@auth0/auth0-spa-js
Version:
Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE
3 lines • 226 kB
JavaScript
!function(e,t){"object"==typeof exports&&"undefined"!=typeof module?t(exports):"function"==typeof define&&define.amd?define(["exports"],t):t((e="undefined"!=typeof globalThis?globalThis:e||self).auth0={})}(this,function(e){"use strict";function t(e,t){var n={};for(var o in e)Object.prototype.hasOwnProperty.call(e,o)&&t.indexOf(o)<0&&(n[o]=e[o]);if(null!=e&&"function"==typeof Object.getOwnPropertySymbols){var i=0;for(o=Object.getOwnPropertySymbols(e);i<o.length;i++)t.indexOf(o[i])<0&&Object.prototype.propertyIsEnumerable.call(e,o[i])&&(n[o[i]]=e[o[i]])}return n}function n(e,t,n,o){if("a"===n&&!o)throw new TypeError("Private accessor was defined without a getter");if("function"==typeof t?e!==t||!o:!t.has(e))throw new TypeError("Cannot read private member from an object whose class did not declare it");return"m"===n?o:"a"===n?o.call(e):o?o.value:t.get(e)}function o(e,t,n,o,i){if("m"===o)throw new TypeError("Private method is not writable");if("a"===o&&!i)throw new TypeError("Private accessor was defined without a setter");if("function"==typeof t?e!==t||!i:!t.has(e))throw new TypeError("Cannot write private member to an object whose class did not declare it");return"a"===o?i.call(e,n):i?i.value=n:t.set(e,n),n}function i(e,t){this.v=e,this.k=t}function r(e,t){(null==t||t>e.length)&&(t=e.length);for(var n=0,o=Array(t);n<t;n++)o[n]=e[n];return o}function s(e,t,n){if("function"==typeof e?e===t:e.has(t))return arguments.length<3?t:n;throw new TypeError("Private element is not present on this object")}function a(e){return new i(e,0)}function c(e,t){if(t.has(e))throw new TypeError("Cannot initialize the same private elements twice on an object")}function u(e,t){return e.get(s(e,t))}function l(e,t,n){c(e,t),t.set(e,n)}function d(e,t,n){return e.set(s(e,t),n),n}function h(e,t){c(e,t),t.add(e)}function p(e,t,n){return(t=function(e){var t=function(e,t){if("object"!=typeof e||!e)return e;var n=e[Symbol.toPrimitive];if(void 0!==n){var o=n.call(e,t||"default");if("object"!=typeof o)return o;throw new TypeError("@@toPrimitive must return a primitive value.")}return("string"===t?String:Number)(e)}(e,"string");return"symbol"==typeof t?t:t+""}(t))in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function f(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);t&&(o=o.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,o)}return n}function m(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?f(Object(n),!0).forEach(function(t){p(e,t,n[t])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):f(Object(n)).forEach(function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))})}return e}function y(e,t){if(null==e)return{};var n,o,i=function(e,t){if(null==e)return{};var n={};for(var o in e)if({}.hasOwnProperty.call(e,o)){if(-1!==t.indexOf(o))continue;n[o]=e[o]}return n}(e,t);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);for(o=0;o<r.length;o++)n=r[o],-1===t.indexOf(n)&&{}.propertyIsEnumerable.call(e,n)&&(i[n]=e[n])}return i}function w(e,t){return function(e){if(Array.isArray(e))return e}(e)||function(e,t){var n=null==e?null:"undefined"!=typeof Symbol&&e[Symbol.iterator]||e["@@iterator"];if(null!=n){var o,i,r,s,a=[],c=!0,u=!1;try{if(r=(n=n.call(e)).next,0===t){if(Object(n)!==n)return;c=!1}else for(;!(c=(o=r.call(n)).done)&&(a.push(o.value),a.length!==t);c=!0);}catch(e){u=!0,i=e}finally{try{if(!c&&null!=n.return&&(s=n.return(),Object(s)!==s))return}finally{if(u)throw i}}return a}}(e,t)||function(e,t){if(e){if("string"==typeof e)return r(e,t);var n={}.toString.call(e).slice(8,-1);return"Object"===n&&e.constructor&&(n=e.constructor.name),"Map"===n||"Set"===n?Array.from(e):"Arguments"===n||/^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(n)?r(e,t):void 0}}(e,t)||function(){throw new TypeError("Invalid attempt to destructure non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method.")}()}function g(e){return function(){return new v(e.apply(this,arguments))}}function v(e){var t,n;function o(t,n){try{var s=e[t](n),a=s.value,c=a instanceof i;Promise.resolve(c?a.v:a).then(function(n){if(c){var i="return"===t&&a.k?t:"next";if(!a.k||n.done)return o(i,n);n=e[i](n).value}r(!!s.done,n)},function(e){o("throw",e)})}catch(e){r(2,e)}}function r(e,i){2===e?t.reject(i):t.resolve({value:i,done:e}),(t=t.next)?o(t.key,t.arg):n=null}this._invoke=function(e,i){return new Promise(function(r,s){var a={key:e,arg:i,resolve:r,reject:s,next:null};n?n=n.next=a:(t=n=a,o(e,i))})},"function"!=typeof e.return&&(this.return=void 0)}"function"==typeof SuppressedError&&SuppressedError,v.prototype["function"==typeof Symbol&&Symbol.asyncIterator||"@@asyncIterator"]=function(){return this},v.prototype.next=function(e){return this._invoke("next",e)},v.prototype.throw=function(e){return this._invoke("throw",e)},v.prototype.return=function(e){return this._invoke("return",e)};const b={timeoutInSeconds:60},_=1e4,k="memory",S="online_access",T={name:"auth0-spa-js",version:"2.26.0"},P=()=>Date.now(),E="default";class C extends Error{constructor(e,t){super(t),this.error=e,this.error_description=t,Object.setPrototypeOf(this,C.prototype)}static fromPayload(e){let t=e.error,n=e.error_description;return new C(t,n)}}class R extends C{constructor(e,t){super("invalid_configuration","".concat(e," ").concat(t)),this.suggestion=t,Object.setPrototypeOf(this,R.prototype)}}class A extends C{constructor(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:null;super(e,t),this.state=n,this.appState=o,Object.setPrototypeOf(this,A.prototype)}}class x extends C{constructor(e,t,n,o){let i=arguments.length>4&&void 0!==arguments[4]?arguments[4]:null;super(e,t),this.connection=n,this.state=o,this.appState=i,Object.setPrototypeOf(this,x.prototype)}}class I extends C{constructor(){super("timeout","Timeout"),Object.setPrototypeOf(this,I.prototype)}}class O extends I{constructor(e){super(),this.popup=e,Object.setPrototypeOf(this,O.prototype)}}class j extends C{constructor(e){super("cancelled","Popup closed"),this.popup=e,Object.setPrototypeOf(this,j.prototype)}}class W extends C{constructor(){super("popup_open","Unable to open a popup for loginWithPopup - window.open returned `null`"),Object.setPrototypeOf(this,W.prototype)}}class M extends C{constructor(e,t,n,o){super(e,t),this.mfa_token=n,this.mfa_requirements=o,Object.setPrototypeOf(this,M.prototype)}}class N extends C{constructor(e,t){super("missing_refresh_token","Missing Refresh Token (audience: '".concat(L(e,["default"]),"', scope: '").concat(L(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,N.prototype)}}class K extends C{constructor(e,t){super("missing_scopes","Missing requested scopes after refresh (audience: '".concat(L(e,["default"]),"', missing scope: '").concat(L(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,K.prototype)}}class U extends C{constructor(e){super("use_dpop_nonce","Server rejected DPoP proof: wrong nonce"),this.newDpopNonce=e,Object.setPrototypeOf(this,U.prototype)}}function L(e){return e&&!(arguments.length>1&&void 0!==arguments[1]?arguments[1]:[]).includes(e)?e:""}const z=()=>window.crypto,J=()=>{const e="0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-_~.";let t="";for(;t.length<43;){const n=z().getRandomValues(new Uint8Array(43-t.length));for(const o of n)t.length<43&&o<198&&(t+=e[o%66])}return t},D=e=>btoa(e),Z=[{key:"name",type:["string"]},{key:"version",type:["string","number"]},{key:"env",type:["object"]}],H=function(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return Object.keys(e).reduce((n,o)=>{if(t&&"env"===o)return n;const i=Z.find(e=>e.key===o);return i&&i.type.includes(typeof e[o])&&(n[o]=e[o]),n},{})},F=e=>{var n=e.clientId,o=t(e,["clientId"]);return new URLSearchParams((e=>Object.keys(e).filter(t=>void 0!==e[t]).reduce((t,n)=>Object.assign(Object.assign({},t),{[n]:e[n]}),{}))(Object.assign({client_id:n},o))).toString()},V=async e=>{const t=z().subtle.digest({name:"SHA-256"},(new TextEncoder).encode(e));return await t},G=e=>(e=>decodeURIComponent(atob(e).split("").map(e=>"%"+("00"+e.charCodeAt(0).toString(16)).slice(-2)).join("")))(e.replace(/_/g,"/").replace(/-/g,"+")),X=e=>{const t=new Uint8Array(e);return(e=>{const t={"+":"-","/":"_","=":""};return e.replace(/[+/=]/g,e=>t[e])})(window.btoa(String.fromCharCode(...Array.from(t))))};var q="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{},Y={},B={};Object.defineProperty(B,"__esModule",{value:!0});var Q=function(){function e(){var e=this;this.locked=new Map,this.addToLocked=function(t,n){var o=e.locked.get(t);void 0===o?void 0===n?e.locked.set(t,[]):e.locked.set(t,[n]):void 0!==n&&(o.unshift(n),e.locked.set(t,o))},this.isLocked=function(t){return e.locked.has(t)},this.lock=function(t){return new Promise(function(n,o){e.isLocked(t)?e.addToLocked(t,n):(e.addToLocked(t),n())})},this.unlock=function(t){var n=e.locked.get(t);if(void 0!==n&&0!==n.length){var o=n.pop();e.locked.set(t,n),void 0!==o&&setTimeout(o,0)}else e.locked.delete(t)}}return e.getInstance=function(){return void 0===e.instance&&(e.instance=new e),e.instance},e}();B.default=function(){return Q.getInstance()};var $=q&&q.__awaiter||function(e,t,n,o){return new(n||(n=Promise))(function(i,r){function s(e){try{c(o.next(e))}catch(e){r(e)}}function a(e){try{c(o.throw(e))}catch(e){r(e)}}function c(e){e.done?i(e.value):new n(function(t){t(e.value)}).then(s,a)}c((o=o.apply(e,t||[])).next())})},ee=q&&q.__generator||function(e,t){var n,o,i,r,s={label:0,sent:function(){if(1&i[0])throw i[1];return i[1]},trys:[],ops:[]};return r={next:a(0),throw:a(1),return:a(2)},"function"==typeof Symbol&&(r[Symbol.iterator]=function(){return this}),r;function a(r){return function(a){return function(r){if(n)throw new TypeError("Generator is already executing.");for(;s;)try{if(n=1,o&&(i=2&r[0]?o.return:r[0]?o.throw||((i=o.return)&&i.call(o),0):o.next)&&!(i=i.call(o,r[1])).done)return i;switch(o=0,i&&(r=[2&r[0],i.value]),r[0]){case 0:case 1:i=r;break;case 4:return s.label++,{value:r[1],done:!1};case 5:s.label++,o=r[1],r=[0];continue;case 7:r=s.ops.pop(),s.trys.pop();continue;default:if(!(i=s.trys,(i=i.length>0&&i[i.length-1])||6!==r[0]&&2!==r[0])){s=0;continue}if(3===r[0]&&(!i||r[1]>i[0]&&r[1]<i[3])){s.label=r[1];break}if(6===r[0]&&s.label<i[1]){s.label=i[1],i=r;break}if(i&&s.label<i[2]){s.label=i[2],s.ops.push(r);break}i[2]&&s.ops.pop(),s.trys.pop();continue}r=t.call(e,s)}catch(e){r=[6,e],o=0}finally{n=i=0}if(5&r[0])throw r[1];return{value:r[0]?r[1]:void 0,done:!0}}([r,a])}}},te=q;Object.defineProperty(Y,"__esModule",{value:!0});var ne=B,oe="browser-tabs-lock-key",ie={key:function(e){return $(te,void 0,void 0,function(){return ee(this,function(e){throw new Error("Unsupported")})})},getItem:function(e){return $(te,void 0,void 0,function(){return ee(this,function(e){throw new Error("Unsupported")})})},clear:function(){return $(te,void 0,void 0,function(){return ee(this,function(e){return[2,window.localStorage.clear()]})})},removeItem:function(e){return $(te,void 0,void 0,function(){return ee(this,function(e){throw new Error("Unsupported")})})},setItem:function(e,t){return $(te,void 0,void 0,function(){return ee(this,function(e){throw new Error("Unsupported")})})},keySync:function(e){return window.localStorage.key(e)},getItemSync:function(e){return window.localStorage.getItem(e)},clearSync:function(){return window.localStorage.clear()},removeItemSync:function(e){return window.localStorage.removeItem(e)},setItemSync:function(e,t){return window.localStorage.setItem(e,t)}};function re(e){return new Promise(function(t){return setTimeout(t,e)})}function se(e){for(var t="0123456789ABCDEFGHIJKLMNOPQRSTUVWXTZabcdefghiklmnopqrstuvwxyz",n="",o=0;o<e;o++){n+=t[Math.floor(61*Math.random())]}return n}var ae=function(){function e(t){this.acquiredIatSet=new Set,this.storageHandler=void 0,this.id=Date.now().toString()+se(15),this.acquireLock=this.acquireLock.bind(this),this.releaseLock=this.releaseLock.bind(this),this.releaseLock__private__=this.releaseLock__private__.bind(this),this.waitForSomethingToChange=this.waitForSomethingToChange.bind(this),this.refreshLockWhileAcquired=this.refreshLockWhileAcquired.bind(this),this.storageHandler=t,void 0===e.waiters&&(e.waiters=[])}return e.prototype.acquireLock=function(t,n){return void 0===n&&(n=5e3),$(this,void 0,void 0,function(){var o,i,r,s,a,c,u;return ee(this,function(l){switch(l.label){case 0:o=Date.now()+se(4),i=Date.now()+n,r=oe+"-"+t,s=void 0===this.storageHandler?ie:this.storageHandler,l.label=1;case 1:return Date.now()<i?[4,re(30)]:[3,8];case 2:return l.sent(),null!==s.getItemSync(r)?[3,5]:(a=this.id+"-"+t+"-"+o,[4,re(Math.floor(25*Math.random()))]);case 3:return l.sent(),s.setItemSync(r,JSON.stringify({id:this.id,iat:o,timeoutKey:a,timeAcquired:Date.now(),timeRefreshed:Date.now()})),[4,re(30)];case 4:return l.sent(),null!==(c=s.getItemSync(r))&&(u=JSON.parse(c)).id===this.id&&u.iat===o?(this.acquiredIatSet.add(o),this.refreshLockWhileAcquired(r,o),[2,!0]):[3,7];case 5:return e.lockCorrector(void 0===this.storageHandler?ie:this.storageHandler),[4,this.waitForSomethingToChange(i)];case 6:l.sent(),l.label=7;case 7:return o=Date.now()+se(4),[3,1];case 8:return[2,!1]}})})},e.prototype.refreshLockWhileAcquired=function(e,t){return $(this,void 0,void 0,function(){var n=this;return ee(this,function(o){return setTimeout(function(){return $(n,void 0,void 0,function(){var n,o,i;return ee(this,function(r){switch(r.label){case 0:return[4,ne.default().lock(t)];case 1:return r.sent(),this.acquiredIatSet.has(t)?(n=void 0===this.storageHandler?ie:this.storageHandler,null===(o=n.getItemSync(e))?(ne.default().unlock(t),[2]):((i=JSON.parse(o)).timeRefreshed=Date.now(),n.setItemSync(e,JSON.stringify(i)),ne.default().unlock(t),this.refreshLockWhileAcquired(e,t),[2])):(ne.default().unlock(t),[2])}})})},1e3),[2]})})},e.prototype.waitForSomethingToChange=function(t){return $(this,void 0,void 0,function(){return ee(this,function(n){switch(n.label){case 0:return[4,new Promise(function(n){var o=!1,i=Date.now(),r=!1;function s(){if(r||(window.removeEventListener("storage",s),e.removeFromWaiting(s),clearTimeout(a),r=!0),!o){o=!0;var t=50-(Date.now()-i);t>0?setTimeout(n,t):n(null)}}window.addEventListener("storage",s),e.addToWaiting(s);var a=setTimeout(s,Math.max(0,t-Date.now()))})];case 1:return n.sent(),[2]}})})},e.addToWaiting=function(t){this.removeFromWaiting(t),void 0!==e.waiters&&e.waiters.push(t)},e.removeFromWaiting=function(t){void 0!==e.waiters&&(e.waiters=e.waiters.filter(function(e){return e!==t}))},e.notifyWaiters=function(){void 0!==e.waiters&&e.waiters.slice().forEach(function(e){return e()})},e.prototype.releaseLock=function(e){return $(this,void 0,void 0,function(){return ee(this,function(t){switch(t.label){case 0:return[4,this.releaseLock__private__(e)];case 1:return[2,t.sent()]}})})},e.prototype.releaseLock__private__=function(t){return $(this,void 0,void 0,function(){var n,o,i,r;return ee(this,function(s){switch(s.label){case 0:return n=void 0===this.storageHandler?ie:this.storageHandler,o=oe+"-"+t,null===(i=n.getItemSync(o))?[2]:(r=JSON.parse(i)).id!==this.id?[3,2]:[4,ne.default().lock(r.iat)];case 1:s.sent(),this.acquiredIatSet.delete(r.iat),n.removeItemSync(o),ne.default().unlock(r.iat),e.notifyWaiters(),s.label=2;case 2:return[2]}})})},e.lockCorrector=function(t){for(var n=Date.now()-5e3,o=t,i=[],r=0;;){var s=o.keySync(r);if(null===s)break;i.push(s),r++}for(var a=!1,c=0;c<i.length;c++){var u=i[c];if(u.includes(oe)){var l=o.getItemSync(u);if(null!==l){var d=JSON.parse(l);(void 0===d.timeRefreshed&&d.timeAcquired<n||void 0!==d.timeRefreshed&&d.timeRefreshed<n)&&(o.removeItemSync(u),a=!0)}}}a&&e.notifyWaiters()},e.waiters=void 0,e}(),ce=Y.default=ae;class ue{async runWithLock(e,t,n){const o=new AbortController,i=setTimeout(()=>o.abort(),t);try{return await navigator.locks.request(e,{mode:"exclusive",signal:o.signal},async e=>{if(clearTimeout(i),!e)throw new Error("Lock not available");return await n()})}catch(e){if(clearTimeout(i),"AbortError"===(null==e?void 0:e.name))throw new I;throw e}}}class le{constructor(){this.activeLocks=new Set,this.lock=new ce,this.pagehideHandler=()=>{this.activeLocks.forEach(e=>this.lock.releaseLock(e)),this.activeLocks.clear()}}async runWithLock(e,t,n){let o=!1;for(let n=0;n<10&&!o;n++)o=await this.lock.acquireLock(e,t);if(!o)throw new I;this.activeLocks.add(e),1===this.activeLocks.size&&"undefined"!=typeof window&&window.addEventListener("pagehide",this.pagehideHandler);try{return await n()}finally{this.activeLocks.delete(e),await this.lock.releaseLock(e),0===this.activeLocks.size&&"undefined"!=typeof window&&window.removeEventListener("pagehide",this.pagehideHandler)}}}function de(){return"undefined"!=typeof navigator&&"function"==typeof(null===(e=navigator.locks)||void 0===e?void 0:e.request)?new ue:new le;var e}let he=null;const pe=new TextEncoder,fe=new TextDecoder;function me(e){return"string"==typeof e?pe.encode(e):fe.decode(e)}function ye(e){if("number"!=typeof e.modulusLength||e.modulusLength<2048)throw new _e(`${e.name} modulusLength must be at least 2048 bits`)}async function we(e,t,n){if(!1===n.usages.includes("sign"))throw new TypeError('private CryptoKey instances used for signing assertions must include "sign" in their "usages"');const o=`${ve(me(JSON.stringify(e)))}.${ve(me(JSON.stringify(t)))}`;return`${o}.${ve(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:"SHA-256"};case"RSA-PSS":return ye(e.algorithm),{name:e.algorithm.name,saltLength:32};case"RSASSA-PKCS1-v1_5":return ye(e.algorithm),{name:e.algorithm.name};case"Ed25519":return{name:e.algorithm.name}}throw new be}(n),n,me(o)))}`}let ge;if(Uint8Array.prototype.toBase64)ge=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;ge=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function ve(e){return ge(e)}class be extends Error{constructor(e){var t;super(null!=e?e:"operation not supported"),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}class _e extends Error{constructor(e){var t;super(e),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}function ke(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){if("SHA-256"===e.algorithm.hash.name)return"PS256";throw new be("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"RSASSA-PKCS1-v1_5":return function(e){if("SHA-256"===e.algorithm.hash.name)return"RS256";throw new be("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"ECDSA":return function(e){if("P-256"===e.algorithm.namedCurve)return"ES256";throw new be("unsupported EcKeyAlgorithm namedCurve")}(e);case"Ed25519":return"Ed25519";default:throw new be("unsupported CryptoKey algorithm name")}}function Se(e){return e instanceof CryptoKey}function Te(e){return Se(e)&&"public"===e.type}async function Pe(e,t,n,o,i,r){const s=null==e?void 0:e.privateKey,a=null==e?void 0:e.publicKey;if(!Se(c=s)||"private"!==c.type)throw new TypeError('"keypair.privateKey" must be a private CryptoKey');var c;if(!Te(a))throw new TypeError('"keypair.publicKey" must be a public CryptoKey');if(!0!==a.extractable)throw new TypeError('"keypair.publicKey.extractable" must be true');if("string"!=typeof t)throw new TypeError('"htu" must be a string');if("string"!=typeof n)throw new TypeError('"htm" must be a string');if(void 0!==o&&"string"!