popup"===this.options.interactiveErrorHandler)return await this._handleInteractiveErrorWithPopup(o);throw e}}_isInteractiveError(e){return e instanceof W||e instanceof E&&this._isIframeMfaError(e)}_isIframeMfaError(e){return"login_required"===e.error&&"Multifactor authentication required"===e.error_description}async _handleInteractiveErrorWithPopup(e){try{await this.loginWithPopup({authorizationParams:e.authorizationParams});const t=await this._getEntryFromCache({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||P,clientId:this.options.clientId});if(!t)throw new E("interactive_handler_cache_miss","Token not found in cache after interactive authentication");return t}catch(e){throw e}}async getTokenWithPopup(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{};var n,o;const i=Object.assign(Object.assign({},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:Me(this.scope,null===(n=e.authorizationParams)||void 0===n?void 0:n.scope,(null===(o=e.authorizationParams)||void 0===o?void 0:o.audience)||this.options.authorizationParams.audience)})});t=Object.assign(Object.assign({},v),t),await this.loginWithPopup(i,t);return(await this.cacheManager.get(new ze({scope:i.authorizationParams.scope,audience:i.authorizationParams.audience||P,clientId:this.options.clientId}),void 0,this.options.useMrrt)).access_token}async isAuthenticated(){return!!await this.getUser()}_buildLogoutUrl(t){null!==t.clientId?t.clientId=t.clientId||this.options.clientId:delete t.clientId;const n=t.logoutParams||{},o=n.federated,i=e(n,["federated"]),r=o?"&federated":"";return this._url("/v2/logout?".concat(H(Object.assign({clientId:t.clientId},i))))+r}async revokeRefreshToken(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!this.options.useRefreshTokens)return;const t=e.audience||this.options.authorizationParams.audience||P,n=await this.cacheManager.getRefreshTokensByAudience(t,this.options.clientId);await async function(e,t){let n=e.baseUrl,o=e.timeout,i=e.auth0Client,r=e.useFormData,s=e.refreshTokens,a=e.audience,c=e.client_id,u=e.onRefreshTokenRevoked;const l=o||b,d="refresh_token",h="".concat(n,"/oauth/revoke"),p={"Content-Type":r?"application/x-www-form-urlencoded":"application/json","Auth0-Client":btoa(JSON.stringify(Z(i||S)))};if(t){const e={client_id:c,token_type_hint:d},n=r?H(e):JSON.stringify(e);try{return await Ie({type:"revoke",timeout:l,fetchUrl:h,fetchOptions:{method:"POST",body:n,headers:p},useFormData:r,auth:{audience:null!=a?a:P}},t)}catch(e){throw new E("revoke_error",e.message)}}for(const e of s){const t={client_id:c,token_type_hint:d,token:e},n=r?H(t):JSON.stringify(t),o=await Oe(h,{method:"POST",body:n,headers:p},l);if(!o.ok){let e,t;try{var f=JSON.parse(await o.text());e=f.error,t=f.error_description}catch(e){}throw new E(e||"revoke_error",t||"HTTP error ".concat(o.status))}await(null==u?void 0:u(e))}}({baseUrl:this.domainUrl,timeout:this.httpTimeoutMs,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,client_id:this.options.clientId,refreshTokens:n,audience:t,onRefreshTokenRevoked:e=>this.cacheManager.stripRefreshToken(e)},this.worker),this.onlineAccess&&await this._clearLocalSession()}async logout(){let t=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var n;this.options.enterpriseConnect&&!0!==(null===(n=t.logoutParams)||void 0===n?void 0:n.federated)&&console.warn("Enterprise Connect logout without `federated: true` leaves the enterprise IdP session alive; the next login may silently reuse the previous user.");const o=vt(t),i=o.openUrl,r=e(o,["openUrl"]);await this._clearLocalSession(t.clientId);const s=this._buildLogoutUrl(r);i?await i(s):!1!