=typeof o)throw new TypeError('"nonce" must be a string or undefined');if(void 0!==i&&"string"!=typeof i)throw new TypeError('"accessToken" must be a string or undefined');if(void 0!==r&&("object"!=typeof r||null===r||Array.isArray(r)))throw new TypeError('"additional" must be an object');const u=Object.assign(Object.create(null),r,{iat:Math.floor(Date.now()/1e3),jti:crypto.randomUUID(),htm:n,nonce:o,htu:t,ath:i?ve(await crypto.subtle.digest("SHA-256",me(i))):void 0});return we({alg:ke(s),typ:"dpop+jwt",jwk:await Ee(a)},u,s)}async function Ee(e){const{kty:t,e:n,n:o,x:i,y:r,crv:s}=await crypto.subtle.exportKey("jwk",e);return{kty:t,crv:s,e:n,n:o,x:i,y:r}}const Ce="dpop-nonce",Re=["authorization_code","refresh_token","urn:ietf:params:oauth:grant-type:token-exchange","urn:okta:params:oauth:grant-type:webauthn","http://auth0.com/oauth/grant-type/mfa-oob","http://auth0.com/oauth/grant-type/mfa-otp","http://auth0.com/oauth/grant-type/mfa-recovery-code"];function Ae(){return async function(e,t){var n;let o;if("string"!=typeof e||0===e.length)throw new TypeError('"alg" must be a non-empty string');switch(e){case"PS256":o={name:"RSA-PSS",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"RS256":o={name:"RSASSA-PKCS1-v1_5",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"ES256":o={name:"ECDSA",namedCurve:"P-256"};break;case"Ed25519":o={name:"Ed25519"};break;default:throw new be}return crypto.subtle.generateKey(o,null!==(n=null==t?void 0:t.extractable)&&void 0!==n&&n,["sign","verify"])}("ES256",{extractable:!1})}function xe(e){return async function(e){if(!Te(e))throw new TypeError('"publicKey" must be a public CryptoKey');if(!0!==e.extractable)throw new TypeError('"publicKey.extractable" must be true');const t=await Ee(e);let n;switch(t.kty){case"EC":n={crv:t.crv,kty:t.kty,x:t.x,y:t.y};break;case"OKP":n={crv:t.crv,kty:t.kty,x:t.x};break;case"RSA":n={e:t.e,kty:t.kty,n:t.n};break;default:throw new be("unsupported JWK kty")}return ve(await crypto.subtle.digest({name:"SHA-256"},me(JSON.stringify(n))))}(e.publicKey)}function Ie(e){let t=e.keyPair,n=e.url,o=e.method,i=e.nonce,r=e.accessToken;const s=function(e){const t=new URL(e);return t.search="",t.hash="",t.href}(n);return Pe(t,s,o,i,r)}const Oe=(e,t)=>new Promise(function(n,o){const i=new MessageChannel;i.port1.onmessage=function(e){e.data.error?o(new Error(e.data.error)):n(e.data),i.port1.close()},t.postMessage(e,[i.port2])}),je=(e,t,n)=>{const o=new AbortController;let i;return t.signal=o.signal,Promise.race([fetch(e,t),new Promise((e,t)=>{i=setTimeout(()=>{o.abort(),t(new Error("Timeout when executing 'fetch'"))},n)})]).finally(()=>{clearTimeout(i)})},We=async function(e,t,n,o,i,r){let s=arguments.length>6&&void 0!==arguments[6]?arguments[6]:_;return i?(async(e,t,n,o,i,r,s,a,c,u)=>Oe({type:"refresh",auth:{audience:t,scope:n},timeout:i,fetchUrl:e,fetchOptions:o,useFormData:s,useMrrt:a,skipTokenStorage:c,preserveRefreshToken:u},r))(e,t,n,o,s,i,r,arguments.length>7?arguments[7]:void 0,arguments.length>8?arguments[8]:void 0,arguments.length>9?arguments[9]:void 0):(async(e,t,n)=>{const o=await je(e,t,n);return{ok:o.ok,json:await o.json(),headers:(i=o.headers,[...i].reduce((e,t)=>{let n=w(t,2),o=n[0],i=n[1];return e[o]=i,e},{}))};var i})(e,o,s)};async function Me(e,n,o,i,r,s,a,c,u,l,d,h){if(u){const t=await u.generateProof({url:e,method:r.method||"GET",nonce:await u.getNonce()});r.headers=Object.assign(Object.assign({},r.headers),{dpop:t})}let p,f=null;for(let t=0;t<3;t++)try{p=await We(e,o,i,r,s,a,n,c,d,h),f=null;break}catch(e){f=e}if(f)throw f;const m=p.json,y=m.error,w=m.error_description,g=t(m,["error","error_description"]),v=p,b=v.headers,_=v.ok;let k;if(u&&(k=b[Ce],k&&await u.setNonce(k)),!_){const t=w||"HTTP error. Unable to fetch ".concat(e);if("mfa_required"===y)throw new M(y,t,g.mfa_token,g.mfa_requirements);if("missing_refresh_token"===y)throw new N(o,i);if("use_dpop_nonce"===y){if(!u||!k||l)throw new U(k);return Me(e,n,o,i,r,s,a,c,u,!0,d,h)}throw new C(y||"request_error",t)}return g}async function Ne(e,n,o){var i=e.baseUrl,r=e.timeout,s=e.audience,a=e.scope,c=e.auth0Client,u=e.useFormData,l=e.useMrrt,d=e.dpop,h=e.preserveRefreshToken,p=t(e,["baseUrl","timeout","audience","scope","auth0Client","useFormData","useMrrt","dpop","preserveRefreshToken"]);const f="urn:ietf:params:oauth:grant-type:token-exchange"===p.grant_type,m="urn:okta:params:oauth:grant-type:webauthn"===p.grant_type,y="refresh_token"===p.grant_type&&l,w=f||m||y,g=Object.assign(Object.assign(Object.assign({},p),w&&s&&{audience:s}),w&&a&&{scope:a}),v=m||!u,b=v?JSON.stringify(g):F(g),_=(k=p.grant_type,Re.includes(k));var k;return await Me("".concat(i,"/oauth/token"),r,s||E,a,{method:"POST",body:b,headers:{"Content-Type":v?"application/json":"application/x-www-form-urlencoded","Auth0-Client":btoa(JSON.stringify(H(c||T)))}},n,u,l,_?d:void 0,void 0,o,h)}const Ke=function(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];return(o=t.filter(Boolean).join(" ").trim().split(/\s+/),Array.from(new Set(o))).join(" ");var o},Ue=(e,t,n)=>{let o;return n&&(o=e[n]),o||(o=e[E]),Ke(o,t)},Le="@@auth0spajs@@",ze="@@user@@";class Je{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:Le,n=arguments.length>2?arguments[2]:void 0;this.prefix=t,this.suffix=n,this.clientId=e.clientId,this.scope=e.scope,this.audience=e.audience}toKey(){return[this.prefix,this.clientId,this.audience,this.scope,this.suffix].filter(Boolean).join("::")}static fromKey(e){const t=w(e.split("::"),4),n=t[0],o=t[1],i=t[2],r=t[3];return new Je({clientId:o,scope:r,audience:i},n)}static fromCacheEntry(e){const t=e.scope,n=e.audience,o=e.client_id;return new Je({scope:t,audience:n,clientId:o})}}class De{set(e,t){localStorage.setItem(e,JSON.stringify(t))}get(e){const t=window.localStorage.getItem(e);if(t)try{return JSON.parse(t)}catch(e){return}}remove(e){localStorage.removeItem(e)}allKeys(){return Object.keys(window.localStorage).filter(e=>e.startsWith(Le))}}class Ze{constructor(){this.enclosedCache=function(){let e={};return{set(t,n){e[t]=n},get(t){const n=e[t];if(n)return n},remove(t){delete e[t]},allKeys:()=>Object.keys(e)}}()}}class He{constructor(e,t,n){this.cache=e,this.keyManifest=t,this.nowProvider=n||P}async setIdToken(e,t,n){var o;const i=this.getIdTokenCacheKey(e);await this.cache.set(i,{id_token:t,decodedToken:n}),await(null===(o=this.keyManifest)||void 0===o?void 0:o.add(i))}async getIdToken(e){const t=await this.cache.get(this.getIdTokenCacheKey(e.clientId));if(!t&&e.scope&&e.audience){const t=await this.get(e);if(!t)return;if(!t.id_token||!t.decodedToken)return;return{id_token:t.id_token,decodedToken:t.decodedToken}}if(t)return{id_token:t.id_token,decodedToken:t.decodedToken}}async get(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:0,n=arguments.length>2&&void 0!==arguments[2]&&arguments[2],o=arguments.length>3?arguments[3]:void 0;var i;let r=await this.cache.get(e.toKey()),s=e;if(!r){const t=await this.getCacheKeys();if(!t)return;const i=this.matchExistingCacheKey(e,t);if(i&&(r=await this.cache.get(i),s=Je.fromKey(i)),!r&&n&&"cache-only"!==o)return this.getEntryWithRefreshToken(e,t)}if(!r)return;const a=await this.nowProvider(),c=Math.floor(a/1e3);return r.expiresAt-t<c?r.body.refresh_token?this.modifiedCachedEntry(r,s):(await this.cache.remove(s.toKey()),void await(null===(i=this.keyManifest)||void 0===i?void 0:i.remove(s.toKey()))):r.body}async modifiedCachedEntry(e,t){const n={refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope},o={body:n,expiresAt:e.expiresAt};return await this.cache.set(t.toKey(),o),{refresh_token:n.refresh_token,audience:n.audience,scope:n.scope}}async set(e){var t;const n=new Je({clientId:e.client_id,scope:e.scope,audience:e.audience}),o=await this.wrapCacheEntry(e);await this.cache.set(n.toKey(),o),await(null===(t=this.keyManifest)||void 0===t?void 0:t.add(n.toKey()))}async remove(e,t,n){const o=new Je({clientId:e,scope:n,audience:t});await this.cache.remove(o.toKey())}async stripRefreshToken(e){var t;const n=await this.getCacheKeys();if(n)for(const o of n){const n=await this.cache.get(o);(null===(t=null==n?void 0:n.body)||void 0===t?void 0:t.refresh_token)===e&&(delete n.body.refresh_token,await this.cache.set(o,n))}}async clear(e){var t;const n=await this.getCacheKeys();n&&(await n.filter(t=>!e||t.includes(e)).reduce(async(e,t)=>{await e,await this.cache.remove(t)},Promise.resolve()),await(null===(t=this.keyManifest)||void 0===t?void 0:t.clear()))}async wrapCacheEntry(e){const t=await this.nowProvider();return{body:e,expiresAt:Math.floor(t/1e3)+e.expires_in}}async getCacheKeys(){var e;return this.keyManifest?null===(e=await this.keyManifest.get())||void 0===e?void 0:e.keys:this.cache.allKeys?this.cache.allKeys():void 0}getIdTokenCacheKey(e){return new Je({clientId:e},Le,ze).toKey()}matchExistingCacheKey(e,t){return t.filter(t=>{var n;const o=Je.fromKey(t),i=new Set(o.scope&&o.scope.split(" ")),r=(null===(n=e.scope)||void 0===n?void 0:n.split(" "))||[],s=o.scope&&r.reduce((e,t)=>e&&i.has(t),!0);return o.prefix===Le&&o.clientId===e.clientId&&o.audience===e.audience&&s})[0]}async getEntryWithRefreshToken(e,t){var n;for(const o of t){const t=Je.fromKey(o);if(t.prefix===Le&&t.clientId===e.clientId){const e=await this.cache.get(o);if(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)return{refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope}}}}async getRefreshTokensByAudience(e,t){var n;const o=await this.getCacheKeys();if(!o)return[];const i=new Set;for(const r of o){const o=Je.fromKey(r);if(o.prefix===Le&&o.clientId===t&&o.audience===e){const e=await this.cache.get(r);(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)&&i.add(e.body.refresh_token)}}return Array.from(i)}async updateEntry(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const i=await this.getCacheKeys();if(i)for(const r of i){if(Je.fromKey(r).clientId!==n)continue;const i=await this.cache.get(r);if(!(null==i?void 0:i.body))continue;const s=i.body.refresh_token;s&&(o||s===e)&&(i.body.refresh_token=t,await this.cache.set(r,i))}}}class Fe{constructor(e,t,n){this.storage=e,this.clientId=t,this.cookieDomain=n,this.storageKey="".concat("a0.spajs.txs",".").concat(this.clientId)}create(e){this.storage.save(this.storageKey,e,{daysUntilExpire:1,cookieDomain:this.cookieDomain})}get(){return this.storage.get(this.storageKey)}remove(){this.storage.remove(this.storageKey,{cookieDomain:this.cookieDomain})}}const Ve=e=>"number"==typeof e,Ge=["iss","aud","exp","nbf","iat","jti","azp","nonce","auth_time","at_hash","c_hash","acr","amr","sub_jwk","cnf","sip_from_tag","sip_date","sip_callid","sip_cseq_num","sip_via_branch","orig","dest","mky","events","toe","txn","rph","sid","vot","vtm"],Xe=e=>{if(!e.id_token)throw new Error("ID token is required but missing");const t=(e=>{const t=e.split("."),n=w(t,3),o=n[0],i=n[1],r=n[2];if(3!==t.length||!o||!i||!r)throw new Error("ID token could not be decoded");const s=JSON.parse(G(i)),a={__raw:e},c={};return Object.keys(s).forEach(e=>{a[e]=s[e],Ge.includes(e)||(c[e]=s[e])}),{encoded:{header:o,payload:i,signature:r},header:JSON.parse(G(o)),claims:a,user:c}})(e.id_token);if(!t.claims.iss)throw new Error("Issuer (iss) claim must be a string present in the ID token");if(t.claims.iss!==e.iss)throw new Error('Issuer (iss) claim mismatch in the ID token; expected "'.concat(e.iss,'", found "').concat(t.claims.iss,'"'));if(!t.user.sub)throw new Error("Subject (sub) claim must be a string present in the ID token");if("RS256"!==t.header.alg)throw new Error('Signature algorithm of "'.concat(t.header.alg,'" is not supported. Expected the ID token to be signed with "RS256".'));if(!t.claims.aud||"string"!=typeof t.claims.aud&&!Array.isArray(t.claims.aud))throw new Error("Audience (aud) claim must be a string or array of strings present in the ID token");if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e.aud))throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but was not one of "').concat(t.claims.aud.join(", "),'"'));if(t.claims.aud.length>1){if(!t.claims.azp)throw new Error("Authorized Party (azp) claim must be a string present in the ID token when Audience (aud) claim has multiple values");if(t.claims.azp!==e.aud)throw new Error('Authorized Party (azp) claim mismatch in the ID token; expected "'.concat(e.aud,'", found "').concat(t.claims.azp,'"'))}}else if(t.claims.aud!==e.aud)throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but found "').concat(t.claims.aud,'"'));if(e.nonce){if(!t.claims.nonce)throw new Error("Nonce (nonce) claim must be a string present in the ID token");if(t.claims.nonce!==e.nonce)throw new Error('Nonce (nonce) claim mismatch in the ID token; expected "'.concat(e.nonce,'", found "').concat(t.claims.nonce,'"'))}if(e.max_age&&!Ve(t.claims.auth_time))throw new Error("Authentication Time (auth_time) claim must be a number present in the ID token when Max Age (max_age) is specified");if(null==t.claims.exp||!Ve(t.claims.exp))throw new Error("Expiration Time (exp) claim must be a number present in the ID token");if(!Ve(t.claims.iat))throw new Error("Issued At (iat) claim must be a number present in the ID token");const n=e.leeway||60,o=new Date(e.now||Date.now()),i=new Date(0);if(i.setUTCSeconds(t.claims.exp+n),o>i)throw new Error("Expiration Time (exp) claim error in the ID token; current time (".concat(o,") is after expiration time (").concat(i,")"));if(null!=t.claims.nbf&&Ve(t.claims.nbf)){const e=new Date(0);if(e.setUTCSeconds(t.claims.nbf-n),o<e)throw new Error("Not Before time (nbf) claim in the ID token indicates that this token can't be used just yet. Current time (".concat(o,") is before ").concat(e))}if(null!=t.claims.auth_time&&Ve(t.claims.auth_time)){const i=new Date(0);if(i.setUTCSeconds(parseInt(t.claims.auth_time)+e.max_age+n),o>i)throw new Error("Authentication Time (auth_time) claim in the ID token indicates that too much time has passed since the last end-user authentication. Current time (".concat(o,") is after last auth at ").concat(i))}if(e.organization){const n=e.organization.trim();if(n.startsWith("org_")){const e=n;if(!t.claims.org_id)throw new Error("Organization ID (org_id) claim must be a string present in the ID token");if(e!==t.claims.org_id)throw new Error('Organization ID (org_id) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_id,'"'))}else{const e=n.toLowerCase();if(!t.claims.org_name)throw new Error("Organization Name (org_name) claim must be a string present in the ID token");if(e!==t.claims.org_name)throw new Error('Organization Name (org_name) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_name,'"'))}}return t};var qe=q&&q.__assign||function(){return qe=Object.assign||function(e){for(var t,n=1,o=arguments.length;n<o;n++)for(var i in t=arguments[n])Object.prototype.hasOwnProperty.call(t,i)&&(e[i]=t[i]);return e},qe.apply(this,arguments)};function Ye(e,t){if(!t)return"";var n="; "+e;return!0===t?n:n+"="+t}function Be(e,t,n){return encodeURIComponent(e).replace(/%(23|24|26|2B|5E|60|7C)/g,decodeURIComponent).replace(/\(/g,"%28").replace(/\)/g,"%29")+"="+encodeURIComponent(t).replace(/%(23|24|26|2B|3A|3C|3E|3D|2F|3F|40|5B|5D|5E|60|7B|7D|7C)/g,decodeURIComponent)+function(e){if("number"==typeof e.expires){var t=new Date;t.setMilliseconds(t.getMilliseconds()+864e5*e.expires),e.expires=t}return Ye("Expires",e.expires?e.expires.toUTCString():"")+Ye("Domain",e.domain)+Ye("Path",e.path)+Ye("Secure",e.secure)+Ye("SameSite",e.sameSite)}(n)}function Qe(){return function(e){for(var t={},n=e?e.split("; "):[],o=/(%[\dA-F]{2})+/gi,i=0;i<n.length;i++){var r=n[i].split("="),s=r.slice(1).join("=");'"'===s.charAt(0)&&(s=s.slice(1,-1));try{t[r[0].replace(o,decodeURIComponent)]=s.replace(o,decodeURIComponent)}catch(e){}}return t}(document.cookie)}var $e=function(e){return Qe()[e]};function et(e,t,n){document.cookie=Be(e,t,qe({path:"/"},n))}var tt=et;var nt=function(e,t){et(e,"",qe(qe({},t),{expires:-1}))};const ot={get(e){const t=$e(e);if(void 0!==t)return JSON.parse(t)},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0,sameSite:"none"}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),tt(e,JSON.stringify(t),o)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),nt(e,n)}},it="_legacy_",rt={get(e){const t=ot.get(e);return t||ot.get("".concat(it).concat(e))},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),tt("".concat(it).concat(e),JSON.stringify(t),o),ot.save(e,t,n)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),nt(e,n),ot.remove(e,t),ot.remove("".concat(it).concat(e),t)}},st={get(e){if("undefined"==typeof sessionStorage)return;const t=sessionStorage.getItem(e);return null!=t?JSON.parse(t):void 0},save(e,t){sessionStorage.setItem(e,JSON.stringify(t))},remove(e){sessionStorage.removeItem(e)}};var at;e.ResponseType=void 0,(at=e.ResponseType||(e.ResponseType={})).Code="code",at.ConnectCode="connect_code";function ct(e,t,n){var o=void 0===t?null:t,i=function(e,t){var n=atob(e);if(t){for(var o=new Uint8Array(n.length),i=0,r=n.length;i<r;++i)o[i]=n.charCodeAt(i);return String.fromCharCode.apply(null,new Uint16Array(o.buffer))}return n}(e,void 0!==n&&n),r=i.indexOf("\n",10)+1,s=i.substring(r)+(o?"//# sourceMappingURL="+o:""),a=new Blob([s],{type:"application/javascript"});return URL.createObjectURL(a)}var ut,lt,dt,ht,pt=(ut="Lyogcm9sbHVwLXBsdWdpbi13ZWItd29ya2VyLWxvYWRlciAqLwohZnVuY3Rpb24oKXsidXNlIHN0cmljdCI7ZnVuY3Rpb24gZShlLHQpeyhudWxsPT10fHx0PmUubGVuZ3RoKSYmKHQ9ZS5sZW5ndGgpO2Zvcih2YXIgcj0wLG89QXJyYXkodCk7cjx0O3IrKylvW3JdPWVbcl07cmV0dXJuIG99ZnVuY3Rpb24gdCh0LHIpe3JldHVybiBmdW5jdGlvbihlKXtpZihBcnJheS5pc0FycmF5KGUpKXJldHVybiBlfSh0KXx8ZnVuY3Rpb24oZSx0KXt2YXIgcj1udWxsPT1lP251bGw6InVuZGVmaW5lZCIhPXR5cGVvZiBTeW1ib2wmJmVbU3ltYm9sLml0ZXJhdG9yXXx8ZVsiQEBpdGVyYXRvciJdO2lmKG51bGwhPXIpe3ZhciBvLG4scyxhLGk9W10sYz0hMCxsPSExO3RyeXtpZihzPShyPXIuY2FsbChlKSkubmV4dCwwPT09dCl7aWYoT2JqZWN0KHIpIT09cilyZXR1cm47Yz0hMX1lbHNlIGZvcig7IShjPShvPXMuY2FsbChyKSkuZG9uZSkmJihpLnB1c2goby52YWx1ZSksaS5sZW5ndGghPT10KTtjPSEwKTt9Y2F0Y2goZSl7bD0hMCxuPWV9ZmluYWxseXt0cnl7aWYoIWMmJm51bGwhPXIucmV0dXJuJiYoYT1yLnJldHVybigpLE9iamVjdChhKSE9PWEpKXJldHVybn1maW5hbGx5e2lmKGwpdGhyb3cgbn19cmV0dXJuIGl9fSh0LHIpfHxmdW5jdGlvbih0LHIpe2lmKHQpe2lmKCJzdHJpbmciPT10eXBlb2YgdClyZXR1cm4gZSh0LHIpO3ZhciBvPXt9LnRvU3RyaW5nLmNhbGwodCkuc2xpY2UoOCwtMSk7cmV0dXJuIk9iamVjdCI9PT1vJiZ0LmNvbnN0cnVjdG9yJiYobz10LmNvbnN0cnVjdG9yLm5hbWUpLCJNYXAiPT09b3x8IlNldCI9PT1vP0FycmF5LmZyb20odCk6IkFyZ3VtZW50cyI9PT1vfHwvXig/OlVpfEkpbnQoPzo4fDE2fDMyKSg/OkNsYW1wZWQpP0FycmF5JC8udGVzdChvKT9lKHQscik6dm9pZCAwfX0odCxyKXx8ZnVuY3Rpb24oKXt0aHJvdyBuZXcgVHlwZUVycm9yKCJJbnZhbGlkIGF0dGVtcHQgdG8gZGVzdHJ1Y3R1cmUgbm9uLWl0ZXJhYmxlIGluc3RhbmNlLlxuSW4gb3JkZXIgdG8gYmUgaXRlcmFibGUsIG5vbi1hcnJheSBvYmplY3RzIG11c3QgaGF2ZSBhIFtTeW1ib2wuaXRlcmF0b3JdKCkgbWV0aG9kLiIpfSgpfWNsYXNzIHIgZXh0ZW5kcyBFcnJvcntjb25zdHJ1Y3RvcihlLHQpe3N1cGVyKHQpLHRoaXMuZXJyb3I9ZSx0aGlzLmVycm9yX2Rlc2NyaXB0aW9uPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsci5wcm90b3R5cGUpfXN0YXRpYyBmcm9tUGF5bG9hZChlKXtsZXQgdD1lLmVycm9yLG89ZS5lcnJvcl9kZXNjcmlwdGlvbjtyZXR1cm4gbmV3IHIodCxvKX19Y2xhc3MgbyBleHRlbmRzIHJ7Y29uc3RydWN0b3IoZSx0KXtzdXBlcigibWlzc2luZ19yZWZyZXNoX3Rva2VuIiwiTWlzc2luZyBSZWZyZXNoIFRva2VuIChhdWRpZW5jZTogJyIuY29uY2F0KG4oZSxbImRlZmF1bHQiXSksIicsIHNjb3BlOiAnIikuY29uY2F0KG4odCksIicpIikpLHRoaXMuYXVkaWVuY2U9ZSx0aGlzLnNjb3BlPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsby5wcm90b3R5cGUpfX1mdW5jdGlvbiBuKGUpe3JldHVybiBlJiYhKGFyZ3VtZW50cy5sZW5ndGg+MSYmdm9pZCAwIT09YXJndW1lbnRzWzFdP2FyZ3VtZW50c1sxXTpbXSkuaW5jbHVkZXMoZSk/ZToiIn0iZnVuY3Rpb24iPT10eXBlb2YgU3VwcHJlc3NlZEVycm9yJiZTdXBwcmVzc2VkRXJyb3I7Y29uc3Qgcz1lPT57dmFyIHQ9ZS5jbGllbnRJZCxyPWZ1bmN0aW9uKGUsdCl7dmFyIHI9e307Zm9yKHZhciBvIGluIGUpT2JqZWN0LnByb3RvdHlwZS5oYXNPd25Qcm9wZXJ0eS5jYWxsKGUsbykmJnQuaW5kZXhPZihvKTwwJiYocltvXT1lW29dKTtpZihudWxsIT1lJiYiZnVuY3Rpb24iPT10eXBlb2YgT2JqZWN0LmdldE93blByb3BlcnR5U3ltYm9scyl7dmFyIG49MDtmb3Iobz1PYmplY3QuZ2V0T3duUHJvcGVydHlTeW1ib2xzKGUpO248by5sZW5ndGg7bisrKXQuaW5kZXhPZihvW25dKTwwJiZPYmplY3QucHJvdG90eXBlLnByb3BlcnR5SXNFbnVtZXJhYmxlLmNhbGwoZSxvW25dKSYmKHJbb1tuXV09ZVtvW25dXSl9cmV0dXJuIHJ9KGUsWyJjbGllbnRJZCJdKTtyZXR1cm4gbmV3IFVSTFNlYXJjaFBhcmFtcygoZT0+T2JqZWN0LmtleXMoZSkuZmlsdGVyKHQ9PnZvaWQgMCE9PWVbdF0pLnJlZHVjZSgodCxyKT0+T2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHQpLHtbcl06ZVtyXX0pLHt9KSkoT2JqZWN0LmFzc2lnbih7Y2xpZW50X2lkOnR9LHIpKSkudG9TdHJpbmcoKX07bGV0IGE9e30saT1udWxsO2NvbnN0IGM9KGUsdCk9PiIiLmNvbmNhdChlLCJ8IikuY29uY2F0KHQpLGw9KGUsdCk9PnQuc3RhcnRzV2l0aCgiIi5jb25jYXQoZSwifCIpKSx1PShlLHQpPT5hW2MoZSx0KV0sZj1lPT57T2JqZWN0LmVudHJpZXMoYSkuZm9yRWFjaChyPT57bGV0IG89dChyLDIpLG49b1swXTtvWzFdPT09ZSYmZGVsZXRlIGFbbl19KX0saD1lPT57Y29uc3QgdD1uZXcgVVJMU2VhcmNoUGFyYW1zKGUpLHI9e307cmV0dXJuIHQuZm9yRWFjaCgoZSx0KT0+e3JbdF09ZX0pLHJ9LGQ9YXN5bmMgZT0+e2xldCByLG4saT1lLmRhdGEsZj1pLnRpbWVvdXQsZD1pLmF1dGgscD1pLmZldGNoVXJsLHk9aS5mZXRjaE9wdGlvbnMsZz1pLnVzZUZvcm1EYXRhLGI9aS51c2VNcnJ0LE89aS5za2lwVG9rZW5TdG9yYWdlLGs9aS5wcmVzZXJ2ZVJlZnJlc2hUb2tlbixtPXQoZS5wb3J0cywxKVswXSxqPXt9O2NvbnN0IHY9ZHx8e30sXz12LmF1ZGllbmNlLHc9di5zY29wZTt0cnl7Y29uc3QgZT1nP2goeS5ib2R5KTpKU09OLnBhcnNlKHkuYm9keSk7aWYoZS5yZWZyZXNoX3Rva2VufHwicmVmcmVzaF90b2tlbiIhPT1lLmdyYW50X3R5cGUpZS5tZmFfdG9rZW4mJihuPXUoXyx3KSwhbiYmYiYmKG49YS5sYXRlc3RfcmVmcmVzaF90b2tlbikpO2Vsc2V7aWYobj11KF8sdyksIW4mJmIpe2NvbnN0IGU9YS5sYXRlc3RfcmVmcmVzaF90b2tlbix0PSgoZSx0KT0+ISFPYmplY3Qua2V5cyhhKS5maW5kKHI9PntpZigibGF0ZXN0X3JlZnJlc2hfdG9rZW4iIT09cil7Y29uc3Qgbz1sKHQsciksbj1yLnNwbGl0KCJ8IilbMV0uc3BsaXQoIiAiKSxzPWUuc3BsaXQoIiAiKS5ldmVyeShlPT5uLmluY2x1ZGVzKGUpKTtyZXR1cm4gbyYmc319KSkodyxfKTtlJiYhdCYmKG49ZSl9aWYoIW4pdGhyb3cgbmV3IG8oXyx3KTt5LmJvZHk9Zz9zKE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpfWxldCBpLGQ7ImZ1bmN0aW9uIj09dHlwZW9mIEFib3J0Q29udHJvbGxlciYmKGk9bmV3IEFib3J0Q29udHJvbGxlcix5LnNpZ25hbD1pLnNpZ25hbCk7dHJ5e2Q9YXdhaXQgUHJvbWlzZS5yYWNlKFsoUD1mLG5ldyBQcm9taXNlKGU9PnNldFRpbWVvdXQoZSxQKSkpLGZldGNoKHAsT2JqZWN0LmFzc2lnbih7fSx5KSldKX1jYXRjaChlKXtyZXR1cm4gdm9pZCBtLnBvc3RNZXNzYWdlKHtlcnJvcjplLm1lc3NhZ2V9KX1pZighZClyZXR1cm4gaSYmaS5hYm9ydCgpLHZvaWQgbS5wb3N0TWVzc2FnZSh7ZXJyb3I6IlRpbWVvdXQgd2hlbiBleGVjdXRpbmcgJ2ZldGNoJyJ9KTtpZihVPWQuaGVhZGVycyxqPVsuLi5VXS5yZWR1Y2UoKGUscik9PntsZXQgbz10KHIsMiksbj1vWzBdLHM9b1sxXTtyZXR1cm4gZVtuXT1zLGV9LHt9KSxyPWF3YWl0IGQuanNvbigpLE8pcmV0dXJuIGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4sdm9pZCBtLnBvc3RNZXNzYWdlKHtvazpkLm9rLGpzb246cixoZWFkZXJzOmp9KTtyLnJlZnJlc2hfdG9rZW4/KGImJihhLmxhdGVzdF9yZWZyZXNoX3Rva2VuPXIucmVmcmVzaF90b2tlbixTPW4sTT1yLnJlZnJlc2hfdG9rZW4sT2JqZWN0LmVudHJpZXMoYSkuZm9yRWFjaChlPT57bGV0IHI9dChlLDIpLG89clswXTtyWzFdPT09UyYmKGFbb109TSl9KSksKChlLHQscik9PnthW2ModCxyKV09ZX0pKHIucmVmcmVzaF90b2tlbixfLHcpLGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4pOmt8fCgoZSx0KT0+e2RlbGV0ZSBhW2MoZSx0KV19KShfLHcpLG0ucG9zdE1lc3NhZ2Uoe29rOmQub2ssanNvbjpyLGhlYWRlcnM6an0pfWNhdGNoKGUpe20ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOmUuZXJyb3IsZXJyb3JfZGVzY3JpcHRpb246ZS5tZXNzYWdlfSxoZWFkZXJzOmp9KX12YXIgUyxNLFUsUH0scD1hc3luYyBlPT57bGV0IHI9ZS5kYXRhLG89ci50aW1lb3V0LG49ci5hdXRoLGk9ci5mZXRjaFVybCxjPXIuZmV0Y2hPcHRpb25zLHU9ci51c2VGb3JtRGF0YSxkPXQoZS5wb3J0cywxKVswXTtjb25zdCBwPShufHx7fSkuYXVkaWVuY2U7dHJ5e2NvbnN0IGU9KGU9Pntjb25zdCByPW5ldyBTZXQ7cmV0dXJuIE9iamVjdC5lbnRyaWVzKGEpLmZvckVhY2gobz0+e2xldCBuPXQobywyKSxzPW5bMF0sYT1uWzFdO2woZSxzKSYmci5hZGQoYSl9KSxBcnJheS5mcm9tKHIpfSkocCk7aWYoMD09PWUubGVuZ3RoKXJldHVybiB2b2lkIGQucG9zdE1lc3NhZ2Uoe29rOiEwfSk7Y29uc3Qgcj11P2goYy5ib2R5KTpKU09OLnBhcnNlKGMuYm9keSk7Zm9yKGNvbnN0IHQgb2YgZSl7Y29uc3QgZT11P3MoT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHIpLHt0b2tlbjp0fSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxyKSx7dG9rZW46dH0pKTtsZXQgbixhLGwsaDsiZnVuY3Rpb24iPT10eXBlb2YgQWJvcnRDb250cm9sbGVyJiYobj1uZXcgQWJvcnRDb250cm9sbGVyLGE9bi5zaWduYWwpO3RyeXtoPWF3YWl0IFByb21pc2UucmFjZShbbmV3IFByb21pc2UoZT0+e2w9c2V0VGltZW91dChlLG8pfSksZmV0Y2goaSxPYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30sYykse2JvZHk6ZSxzaWduYWw6YX0pKV0pLmZpbmFsbHkoKCk9PmNsZWFyVGltZW91dChsKSl9Y2F0Y2goZSl7cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZS5tZXNzYWdlfSl9aWYoIWgpcmV0dXJuIG4mJm4uYWJvcnQoKSx2b2lkIGQucG9zdE1lc3NhZ2Uoe2Vycm9yOiJUaW1lb3V0IHdoZW4gZXhlY3V0aW5nICdmZXRjaCcifSk7aWYoIWgub2spe2xldCBlO3RyeXtjb25zdCB0PUpTT04ucGFyc2UoYXdhaXQgaC50ZXh0KCkpO2U9dC5lcnJvcl9kZXNjcmlwdGlvbn1jYXRjaChlKXt9cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZXx8IkhUVFAgZXJyb3IgIi5jb25jYXQoaC5zdGF0dXMpfSl9Zih0KX1kLnBvc3RNZXNzYWdlKHtvazohMH0pfWNhdGNoKGUpe2QucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZXx8IlVua25vd24gZXJyb3IgZHVyaW5nIHRva2VuIHJldm9jYXRpb24ifSl9fSx5PShlLHQpPT57aWYoIWkpcmV0dXJuITE7dHJ5e2NvbnN0IHI9bmV3IFVSTChpKS5vcmlnaW4sbz1uZXcgVVJMKGUuZmV0Y2hVcmwpO3JldHVybiBvLm9yaWdpbj09PXImJm8ucGF0aG5hbWU9PT10fWNhdGNoKGUpe3JldHVybiExfX07YWRkRXZlbnRMaXN0ZW5lcigibWVzc2FnZSIsZT0+e2NvbnN0IHI9ZS5kYXRhLG89dChlLnBvcnRzLDEpWzBdO2lmKCEoInR5cGUiaW4gcil8fCJpbml0IiE9PXIudHlwZSlyZXR1cm4idHlwZSJpbiByJiYiY2xlYXIiPT09ci50eXBlPyhhPXt9LHZvaWQobnVsbD09b3x8by5wb3N0TWVzc2FnZSh7b2s6ITB9KSkpOiJ0eXBlImluIHImJiJyZXZva2UiPT09ci50eXBlP3kociwiL29hdXRoL3Jldm9rZSIpP3ZvaWQgcChlKTp2b2lkKG51bGw9PW98fG8ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOiJpbnZhbGlkX2ZldGNoX3VybCIsZXJyb3JfZGVzY3JpcHRpb246IlVuYXV0aG9yaXplZCBmZXRjaCBVUkwifSxoZWFkZXJzOnt9fSkpOnZvaWQoImZldGNoVXJsImluIHImJnkociwiL29hdXRoL3Rva2VuIik/ZChlKTpudWxsPT1vfHxvLnBvc3RNZXNzYWdlKHtvazohMSxqc29uOntlcnJvcjoiaW52YWxpZF9mZXRjaF91cmwiLGVycm9yX2Rlc2NyaXB0aW9uOiJVbmF1dGhvcml6ZWQgZmV0Y2ggVVJMIn0saGVhZGVyczp7fX0pKTtpZihudWxsPT09aSl0cnl7bmV3IFVSTChyLmFsbG93ZWRCYXNlVXJsKSxpPXIuYWxsb3dlZEJhc2VVcmx9Y2F0Y2goZSl7cmV0dXJufX0pfSgpOwoK",lt=null,dt=!1,function(e){return ht=ht||ct(ut,lt,dt),new Worker(ht,e)});class ft{constructor(e,t){this.cache=e,this.clientId=t,this.manifestKey=this.createManifestKeyFrom(this.clientId)}async add(e){var t;const n=new Set((null===(t=await this.cache.get(this.manifestKey))||void 0===t?void 0:t.keys)||[]);n.add(e),await this.cache.set(this.manifestKey,{keys:[...n]})}async remove(e){const t=await this.cache.get(this.manifestKey);if(t){const n=new Set(t.keys);return n.delete(e),n.size>0?await this.cache.set(this.manifestKey,{keys:[...n]}):await this.cache.remove(this.manifestKey)}}get(){return this.cache.get(this.manifestKey)}clear(){return this.cache.remove(this.manifestKey)}createManifestKeyFrom(e){return"".concat(Le,"::").concat(e)}}const mt="auth0.is.authenticated",yt={memory:()=>(new Ze).enclosedCache,localstorage:()=>new De},wt=e=>yt[e],gt=e=>{const n=e.openUrl,o=e.onRedirect,i=t(e,["openUrl","onRedirect"]);return Object.assign(Object.assign({},i),{openUrl:!1===n||n?n:o})},vt=(e,t,n)=>{const o=(null==e?void 0:e.split(" "))||[],i=n?o.filter(e=>e!==S):o;const r=(null==t?void 0:t.split(" "))||[];return i.filter(e=>-1==r.indexOf(e)).join(",")},bt={NONCE:"nonce",KEYPAIR:"keypair"};class _t{constructor(e){this.clientId=e}getVersion(){return 1}createDbHandle(){const e=window.indexedDB.open("auth0-spa-js",this.getVersion());return new Promise((t,n)=>{e.onupgradeneeded=()=>Object.values(bt).forEach(t=>e.result.createObjectStore(t)),e.onerror=()=>n(e.error),e.onsuccess=()=>t(e.result)})}async getDbHandle(){return this.dbHandle||(this.dbHandle=await this.createDbHandle()),this.dbHandle}async executeDbRequest(e,t,n){const o=n((await this.getDbHandle()).transaction(e,t).objectStore(e));return new Promise((e,t)=>{o.onsuccess=()=>e(o.result),o.onerror=()=>t(o.error)})}buildKey(e){const t=e?"_".concat(e):"auth0";return"".concat(this.clientId,"::").concat(t)}setNonce(e,t){return this.save(bt.NONCE,this.buildKey(t),e)}setKeyPair(e){return this.save(bt.KEYPAIR,this.buildKey(),e)}async save(e,t,n){await this.executeDbRequest(e,"readwrite",e=>e.put(n,t))}findNonce(e){return this.find(bt.NONCE,this.buildKey(e))}findKeyPair(){return this.find(bt.KEYPAIR,this.buildKey())}find(e,t){return this.executeDbRequest(e,"readonly",e=>e.get(t))}async deleteBy(e,t){const n=await this.executeDbRequest(e,"readonly",e=>e.getAllKeys());await Promise.all((null==n?void 0:n.filter(t).map(t=>this.executeDbRequest(e,"readwrite",e=>e.delete(t))))||[])}deleteByClientId(e,t){return this.deleteBy(e,e=>"string"==typeof e&&e.startsWith("".concat(t,"::")))}clearNonces(){return this.deleteByClientId(bt.NONCE,this.clientId)}clearKeyPairs(){return this.deleteByClientId(bt.KEYPAIR,this.clientId)}}class kt{constructor(e){this.storage=new _t(e)}getNonce(e){return this.storage.findNonce(e)}setNonce(e,t){return this.storage.setNonce(e,t)}async getOrGenerateKeyPair(){let e=await this.storage.findKeyPair();return e||(e=await Ae(),await this.storage.setKeyPair(e)),e}async generateProof(e){const t=await this.getOrGenerateKeyPair();return Ie(Object.assign({keyPair:t},e))}async calculateThumbprint(){return xe(await this.getOrGenerateKeyPair())}async clear(){await Promise.all([this.storage.clearNonces(),this.storage.clearKeyPairs()])}}var St;!function(e){e.Bearer="Bearer",e.DPoP="DPoP"}(St||(St={}));class Tt{constructor(e,t){this.hooks=t,this.config=Object.assign(Object.assign({},e),{fetch:e.fetch||("undefined"==typeof window?fetch:window.fetch.bind(window))})}isAbsoluteUrl(e){return/^(https?:)?\/\//i.test(e)}buildUrl(e,t){if(t){if(this.isAbsoluteUrl(t))return t;if(e)return"".concat(e.replace(/\/?\/$/,""),"/").concat(t.replace(/^\/+/,""))}throw new TypeError("`url` must be absolute or `baseUrl` non-empty.")}getAccessToken(e){return this.config.getAccessToken?this.config.getAccessToken(e):this.hooks.getAccessToken(e)}extractUrl(e){return"string"==typeof e?e:e instanceof URL?e.href:e.url}buildBaseRequest(e,t){if(!this.config.baseUrl)return new Request(e,t);const n=this.buildUrl(this.config.baseUrl,this.extractUrl(e)),o=e instanceof Request?new Request(n,e):n;return new Request(o,t)}setAuthorizationHeader(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:St.Bearer;e.headers.set("authorization","".concat(n," ").concat(t))}async setDpopProofHeader(e,t){if(!this.config.dpopNonceId)return;const n=await this.hooks.getDpopNonce(),o=await this.hooks.generateDpopProof({accessToken:t,method:e.method,nonce:n,url:e.url});e.headers.set("dpop",o)}async prepareRequest(e,t){const n=await this.getAccessToken(t);if(void 0===n)throw new C("missing_access_token","No access token available");let o,i;"string"==typeof n?(o=this.config.dpopNonceId?St.DPoP:St.Bearer,i=n):(o=n.token_type,i=n.access_token),this.setAuthorizationHeader(e,i,o),o===St.DPoP&&await this.setDpopProofHeader(e,i)}getHeader(e,t){return Array.isArray(e)?new Headers(e).get(t)||"":"function"==typeof e.get?e.get(t)||"":e[t]||""}hasUseDpopNonceError(e){if(401!==e.status)return!1;const t=this.getHeader(e.headers,"www-authenticate");return t.includes("invalid_dpop_nonce")||t.includes("use_dpop_nonce")}async handleResponse(e,t){const n=this.getHeader(e.headers,Ce);if(n&&await this.hooks.setDpopNonce(n),!this.hasUseDpopNonceError(e))return e;if(!n||!t.onUseDpopNonceError)throw new U(n);return t.onUseDpopNonceError()}async internalFetchWithAuth(e,t,n,o){const i=this.buildBaseRequest(e,t);await this.prepareRequest(i,o);const r=await this.config.fetch(i);return this.handleResponse(r,n)}fetchWithAuth(e,t,n){const o={onUseDpopNonceError:()=>this.internalFetchWithAuth(e,t,Object.assign(Object.assign({},o),{onUseDpopNonceError:void 0}),n)};return this.internalFetchWithAuth(e,t,o,n)}}class Pt{constructor(e,t){this.myAccountFetcher=e,this.apiBase=t}async connectAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/connect"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:connected_accounts"]});return this._handleResponse(t)}async completeAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/complete"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:connected_accounts"]});return this._handleResponse(t)}async getFactors(){const e=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/factors"),{method:"GET"},{scope:["read:me:factors"]});return(await this._handleResponse(e)).factors}async getAuthenticationMethods(e){const t=e?"?".concat(new URLSearchParams({type:e})):"",n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods").concat(t),{method:"GET"},{scope:["read:me:authentication_methods"]});return(await this._handleResponse(n)).authentication_methods}async getAuthenticationMethod(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"GET"},{scope:["read:me:authentication_methods"]});return this._handleResponse(t)}async deleteAuthenticationMethod(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"DELETE"},{scope:["delete:me:authentication_methods"]});t.ok||await this._handleResponse(t)}async updateAuthenticationMethod(e,t){const n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"PATCH",headers:{"Content-Type":"application/json"},body:JSON.stringify(t)},{scope:["update:me:authentication_methods"]});return this._handleResponse(n)}async enrollmentChallenge(e){var t;const n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:authentication_methods"]}),o=await this._handleResponse(n),i=null!==(t=n.headers.get("location"))&&void 0!==t?t:"",r=decodeURIComponent(i.split("/").pop()||"");return Object.assign(Object.assign({},o),{id:r,location:i})}async enrollmentVerify(e){const n=e,o=n.location;n.type;const i=t(n,["location","type"]),r=await this.myAccountFetcher.fetchWithAuth("".concat(o,"/verify"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(i)},{scope:["create:me:authentication_methods"]});return this._handleResponse(r)}async _handleResponse(e){let t;try{t=await e.text(),t=JSON.parse(t)}catch(n){throw new Et({type:"invalid_json",status:e.status,title:"Invalid JSON response",detail:t||String(n)})}if(e.ok)return t;throw new Et(t)}}class Et extends Error{constructor(e){let t=e.type,n=e.status,o=e.title,i=e.detail,r=e.validation_errors;super(i),this.name="MyAccountApiError",this.type=t,this.status=n,this.title=o,this.detail=i,this.validation_errors=r,Object.setPrototypeOf(this,Et.prototype)}}const Ct={otp:{authenticatorTypes:["otp"]},sms:{authenticatorTypes:["oob"],oobChannels:["sms"]},email:{authenticatorTypes:["oob"],oobChannels:["email"]},push:{authenticatorTypes:["oob"],oobChannels:["auth0"]},voice:{authenticatorTypes:["oob"],oobChannels:["voice"]}},Rt="http://auth0.com/oauth/grant-type/mfa-otp",At="http://auth0.com/oauth/grant-type/mfa-oob",xt="http://auth0.com/oauth/grant-type/mfa-recovery-code";var It,Ot;let jt;if("undefined"==typeof navigator||null===(It=navigator.userAgent)||void 0===It||null===(Ot=It.startsWith)||void 0===Ot||!Ot.call(It,"Mozilla/5.0 ")){const e="v3.8.6";jt="".concat("oauth4webapi","/").concat(e)}function Wt(e,t){if(null==e)return!1;try{return e instanceof t||Object.getPrototypeOf(e)[Symbol.toStringTag]===t.prototype[Symbol.toStringTag]}catch(e){return!1}}const Mt="ERR_INVALID_ARG_VALUE",Nt="ERR_INVALID_ARG_TYPE";function Kt(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}const Ut=Symbol(),Lt=Symbol(),zt=Symbol(),Jt=Symbol(),Dt=Symbol(),Zt=Symbol(),Ht=new TextEncoder,Ft=new TextDecoder;function Vt(e){return"string"==typeof e?Ht.encode(e):Ft.decode(e)}let Gt,Xt;if(Uint8Array.prototype.toBase64)Gt=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;Gt=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function qt(e){return"string"==typeof e?Xt(e):Gt(e)}Xt=Uint8Array.fromBase64?e=>{try{return Uint8Array.fromBase64(e,{alphabet:"base64url"})}catch(e){throw Kt("The input to be decoded is not correctly encoded.",Mt,e)}}:e=>{try{const t=atob(e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"")),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}catch(e){throw Kt("The input to be decoded is not correctly encoded.",Mt,e)}};class Yt extends Error{constructor(e,t){var n;super(e,t),p(this,"code",void 0),this.name=this.constructor.name,this.code=io,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class Bt extends Error{constructor(e,t){var n;super(e,t),p(this,"code",void 0),this.name=this.constructor.name,null!=t&&t.code&&(this.code=null==t?void 0:t.code),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function Qt(e,t,n){return new Bt(e,{code:t,cause:n})}function $t(e,t){if(function(e,t){if(!(e instanceof CryptoKey))throw Kt("".concat(t," must be a CryptoKey"),Nt)}(e,t),"private"!==e.type)throw Kt("".concat(t," must be a private CryptoKey"),Mt)}function en(e){return null!==e&&"object"==typeof e&&!Array.isArray(e)}function tn(e){Wt(e,Headers)&&(e=Object.fromEntries(e.entries()));const t=new Headers(null!=e?e:{});if(jt&&!t.has("user-agent")&&t.set("user-agent",jt),t.has("authorization"))throw Kt('"options.headers" must not include the "authorization" header name',Mt);return t}function nn(e,t){if(void 0!==t){if("function"==typeof t&&(t=t(e.href)),!(t instanceof AbortSignal))throw Kt('"options.signal" must return or be an instance of AbortSignal',Nt);return t}}function on(e){return e.includes("//")?e.replace("//","/"):e}async function rn(e,t){return async function(e,t,n,o){if(!(e instanceof URL))throw Kt('"'.concat(t,'" must be an instance of URL'),Nt);vn(e,!0!==(null==o?void 0:o[Ut]));const i=n(new URL(e.href)),r=tn(null==o?void 0:o.headers);return r.set("accept","application/json"),((null==o?void 0:o[Jt])||fetch)(i.href,{body:void 0,headers:Object.fromEntries(r.entries()),method:"GET",redirect:"manual",signal:nn(i,null==o?void 0:o.signal)})}(e,"issuerIdentifier",e=>{switch(null==t?void 0:t.algorithm){case void 0:case"oidc":!function(e,t){e.pathname=on("".concat(e.pathname,"/").concat(t))}(e,".well-known/openid-configuration");break;case"oauth2":!function(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];"/"===e.pathname?e.pathname=t:e.pathname=on("".concat(t,"/").concat(n?e.pathname:e.pathname.replace(/(\/)$/,"")))}(e,".well-known/oauth-authorization-server");break;default:throw Kt('"options.algorithm" must be "oidc" (default), or "oauth2"',Mt)}return e},t)}function sn(e,t,n,o,i){try{if("number"!=typeof e||!Number.isFinite(e))throw Kt("".concat(n," must be a number"),Nt,i);if(e>0)return;if(t){if(0!==e)throw Kt("".concat(n," must be a non-negative number"),Mt,i);return}throw Kt("".concat(n," must be a positive number"),Mt,i)}catch(e){if(o)throw Qt(e.message,o,i);throw e}}function an(e,t,n,o){try{if("string"!=typeof e)throw Kt("".concat(t," must be a string"),Nt,o);if(0===e.length)throw Kt("".concat(t," must not be empty"),Mt,o)}catch(e){if(n)throw Qt(e.message,n,o);throw e}}function cn(e){!function(e,t){if(Nn(e)!