==i&&window.location.assign(s)}async _getTokenFromIFrame(e){const t=(n=this.options.clientId,"".concat("auth0.lock.getTokenFromIFrame",".").concat(n));var n;try{return await this.lockManager.runWithLock(t,5e3,async()=>{const t=Object.assign(Object.assign({},e.authorizationParams),{prompt:"none"}),n=this.cookieStorage.get(this.orgHintCookieName);n&&!t.organization&&(t.organization=n);const o=await this._prepareAuthorizeUrl(t,{response_mode:"web_message"},window.location.origin),i=o.url,r=o.state,s=o.nonce,a=o.code_verifier,c=o.redirect_uri,u=o.scope,l=o.audience;if(window.crossOriginIsolated)throw new E("login_required","The application is running in a Cross-Origin Isolated context, silently retrieving a token without refresh token is not possible.");const d=e.timeoutInSeconds||this.options.authorizeTimeoutInSeconds;let h;try{h=new URL(this.domainUrl).origin}catch(e){h=this.domainUrl}const p=await function(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:60;return new Promise((o,i)=>{const r=window.document.createElement("iframe");r.setAttribute("width","0"),r.setAttribute("height","0"),r.style.display="none";const s=()=>{window.document.body.contains(r)&&(window.document.body.removeChild(r),window.removeEventListener("message",a,!1))};let a;const c=setTimeout(()=>{i(new x),s()},1e3*n);a=function(e){if(e.origin!=t)return;if(!e.data||"authorization_response"!==e.data.type)return;const n=e.source;n&&n.close(),e.data.response.error?i(E.fromPayload(e.data.response)):o(e.data.response),clearTimeout(c),window.removeEventListener("message",a,!1),setTimeout(s,2e3)},window.addEventListener("message",a,!1),window.document.body.appendChild(r),r.setAttribute("src",e)})}(i,h,d);if(r!==p.state)throw new E("state_mismatch","Invalid state");const f=await this._requestToken(Object.assign(Object.assign({},e.authorizationParams),{code_verifier:a,code:p.code,grant_type:"authorization_code",redirect_uri:c,timeout:e.authorizationParams.timeout||this.httpTimeoutMs}),{nonceIn:s,organization:t.organization});return Object.assign(Object.assign({},f),{scope:u,oauthTokenScope:f.scope,audience:l})})}catch(e){if("login_required"===e.error){e instanceof E&&this._isIframeMfaError(e)&&"popup"===this.options.interactiveErrorHandler||this.logout({openUrl:!1})}throw e}}async _getTokenUsingRefreshToken(e){const t=await this.cacheManager.get(new ze({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||P,clientId:this.options.clientId}),void 0,this.options.useMrrt);if(!(t&&t.refresh_token||this.worker)){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw new N(e.authorizationParams.audience||P,e.authorizationParams.scope)}const n=e.authorizationParams.redirect_uri||this.options.authorizationParams.redirect_uri||window.location.origin,o="number"==typeof e.timeoutInSeconds?1e3*e.timeoutInSeconds:null,i=((e,t,n,o)=>{var i;if(e&&n&&o){if(t.audience!==n)return t.scope;const e=o.split(" "),r=(null===(i=t.scope)||void 0===i?void 0:i.split(" "))||[],s=r.every(t=>e.includes(t));return e.length>=r.length&&s?o:t.scope}return t.scope})(this.options.useMrrt,e.authorizationParams,null==t?void 0:t.audience,null==t?void 0:t.scope);try{const u=await this._requestToken(Object.assign(Object.assign(Object.assign({},e.authorizationParams),{grant_type:"refresh_token",refresh_token:t&&t.refresh_token,redirect_uri:n}),o&&{timeout:o}),{scopesToRequest:i});if(await this._propagateRotatedRefreshToken(null==t?void 0:t.refresh_token,u.refresh_token),this.options.useMrrt){if(r=null==t?void 0:t.audience,s=null==t?void 0:t.scope,a=e.authorizationParams.audience,c=e.authorizationParams.scope,r!