==t)throw function(e){let t='"response" content-type must be ';for(var n=arguments.length,o=new Array(n>1?n-1:0),i=1;i<n;i++)o[i-1]=arguments[i];if(o.length>2){const e=o.pop();t+="".concat(o.join(", "),", or ").concat(e)}else 2===o.length?t+="".concat(o[0]," or ").concat(o[1]):t+=o[0];return Qt(t,uo,e)}(e,t)}(e,"application/json")}function un(){return qt(crypto.getRandomValues(new Uint8Array(32)))}function ln(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"PS256";case"SHA-384":return"PS384";case"SHA-512":return"PS512";default:throw new Yt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"RSASSA-PKCS1-v1_5":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"RS256";case"SHA-384":return"RS384";case"SHA-512":return"RS512";default:throw new Yt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"ECDSA":return function(e){switch(e.algorithm.namedCurve){case"P-256":return"ES256";case"P-384":return"ES384";case"P-521":return"ES512";default:throw new Yt("unsupported EcKeyAlgorithm namedCurve",{cause:e})}}(e);case"Ed25519":case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return e.algorithm.name;case"EdDSA":return"Ed25519";default:throw new Yt("unsupported CryptoKey algorithm name",{cause:e})}}function dn(e){const t=null==e?void 0:e[Lt];return"number"==typeof t&&Number.isFinite(t)?t:0}function hn(e){const t=null==e?void 0:e[zt];return"number"==typeof t&&Number.isFinite(t)&&-1!==Math.sign(t)?t:30}function pn(){return Math.floor(Date.now()/1e3)}function fn(e){if("object"!=typeof e||null===e)throw Kt('"as" must be an object',Nt);an(e.issuer,'"as.issuer"')}function mn(e){if("object"!=typeof e||null===e)throw Kt('"client" must be an object',Nt);an(e.client_id,'"client.client_id"')}function yn(e){return an(e,'"clientSecret"'),(t,n,o,i)=>{o.set("client_id",n.client_id),o.set("client_secret",e)}}function wn(e,t){const n=(r=e)instanceof CryptoKey?{key:r}:(null==r?void 0:r.key)instanceof CryptoKey?(void 0!==r.kid&&an(r.kid,'"kid"'),{key:r.key,kid:r.kid}):{},o=n.key,i=n.kid;var r;return $t(o,'"clientPrivateKey.key"'),async(e,n,r,s)=>{var a;const c={alg:ln(o),kid:i},u=function(e,t){const n=pn()+dn(t);return{jti:un(),aud:e.issuer,exp:n+60,iat:n,nbf:n,iss:t.client_id,sub:t.client_id}}(e,n);null==t||null===(a=t[Dt])||void 0===a||a.call(t,c,u),r.set("client_id",n.client_id),r.set("client_assertion_type","urn:ietf:params:oauth:client-assertion-type:jwt-bearer"),r.set("client_assertion",await async function(e,t,n){if(!n.usages.includes("sign"))throw Kt('CryptoKey instances used for signing assertions must include "sign" in their "usages"',Mt);const o="".concat(qt(Vt(JSON.stringify(e))),".").concat(qt(Vt(JSON.stringify(t)))),i=qt(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:ko(e)};case"RSA-PSS":switch(_o(e),e.algorithm.hash.name){case"SHA-256":case"SHA-384":case"SHA-512":return{name:e.algorithm.name,saltLength:parseInt(e.algorithm.hash.name.slice(-3),10)>>3};default:throw new Yt("unsupported RSA-PSS hash name",{cause:e})}case"RSASSA-PKCS1-v1_5":return _o(e),e.algorithm.name;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":case"Ed25519":return e.algorithm.name}throw new Yt("unsupported CryptoKey algorithm name",{cause:e})}(n),n,Vt(o)));return"".concat(o,".").concat(i)}(c,u,o))}}const gn=URL.parse?(e,t)=>URL.parse(e,t):(e,t)=>{try{return new URL(e,t)}catch(e){return null}};function vn(e,t){if(t&&"https:"!==e.protocol)throw Qt("only requests to HTTPS are allowed",ho,e);if("https:"!==e.protocol&&"http:"!==e.protocol)throw Qt("only HTTP and HTTPS requests are allowed",po,e)}function bn(e,t,n,o){let i;if("string"!=typeof e||!(i=gn(e)))throw Qt("authorization server metadata does not contain a valid ".concat(n?'"as.mtls_endpoint_aliases.'.concat(t,'"'):'"as.'.concat(t,'"')),void 0===e?wo:go,{attribute:n?"mtls_endpoint_aliases.".concat(t):t});return vn(i,o),i}function _n(e,t,n,o){return n&&e.mtls_endpoint_aliases&&t in e.mtls_endpoint_aliases?bn(e.mtls_endpoint_aliases[t],t,n,o):bn(e[t],t,n,o)}class kn extends Error{constructor(e,t){var n;super(e,t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"error",void 0),p(this,"status",void 0),p(this,"error_description",void 0),p(this,"response",void 0),this.name=this.constructor.name,this.code=oo,this.cause=t.cause,this.error=t.cause.error,this.status=t.response.status,this.error_description=t.cause.error_description,Object.defineProperty(this,"response",{enumerable:!1,value:t.response}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class Sn extends Error{constructor(e,t){var n,o;super(e,t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"error",void 0),p(this,"error_description",void 0),this.name=this.constructor.name,this.code=ro,this.cause=t.cause,this.error=t.cause.get("error"),this.error_description=null!==(n=t.cause.get("error_description"))&&void 0!==n?n:void 0,null===(o=Error.captureStackTrace)||void 0===o||o.call(Error,this,this.constructor)}}class Tn extends Error{constructor(e,t){var n;super(e,t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"response",void 0),p(this,"status",void 0),this.name=this.constructor.name,this.code=no,this.cause=t.cause,this.status=t.response.status,this.response=t.response,Object.defineProperty(this,"response",{enumerable:!1}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}const Pn="[a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+",En="("+Pn+')\\s*=\\s*"((?:[^"\\\\]|\\\\[\\s\\S])*)"',Cn="("+Pn+")\\s*=\\s*("+Pn+")",Rn=new RegExp("^[,\\s]*("+Pn+")"),An=new RegExp("^[,\\s]*"+En+"[,\\s]*(.*)"),xn=new RegExp("^[,\\s]*"+Cn+"[,\\s]*(.*)"),In=new RegExp("^([a-zA-Z0-9\\-\\._\\~\\+\\/]+={0,2})(?:$|[,\\s])(.*)");async function On(e,t,n){if(e.status!==t){let t;var o;if(Hn(e),t=await async function(e){if(e.status>399&&e.status<500){bo(e),cn(e);try{const t=await e.clone().json();if(en(t)&&"string"==typeof t.error&&t.error.length)return t}catch(e){}}}(e))throw await(null===(o=e.body)||void 0===o?void 0:o.cancel()),new kn("server responded with an error in the response body",{cause:t,response:e});throw Qt('"response" is not a conform '.concat(n," response (unexpected HTTP status code)"),lo,e)}}function jn(e){if(!qn.has(e))throw Kt('"options.DPoP" is not a valid DPoPHandle',Mt)}async function Wn(e,t,n,o){fn(e),mn(t);const i=_n(e,"userinfo_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==o?void 0:o[Ut])),r=tn(null==o?void 0:o.headers);return t.userinfo_signed_response_alg?r.set("accept","application/jwt"):(r.set("accept","application/json"),r.append("accept","application/jwt")),async function(e,t,n,o,i,r){var s;if(an(e,'"accessToken"'),!(n instanceof URL))throw Kt('"url" must be an instance of URL',Nt);vn(n,!0!==(null==r?void 0:r[Ut])),o=tn(o),null!=r&&r.DPoP&&(jn(r.DPoP),await r.DPoP.addProof(n,o,t.toUpperCase(),e)),o.set("authorization","".concat(o.has("dpop")?"DPoP":"Bearer"," ").concat(e));const a=await((null==r?void 0:r[Jt])||fetch)(n.href,{duplex:Wt(i,ReadableStream)?"half":void 0,body:i,headers:Object.fromEntries(o.entries()),method:t,redirect:"manual",signal:nn(n,null==r?void 0:r.signal)});return null==r||null===(s=r.DPoP)||void 0===s||s.cacheNonce(a,n),a}(n,"GET",i,r,null,m(m({},o),{},{[Lt]:dn(t)}))}const Mn=Symbol();function Nn(e){var t;return null===(t=e.headers.get("content-type"))||void 0===t?void 0:t.split(";")[0]}async function Kn(e,t,n,o,i){if(fn(e),mn(t),!Wt(o,Response))throw Kt('"response" must be an instance of Response',Nt);if(Hn(o),200!==o.status)throw Qt('"response" is not a conform UserInfo Endpoint response (unexpected HTTP status code)',lo,o);let r;if(bo(o),"application/jwt"===Nn(o)){const n=await So(await o.text(),Po.bind(void 0,t.userinfo_signed_response_alg,e.userinfo_signing_alg_values_supported,void 0),dn(t),hn(t),null==i?void 0:i[Zt]).then(Fn.bind(void 0,t.client_id)).then(Gn.bind(void 0,e)),s=n.claims,a=n.jwt;Jn.set(o,a),r=s}else{if(t.userinfo_signed_response_alg)throw Qt("JWT UserInfo Response expected",so,o);r=await xo(o)}if(an(r.sub,'"response" body "sub" property',co,{body:r}),n===Mn);else if(an(n,'"expectedSubject"'),r.sub!==n)throw Qt('unexpected "response" body "sub" property value',yo,{expected:n,body:r,attribute:"sub"});return r}async function Un(e,t,n,o,i,r,s){return await n(e,t,i,r),r.set("content-type","application/x-www-form-urlencoded;charset=UTF-8"),((null==s?void 0:s[Jt])||fetch)(o.href,{body:i,headers:Object.fromEntries(r.entries()),method:"POST",redirect:"manual",signal:nn(o,null==s?void 0:s.signal)})}async function Ln(e,t,n,o,i,r){var s;const a=_n(e,"token_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==r?void 0:r[Ut]));i.set("grant_type",o);const c=tn(null==r?void 0:r.headers);c.set("accept","application/json"),void 0!==(null==r?void 0:r.DPoP)&&(jn(r.DPoP),await r.DPoP.addProof(a,c,"POST"));const u=await Un(e,t,n,a,i,c,r);return null==r||null===(s=r.DPoP)||void 0===s||s.cacheNonce(u,a),u}const zn=new WeakMap,Jn=new WeakMap;function Dn(e){if(!e.id_token)return;const t=zn.get(e);if(!t)throw Kt('"ref" was already garbage collected or did not resolve from the proper sources',Mt);return t}async function Zn(e,t,n,o,i,r){if(fn(e),mn(t),!Wt(n,Response))throw Kt('"response" must be an instance of Response',Nt);await On(n,200,"Token Endpoint"),bo(n);const s=await xo(n);if(an(s.access_token,'"response" body "access_token" property',co,{body:s}),an(s.token_type,'"response" body "token_type" property',co,{body:s}),s.token_type=s.token_type.toLowerCase(),void 0!==s.expires_in){let e="number"!=typeof s.expires_in?parseFloat(s.expires_in):s.expires_in;sn(e,!0,'"response" body "expires_in" property',co,{body:s}),s.expires_in=e}if(void 0!==s.refresh_token&&an(s.refresh_token,'"response" body "refresh_token" property',co,{body:s}),void 0!==s.scope&&"string"!=typeof s.scope)throw Qt('"response" body "scope" property must be a string',co,{body:s});if(void 0!==s.id_token){an(s.id_token,'"response" body "id_token" property',co,{body:s});const r=["aud","exp","iat","iss","sub"];!0===t.require_auth_time&&r.push("auth_time"),void 0!==t.default_max_age&&(sn(t.default_max_age,!0,'"client.default_max_age"'),r.push("auth_time")),null!=o&&o.length&&r.push(...o);const a=await So(s.id_token,Po.bind(void 0,t.id_token_signed_response_alg,e.id_token_signing_alg_values_supported,"RS256"),dn(t),hn(t),i).then(Qn.bind(void 0,r)).then(Xn.bind(void 0,e)).then(Vn.bind(void 0,t.client_id)),c=a.claims,u=a.jwt;if(Array.isArray(c.aud)&&1!==c.aud.length){if(void 0===c.azp)throw Qt('ID Token "aud" (audience) claim includes additional untrusted audiences',mo,{claims:c,claim:"aud"});if(c.azp!==t.client_id)throw Qt('unexpected ID Token "azp" (authorized party) claim value',mo,{expected:t.client_id,claims:c,claim:"azp"})}void 0!==c.auth_time&&sn(c.auth_time,!0,'ID Token "auth_time" (authentication time)',co,{claims:c}),Jn.set(n,u),zn.set(s,c)}if(void 0!==(null==r?void 0:r[s.token_type]))r[s.token_type](n,s);else if("dpop"!==s.token_type&&"bearer"!==s.token_type)throw new Yt("unsupported `token_type` value",{cause:{body:s}});return s}function Hn(e){let t;if(t=function(e){if(!Wt(e,Response))throw Kt('"response" must be an instance of Response',Nt);const t=e.headers.get("www-authenticate");if(null===t)return;const n=[];let o=t;for(;o;){var i;let e=o.match(Rn);const t=null===(i=e)||void 0===i?void 0:i[1].toLowerCase();if(!t)return;const c=o.substring(e[0].length);if(c&&!c.match(/^[\s,]/))return;const u=c.match(/^\s+(.*)$/),l=!!u;o=u?u[1]:void 0;const d={};let h;if(l)for(;o;){let t,n;if(e=o.match(An)){var r=w(e,4);if(t=r[1],n=r[2],o=r[3],n.includes("\\"))try{n=JSON.parse('"'.concat(n,'"'))}catch(e){}d[t.toLowerCase()]=n}else{if(!(e=o.match(xn))){if(e=o.match(In)){if(Object.keys(d).length)break;var s=w(e,3);h=s[1],o=s[2];break}return}var a=w(e,4);t=a[1],n=a[2],o=a[3],d[t.toLowerCase()]=n}}else o=c||void 0;const p={scheme:t,parameters:d};h&&(p.token68=h),n.push(p)}return n.length?n:void 0}(e))throw new Tn("server responded with a challenge in the WWW-Authenticate HTTP Header",{cause:t,response:e})}function Fn(e,t){return void 0!==t.claims.aud?Vn(e,t):t}function Vn(e,t){if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e))throw Qt('unexpected JWT "aud" (audience) claim value',mo,{expected:e,claims:t.claims,claim:"aud"})}else if(t.claims.aud!==e)throw Qt('unexpected JWT "aud" (audience) claim value',mo,{expected:e,claims:t.claims,claim:"aud"});return t}function Gn(e,t){return void 0!==t.claims.iss?Xn(e,t):t}function Xn(e,t){var n,o;const i=null!==(n=null===(o=e[Oo])||void 0===o?void 0:o.call(e,t))&&void 0!==n?n:e.issuer;if(t.claims.iss!==i)throw Qt('unexpected JWT "iss" (issuer) claim value',mo,{expected:i,claims:t.claims,claim:"iss"});return t}const qn=new WeakSet;const Yn=Symbol();const Bn={aud:"audience",c_hash:"code hash",client_id:"client id",exp:"expiration time",iat:"issued at",iss:"issuer",jti:"jwt id",nonce:"nonce",s_hash:"state hash",sub:"subject",ath:"access token hash",htm:"http method",htu:"http uri",cnf:"confirmation",auth_time:"authentication time"};function Qn(e,t){for(const n of e)if(void 0===t.claims[n])throw Qt('JWT "'.concat(n,'" (').concat(Bn[n],") claim missing"),co,{claims:t.claims});return t}const $n=Symbol(),eo=Symbol();async function to(e,t,n,o){return"string"==typeof(null==o?void 0:o.expectedNonce)||"number"==typeof(null==o?void 0:o.maxAge)||null!=o&&o.requireIdToken?async function(e,t,n,o,i,r,s){const a=[];switch(o){case void 0:o=$n;break;case $n:break;default:an(o,'"expectedNonce" argument'),a.push("nonce")}switch(null!=i||(i=t.default_max_age),i){case void 0:i=eo;break;case eo:break;default:sn(i,!0,'"maxAge" argument'),a.push("auth_time")}const c=await Zn(e,t,n,a,r,s);an(c.id_token,'"response" body "id_token" property',co,{body:c});const u=Dn(c);if(i!==eo){const e=pn()+dn(t),n=hn(t);if(u.auth_time+i<e-n)throw Qt("too much time has elapsed since the last End-User authentication",fo,{claims:u,now:e,tolerance:n,claim:"auth_time"})}if(o===$n){if(void 0!==u.nonce)throw Qt('unexpected ID Token "nonce" claim value',mo,{expected:void 0,claims:u,claim:"nonce"})}else if(u.nonce!==o)throw Qt('unexpected ID Token "nonce" claim value',mo,{expected:o,claims:u,claim:"nonce"});return c}(e,t,n,o.expectedNonce,o.maxAge,o[Zt],o.recognizedTokenTypes):async function(e,t,n,o,i){const r=await Zn(e,t,n,void 0,o,i),s=Dn(r);if(s){if(void 0!==t.default_max_age){sn(t.default_max_age,!0,'"client.default_max_age"');const e=pn()+dn(t),n=hn(t);if(s.auth_time+t.default_max_age<e-n)throw Qt("too much time has elapsed since the last End-User authentication",fo,{claims:s,now:e,tolerance:n,claim:"auth_time"})}if(void 0!==s.nonce)throw Qt('unexpected ID Token "nonce" claim value',mo,{expected:void 0,claims:s,claim:"nonce"})}return r}(e,t,n,null==o?void 0:o[Zt],null==o?void 0:o.recognizedTokenTypes)}const no="OAUTH_WWW_AUTHENTICATE_CHALLENGE",oo="OAUTH_RESPONSE_BODY_ERROR",io="OAUTH_UNSUPPORTED_OPERATION",ro="OAUTH_AUTHORIZATION_RESPONSE_ERROR",so="OAUTH_JWT_USERINFO_EXPECTED",ao="OAUTH_PARSE_ERROR",co="OAUTH_INVALID_RESPONSE",uo="OAUTH_RESPONSE_IS_NOT_JSON",lo="OAUTH_RESPONSE_IS_NOT_CONFORM",ho="OAUTH_HTTP_REQUEST_FORBIDDEN",po="OAUTH_REQUEST_PROTOCOL_FORBIDDEN",fo="OAUTH_JWT_TIMESTAMP_CHECK_FAILED",mo="OAUTH_JWT_CLAIM_COMPARISON_FAILED",yo="OAUTH_JSON_ATTRIBUTE_COMPARISON_FAILED",wo="OAUTH_MISSING_SERVER_METADATA",go="OAUTH_INVALID_SERVER_METADATA";async function vo(e){if(!Wt(e,Response))throw Kt('"response" must be an instance of Response',Nt);await On(e,200,"Revocation Endpoint")}function bo(e){if(e.bodyUsed)throw Kt('"response" body has been used already',Mt)}function _o(e){const t=e.algorithm;if("number"!=typeof t.modulusLength||t.modulusLength<2048)throw new Yt("unsupported ".concat(t.name," modulusLength"),{cause:e})}function ko(e){switch(e.algorithm.namedCurve){case"P-256":return"SHA-256";case"P-384":return"SHA-384";case"P-521":return"SHA-512";default:throw new Yt("unsupported ECDSA namedCurve",{cause:e})}}async function So(e,t,n,o,i){let r,s,a=e.split("."),c=a[0],u=a[1],l=a.length;if(5===l){if(void 0===i)throw new Yt("JWE decryption is not configured",{cause:e});var d=(e=await i(e)).split(".");c=d[0],u=d[1],l=d.length}if(3!==l)throw Qt("Invalid JWT",co,e);try{r=JSON.parse(Vt(qt(c)))}catch(e){throw Qt("failed to parse JWT Header body as base64url encoded JSON",ao,e)}if(!en(r))throw Qt("JWT Header must be a top level object",co,e);if(t(r),void 0!==r.crit)throw new Yt('no JWT "crit" header parameter extensions are supported',{cause:{header:r}});try{s=JSON.parse(Vt(qt(u)))}catch(e){throw Qt("failed to parse JWT Payload body as base64url encoded JSON",ao,e)}if(!en(s))throw Qt("JWT Payload must be a top level object",co,e);const h=pn()+n;if(void 0!==s.exp){if("number"!=typeof s.exp)throw Qt('unexpected JWT "exp" (expiration time) claim type',co,{claims:s});if(s.exp<=h-o)throw Qt('unexpected JWT "exp" (expiration time) claim value, expiration is past current timestamp',fo,{claims:s,now:h,tolerance:o,claim:"exp"})}if(void 0!==s.iat&&"number"!=typeof s.iat)throw Qt('unexpected JWT "iat" (issued at) claim type',co,{claims:s});if(void 0!==s.iss&&"string"!=typeof s.iss)throw Qt('unexpected JWT "iss" (issuer) claim type',co,{claims:s});if(void 0!==s.nbf){if("number"!=typeof s.nbf)throw Qt('unexpected JWT "nbf" (not before) claim type',co,{claims:s});if(s.nbf>h+o)throw Qt('unexpected JWT "nbf" (not before) claim value',fo,{claims:s,now:h,tolerance:o,claim:"nbf"})}if(void 0!==s.aud&&"string"!=typeof s.aud&&!Array.isArray(s.aud))throw Qt('unexpected JWT "aud" (audience) claim type',co,{claims:s});return{header:r,claims:s,jwt:e}}async function To(e){if("POST"!==e.method)throw Kt("form_post responses are expected to use the POST method",Mt,{cause:e});if("application/x-www-form-urlencoded"!==Nn(e))throw Kt("form_post responses are expected to use the application/x-www-form-urlencoded content-type",Mt,{cause:e});return async function(e){if(e.bodyUsed)throw Kt("form_post Request instances must contain a readable body",Mt,{cause:e});return e.text()}(e)}function Po(e,t,n,o){if(void 0===e)if(Array.isArray(t)){if(!t.includes(o.alg))throw Qt('unexpected JWT "alg" header parameter',co,{header:o,expected:t,reason:"authorization server metadata"})}else{if(void 0===n)throw Qt('missing client or server configuration to verify used JWT "alg" header parameter',void 0,{client:e,issuer:t,fallback:n});if("string"==typeof n?o.alg!==n:"function"==typeof n?!n(o.alg):!n.includes(o.alg))throw Qt('unexpected JWT "alg" header parameter',co,{header:o,expected:n,reason:"default value"})}else if("string"==typeof e?o.alg!==e:!e.includes(o.alg))throw Qt('unexpected JWT "alg" header parameter',co,{header:o,expected:e,reason:"client configuration"})}function Eo(e,t){const n=e.getAll(t),o=n[0];if(n.length>1)throw Qt('"'.concat(t,'" parameter must be provided only once'),co);return o}const Co=Symbol(),Ro=Symbol();function Ao(e,t,n,o){if(fn(e),mn(t),n instanceof URL&&(n=n.searchParams),!(n instanceof URLSearchParams))throw Kt('"parameters" must be an instance of URLSearchParams, or URL',Nt);if(Eo(n,"response"))throw Qt('"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()',co,{parameters:n});const i=Eo(n,"iss"),r=Eo(n,"state");if(!i&&e.authorization_response_iss_parameter_supported)throw Qt('response parameter "iss" (issuer) missing',co,{parameters:n});if(i&&i!==e.issuer)throw Qt('unexpected "iss" (issuer) response parameter value',co,{expected:e.issuer,parameters:n});switch(o){case void 0:case Ro:if(void 0!==r)throw Qt('unexpected "state" response parameter encountered',co,{expected:void 0,parameters:n});break;case Co:break;default:if(an(o,'"expectedState" argument'),r!==o)throw Qt(void 0===r?'response parameter "state" missing':'unexpected "state" response parameter value',co,{expected:o,parameters:n})}if(Eo(n,"error"))throw new Sn("authorization response from the server is an error",{cause:n});const s=Eo(n,"id_token"),a=Eo(n,"token");if(void 0!==s||void 0!