==a||!((e,t)=>{const n=(null==t?void 0:t.split(" "))||[];return((null==e?void 0:e.split(" "))||[]).every(e=>n.includes(e))})(c,s)){const t=bt(i,u.scope,this.onlineAccess);if(t){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw await this.cacheManager.remove(this.options.clientId,e.authorizationParams.audience,e.authorizationParams.scope),new K(e.authorizationParams.audience||"default",t)}}}return Object.assign(Object.assign({},u),{scope:e.authorizationParams.scope,oauthTokenScope:u.scope,audience:e.authorizationParams.audience||P})}catch(t){if(t.message){if(t.message.includes("user is blocked"))throw await this.logout({openUrl:!1}),t;if((t.message.includes("Missing Refresh Token")||t.message.includes("invalid refresh token"))&&this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e)}throw t}var r,s,a,c}async _propagateRotatedRefreshToken(e,t){!this.onlineAccess&&t&&e&&await this.cacheManager.updateEntry(e,t,this.options.clientId,this.options.useMrrt)}async _saveEntryInCache(t){const n=t.decodedToken.claims,o=n.session_expiry,i=n.iat;if(void 0!==o){if("number"!=typeof o)throw new E("invalid_token","Invalid session_expiry: value must be a number.");if(o>=1e10)throw new E("invalid_token","Invalid session_expiry: value appears to be in milliseconds; expected a Unix timestamp in seconds.");if(void 0===i||o<=i)throw new E("invalid_token","Invalid session_expiry: session ceiling is before or at the token issue time.")}const r=t.id_token,s=t.decodedToken,a=e(t,["id_token","decodedToken"]);this.userCache.set(Le,{id_token:r,decodedToken:s}),await this.cacheManager.setIdToken(this.options.clientId,t.id_token,t.decodedToken),await this.cacheManager.set(a)}async _clearLocalSession(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:this.options.clientId;var t;null===e?await this.cacheManager.clear():await this.cacheManager.clear(e),this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(this.isAuthenticatedCookieName,{cookieDomain:this.options.cookieDomain}),this.userCache.remove(Le);try{await(null===(t=this.dpop)||void 0===t?void 0:t.clear())}catch(e){}if(this.worker)try{await Ie({type:"clear"},this.worker)}catch(e){}}async _isSessionCeilingReached(){var e,t;const n=this.userCache.get(Le),o=null!=n?n:await this.cacheManager.getIdToken(new ze({clientId:this.options.clientId})),i=null===(t=null===(e=null==o?void 0:o.decodedToken)||void 0===e?void 0:e.claims)||void 0===t?void 0:t.session_expiry;if(void 0===i)return!1;const r=await this.nowProvider();return Math.floor(r/1e3)>=i-30&&(await this._clearLocalSession(),!0)}async _getIdTokenFromCache(){const e=this.options.authorizationParams.audience||P,t=this.scope[e],n=await this.cacheManager.getIdToken(new ze({clientId:this.options.clientId,audience:e,scope:t})),o=this.userCache.get(Le);return n&&n.id_token===(null==o?void 0:o.id_token)?o:(this.userCache.set(Le,n),n)}async _getEntryFromCache(e){let t=e.scope,n=e.audience,o=e.clientId,i=e.cacheMode;const r=await this.cacheManager.get(new ze({scope:t,audience:n,clientId:o}),60,this.options.useMrrt,i);if(r&&r.access_token){const e=r.token_type,t=r.access_token,n=r.oauthTokenScope,o=r.expires_in,i=await this._getIdTokenFromCache();return i&&Object.assign(Object.assign({id_token:i.id_token,token_type:e||"Bearer",access_token:t},n?