==a)throw new Yt("implicit and hybrid flows are not supported");return c=new URLSearchParams(n),qn.add(c),c;var c}async function xo(e){let t,n=arguments.length>1&&void 0!==arguments[1]?arguments[1]:cn;try{t=await e.json()}catch(t){throw n(e),Qt('failed to parse "response" body as JSON',ao,t)}if(!en(t))throw Qt('"response" body must be a top level object',co,{body:t});return t}const Io=Symbol(),Oo=Symbol(),jo=new TextEncoder,Wo=new TextDecoder,Mo=new TextDecoder("utf-8",{fatal:!0});function No(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];const o=t.reduce((e,t)=>e+t.length,0),i=new Uint8Array(o);let r=0;for(const e of t)i.set(e,r),r+=e.length;return i}function Ko(e){const t=new Uint8Array(e.length);for(let n=0;n<e.length;n++){const o=e.charCodeAt(n);if(o>127)throw new TypeError("non-ASCII string encountered in encode()");t[n]=o}return t}const Uo=function(e){return new TypeError("CryptoKey does not support this operation, its ".concat(arguments.length>1&&void 0!==arguments[1]?arguments[1]:"algorithm.name"," must be ").concat(e))};function Lo(e,t,n){var o;const i=e.algorithm;if(i.name!==t.name)throw Uo(t.name);if(t.hash&&(null===(o=i.hash)||void 0===o?void 0:o.name)!==t.hash)throw Uo(t.hash,"algorithm.hash");if(t.namedCurve&&i.namedCurve!==t.namedCurve)throw Uo(t.namedCurve,"algorithm.namedCurve");if(void 0!==t.length&&i.length!==t.length)throw Uo(t.length,"algorithm.length");!function(e,t){if(t&&!e.usages.includes(t))throw new TypeError("CryptoKey does not support this operation, its usages must include ".concat(t,"."))}(e,n)}const zo=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];return function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];if(o.length>2){const t=o.pop();e+="one of type ".concat(o.join(", "),", or ").concat(t,".")}else 2===o.length?e+="one of type ".concat(o[0]," or ").concat(o[1],"."):e+="of type ".concat(o[0],".");if(null==t)e+=" Received ".concat(t);else if("function"==typeof t&&t.name)e+=" Received function ".concat(t.name);else if("object"==typeof t&&null!=t){var r;null!==(r=t.constructor)&&void 0!==r&&r.name&&(e+=" Received an instance of ".concat(t.constructor.name))}return e}("Key for the ".concat(e," algorithm must be "),t,...o)};class Jo extends Error{constructor(e,t){var n;super(e,t),p(this,"code","ERR_JOSE_GENERIC"),this.name=this.constructor.name,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}p(Jo,"code","ERR_JOSE_GENERIC");class Do extends Jo{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),p(this,"code","ERR_JWT_CLAIM_VALIDATION_FAILED"),p(this,"claim",void 0),p(this,"reason",void 0),p(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}p(Do,"code","ERR_JWT_CLAIM_VALIDATION_FAILED");class Zo extends Jo{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),p(this,"code","ERR_JWT_EXPIRED"),p(this,"claim",void 0),p(this,"reason",void 0),p(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}p(Zo,"code","ERR_JWT_EXPIRED");class Ho extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JOSE_ALG_NOT_ALLOWED")}}p(Ho,"code","ERR_JOSE_ALG_NOT_ALLOWED");class Fo extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JOSE_NOT_SUPPORTED")}}p(Fo,"code","ERR_JOSE_NOT_SUPPORTED");p(class extends Jo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"decryption operation failed",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWE_DECRYPTION_FAILED")}},"code","ERR_JWE_DECRYPTION_FAILED");p(class extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JWE_INVALID")}},"code","ERR_JWE_INVALID");class Vo extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JWS_INVALID")}}p(Vo,"code","ERR_JWS_INVALID");class Go extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JWT_INVALID")}}p(Go,"code","ERR_JWT_INVALID");p(class extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JWK_INVALID")}},"code","ERR_JWK_INVALID");class Xo extends Jo{constructor(){super(...arguments),p(this,"code","ERR_JWKS_INVALID")}}p(Xo,"code","ERR_JWKS_INVALID");class qo extends Jo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"no applicable key found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWKS_NO_MATCHING_KEY")}}p(qo,"code","ERR_JWKS_NO_MATCHING_KEY");class Yo extends Jo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"multiple matching keys found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),p(this,Symbol.asyncIterator,g(function*(){})),p(this,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS")}}p(Yo,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS");class Bo extends Jo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"request timed out",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWKS_TIMEOUT")}}p(Bo,"code","ERR_JWKS_TIMEOUT");class Qo extends Jo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"signature verification failed",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED")}}p(Qo,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED");const $o=e=>{if("CryptoKey"===(null==e?void 0:e[Symbol.toStringTag]))return!0;try{return e instanceof CryptoKey}catch(e){return!1}},ei=e=>$o(e)||(e=>"KeyObject"===(null==e?void 0:e[Symbol.toStringTag]))(e);function ti(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);const t=atob(e),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}const ni="The input to be decoded is not correctly encoded.";function oi(e){if(Uint8Array.fromBase64)try{return Uint8Array.fromBase64("string"==typeof e?e:Wo.decode(e),{alphabet:"base64url"})}catch(e){throw new TypeError(ni,{cause:e})}let t=e;if(t instanceof Uint8Array&&(t=Wo.decode(t)),t.includes("+")||t.includes("/"))throw new TypeError(ni);t=t.replace(/-/g,"+").replace(/_/g,"/");try{return ti(t)}catch(e){throw new TypeError(ni)}}function ii(e){let t=e;return"string"==typeof t&&(t=jo.encode(t)),Uint8Array.prototype.toBase64?t.toBase64({alphabet:"base64url",omitPadding:!0}):function(e){if(Uint8Array.prototype.toBase64)return e.toBase64();const t=[];for(let n=0;n<e.length;n+=32768)t.push(String.fromCharCode.apply(null,e.subarray(n,n+32768)));return btoa(t.join(""))}(t).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}function ri(e){if("object"!=typeof e||null===e||"[object Object]"!==Object.prototype.toString.call(e))return!1;const t=Object.getPrototypeOf(e);return null===t||null===Object.getPrototypeOf(t)}function si(e){return ri(e)&&Array.isArray(e.keys)&&Array.from(e.keys).every(ri)}function ai(e,t,n){try{return oi(e)}catch(e){throw new n("Failed to base64url decode the ".concat(t))}}async function ci(e,t){var n,o,i,r;if("RSA"===t.kty&&"oth"in t&&void 0!==t.oth)throw new Fo('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');if(!e.kty.includes(t.kty))throw new Fo('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');const s=null!==(n=null===(o=e.resolve)||void 0===o?void 0:o.call(e,{kty:t.kty,crv:t.crv}))&&void 0!==n?n:e.subtle,a=!(!t.d&&!t.priv),c=m({},t);return"AKP"!==c.kty&&delete c.alg,delete c.use,crypto.subtle.importKey("jwk",c,s,null!==(i=t.ext)&&void 0!==i?i:!a,null!==(r=t.key_ops)&&void 0!==r?r:e.usages[a?1:0])}function ui(e){return m({__proto__:null},e)}const li=e=>e[Symbol.toStringTag];function di(e,t,n){const o=e.alg,i=e.secret,r="decrypt"===n||"sign"===n;if(i&&t instanceof Uint8Array)return[hi,t];if(ri(t)){const s=function(e){const t=ui(e);if(void 0!==t.ext&&"boolean"!=typeof t.ext)throw new TypeError('"ext" (Extractable) Parameter must be a boolean');if(void 0!==t.key_ops){const e=t.key_ops,n=Array.isArray(e)?[...e]:void 0;if(!n||n.some(e=>"string"!=typeof e)||new Set(n).size!==n.length)throw new TypeError('"key_ops" (Key Operations) Parameter must be an array of unique strings');t.key_ops=n}return t}(t);if("string"!=typeof s.kty)throw new TypeError(i?zo(o,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"):zo(o,t,"CryptoKey","KeyObject","JSON Web Key"));if(!(i?"oct"===s.kty&&"string"==typeof s.k:"oct"!==s.kty&&(r?"AKP"===s.kty&&"string"==typeof s.priv||"string"==typeof s.d:void 0===s.d&&void 0===s.priv)))throw new TypeError(i?'JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present':"JSON Web Key for this operation must be a ".concat(r?"private":"public"," JWK"));return((e,t,n)=>{const o=e.alg;if(void 0!==t.use){const e="sign"===n||"verify"===n?"sig":"enc";if(t.use!==e)throw new TypeError('Invalid key for this operation, its "use" must be "'.concat(e,'" when present'))}if(void 0!==t.alg&&t.alg!==o)throw new TypeError('Invalid key for this operation, its "alg" must be "'.concat(o,'" when present'));if(Array.isArray(t.key_ops)){var i;const o="encrypt"===n||"decrypt"===n?null===(i=e.ops)||void 0===i?void 0:i["encrypt"===n?0:1]:n;if(o&&!t.key_ops.includes(o))throw new TypeError('Invalid key for this operation, its "key_ops" must include "'.concat(o,'" when present'))}})(e,s,n),[mi,t,s]}if(!ei(t))throw new TypeError(i?zo(o,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"):zo(o,t,"CryptoKey","KeyObject","JSON Web Key"));if(i){if("secret"!==t.type)throw new TypeError("".concat(li(t),' instances for symmetric algorithms must be of type "secret"'))}else{if("secret"===t.type)throw new TypeError("".concat(li(t),' instances for asymmetric algorithms must not be of type "secret"'));const e=r?"private":"public";if(("public"===t.type||"private"===t.type)&&t.type!==e){const o="sign"===n?"signing":"verify"===n?"verifying":"".concat(n.slice(0,-1),"tion");throw new TypeError("".concat(li(t)," instances for asymmetric algorithm ").concat(o,' must be of type "').concat(e,'"'))}}return $o(t)?[pi,t]:[fi,t]}const hi=0,pi=1,fi=2,mi=3;let yi;const wi={__proto__:null,prime256v1:"P-256",secp384r1:"P-384",secp521r1:"P-521"};function gi(e,t,n){yi||(yi=new WeakMap);const o=yi.get(e);return n&&(o?o[t]=n:yi.set(e,{[t]:n})),null!=n?n:null==o?void 0:o[t]}const vi=async(e,t,n)=>{var o;return null!==(o=gi(e,n.alg))&&void 0!==o?o:gi(e,n.alg,await ci(n,m(m({},t),{},{alg:n.alg})))};async function bi(e,t,n){const o=di(e,t,n);switch(o[0]){case hi:case pi:return o[1];case mi:{const t=o[1],n=o[2];if("oct"===n.kty)return oi(n.k);if(!Object.isFrozen(t)){const e=t.key_ops;Array.isArray(e)&&Object.freeze(e),Object.freeze(t)}return vi(t,n,e)}case fi:{const t=o[1];return"secret"===t.type?t.export():"toCryptoKey"in t&&"function"==typeof t.toCryptoKey?((e,t)=>{var n,o,i;const r=gi(e,t.alg);if(r)return r;const s="public"===e.type,a=t.usages[s?0:1],c=e.asymmetricKeyType,u=wi[null===(n=e.asymmetricKeyDetails)||void 0===n?void 0:n.namedCurve],l=null!==(o=null===(i=t.resolve)||void 0===i?void 0:i.call(t,{crv:u,asymmetricKeyType:c}))&&void 0!==o?o:t.subtle;return gi(e,t.alg,e.toCryptoKey(l,s,a))})(t,e):vi(t,t.export({format:"jwk"}),e)}}}function _i(e){const t={__proto__:null};for(const n in e)t[n]=m(m({},e[n]),{},{alg:n});return t}const ki=[["encrypt","wrapKey"],["decrypt","unwrapKey"]],Si=[[],["deriveBits"]],Ti=[[],[]];function Pi(e){return{kty:["RSA"],subtle:{name:"RSA-OAEP",hash:"SHA-".concat(e)},usages:ki,ops:["wrapKey","unwrapKey"]}}function Ei(){return{kty:["EC","OKP"],subtle:{name:"ECDH"},resolve:e=>{let t=e.kty,n=e.crv,o=e.asymmetricKeyType;if("X25519"===n||"x25519"===o)return{name:"X25519"};if("OKP"===t)throw new Fo('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');return{name:"ECDH",namedCurve:n}},usages:Si,ops:[void 0,"deriveBits"]}}function Ci(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return{kty:["oct"],secret:!0,subtle:{name:t?"AES-GCM":"AES-KW",length:e},usages:Ti,ops:t?["encrypt","decrypt"]:["wrapKey","unwrapKey"]}}function Ri(){return{kty:["oct"],secret:!0,subtle:{name:"PBKDF2"},usages:Ti,ops:["deriveBits","deriveBits"]}}const Ai=_i({dir:{kty:["oct"],secret:!0,subtle:{name:"AES-GCM"},usages:Ti,ops:["encrypt","decrypt"]},"RSA-OAEP":Pi(1),"RSA-OAEP-256":Pi(256),"RSA-OAEP-384":Pi(384),"RSA-OAEP-512":Pi(512),"ECDH-ES":Ei(),"ECDH-ES+A128KW":Ei(),"ECDH-ES+A192KW":Ei(),"ECDH-ES+A256KW":Ei(),A128KW:Ci(128),A192KW:Ci(192),A256KW:Ci(256),A128GCMKW:Ci(128,!0),A192GCMKW:Ci(192,!0),A256GCMKW:Ci(256,!0),"PBES2-HS256+A128KW":Ri(),"PBES2-HS384+A192KW":Ri(),"PBES2-HS512+A256KW":Ri()}),xi=["encrypt","decrypt"];function Ii(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return{kty:["oct"],secret:!0,subtle:{name:t?"AES-CBC":"AES-GCM",length:e},usages:Ti,ops:xi,cekBits:e,ivBits:t?128:96,cbc:t}}_i({A128GCM:Ii(128),A192GCM:Ii(192),A256GCM:Ii(256),"A128CBC-HS256":Ii(256,!0),"A192CBC-HS384":Ii(384,!0),"A256CBC-HS512":Ii(512,!0)});const Oi={__proto__:null,b64:!0};function ji(e,t){if(void 0!==t&&(!Array.isArray(t)||t.some(e=>"string"!=typeof e)))throw new TypeError('"'.concat(e,'" option must be an array of strings'));if(t)return new Set(t)}function Wi(e,t,n,o,i){if(void 0!==i.crit&&void 0===(null==o?void 0:o.crit))throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!o||void 0===o.crit)return[];if(!Array.isArray(o.crit)||0===o.crit.length||o.crit.some(e=>"string"!=typeof e||0===e.length))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');const r=void 0===n?t:m(m({__proto__:null},n),t);for(const t of o.crit){if(!(t in r))throw new Fo('Extension Header Parameter "'.concat(t,'" is not recognized'));if(!Object.hasOwn(i,t)||void 0===i[t])throw new e('Extension Header Parameter "'.concat(t,'" is missing'));if(r[t]&&(!Object.hasOwn(o,t)||void 0===o[t]))throw new e('Extension Header Parameter "'.concat(t,'" MUST be integrity protected'))}return o.crit}function Mi(e,t){if(t.includes("b64")){const t=e.b64;if("boolean"!=typeof t)throw new Vo('The "b64" (base64url-encode payload) Header Parameter must be a boolean');return t}return!0}var Ni,Ki;let Ui,Li;if("undefined"==typeof navigator||null===(Ni=navigator.userAgent)||void 0===Ni||null===(Ki=Ni.startsWith)||void 0===Ki||!Ki.call(Ni,"Mozilla/5.0 ")){const e="v6.8.4";Li="".concat("openid-client","/").concat(e),Ui={"user-agent":Li}}const zi=e=>Ji.get(e);let Ji,Di;function Zi(e){return void 0!==e?yn(e):(Di||(Di=new WeakMap),(e,t,n,o)=>{let i;return(i=Di.get(t))||(!function(e,t){if("string"!=typeof e)throw Xi("".concat(t," must be a string"),Gi);if(0===e.length)throw Xi("".concat(t," must not be empty"),Vi)}(t.client_secret,'"metadata.client_secret"'),i=yn(t.client_secret),Di.set(t,i)),i(e,t,n,o)})}const Hi=Mn,Fi=Jt,Vi="ERR_INVALID_ARG_VALUE",Gi="ERR_INVALID_ARG_TYPE";function Xi(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}function qi(e){return async function(e){return an(e,"codeVerifier"),qt(await crypto.subtle.digest("SHA-256",Vt(e)))}(e)}function Yi(){return un()}class Bi extends Error{constructor(e,t){var n;super(e,t),p(this,"code",void 0),this.name=this.constructor.name,this.code=null==t?void 0:t.code,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function Qi(e,t,n){return new Bi(e,{cause:t,code:n})}function $i(e){if(e instanceof TypeError||e instanceof Bi||e instanceof kn||e instanceof Sn||e instanceof Tn)throw e;if(e instanceof Bt)switch(e.code){case ho:throw Qi("only requests to HTTPS are allowed",e,e.code);case po:throw Qi("only requests to HTTP or HTTPS are allowed",e,e.code);case lo:throw Qi("unexpected HTTP response status code",e.cause,e.code);case uo:throw Qi("unexpected response content-type",e.cause,e.code);case ao:throw Qi("parsing error occured",e,e.code);case co:throw Qi("invalid response encountered",e,e.code);case mo:throw Qi("unexpected JWT claim value encountered",e,e.code);case yo:throw Qi("unexpected JSON attribute value encountered",e,e.code);case fo:throw Qi("JWT timestamp claim value failed validation",e,e.code);default:throw Qi(e.message,e,e.code)}if(e instanceof Yt)throw Qi("unsupported operation",e,e.code);if(e instanceof DOMException)switch(e.name){case"OperationError":throw Qi("runtime operation error",e,io);case"NotSupportedError":throw Qi("runtime unsupported operation",e,io);case"TimeoutError":throw Qi("operation timed out",e,"OAUTH_TIMEOUT");case"AbortError":throw Qi("operation aborted",e,"OAUTH_ABORT")}throw new Bi("something went wrong",{cause:e})}async function er(e,t,n,o,i){const r=await async function(e,t){var n,o;if(!(e instanceof URL))throw Xi('"server" must be an instance of URL',Gi);const i=!e.href.includes("/.well-known/"),r=null!==(n=null==t?void 0:t.timeout)&&void 0!==n?n:30,s=AbortSignal.timeout(1e3*r),a=await(i?rn(e,{algorithm:null==t?void 0:t.algorithm,[Jt]:null==t?void 0:t[Fi],[Ut]:null==t||null===(o=t.execute)||void 0===o?void 0:o.includes(cr),signal:s,headers:new Headers(Ui)}):((null==t?void 0:t[Fi])||fetch)((vn(e,null==t||null===(c=t.execute)||void 0===c||!c.includes(cr)),e.href),{headers:Object.fromEntries(new Headers(m({accept:"application/json"},Ui)).entries()),body:void 0,method:"GET",redirect:"manual",signal:s})).then(e=>async function(e,t){const n=e;if(!(n instanceof URL)&&n!==Io)throw Kt('"expectedIssuerIdentifier" must be an instance of URL',Nt);if(!Wt(t,Response))throw Kt('"response" must be an instance of Response',Nt);if(200!==t.status)throw Qt('"response" is not a conform Authorization Server Metadata response (unexpected HTTP status code)',lo,t);bo(t);const o=await xo(t);if(an(o.issuer,'"response" body "issuer" property',co,{body:o}),n!==Io&&new URL(o.issuer).href!==n.href)throw Qt('"response" body "issuer" property does not match the expected value',yo,{expected:n.href,body:o,attribute:"issuer"});return o}(Io,e)).catch($i);var c;i&&new URL(a.issuer).href!==e.href&&(function(e,t,n){return!("https://login.microsoftonline.com"!==e.origin||null!=n&&n.algorithm&&"oidc"!==n.algorithm||(t[tr]=!0,0))}(e,a,t)||function(e,t){return!(!e.hostname.endsWith(".b2clogin.com")||null!=t&&t.algorithm&&"oidc"!==t.algorithm)}(e,t)||(()=>{throw new Bi("discovered metadata issuer does not match the expected issuer",{code:yo,cause:{expected:e.href,body:a,attribute:"issuer"}})})());return a}(e,i),s=new nr(r,t,n,o);let a=zi(s);if(null!=i&&i[Fi]&&(a.fetch=i[Fi]),null!=i&&i.timeout&&(a.timeout=i.timeout),null!=i&&i.execute)for(const e of i.execute)e(s);return s}new TextDecoder;const tr=Symbol();class nr{constructor(e,t,n,o){var i,r,s,a,c;if("string"!=typeof t||!t.length)throw Xi('"clientId" must be a non-empty string',Gi);if("string"==typeof n&&(n={client_secret:n}),void 0!==(null===(i=n)||void 0===i?void 0:i.client_id)&&t!==n.client_id)throw Xi('"clientId" and "metadata.client_id" must be the same',Vi);const u=m(m({},structuredClone(n)),{},{client_id:t});let l;u[Lt]=null!==(r=null===(s=n)||void 0===s?void 0:s[Lt])&&void 0!==r?r:0,u[zt]=null!==(a=null===(c=n)||void 0===c?void 0:c[zt])&&void 0!==a?a:30,l=o||("string"==typeof u.client_secret&&u.client_secret.length?Zi(u.client_secret):(e,t,n,o)=>{n.set("client_id",t.client_id)});let d=Object.freeze(u);const h=structuredClone(e);tr in e&&(h[Oo]=t=>{let n=t.claims.tid;return e.issuer.replace("{tenantid}",n)});let p=Object.freeze(h);Ji||(Ji=new WeakMap),Ji.set(this,{__proto__:null,as:p,c:d,auth:l,tlsOnly:!0,jwksCache:{}})}serverMetadata(){const e=structuredClone(zi(this).as);return function(e){Object.defineProperties(e,function(e){return{supportsPKCE:{__proto__:null,value(){var t;let n=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"S256";return!0===(null===(t=e.code_challenge_methods_supported)||void 0===t?void 0:t.includes(n))}}}}(e))}(e),e}clientMetadata(){return structuredClone(zi(this).c)}get timeout(){return zi(this).timeout}set timeout(e){zi(this).timeout=e}get[Fi](){return zi(this).fetch}set[Fi](e){zi(this).fetch=e}}function or(e){Object.defineProperties(e,function(e){let t;if(void 0!==e.expires_in){const n=new Date;n.setSeconds(n.getSeconds()+e.expires_in),t=n.getTime()}return{expiresIn:{__proto__:null,value(){if(t){const e=Date.now();return t>e?Math.floor((t-e)/1e3):0}}},claims:{__proto__:null,value(){try{return Dn(this)}catch(e){return}}}}}(e))}async function ir(e,t,n){var o;let i=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const r=null===(o=e.headers.get("retry-after"))||void 0===o?void 0:o.trim();if(void 0===r)return;let s;if(/^\d+$/.test(r))s=parseInt(r,10);else{const e=new Date(r);if(Number.isFinite(e.getTime())){const t=new Date,n=e.getTime()-t.getTime();n>0&&(s=Math.ceil(n/1e3))}}if(i&&!Number.isFinite(s))throw new Bt("invalid Retry-After header value",{cause:e});s>t&&await rr(s-t,n)}function rr(e,t){return new Promise((n,o)=>{const i=e=>{try{t.throwIfAborted()}catch(e){return void o(e)}if(e<=0)return void n();const r=Math.min(e,5);setTimeout(()=>i(e-r),1e3*r)};i(e)})}async function sr(e,t){fr(e);const n=zi(e),o=n.as,i=n.c,r=n.auth,s=n.fetch,a=n.tlsOnly,c=n.timeout;return async function(e,t,n,o,i){fn(e),mn(t);const r=_n(e,"backchannel_authentication_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[Ut])),s=new URLSearchParams(o);s.set("client_id",t.client_id);const a=tn(null==i?void 0:i.headers);return a.set("accept","application/json"),Un(e,t,n,r,s,a,i)}(o,i,r,t,{[Jt]:s,[Ut]:!a,headers:new Headers(Ui),signal:mr(c)}).then(e=>async function(e,t,n){if(fn(e),mn(t),!Wt(n,Response))throw Kt('"response" must be an instance of Response',Nt);await On(n,200,"Backchannel Authentication Endpoint"),bo(n);const o=await xo(n);an(o.auth_req_id,'"response" body "auth_req_id" property',co,{body:o});let i="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return sn(i,!0,'"response" body "expires_in" property',co,{body:o}),o.expires_in=i,void 0!==o.interval&&sn(o.interval,!1,'"response" body "interval" property',co,{body:o}),o}(o,i,e)).catch($i)}async function ar(e,t,n,o){var i,r;fr(e),n=new URLSearchParams(n);let s=null!==(i=t.interval)&&void 0!==i?i:5;const a=null!==(r=null==o?void 0:o.signal)&&void 0!==r?r:AbortSignal.timeout(1e3*t.expires_in);try{await rr(s,a)}catch(e){$i(e)}const c=zi(e),u=c.as,l=c.c,d=c.auth,h=c.fetch,p=c.tlsOnly,f=c.nonRepudiation,y=c.timeout,w=c.decrypt,g=(i,r)=>ar(e,m(m({},t),{},{interval:i}),n,m(m({},o),{},{signal:a,flag:r})),v=function(e,t){const n=mr(t);if(!n)return{signal:e,cleanup(){}};const o=new AbortController,i=e=>{const t=e.target;o.abort(t.reason)};return e.aborted?o.abort(e.reason):n.aborted?o.abort(n.reason):(e.addEventListener("abort",i,{once:!0}),n.addEventListener("abort",i,{once:!0})),{signal:o.signal,cleanup(){e.removeEventListener("abort",i),n.removeEventListener("abort",i)}}}(a,y),b=await async function(e,t,n,o,i){fn(e),mn(t),an(o,'"authReqId"');const r=new URLSearchParams(null==i?void 0:i.additionalParameters);return r.set("auth_req_id",o),Ln(e,t,n,"urn:openid:params:grant-type:ciba",r,i)}(u,l,d,t.auth_req_id,{[Jt]:h,[Ut]:!p,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Ui),signal:v.signal}).catch($i).finally(v.cleanup);var _;if(503===b.status&&b.headers.has("retry-after"))return await ir(b,s,a,!0),await(null===(_=b.body)||void 0===_?void 0:_.cancel()),g(s);const k=async function(e,t,n,o){return Zn(e,t,n,void 0,null==o?void 0:o[Zt],null==o?void 0:o.recognizedTokenTypes)}(u,l,b,{[Zt]:w});let S;try{S=await k}catch(e){if(wr(e,o))return g(s,gr);if(e instanceof kn)switch(e.error){case"slow_down":s+=5;case"authorization_pending":return await ir(e.response,s,a),g(s)}$i(e)}return S.id_token&&await(null==f?void 0:f(b)),or(S),S}function cr(e){zi(e).tlsOnly=!1}async function ur(e,t,n,o,i){if(fr(e),!((null==i?void 0:i.flag)===gr||t instanceof URL||function(e,t){try{return Object.getPrototypeOf(e)[Symbol.toStringTag]===t}catch(e){return!1}}(t,"Request")))throw Xi('"currentUrl" must be an instance of URL, or Request',Gi);let r,s;const a=zi(e),c=a.as,u=a.c,l=a.auth,d=a.fetch,h=a.tlsOnly,p=a.jarm,f=a.hybrid,y=a.nonRepudiation,g=a.timeout,v=a.decrypt,b=a.implicit;if((null==i?void 0:i.flag)===gr)r=i.authResponse,s=i.redirectUri;else{if(!(t instanceof URL)){const e=t;switch(t=new URL(t.url),e.method){case"GET":break;case"POST":const n=new URLSearchParams(await To(e));if(f)t.hash=n.toString();else for(const e of n.entries()){var _=w(e,2);const n=_[0],o=_[1];t.searchParams.append(n,o)}break;default:throw Xi("unexpected Request HTTP method",Vi)}}switch(s=function(e){return(e=new URL(e)).search="",e.hash="",e.href}(t),!0){case!!p:r=await p(t,null==n?void 0:n.expectedState);break;case!!f:r=await f(t,null==n?void 0:n.expectedNonce,null==n?void 0:n.expectedState,null==n?void 0:n.maxAge);break;case!!b:throw new TypeError("authorizationCodeGrant() cannot be used by response_type=id_token clients");default:try{r=Ao(c,u,t.searchParams,null==n?void 0:n.expectedState)}catch(e){$i(e)}}}const k=await async function(e,t,n,o,i,r,s){if(fn(e),mn(t),!qn.has(o))throw Kt('"callbackParameters" must be an instance of URLSearchParams obtained from "validateAuthResponse()", or "validateJwtAuthResponse()',Mt);an(i,'"redirectUri"');const a=Eo(o,"code");if(!a)throw Qt('no authorization code in "callbackParameters"',co);const c=new URLSearchParams(null==s?void 0:s.additionalParameters);return c.set("redirect_uri",i),c.set("code",a),r!==Yn&&(an(r,'"codeVerifier"'),c.set("code_verifier",r)),Ln(e,t,n,"authorization_code",c,s)}(c,u,l,r,s,(null==n?void 0:n.pkceCodeVerifier)||Yn,{additionalParameters:o,[Jt]:d,[Ut]:!h,DPoP:null==i?void 0:i.DPoP,headers:new Headers(Ui),signal:mr(g)}).catch($i);"string"!=typeof(null==n?void 0:n.expectedNonce)&&"number"!=typeof(null==n?void 0:n.maxAge)||(n.idTokenExpected=!0);const S=to(c,u,k,{expectedNonce:null==n?void 0:n.expectedNonce,maxAge:null==n?void 0:n.maxAge,requireIdToken:null==n?void 0:n.idTokenExpected,[Zt]:v});let T;try{T=await S}catch(t){if(wr(t,i))return ur(e,void 0,n,o,m(m({},i),{},{flag:gr,authResponse:r,redirectUri:s}));$i(t)}return T.id_token&&await(null==y?void 0:y(k)),or(T),T}async function lr(e,t,n,o){fr(e),n=new URLSearchParams(n);const i=zi(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.nonRepudiation,d=i.timeout,h=i.decrypt,p=await async function(e,t,n,o,i){fn(e),mn(t),an(o,'"refreshToken"');const r=new URLSearchParams(null==i?void 0:i.additionalParameters);return r.set("refresh_token",o),Ln(e,t,n,"refresh_token",r,i)}(r,s,a,t,{[Jt]:c,[Ut]:!u,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Ui),signal:mr(d)}).catch($i),f=async function(e,t,n,o){return Zn(e,t,n,void 0,null==o?void 0:o[Zt],null==o?void 0:o.recognizedTokenTypes)}(r,s,p,{[Zt]:h});let y;try{y=await f}catch(i){if(wr(i,o))return lr(e,t,n,m(m({},o),{},{flag:gr}));$i(i)}return y.id_token&&await(null==l?void 0:l(p)),or(y),y}async function dr(e,t,n){fr(e),t=new URLSearchParams(t);const o=zi(e),i=o.as,r=o.c,s=o.auth,a=o.fetch,c=o.tlsOnly,u=o.timeout,l=await async function(e,t,n,o,i){return fn(e),mn(t),Ln(e,t,n,"client_credentials",new URLSearchParams(o),i)}(i,r,s,t,{[Jt]:a,[Ut]:!c,DPoP:null==n?void 0:n.DPoP,headers:new Headers(Ui),signal:mr(u)}).catch($i),d=async function(e,t,n,o){return Zn(e,t,n,void 0,null==o?void 0:o[Zt],null==o?void 0:o.recognizedTokenTypes)}(i,r,l);let h;try{h=await d}catch(o){if(wr(o,n))return dr(e,t,m(m({},n),{},{flag:gr}));$i(o)}return or(h),h}function hr(e,t){fr(e);const n=zi(e),o=n.as,i=n.c,r=n.tlsOnly,s=n.hybrid,a=n.jarm,c=n.implicit,u=_n(o,"authorization_endpoint",!1,r);if((t=new URLSearchParams(t)).has("client_id")||t.set("client_id",i.client_id),!t.has("request_uri")&&!t.has("request")){if(t.has("response_type")||t.set("response_type",s?"code id_token":c?"id_token":"code"),c&&!t.has("nonce"))throw Xi("response_type=id_token clients must provide a nonce parameter in their authorization request parameters",Vi);a&&t.set("response_mode","jwt")}for(const e of t.entries()){var l=w(e,2);const t=l[0],n=l[1];u.searchParams.append(t,n)}return u}async function pr(e,t,n){fr(e);const o=hr(e,t),i=zi(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.timeout,d=await async function(e,t,n,o,i){var r;fn(e),mn(t);const s=_n(e,"pushed_authorization_request_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[Ut])),a=new URLSearchParams(o);a.set("client_id",t.client_id);const c=tn(null==i?void 0:i.headers);c.set("accept","application/json"),void 0!==(null==i?void 0:i.DPoP)&&(jn(i.DPoP),await i.DPoP.addProof(s,c,"POST"));const u=await Un(e,t,n,s,a,c,i);return null==i||null===(r=i.DPoP)||void 0===r||r.cacheNonce(u,s),u}(r,s,a,o.searchParams,{[Jt]:c,[Ut]:!u,DPoP:null==n?void 0:n.DPoP,headers:new Headers(Ui),signal:mr(l)}).catch($i),h=async function(e,t,n){if(fn(e),mn(t),!Wt(n,Response))throw Kt('"response" must be an instance of Response',Nt);await On(n,201,"Pushed Authorization Request Endpoint"),bo(n);const o=await xo(n);an(o.request_uri,'"response" body "request_uri" property',co,{body:o});let i="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return sn(i,!0,'"response" body "expires_in" property',co,{body:o}),o.expires_in=i,o}(r,s,d);let p;try{p=await h}catch(o){if(wr(o,n))return pr(e,t,m(m({},n),{},{flag:gr}));$i(o)}return hr(e,{request_uri:p.request_uri})}function fr(e){if(!(e instanceof nr))throw Xi('"config" must be an instance of Configuration',Gi);if(Object.getPrototypeOf(e)!==nr.prototype)throw Xi("subclassing Configuration is not allowed",Vi)}function mr(e){return e?AbortSignal.timeout(1e3*e):void 0}async function yr(e,t,n,o){fr(e);const i=zi(e),r=i.as,s=i.c,a=i.fetch,c=i.tlsOnly,u=i.nonRepudiation,l=i.timeout,d=i.decrypt,h=await Wn(r,s,t,{[Jt]:a,[Ut]:!c,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Ui),signal:mr(l)}).catch($i);let p,f=Kn(r,s,n,h,{[Zt]:d});try{p=await f}catch(i){if(wr(i,o))return yr(e,t,n,m(m({},o),{},{flag:gr}));$i(i)}return"application/jwt"===Nn(h)&&await(null==u?void 0:u(h)),p}function wr(e,t){return!(null==t||!t.DPoP||t.flag===gr)&&function(e){if(e instanceof Tn){const t=e.cause,n=t[0];return 1===t.length&&"dpop"===n.scheme&&"use_dpop_nonce"===n.parameters.error}return e instanceof kn&&"use_dpop_nonce"===e.error}(e)}Object.freeze(nr.prototype);const gr=Symbol();async function vr(e,t,n,o){fr(e);const i=zi(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.timeout,d=i.decrypt,h=i.nonRepudiation,p=await async function(e,t,n,o,i,r){return fn(e),mn(t),an(o,'"grantType"'),Ln(e,t,n,o,new URLSearchParams(i),r)}(r,s,a,t,new URLSearchParams(n),{[Jt]:c,[Ut]:!u,DPoP:null==o?void 0:o.DPoP,headers:new Headers(Ui),signal:mr(l)}).catch($i);let f;"urn:ietf:params:oauth:grant-type:token-exchange"===t&&(f={n_a:()=>{}});const y=async function(e,t,n,o){return Zn(e,t,n,void 0,null==o?void 0:o[Zt],null==o?void 0:o.recognizedTokenTypes)}(r,s,p,{[Zt]:d,recognizedTokenTypes:f});let w;try{w=await y}catch(i){if(wr(i,o))return vr(e,t,n,m(m({},o),{},{flag:gr}));$i(i)}return w.id_token&&await(null==h?void 0:h(p)),or(w),w}async function br(e,t,n){fr(e);const o=zi(e),i=o.as,r=o.c,s=o.auth,a=o.fetch,c=o.tlsOnly,u=o.timeout;return async function(e,t,n,o,i){fn(e),mn(t),an(o,'"token"');const r=_n(e,"revocation_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[Ut])),s=new URLSearchParams(null==i?void 0:i.additionalParameters);s.set("token",o);const a=tn(null==i?void 0:i.headers);return a.delete("accept"),Un(e,t,n,r,s,a,i)}(i,r,s,t,{[Jt]:a,[Ut]:!c,additionalParameters:new URLSearchParams(n),headers:new Headers(Ui),signal:mr(u)}).then(vo).catch($i)}async function _r(e,t,n){return t instanceof Uint8Array?crypto.subtle.importKey("raw",t,e.subtle,!1,[n]):(Lo(t,e.subtle,n),e.minRsaBits&&function(e,t){const n=t.algorithm.modulusLength;if("number"!=typeof n||n<2048)throw new TypeError("".concat(e," requires key modulusLength to be 2048 bits or larger"))}(e.alg,t),t)}const kr=[["verify"],["sign"]];function Sr(e){const t={name:"HMAC",hash:"SHA-".concat(e)};return{kty:["oct"],secret:!0,subtle:t,signing:t,usages:kr}}function Tr(e,t){const n={name:t?"RSA-PSS":"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(e)};return{kty:["RSA"],subtle:n,signing:t?m(m({},n),{},{saltLength:t}):n,usages:kr,minRsaBits:2048}}function Pr(e,t){return{kty:["EC"],crv:e,subtle:{name:"ECDSA",namedCurve:e},signing:{name:"ECDSA",hash:"SHA-".concat(t)},usages:kr}}function Er(){const e={name:"Ed25519"};return{kty:["OKP"],crv:"Ed25519",subtle:e,signing:e,usages:kr}}function Cr(e){const t={name:"ML-DSA-".concat(e)};return{kty:["AKP"],subtle:t,signing:t,usages:kr}}const Rr=_i({HS256:Sr(256),HS384:Sr(384),HS512:Sr(512),RS256:Tr(256),RS384:Tr(384),RS512:Tr(512),PS256:Tr(256,32),PS384:Tr(384,48),PS512:Tr(512,64),ES256:Pr("P-256",256),ES384:Pr("P-384",384),ES512:Pr("P-521",512),EdDSA:Er(),Ed25519:Er(),"ML-DSA-44":Cr(44),"ML-DSA-65":Cr(65),"ML-DSA-87":Cr(87)});function Ar(e){const t="string"==typeof e?Rr[e]:void 0;if(!t)throw new Fo("alg ".concat(e," is not supported either by JOSE or your javascript runtime"));return t}function xr(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:void 0===e?{}:function(e,t,n){let o;try{o=JSON.parse(Mo.decode(oi(e)))}catch(e){throw new t(n)}if(!ri(o))throw new t(n);return o}(e,Vo,"JWS Protected Header is invalid");return t}async function Ir(e,t,n,o,i,r,s){var a;let c=!1;"function"==typeof n&&(n=await n(i,e),c=!0);const u="string"==typeof s,l=Ar(r),d=No(void 0!==o?Ko(o):new Uint8Array,Ko("."),u?null!==(a=t[2])&&void 0!==a?a:t[2]=function(e,t,n){try{return Ko(e)}catch(e){throw new n("The ".concat(t," is not a valid base64url string"))}}(s,"payload",Vo):s),h=ai(e.signature,"signature",Vo),p=await bi(l,n,"verify");if(!await async function(e,t,n,o){const i=await _r(e,t,"verify");try{return await crypto.subtle.verify(e.signing,i,n,o)}catch(e){return!1}}(l,p,h,d))throw new Qo;return[u?ai(s,"payload",Vo):s,i,u,p,c]}async function Or(e,t,n){if(e instanceof Uint8Array&&(e=Wo.decode(e)),"string"!=typeof e)throw new Vo("Compact JWS must be a string or Uint8Array");const o=e.split("."),i=o[0],r=o[1],s=o[2];if(3!==o.length)throw new Vo("Invalid Compact JWS");const a={payload:r,protected:i,signature:s},c=xr(i),u=function(e,t,n){const o=Mi(e,Wi(Vo,Oi,n[1],e,t)),i=t.alg;if("string"!=typeof i||!i)throw new Vo('JWS "alg" (Algorithm) Header Parameter missing or invalid');if(n[0]&&!n[0].has(i))throw new Ho('"alg" (Algorithm) Header Parameter value not allowed');return[o,i]}(c,c,t),l=w(u,2),d=l[0],h=l[1],p=d?r:function(e){try{return Ko(e)}catch(e){throw new Vo("JWS Compact Serialization payload must use only ASCII characters")}}(r);return Ir(a,t,n,i,c,h,p)}const jr=e=>Math.floor(e.getTime()/1e3),Wr={s:1,m:60,h:3600,d:86400,w:604800,y:31557600},Mr=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i,Nr="check_failed";function Kr(){throw new TypeError("Invalid time period format")}function Ur(e){"string"!=typeof e&&Kr();const t=Mr.exec(e);(!t||t[4]&&t[1])&&Kr();const n=parseFloat(t[2]),o=Math.round(n*Wr[t[3][0].toLowerCase()]);return Number.isFinite(o)||Kr(),"-"===t[1]||"ago"===t[4]?-o:o}function Lr(e,t){if(!Number.isFinite(t))throw new TypeError("Invalid ".concat(e," input"));return t}function zr(e,t){if("string"!=typeof t)throw new TypeError('"'.concat(e,'" claim must be a string'))}function Jr(e,t){return"number"==typeof e?Lr(t,e):e instanceof Date?Lr(t,jr(e)):jr(new Date)+Ur(e)}const Dr=e=>{const t=e.toLowerCase();return e.includes("/")?t:"application/".concat(t)};function Zr(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];const o=e[t];if(void 0!==o||n){if("number"!=typeof o)throw new Do('"'.concat(t,'" claim must be a number'),e,t,"invalid");return o}}function Hr(e,t){throw new Do('unexpected "'.concat(t,'" claim value'),e,t,Nr)}function Fr(e,t){let n,o=arguments.length>2&&void 0!==arguments[2]?arguments[2]:{};try{n=JSON.parse(Mo.decode(t))}catch(e){}if(!ri(n))throw new Go("JWT Claims Set must be a top-level JSON object");const i=o.typ;if(void 0!==i&&("string"!=typeof e.typ||Dr(e.typ)!==Dr(i)))throw new Do('unexpected "typ" JWT header value',n,"typ",Nr);const r=o.requiredClaims,s=void 0===r?[]:r,a=o.issuer,c=o.subject,u=o.audience,l=o.maxTokenAge,d=[...s];void 0!==l&&d.push("iat"),void 0!==u&&d.push("aud"),void 0!==c&&d.push("sub"),void 0!==a&&d.push("iss");for(const e of new Set(d.reverse()))if(!Object.hasOwn(n,e))throw new Do('missing required "'.concat(e,'" claim'),n,e,"missing");var h,p;void 0===a||(Array.isArray(a)?a:[a]).includes(n.iss)||Hr(n,"iss"),void 0!==c&&n.sub!==c&&Hr(n,"sub"),void 0===u||(h=n.aud,p="string"==typeof u?[u]:u,"string"==typeof h?p.includes(h):Array.isArray(h)&&p.some(e=>h.includes(e)))||Hr(n,"aud");const f=o.clockTolerance;let m=0;if("string"==typeof f)m=Ur(f);else if(void 0!==f){if("number"!=typeof f)throw new TypeError("Invalid clockTolerance option type");m=f}Lr("clockTolerance option",m);const y=o.currentDate,w=Lr("currentDate option",jr(void 0===y?new Date:y)),g=Zr(n,"iat",void 0!==l),v=Zr(n,"nbf");if(void 0!==v&&v>w+m)throw new Do('"nbf" claim timestamp check failed',n,"nbf",Nr);const b=Zr(n,"exp");if(void 0!==b&&b<=w-m)throw new Zo('"exp" claim timestamp check failed',n,"exp",Nr);if(void 0!==l){const e=w-g;if(e-m>Lr("maxTokenAge option","number"==typeof l?l:Ur(l)))throw new Zo('"iat" claim timestamp check failed (too far in the past)',n,"iat",Nr);if(e<-m)throw new Do('"iat" claim timestamp check failed (it should be in the past)',n,"iat",Nr)}return n}let Vr;function Gr(e){return Vr.get(e)}async function Xr(e,t,n){const o=await Or(e,function(e){return[e&&ji("algorithms",e.algorithms),null==e?void 0:e.crit]}(n),t);if(!o[2])throw new Go("JWTs MUST NOT use unencoded payload");const i={payload:Fr(o[1],o[0],n),protectedHeader:o[1]};return"function"==typeof t?m(m({},i),{},{key:o[3]}):i}function qr(e){if(void 0===e)return[void 0,""];const t=function(e,t){let n,o;try{n=JSON.stringify(t),o=JSON.parse(n)}catch(t){throw new e("JOSE Header is not valid JSON",{cause:t})}if(!ri(o))throw new e("JOSE Header is not a JSON object");return[o,n]}(Vo,e);return[t[0],ii(t[1])]}function Yr(e,t,n){return function(e,t){const n=(null!=t?t:{}).crit;if(Array.isArray(n)&&new Set(n).size!==n.length)throw new e('"crit" (Critical) Header Parameter MUST NOT contain duplicate values')}(Vo,e),Mi(e,Wi(Vo,Oi,n,e,t))}async function Br(e,t,n,o){const i=No(Ko(e),Ko("."),t),r=await bi(n,o,"sign");return ii(await async function(e,t,n){const o=await _r(e,t,"sign"),i=await crypto.subtle.sign(e.signing,o,n);return new Uint8Array(i)}(n,r,i))}async function Qr(e,t,n,o,i){const r=w(qr(t),2),s=r[0],a=r[1];if(!s)throw new Vo("either setProtectedHeader or setUnprotectedHeader must be called before #sign()");Yr(s,s,n)||i();const c=function(e){const t=e.alg;if("string"!=typeof t||!t)throw new Vo('JWS "alg" (Algorithm) Header Parameter missing or invalid');return Ar(t)}(s),u=ii(e),l=await Br(a,Ko(u),c,o);return"".concat(a,".").concat(u,".").concat(l)}const $r=class{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!ri(e))throw new TypeError("JWT Claims Set MUST be an object");(Vr||(Vr=new WeakMap)).set(this,structuredClone(e))}setIssuer(e){return zr("iss",e),Gr(this).iss=e,this}setSubject(e){return zr("sub",e),Gr(this).sub=e,this}setAudience(e){return function(e){if("string"!=typeof e&&(!Array.isArray(e)||Array.from(e).some(e=>"string"!=typeof e)))throw new TypeError('"aud" claim must be a string or an array of strings')}(e),Gr(this).aud=e,this}setJti(e){return zr("jti",e),Gr(this).jti=e,this}setNotBefore(e){return Gr(this).nbf=Jr(e,"setNotBefore"),this}setExpirationTime(e){return Gr(this).exp=Jr(e,"setExpirationTime"),this}setIssuedAt(e){const t=Gr(this);return t.iat=void 0===e?jr(new Date):"string"==typeof e?Lr("setIssuedAt",jr(new Date)+Ur(e)):Jr(e,"setIssuedAt"),this}};var es=new WeakMap;class ts extends $r{constructor(){super(...arguments),l(this,es,void 0)}setProtectedHeader(e){return function(e,t){if(void 0!