{scope:n}:null),{expires_in:o})}}_storeMfaContext(e,t,n){e instanceof W&&this.mfa.setMFAAuthDetails(e.mfa_token,t,n,e.mfa_requirements)}async _requestToken(e,t){var n,o,i,r,s,a;const c=t||{},u=c.nonceIn,l=c.organization,d=c.scopesToRequest;try{const t=await Ne(Object.assign(Object.assign({baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,useMrrt:this.options.useMrrt,dpop:this.dpop,preserveRefreshToken:this.onlineAccess},e),{scope:d||e.scope}),this.worker);let c=await this._verifyIdToken(t.id_token,u,l);if("authorization_code"===e.grant_type){const e=await this._getIdTokenFromCache();(null===(o=null===(n=null==e?void 0:e.decodedToken)||void 0===n?void 0:n.claims)||void 0===o?void 0:o.sub)&&e.decodedToken.claims.sub!==c.claims.sub&&(await this.cacheManager.clear(this.options.clientId),this.userCache.remove(Le))}if("authorization_code"!==e.grant_type){const e=await this._getIdTokenFromCache(),t=null===(r=null===(i=null==e?void 0:e.decodedToken)||void 0===i?void 0:i.claims)||void 0===r?void 0:r.session_expiry;void 0!==t&&(c=Object.assign(Object.assign({},c),{claims:Object.assign(Object.assign({},c.claims),{session_expiry:t})}))}return!t.refresh_token&&this.onlineAccess&&(t.refresh_token=null!==(s=e.refresh_token)&&void 0!==s?s:null===(a=await this.cacheManager.get(new ze({scope:d||e.scope,audience:e.audience||P,clientId:this.options.clientId}),void 0,this.options.useMrrt))||void 0===a?void 0:a.refresh_token),await this._saveEntryInCache(Object.assign(Object.assign(Object.assign(Object.assign({},t),{decodedToken:c,scope:e.scope,audience:e.audience||P}),t.scope?{oauthTokenScope:t.scope}:null),{client_id:this.options.clientId})),this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this._processOrgHint(l||c.claims.org_id),Object.assign(Object.assign({},t),{decodedToken:c})}catch(t){throw"authorization_code"!==e.grant_type&&this._storeMfaContext(t,d||e.scope,e.audience),t}}_buildTokenExchangeParams(e){return Object.assign(Object.assign(Object.assign(Object.assign(Object.assign({},e),{grant_type:"urn:ietf:params:oauth:grant-type:token-exchange",subject_token:e.subject_token,subject_token_type:e.subject_token_type}),e.actor_token&&{actor_token:e.actor_token}),e.actor_token_type&&{actor_token_type:e.actor_token_type}),{scope:Me(this.scope,e.scope,e.audience||this.options.authorizationParams.audience),audience:e.audience||this.options.authorizationParams.audience,organization:e.organization||this.options.authorizationParams.organization})}async loginWithCustomTokenExchange(e){return this._requestToken(this._buildTokenExchangeParams(e))}async customTokenExchange(e){const t=this._buildTokenExchangeParams(e);try{const n=await Ne(Object.assign(Object.assign({},t),{baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,dpop:this.dpop}),this.worker,!0);return n.id_token&&await this._verifyIdToken(n.id_token,void 0,e.organization),n}catch(e){throw this._storeMfaContext(e,t.scope,t.audience),e}}async exchangeToken(e){return this.loginWithCustomTokenExchange(e)}_assertDpop(e){if(!e)throw new Error("`useDpop` option must be enabled before using DPoP.")