==e)throw new TypeError("".concat(t," can only be called once"))}(u(es,this),"setProtectedHeader"),d(es,this,e),this}async sign(e,t){return Qr(function(e){const t=Gr(e);for(const e of["iat","nbf","exp"]){const n=t[e];if("number"==typeof n&&!Number.isFinite(n))throw new TypeError('"'.concat(e,'" claim must be a finite number'))}return jo.encode(JSON.stringify(t))}(this),u(es,this),null==t?void 0:t.crit,e,()=>{throw new Go("JWTs MUST NOT use unencoded payload")})}}const ns='"alg" (Algorithm)';function os(){throw new Fo("Invalid or unsupported ".concat(arguments.length>0&&void 0!==arguments[0]?arguments[0]:'JWK "alg" (Algorithm) Parameter'," value"))}const is=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let n=0;n<e.byteLength;n++)if(e[n]!==t[n])return!1;return!0},rs=e=>{const t=e.data[e.pos++];if(void 0===t)throw new Error("Unexpected end of ASN.1 input");return t},ss=e=>{const t=rs(e);if(128&t){const n=127&t;let o=0;for(let t=0;t<n;t++)o=o<<8|rs(e);return o}return t},as=(e,t,n)=>{if(rs(e)!==t)throw new Error(n)},cs=(e,t)=>{if(t<0||e.pos+t>e.data.length)throw new Error("Unexpected end of ASN.1 input");const n=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,n};const us=e=>{const t=(e=>{as(e,6,"Expected algorithm OID");const t=ss(e);return cs(e,t)})(e);if(is(t,[43,101,110]))return"X25519";if(!is(t,[42,134,72,206,61,2,1]))throw new Error("Unsupported key algorithm");as(e,6,"Expected curve OID");const n=ss(e),o=cs(e,n);if(is(o,[42,134,72,206,61,3,1,7]))return"P-256";if(is(o,[43,129,4,0,34]))return"P-384";if(is(o,[43,129,4,0,35]))return"P-521";throw new Error("Unsupported named curve")},ls=async(e,t,n,o)=>{const i=function(e){if(void 0!==e&&"boolean"!=typeof e)throw new TypeError('"extractable" option must be a boolean');return e}(null==o?void 0:o.extractable),r=function(e,t){var n,o;return null!==(n="string"==typeof e?null!==(o=Rr[e])&&void 0!==o?o:Ai[e]:void 0)&&void 0!==n?n:os(t)}(n,ns);r.secret&&os(ns);const s="spki"===e;let a;if(r.resolve)try{const n={data:t,pos:0};!function(e,t){if(as(e,48,"Invalid ".concat("spki"===t?"SPKI":"PKCS#8"," structure")),ss(e),"pkcs8"===t){as(e,2,"Expected version field");const t=ss(e);e.pos+=t}as(e,48,"Expected algorithm identifier"),ss(e)}(n,e),a=r.resolve({crv:us(n)})}catch(e){throw new Fo("Invalid or unsupported key format")}else a=r.subtle;return crypto.subtle.importKey(e,t,a,null!=i?i:s,r.usages[s?0:1])},ds=(e,t,n)=>{const o=((e,t)=>ti(e.replace(t,"")))(e,/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g);return ls("pkcs8",o,t,n)};async function hs(e,t,n){const o=e.get(t)||e.set(t,{}).get(t),i=n.alg;if(void 0===o[i]){const e=await ci(n,m(m({},t),{},{alg:i,ext:!0}));if("public"!==e.type)throw new Xo("JSON Web Key Set members must be public keys");o[i]=e}return o[i]}function ps(e){let t;try{t=structuredClone(e)}catch(e){}if(!si(t))throw new Xo("JSON Web Key Set malformed");const n=new WeakMap;return Object.defineProperty(async(e,o)=>{const i=m(m({},e),null==o?void 0:o.header),r=i.alg,s=i.kid,c="string"==typeof r?Rr[r]:void 0;if(!c||c.secret)throw new Fo('Unsupported "alg" value for a JSON Web Key Set');const u=t.keys.filter(e=>function(e,t,n,o){const i=ui(e),r=i.kty,s=i.key_ops,a=i.ext,c=i.kid,u=i.alg,l=i.use,d=i.crv,h=Array.isArray(s)?[...s]:s;return(void 0===a||"boolean"==typeof a)&&(void 0===h||Array.isArray(h)&&h.every((e,t)=>"string"==typeof e&&h.indexOf(e)===t)&&h.includes("verify"))&&t.kty.includes(r)&&(void 0===o||"string"==typeof o&&o===c)&&(void 0===u?"AKP"!==r:n===u)&&(void 0===l||"sig"===l)&&(!t.crv||d===t.crv)}(e,c,r,s)),l=u[0],d=u.length;if(!d)throw new qo;if(1!==d){const e=new Yo;throw e[Symbol.asyncIterator]=g(function*(){for(const e of u)try{yield yield a(hs(n,e,c))}catch(e){}}),e}return hs(n,l,c)},"jwks",{value:()=>structuredClone(t)})}var fs,ms;let ys;if("undefined"==typeof navigator||null===(fs=navigator.userAgent)||void 0===fs||null===(ms=fs.startsWith)||void 0===ms||!ms.call(fs,"Mozilla/5.0 ")){const e="v6.2.10";ys="".concat("jose","/").concat(e)}const ws=Symbol();const gs=Symbol();function vs(e,t){return Number.isFinite(e)&&Date.now()<e+t}function bs(e,t,n){if(Number.isNaN(e))throw new TypeError('"'.concat(n,'" option must not be NaN'));return"number"==typeof e?e:t}function _s(e,t){if(!(e instanceof URL))throw new TypeError("url must be an instance of URL");const n=new URL(e.href).href,o=null!=t?t:{},i=o.timeoutDuration;if("number"==typeof i&&(!Number.isInteger(i)||i<0))throw new TypeError('"timeoutDuration" option must be a non-negative integer');const r="number"==typeof i?i:5e3,s=bs(o.cooldownDuration,3e4,"cooldownDuration"),a=bs(o.cacheMaxAge,6e5,"cacheMaxAge"),c=new Headers(o.headers);ys&&!c.has("User-Agent")&&c.set("User-Agent",ys),c.has("accept")||c.set("accept","application/json, application/jwk-set+json");const u=o[ws],l=o[gs];let d,h,p,f=0,m=0;if(l&&"object"==typeof l){const e=l.uat,t=l.jwks;vs(e,a)&&si(t)&&(d=e,p=ps(t))}const y=async()=>{if(h&&("undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime)&&(h=void 0),!h){const e=++f,t=h=async function(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:fetch;const i=await o(e,{method:"GET",signal:n,redirect:"manual",headers:t}).catch(e=>{if("TimeoutError"===e.name)throw new Bo;throw e});if(200!==i.status)throw new Jo("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await i.json()}catch(e){throw new Jo("Failed to parse the JSON Web Key Set HTTP response as JSON")}}(n,c,AbortSignal.timeout(r),u).then(t=>{const n=ps(t);if(e<=m)return;p=n;const o=Date.now();l&&(l.uat=o,l.jwks=t),d=o,m=e}).finally(()=>{h===t&&(h=void 0)})}await h};return Object.defineProperties(async(e,t)=>{p&&vs(d,a)||await y();try{return await p(e,t)}catch(n){if(n instanceof qo&&!vs(d,s))return await y(),p(e,t);throw n}},{coolingDown:{get:()=>vs(d,s),enumerable:!0},fresh:{get:()=>vs(d,a),enumerable:!0},reload:{value:y,enumerable:!0},reloading:{get:()=>!!h,enumerable:!0},jwks:{value:()=>{var e;return null===(e=p)||void 0===e?void 0:e.jwks()},enumerable:!0}})}async function ks(e,t,n){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw new TypeError('"pkcs8" must be PKCS#8 formatted string');return ds(e,t,n)}const Ss=["mfaToken"],Ts=["mfaToken"];var Ps,Es,Cs,Rs,As,xs,Is,Os,js,Ws,Ms,Ns,Ks,Us,Ls,zs,Js,Ds,Zs,Hs,Fs,Vs,Gs,Xs,qs,Ys,Bs,Qs,$s,ea,ta,na,oa,ia,ra,sa,aa,ca,ua,la,da,ha,pa,fa,ma,ya,wa,ga,va,ba,_a,ka;function Sa(e){if("object"!=typeof e||null===e)return{};const t=e;return{statusCode:"number"==typeof t.statusCode?t.statusCode:void 0,headers:t.headers instanceof Headers?t.headers:void 0,body:"string"==typeof t.body?t.body:void 0}}function Ta(e){var t,n;if("object"!=typeof e||null===e)return{error:"unknown_error",error_description:String(e)};const o=e;let i;if(o.response instanceof Response)try{i=new Headers(o.response.headers),i.delete("set-cookie")}catch(e){i=void 0}const r={error:null!==(t=o.error)&&void 0!==t?t:"",error_description:null!==(n=o.error_description)&&void 0!==n?n:"",message:o.message,statusCode:"number"==typeof o.status?o.status:void 0,headers:i};if("mfa_required"===o.error&&o.cause){r.mfa_token="string"==typeof o.cause.mfa_token?o.cause.mfa_token:void 0;const e=o.cause.mfa_requirements;"object"==typeof e&&null!==e&&(r.mfa_requirements=e)}return r}var Pa=class extends Error{constructor(e,t){super(t),p(this,"code",void 0),this.name="NotSupportedError",this.code=e}},Ea=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements};const o=Sa(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},Ca=class extends Ea{constructor(e,t){super("token_by_code_error",e,t),this.name="TokenByCodeError"}},Ra=class extends Ea{constructor(e,t){super("token_by_client_credentials_error",e,t),this.name="TokenByClientCredentialsError"}},Aa=class extends Ea{constructor(e,t){super("token_by_refresh_token_error",e,t),this.name="TokenByRefreshTokenError"}},xa=class extends Ea{constructor(e,t){super("token_by_password_error",e,t),this.name="TokenByPasswordError"}},Ia=class extends Ea{constructor(e,t){super("token_for_connection_error",e,t),this.name="TokenForConnectionErrorCode"}},Oa=class extends Ea{constructor(e,t){super("token_exchange_error",e,t),this.name="TokenExchangeError"}},ja=class extends Ea{constructor(e,t){super("token_revocation_error",e,t),this.name="TokenRevocationError"}},Wa=class extends Ea{constructor(e,t){super("user_info_error",e,t),this.name="UserInfoError"}},Ma=class extends Error{constructor(e){super(e),p(this,"code","verify_logout_token_error"),this.name="VerifyLogoutTokenError"}},Na=class extends Ea{constructor(e){super("backchannel_authentication_error","There was an error when trying to use Client-Initiated Backchannel Authentication.",e),p(this,"code","backchannel_authentication_error"),this.name="BackchannelAuthenticationError"}},Ka=class extends Ea{constructor(e){super("build_authorization_url_error","There was an error when trying to build the authorization URL.",e),this.name="BuildAuthorizationUrlError"}},Ua=class extends Ea{constructor(e){super("build_link_user_url_error","There was an error when trying to build the Link User URL.",e),this.name="BuildLinkUserUrlError"}},La=class extends Ea{constructor(e){super("build_unlink_user_url_error","There was an error when trying to build the Unlink User URL.",e),this.name="BuildUnlinkUserUrlError"}},za=class extends Error{constructor(){super("The client secret or client assertion signing key must be provided."),p(this,"code","missing_client_auth_error"),this.name="MissingClientAuthError"}},Ja=class extends Error{constructor(e){super(e),p(this,"code","organization_validation_error"),this.name="OrganizationValidationError"}},Da=class extends Error{constructor(e){super(e||"fullResponse: true requested but no HTTP Response was captured. This is a bug in CapturingFetch."),p(this,"code","missing_captured_response_error"),this.name="MissingCapturedResponseError"}};function Za(e){try{const t=new Headers(e);return t.delete("set-cookie"),t}catch(e){return new Headers}}function Ha(e,t,n){var o;const i="object"==typeof t&&null!==t?t:void 0,r=null!==(o=null==i?void 0:i.response)&&void 0!==o?o:n,s="number"==typeof(null==i?void 0:i.status)?i.status:null==r?void 0:r.status;"number"==typeof s&&(e.statusCode=s),null!=r&&r.headers&&(e.headers=Za(r.headers))}function Fa(e){return Object.entries(e).filter(e=>void 0!==w(e,2)[1]).reduce((e,t)=>m(m({},e),{},{[t[0]]:t[1]}),{})}function Va(e){if(!e.trim())throw new Ja("organization must not be blank")}function Ga(e,t){if(!e)return;const n=t.trim();if(n.startsWith("org_")){const t=e.org_id;if("string"!=typeof t)throw new Ja("Organization Id (org_id) claim must be a string present in the ID token");if(t!==n)throw new Ja('Organization Id (org_id) claim value mismatch in the ID token; expected "'.concat(n,'", found "').concat(t,'"'))}else{const t=e.org_name;if("string"!=typeof t)throw new Ja("Organization Name (org_name) claim must be a string present in the ID token");if(t.toLowerCase()!==n.toLowerCase())throw new Ja('Organization Name (org_name) claim value mismatch in the ID token; expected "'.concat(n,'", found "').concat(t,'"'))}}var Xa=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Sa(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},qa=class extends Xa{constructor(e,t){super("mfa_list_authenticators_error",e,t),this.name="MfaListAuthenticatorsError"}},Ya=class extends Xa{constructor(e,t){super("mfa_enrollment_error",e,t),this.name="MfaEnrollmentError"}},Ba=class extends Xa{constructor(e,t){super("mfa_delete_authenticator_error",e,t),this.name="MfaDeleteAuthenticatorError"}},Qa=class extends Xa{constructor(e,t){super("mfa_challenge_error",e,t),this.name="MfaChallengeError"}},$a=class extends Xa{constructor(e,t){super("mfa_verify_error",e,t),this.name="MfaVerifyError"}};function ec(e){return{id:e.id,authenticatorType:e.authenticator_type,active:e.active,name:e.name,oobChannels:e.oob_channels,type:e.type}}var tc=class e{constructor(e,t,n,o,i,r,s){p(this,"accessToken",void 0),p(this,"idToken",void 0),p(this,"refreshToken",void 0),p(this,"expiresAt",void 0),p(this,"scope",void 0),p(this,"claims",void 0),p(this,"authorizationDetails",void 0),p(this,"tokenType",void 0),p(this,"issuedTokenType",void 0),p(this,"recoveryCode",void 0),p(this,"act",void 0),this.accessToken=e,this.idToken=n,this.refreshToken=o,this.expiresAt=t,this.scope=i,this.claims=r,this.authorizationDetails=s}static fromTokenEndpointResponse(t){const n=t.id_token?t.claims():void 0,o=new e(t.access_token,Math.floor(Date.now()/1e3)+Number(t.expires_in),t.id_token,t.refresh_token,t.scope,n,t.authorization_details);return o.tokenType=t.token_type,o.issuedTokenType=t.issued_token_type,o}};function nc(e,t){if(!1===t.enabled)return e;const n={name:t.name,version:t.version},o=btoa(JSON.stringify(n));return async(t,n)=>{const i=t instanceof Request?new Headers(t.headers):new Headers;if(null!=n&&n.headers){new Headers(n.headers).forEach((e,t)=>{i.set(t,e)})}return i.set("Auth0-Client",o),e(t,m(m({},n),{},{headers:i}))}}function oc(e){var t,n;return!1===(null==e?void 0:e.enabled)?e:{enabled:!0,name:null!==(t=null==e?void 0:e.name)&&void 0!==t?t:"@auth0/auth0-auth-js",version:null!==(n=null==e?void 0:e.version)&&void 0!==n?n:"1.15.0"}}function ic(e){let t;const n=async(n,o)=>{const i=await e(n,o);return t=i.clone(),i};return n.getCapturedResponse=()=>t,n}function rc(e,t,n){if(!t)return e;const o=t.signal,i=t.headers,r=t.customFetch,s=r?nc(r,n):e;return o||i?async(e,t)=>{const n=i?new Headers(e instanceof Request?e.headers:void 0):void 0;if(n&&null!=t&&t.headers&&new Headers(t.headers).forEach((e,t)=>n.set(t,e)),i)for(const e of Object.entries(i)){var r=w(e,2);const t=r[0],o=r[1],i=t.toLowerCase();"authorization"!==i&&"auth0-client"!==i&&n.set(t,o)}const a=function(e,t){if(!e)return{signal:null!=t?t:void 0};if(!t)return{signal:e};if("undefined"!=typeof AbortSignal&&"function"==typeof AbortSignal.any)return{signal:AbortSignal.any([e,t])};const n=new AbortController,o=[e,t],i=o.find(e=>e.aborted);if(i)return n.abort(i.reason),{signal:n.signal};const r=[],s=()=>{o.forEach((e,t)=>{const n=r[t];n&&e.removeEventListener("abort",n)})};return o.forEach((e,t)=>{const o=()=>{s(),n.abort(e.reason)};r[t]=o,e.addEventListener("abort",o,{once:!0})}),{signal:n.signal,cleanup:s}}(o,null==t?void 0:t.signal);try{return await s(e,m(m(m({},t),n&&{headers:n}),{},{signal:a.signal}))}finally{var c;null===(c=a.cleanup)||void 0===c||c.call(a)}}:s}var sc={otp:"http://auth0.com/oauth/grant-type/mfa-otp",oob:"http://auth0.com/oauth/grant-type/mfa-oob","recovery-code":"http://auth0.com/oauth/grant-type/mfa-recovery-code"},ac=(Ps=new WeakMap,Es=new WeakMap,Cs=new WeakMap,Rs=new WeakMap,As=new WeakMap,xs=new WeakMap,Is=new WeakMap,Os=new WeakSet,class{constructor(e){var t,n;h(this,Os),l(this,Ps,void 0),l(this,Es,void 0),l(this,Cs,void 0),l(this,Rs,void 0),l(this,As,void 0),l(this,xs,void 0),l(this,Is,void 0),d(Ps,this,"https://".concat(e.domain)),d(Es,this,e.clientId),d(Cs,this,e.clientSecret),d(Rs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(As,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:oc()),d(xs,this,e.getConfiguration),d(Is,this,e.createCaptureConfiguration)}async listAuthenticators(e,t){const n="".concat(u(Ps,this),"/mfa/authenticators"),o=e.mfaToken,i=await s(Os,this,cc).call(this,t)(n,{method:"GET",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"}});if(!i.ok){const e=await i.clone().text(),t=i.status,n=Za(i.headers);let o;try{o=JSON.parse(e)}catch(o){throw new qa("Failed to list authenticators",{error:"unknown_error",error_description:"Failed to list authenticators",statusCode:t,headers:n,body:e})}throw new qa(o.error_description||"Failed to list authenticators",m(m({},o),{},{statusCode:t,headers:n,body:e}))}return(await i.json()).map(ec)}async enrollAuthenticator(e,t){const n="".concat(u(Ps,this),"/mfa/associate"),o=e.mfaToken,i=y(e,Ss),r={authenticator_types:i.authenticatorTypes};"oobChannels"in i&&(r.oob_channels=i.oobChannels),"phoneNumber"in i&&i.phoneNumber&&(r.phone_number=i.phoneNumber),"email"in i&&i.email&&(r.email=i.email);const a=await s(Os,this,cc).call(this,t)(n,{method:"POST",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"},body:JSON.stringify(r)});if(!a.ok){const e=await a.clone().text(),t=a.status,n=Za(a.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Ya("Failed to enroll authenticator",{error:"unknown_error",error_description:"Failed to enroll authenticator",statusCode:t,headers:n,body:e})}throw new Ya(o.error_description||"Failed to enroll authenticator",m(m({},o),{},{statusCode:t,headers:n,body:e}))}return function(e){if("otp"===e.authenticator_type)return{authenticatorType:"otp",secret:e.secret,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes,id:e.id};if("oob"===e.authenticator_type)return{authenticatorType:"oob",oobChannel:e.oob_channel,oobCode:e.oob_code,bindingMethod:e.binding_method,id:e.id,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes};throw new Error("Unexpected authenticator type: ".concat(e.authenticator_type))}(await a.json())}async deleteAuthenticator(e,t){const n=e.authenticatorId,o=e.mfaToken,i="".concat(u(Ps,this),"/mfa/authenticators/").concat(encodeURIComponent(n)),r=await s(Os,this,cc).call(this,t)(i,{method:"DELETE",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"}});if(!r.ok){const e=await r.clone().text(),t=r.status,n=Za(r.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Ba("Failed to delete authenticator",{error:"unknown_error",error_description:"Failed to delete authenticator",statusCode:t,headers:n,body:e})}throw new Ba(o.error_description||"Failed to delete authenticator",m(m({},o),{},{statusCode:t,headers:n,body:e}))}}async challengeAuthenticator(e,t){const n="".concat(u(Ps,this),"/mfa/challenge"),o=e.mfaToken,i=y(e,Ts),r={mfa_token:o,client_id:u(Es,this),challenge_type:i.challengeType};u(Cs,this)&&(r.client_secret=u(Cs,this)),i.authenticatorId&&(r.authenticator_id=i.authenticatorId);const a=await s(Os,this,cc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(r)});if(!a.ok){const e=await a.clone().text(),t=a.status,n=Za(a.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Qa("Failed to challenge authenticator",{error:"unknown_error",error_description:"Failed to challenge authenticator",statusCode:t,headers:n,body:e})}throw new Qa(o.error_description||"Failed to challenge authenticator",m(m({},o),{},{statusCode:t,headers:n,body:e}))}return function(e){const t={challengeType:e.challenge_type};return void 0!==e.oob_code&&(t.oobCode=e.oob_code),void 0!==e.binding_method&&(t.bindingMethod=e.binding_method),t}(await a.json())}async verify(e,t){if(!u(xs,this))throw new Error("MFA verify requires a configuration provider (getConfiguration was not set)");const n={mfa_token:e.mfaToken};if(e.audience&&(n.audience=e.audience),"otp"===e.factorType?n.otp=e.otp:"oob"===e.factorType?(n.oob_code=e.oobCode,e.bindingCode&&(n.binding_code=e.bindingCode)):"recovery-code"===e.factorType&&(n.recovery_code=e.recoveryCode),e.fullResponse){var o;if(!u(Is,this))throw new Error("MFA verify fullResponse requires a capture-config factory (createCaptureConfiguration was not set)");const a=ic(null!