}getDpopNonce(e){return this._assertDpop(this.dpop),this.dpop.getNonce(e)}setDpopNonce(e,t){return this._assertDpop(this.dpop),this.dpop.setNonce(e,t)}generateDpopProof(e){return this._assertDpop(this.dpop),this.dpop.generateProof(e)}createFetcher(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};return new Pt(e,{isDpopEnabled:()=>!!this.options.useDpop,getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:null==e?void 0:e.audience},detailedResponse:!0})},getDpopNonce:()=>this.getDpopNonce(e.dpopNonceId),setDpopNonce:t=>this.setDpopNonce(t,e.dpopNonceId),generateDpopProof:e=>this.generateDpopProof(e)})}async connectAccountWithRedirect(e){const t=e.openUrl,n=e.appState,o=e.connection,i=e.scopes,r=e.authorization_params,s=e.redirectUri,a=void 0===s?this.options.authorizationParams.redirect_uri||window.location.origin:s;if(!o)throw new Error("connection is required");const c=J(z()),u=z(),l=await F(u),d=X(l),h=await this.myAccount.connectAccount({connection:o,scopes:i,redirect_uri:a,state:c,code_challenge:d,code_challenge_method:"S256",authorization_params:r}),p=h.connect_uri,f=h.connect_params,m=h.auth_session;this.transactionManager.create({state:c,code_verifier:u,auth_session:m,redirect_uri:a,appState:n,connection:o,response_type:at.ConnectCode});const y=new URL(p);y.searchParams.set("ticket",f.ticket),t?await t(y.toString()):window.location.assign(y)}async _requestTokenForPasskey(e){const t=e.audience||this.options.authorizationParams.audience,n=e.organization||this.options.authorizationParams.organization;return this._requestToken(Object.assign(Object.assign(Object.assign({grant_type:"urn:okta:params:oauth:grant-type:webauthn",auth_session:e.authSession,authn_response:e.credential},e.realm&&{realm:e.realm}),n&&{organization:n}),{scope:Me(this.scope,e.scope,t),audience:t}))}async _requestTokenForMfa(t,n){const o=t.mfaToken,i=e(t,["mfaToken"]),r=await this.cacheManager.get(new ze({scope:i.scope,audience:i.audience||P,clientId:this.options.clientId}),void 0,this.options.useMrrt),s=await this._requestToken(Object.assign(Object.assign({},i),{mfa_token:o}),n);return await this._propagateRotatedRefreshToken(null==r?void 0:r.refresh_token,s.refresh_token),s}}function Wu(e,t,n){var o;return async function(e,t,n){const o=t.toLowerCase(),i=e.replace(/^https?:\/\//,""),r="".concat(i,"|").concat(o),s=fu.get(r);if(void 0!==s)return s;try{var a;const e=new URL("https://".concat(i,"/.well-known/webfinger"));e.searchParams.set("resource","urn:auth0:discovery:domain:".concat(o)),e.searchParams.set("rel","http://openid.net/specs/connect/1.0/issuer");let t=null!==(a=null==n?void 0:n.customFetch)&&void 0!==a?a:globalThis.fetch;null!=n&&n.telemetry&&!1!==n.telemetry.enabled&&(t=oc(t,n.telemetry));const s=await t(e.toString());return s.ok?(fu.set(r,!0),!0):404===s.status?(fu.set(r,!1,15e3),!1):429===s.status&&(console.warn("[Auth0] isFederatedDomain: rate limit hit (429)"),!1)}catch(e){return!1}}(e.replace(/^https?:\/\//i,"").toLowerCase(),t.toLowerCase(),Object.assign(Object.assign({},n),{telemetry:null!==(o=null==n?void 0:n.telemetry)&&void 0!==o?o:S}))}async function Nu(e){const t=new ju(e);return await t.checkSession(),t}export{ju as Auth0Client,R as AuthenticationError,ze as CacheKey,A as ConnectError,E as GenericError,De as InMemoryCache,C as InvalidConfigurationError,Je as LocalStorageCache,ku as MfaApiClient,gu as MfaChallengeError,wu as MfaEnrollmentError,bu as MfaEnrollmentFactorsError,mu as MfaError,yu as MfaListAuthenticatorsError,W as MfaRequiredError,vu as MfaVerifyError,N as MissingRefreshTokenError,K as MissingScopesError,Et as MyAccountApiClient,Ct as MyAccountApiError,Eu as PasskeyApiClient,hc as PasskeyChallengeError,Su as PasskeyError,pc as PasskeyGetTokenError,dc as PasskeyRegisterError,O as PopupCancelledError,j as PopupOpenError,I as PopupTimeoutError,st as RefreshTokenMode,at as ResponseType,x as TimeoutError,M as UseDpopNonceError,ct as User,Nu as createAuth0Client,Wu as isFederatedDomain};
//# sourceMappingURL=auth0-spa-js.production.esm.js.map