==(o=(await u(xs,this).call(this,t))[Fi])&&void 0!==o?o:fetch),c=await u(Is,this).call(this,a);try{const t=await vr(c,sc[e.factorType],n),o=tc.fromTokenEndpointResponse(t);t.recovery_code&&(o.recoveryCode=t.recovery_code);const i=a.getCapturedResponse();if(!i)throw new Da;return{data:o,response:i}}catch(e){var i,r,s;if(e instanceof Da)throw e;if(e instanceof $a)throw e;const t=e,n=new $a(t.error_description||t.message||"Failed to verify MFA challenge",{error:null!==(i=t.error)&&void 0!==i?i:"mfa_verify_error",error_description:null!==(r=null!==(s=t.error_description)&&void 0!==s?s:t.message)&&void 0!==r?r:"Failed to verify MFA challenge"});throw Ha(n,e,a.getCapturedResponse()),n}}const a=await u(xs,this).call(this,t);try{const t=await vr(a,sc[e.factorType],n),o=tc.fromTokenEndpointResponse(t);return t.recovery_code&&(o.recoveryCode=t.recovery_code),o}catch(e){var c,l,d;if(e instanceof $a)throw e;const t=e,n=new $a(t.error_description||t.message||"Failed to verify MFA challenge",{error:null!==(c=t.error)&&void 0!==c?c:"mfa_verify_error",error_description:null!==(l=null!==(d=t.error_description)&&void 0!==d?d:t.message)&&void 0!==l?l:"Failed to verify MFA challenge"});throw Ha(n,e),n}}});function cc(e){return rc(u(Rs,this),e,u(As,this))}var uc=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Sa(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},lc=class extends uc{constructor(e,t){super("passkey_register_error",e,t),this.name="PasskeyRegisterError"}},dc=class extends uc{constructor(e,t){super("passkey_challenge_error",e,t),this.name="PasskeyChallengeError"}},hc=class extends uc{constructor(e,t){super("passkey_get_token_error",e,t),this.name="PasskeyGetTokenError",this.cause=t&&{error:t.error,error_description:t.error_description,message:t.message,mfa_token:t.mfa_token,mfa_requirements:t.mfa_requirements}}};function pc(e){return e.useMtls?{}:e.clientSecret?{client_secret:e.clientSecret}:{}}var fc="urn:okta:params:oauth:grant-type:webauthn",mc=(js=new WeakMap,Ws=new WeakMap,Ms=new WeakMap,Ns=new WeakMap,Ks=new WeakMap,Us=new WeakMap,Ls=new WeakSet,class{constructor(e){var t,n;h(this,Ls),l(this,js,void 0),l(this,Ws,void 0),l(this,Ms,void 0),l(this,Ns,void 0),l(this,Ks,void 0),l(this,Us,void 0),d(js,this,"https://".concat(e.domain)),d(Ws,this,e.clientId),d(Ms,this,{clientSecret:e.clientSecret,useMtls:e.useMtls}),d(Ns,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(Ks,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:oc()),d(Us,this,e.grantRequest)}async register(e,t){const n="".concat(u(js,this),"/passkey/register"),o=m(m(m(m(m(m(m(m({},e.email&&{email:e.email}),e.name&&{name:e.name}),e.phoneNumber&&{phone_number:e.phoneNumber}),e.username&&{username:e.username}),e.givenName&&{given_name:e.givenName}),e.familyName&&{family_name:e.familyName}),e.nickname&&{nickname:e.nickname}),e.picture&&{picture:e.picture}),i=m(m({client_id:u(Ws,this)},pc(u(Ms,this))),{},{user_profile:o});e.realm&&(i.realm=e.realm),e.organization&&(i.organization=e.organization),e.userMetadata&&(i.user_metadata=e.userMetadata);const r=await s(Ls,this,yc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(i)});if(!r.ok){const e=await s(Ls,this,wc).call(this,r),t=new lc(e.error_description||"Failed to request signup challenge",e);throw t.statusCode=r.status,t.headers=Za(r.headers),t}const a=await r.json();return{authSession:(c=a).auth_session,authnParamsPublicKey:m({},c.authn_params_public_key)};var c}async challenge(e,t){const n="".concat(u(js,this),"/passkey/challenge"),o=m({client_id:u(Ws,this)},pc(u(Ms,this)));null!=e&&e.realm&&(o.realm=e.realm),null!=e&&e.organization&&(o.organization=e.organization);const i=await s(Ls,this,yc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(o)});if(!i.ok){const e=await s(Ls,this,wc).call(this,i),t=new dc(e.error_description||"Failed to request login challenge",e);throw t.statusCode=i.status,t.headers=Za(i.headers),t}const r=await i.json();return{authSession:(a=r).auth_session,authnParamsPublicKey:m({},a.authn_params_public_key)};var a}async getTokenByPasskey(e,t){void 0!==e.organization&&Va(e.organization);const n=new URLSearchParams({auth_session:e.authSession,authn_response:JSON.stringify(e.credential)});let o;e.realm&&n.append("realm",e.realm),e.scope&&n.append("scope",e.scope),e.audience&&n.append("audience",e.audience),e.organization&&n.append("organization",e.organization);try{o=await u(Us,this).call(this,fc,n,t,e.fullResponse)}catch(e){if(e instanceof Da)throw e;const t=Ta(e),n=new hc(t.error_description||"Failed to exchange passkey credential for tokens.",t);throw Ha(n,e),n}if(e.fullResponse){const t=o;return e.organization&&Ga(t.data.claims,e.organization),t}const i=o;return e.organization&&Ga(i.claims,e.organization),i}});function yc(e){return rc(u(Ns,this),e,u(Ks,this))}async function wc(e){const t=await e.clone().text();try{return m(m({},JSON.parse(t)),{},{statusCode:e.status,headers:e.headers,body:t})}catch(n){return{error:"unknown_error",error_description:"HTTP ".concat(e.status," ").concat(e.statusText),statusCode:e.status,headers:e.headers,body:t}}}var gc=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&(n.error||n.error_description)?{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements}:void 0;const o=Sa(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},vc=class extends gc{constructor(e,t){super("passwordless_start_error",e,t),this.name="PasswordlessStartError"}},bc=class extends gc{constructor(e,t){super("passwordless_verify_error",e,t),this.name="PasswordlessVerifyError"}},_c=class extends gc{constructor(e,t){super("passwordless_db_get_token_error",e,t),this.name="PasswordlessDbGetTokenError"}},kc=class extends gc{constructor(e,t,n,o,i){super("passwordless_challenge_error",e,n),p(this,"statusCode",void 0),p(this,"validationErrors",void 0),this.name="PasswordlessChallengeError",this.statusCode=t,this.validationErrors=o,this.headers=null!=i?i:this.headers}};function Sc(e){return/^\+[1-9]\d{1,14}$/.test(e)}async function Tc(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){var o;const i=null!==(o=e.clientAssertionSigningAlg)&&void 0!==o?o:"RS256",r=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await ks(e.clientAssertionSigningKey,i);return{client_assertion:await new ts({}).setProtectedHeader({alg:i}).setIssuer(t).setSubject(t).setAudience("https://".concat(n,"/")).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime("".concat(120,"s")).sign(r),client_assertion_type:"urn:ietf:params:oauth:client-assertion-type:jwt-bearer"}}if(e.clientSecret)return{client_secret:e.clientSecret};throw new za}var Pc=(zs=new WeakMap,Js=new WeakMap,Ds=new WeakMap,Zs=new WeakMap,Hs=new WeakMap,Fs=new WeakMap,Vs=new WeakMap,Gs=new WeakSet,class{constructor(e){var t,n;h(this,Gs),l(this,zs,void 0),l(this,Js,void 0),l(this,Ds,void 0),l(this,Zs,void 0),l(this,Hs,void 0),l(this,Fs,void 0),l(this,Vs,void 0),d(Js,this,e.domain),d(zs,this,"https://".concat(e.domain)),d(Ds,this,e.clientId),d(Zs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(Hs,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:oc()),d(Fs,this,{clientSecret:e.clientSecret,clientAssertionSigningKey:e.clientAssertionSigningKey,clientAssertionSigningAlg:e.clientAssertionSigningAlg,useMtls:e.useMtls}),d(Vs,this,e.grantRequest)}async sendEmail(e,t){const n=await s(Gs,this,Cc).call(this,function(e){var t;const n=null!==(t=e.send)&&void 0!==t?t:"code",o={email:e.email,connection:"email",send:n};return"link"===n&&e.authParams&&(o.authParams=e.authParams),o}(e),"Failed to send passwordless email",e.language,t);if(e.fullResponse)return{data:void 0,response:n}}async sendSms(e,t){if(!Sc(e.phoneNumber))throw new vc("Phone number must be in E.164 format (e.g. +14155550100).");const n=await s(Gs,this,Cc).call(this,function(e){return{phone_number:e.phoneNumber,connection:"sms"}}(e),"Failed to send passwordless SMS",e.language,t);if(e.fullResponse)return{data:void 0,response:n}}async challengeWithEmail(e,t){const n=function(e){var t;return{email:e.email,connection:e.connection,allow_signup:null!==(t=e.allowSignup)&&void 0!==t&&t}}(e);return s(Gs,this,Rc).call(this,n,"Failed to request email OTP challenge",t)}async challengeWithPhoneNumber(e,t){if(!Sc(e.phoneNumber))throw new kc("Phone number must be in E.164 format (e.g. +14155550100).",0,void 0,void 0);const n=function(e){var t;const n={phone_number:e.phoneNumber,connection:e.connection,allow_signup:null!==(t=e.allowSignup)&&void 0!==t&&t};return e.deliveryMethod&&(n.delivery_method=e.deliveryMethod),n}(e);return s(Gs,this,Rc).call(this,n,"Failed to request phone OTP challenge",t)}async getTokenByPasswordlessDbConnection(e,t){const n=new URLSearchParams({auth_session:e.authSession,otp:e.otp});if(e.scope&&n.append("scope",e.scope),e.audience&&n.append("audience",e.audience),!u(Vs,this))throw new _c("Missing grant request delegate.",Ta(new Error("missing grantRequest")));try{return await u(Vs,this).call(this,"http://auth0.com/oauth/grant-type/passwordless/otp",n,t,e.fullResponse)}catch(e){if(e instanceof Da)throw e;const t=new _c("There was an error while trying to request a token.",Ta(e)),n=e;throw t.statusCode=n._statusCode,t.headers=n._headers,t}}});function Ec(e){return rc(u(Zs,this),e,u(Hs,this))}async function Cc(e,t,n,o){var i;const r=await Tc(u(Fs,this),u(Ds,this),u(Js,this)),a=m(m({client_id:u(Ds,this)},e),r);let c;try{c=await s(Gs,this,Ec).call(this,o)("".concat(u(zs,this),"/passwordless/start"),{method:"POST",headers:m({"Content-Type":"application/json"},n?{"x-request-language":n}:{}),body:JSON.stringify(a)})}catch(e){throw new vc("".concat(t,": a network error occurred."))}if(c.ok)return c;const l=await c.clone().text();let d;if(204!==c.status)try{d=JSON.parse(l)}catch(e){d=void 0}const h=new vc((null===(i=d)||void 0===i?void 0:i.error_description)||t,d);throw h.statusCode=c.status,h.headers=Za(c.headers),h.body=l,h}async function Rc(e,t,n){var o,i;const r=await Tc(u(Fs,this),u(Ds,this),u(Js,this)),a=m(m({client_id:u(Ds,this)},e),r);let c;try{c=await s(Gs,this,Ec).call(this,n)("".concat(u(zs,this),"/otp/challenge"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(a)})}catch(e){throw new kc("challenge error: a network error occurred.",0,void 0,void 0)}if(c.ok){let e;try{e=await c.json()}catch(e){throw new kc("".concat(t,": could not parse the response body."),c.status,void 0,void 0,Za(c.headers))}return{authSession:e.auth_session}}const l=await c.clone().text();let d;try{d=JSON.parse(l)}catch(e){d=void 0}const h=d?m(m({},d),{},{statusCode:c.status,headers:c.headers,body:l}):{error:"",error_description:"",statusCode:c.status,headers:c.headers,body:l};throw new kc((null===(o=d)||void 0===o?void 0:o.error_description)||t,c.status,h,null===(i=d)||void 0===i?void 0:i.validation_errors,Za(c.headers))}var Ac=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Sa(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},xc=class extends Ac{constructor(e,t){super("signup_error",e,t),this.name="SignUpError"}},Ic=class extends Ac{constructor(e,t){super("change_password_error",e,t),this.name="ChangePasswordError"}};function Oc(e,t,n){for(const o of t)if(null===e[o]||void 0===e[o]||""===e[o])throw new n('Required parameter "'.concat(String(o),'" was null, undefined, or empty.'))}function jc(e){var t,n;return{id:null!==(t=null!==(n=e._id)&&void 0!==n?n:e.user_id)&&void 0!==t?t:e.id,email:"string"==typeof e.email?e.email:"",emailVerified:Boolean(e.email_verified),username:e.username,givenName:e.given_name,familyName:e.family_name,name:e.name,nickname:e.nickname,picture:e.picture,userMetadata:e.user_metadata}}var Wc=(Xs=new WeakMap,qs=new WeakMap,Ys=new WeakMap,Bs=new WeakMap,Qs=new WeakSet,class{constructor(e){var t,n;h(this,Qs),l(this,Xs,void 0),l(this,qs,void 0),l(this,Ys,void 0),l(this,Bs,void 0),d(Xs,this,"https://".concat(e.domain)),d(qs,this,e.clientId),d(Ys,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(Bs,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:oc())}async signUp(e,t){var n;Oc(e,["email","password","connection"],xc);const o=m({client_id:null!==(n=e.clientId)&&void 0!==n?n:u(qs,this)},function(e){const t={email:e.email,password:e.password,connection:e.connection};return void 0!==e.username&&(t.username=e.username),void 0!==e.givenName&&(t.given_name=e.givenName),void 0!==e.familyName&&(t.family_name=e.familyName),void 0!==e.name&&(t.name=e.name),void 0!==e.nickname&&(t.nickname=e.nickname),void 0!==e.picture&&(t.picture=e.picture),void 0!==e.userMetadata&&(t.user_metadata=e.userMetadata),t}(e)),i=await s(Qs,this,Mc).call(this,"/dbconnections/signup",o,xc,"Failed to sign up",t);if(e.fullResponse){const e=i.clone();return{data:jc(await i.json()),response:e}}return jc(await i.json())}async changePassword(e,t){var n;if(Oc(e,["connection"],Ic),!e.email&&!e.username)throw new Ic('Either "email" or "username" is required.');const o=m({client_id:null!==(n=e.clientId)&&void 0!==n?n:u(qs,this)},function(e){const t={connection:e.connection};return void 0!==e.email&&(t.email=e.email),void 0!==e.username&&(t.username=e.username),void 0!==e.organization&&(t.organization=e.organization),t}(e)),i=await s(Qs,this,Mc).call(this,"/dbconnections/change_password",o,Ic,"Failed to request a password change",t);if(e.fullResponse){const e=i.clone();return{data:await i.text(),response:e}}return i.text()}});async function Mc(e,t,n,o,i){const r=rc(u(Ys,this),i,u(Bs,this));let s;try{s=await r("".concat(u(Xs,this)).concat(e),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(t)})}catch(e){throw new n("".concat(o,": a network error occurred."))}if(s.ok)return s;const a=await s.clone().text(),c=await async function(e){let t;try{t=await e.json()}catch(e){return}return"string"==typeof t.error?t:"string"==typeof t.code?{error:t.code,error_description:"string"==typeof t.description?t.description:""}:void 0}(s.clone()),l=new n((null==c?void 0:c.error_description)||o,null!=c?c:{error:"unknown_error",error_description:o});throw l.statusCode=s.status,l.headers=Za(s.headers),l.body=a,l}var Nc=class extends Error{constructor(e,t,n){super(t),p(this,"code",void 0),p(this,"cause",void 0),this.name="AnonymousSessionError",this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}};var Kc=new Set(["session_expired","invalid_session_token"]);async function Uc(e){const t="Request failed with status ".concat(e.status);let n={};try{n=await e.json()}catch(e){}return{error:"string"==typeof n.error?n.error:"server_error",error_description:"string"==typeof n.error_description?n.error_description:t}}var Lc=($s=new WeakMap,ea=new WeakMap,ta=new WeakMap,na=new WeakMap,oa=new WeakMap,ia=new WeakMap,ra=new WeakMap,sa=new WeakMap,aa=new WeakSet,class{constructor(e){var t;h(this,aa),l(this,$s,void 0),l(this,ea,void 0),l(this,ta,void 0),l(this,na,void 0),l(this,oa,void 0),l(this,ia,void 0),l(this,ra,void 0),l(this,sa,void 0),d($s,this,e.domain),d(ea,this,"https://".concat(e.domain)),d(ta,this,e.clientId),d(na,this,e.clientSecret),d(oa,this,e.clientAssertionSigningKey),d(ia,this,e.clientAssertionSigningAlg),d(ra,this,e.useMtls),d(sa,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)})}async createSession(e){const t={client_id:u(ta,this)};null!=e&&e.audience&&(t.audience=e.audience),null!=e&&e.scope&&(t.scope=e.scope),null!=e&&e.metadata&&(t.metadata=e.metadata);const n=await s(aa,this,Jc).call(this,t);if(!n.sessionToken)throw new Nc("server_error","session_token missing from create session response");return{sessionToken:n.sessionToken,accessToken:n.accessToken,expiresAt:n.expiresAt,sessionTokenExpiresAt:n.sessionTokenExpiresAt,scope:n.scope}}async getAccessToken(e){if(null==e||!e.sessionToken)return this.createSession({audience:null==e?void 0:e.audience,scope:null==e?void 0:e.scope});try{return await s(aa,this,zc).call(this,e.sessionToken,e)}catch(t){if(t instanceof Nc&&Kc.has(t.code)){return m(m({},await this.createSession({audience:null==e?void 0:e.audience,scope:null==e?void 0:e.scope})),{},{sessionReplaced:!0})}throw t}}async logout(){const e="".concat(u(ea,this),"/anonymous/logout"),t={client_id:u(ta,this)},n=await u(sa,this).call(this,e,{method:"POST",headers:{"Content-Type":"application/json"},credentials:"include",redirect:"error",body:JSON.stringify(t)});if(!n.ok){const e=await Uc(n);throw new Nc(e.error,e.error_description||"Failed to end anonymous session",e)}}});async function zc(e,t){const n={client_id:u(ta,this),session_token:e};null!=t&&t.audience&&(n.audience=t.audience),null!=t&&t.scope&&(n.scope=t.scope);const o=await s(aa,this,Jc).call(this,n);return{sessionToken:e,accessToken:o.accessToken,expiresAt:o.expiresAt,sessionTokenExpiresAt:o.sessionTokenExpiresAt,scope:o.scope,sessionReplaced:!1}}async function Jc(e){const t="".concat(u(ea,this),"/anonymous/token"),n=await async function(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){var o;const i=null!==(o=e.clientAssertionSigningAlg)&&void 0!==o?o:"RS256",r=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await ks(e.clientAssertionSigningKey,i);return{client_assertion:await new ts({}).setProtectedHeader({alg:i}).setIssuer(t).setSubject(t).setAudience("https://".concat(n,"/")).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime("".concat(120,"s")).sign(r),client_assertion_type:"urn:ietf:params:oauth:client-assertion-type:jwt-bearer"}}return e.clientSecret?{client_secret:e.clientSecret}:{}}({clientSecret:u(na,this),clientAssertionSigningKey:u(oa,this),clientAssertionSigningAlg:u(ia,this),useMtls:u(ra,this)},u(ta,this),u($s,this));Object.assign(e,n);const o=await u(sa,this).call(this,t,{method:"POST",headers:{"Content-Type":"application/json"},credentials:"include",redirect:"error",body:JSON.stringify(e)});if(!o.ok){const e=await Uc(o);throw new Nc(e.error,e.error_description||"Anonymous token request failed",e)}let i;try{i=await o.json()}catch(e){throw new Nc("server_error","Invalid response from anonymous token endpoint")}return function(e){const t=Math.floor(Date.now()/1e3);if("string"!=typeof e.access_token||!e.access_token)throw new Nc("server_error","access_token missing or invalid in anonymous token response");const n=e.expires_in;if("number"!=typeof n||!Number.isFinite(n))throw new Nc("server_error","expires_in missing or invalid in anonymous token response");return{accessToken:e.access_token,expiresAt:t+n,scope:e.scope,sessionToken:e.session_token,sessionTokenExpiresAt:"number"==typeof e.session_expires_in&&Number.isFinite(e.session_expires_in)?t+e.session_expires_in:void 0}}(i)}var Dc=(ca=new WeakMap,ua=new WeakMap,la=new WeakMap,class{constructor(e,t){l(this,ca,new Map),l(this,ua,void 0),l(this,la,void 0),d(la,this,Math.max(1,Math.floor(e))),d(ua,this,Math.max(0,Math.floor(t)))}get(e){const t=u(ca,this).get(e);if(t){if(!(Date.now()>=t.expiresAt))return u(ca,this).delete(e),u(ca,this).set(e,t),t.value;u(ca,this).delete(e)}}set(e,t,n){u(ca,this).has(e)&&u(ca,this).delete(e);const o=null!=n&&Number.isFinite(n)&&n>0?n:u(ua,this);for(u(ca,this).set(e,{value:t,expiresAt:Date.now()+o});u(ca,this).size>u(la,this);){const e=u(ca,this).keys().next().value;if(void 0===e)break;u(ca,this).delete(e)}}}),Zc=new Map;function Hc(e){return{ttlMs:1e3*("number"==typeof(null==e?void 0:e.ttl)?e.ttl:600),maxEntries:"number"==typeof(null==e?void 0:e.maxEntries)&&e.maxEntries>0?e.maxEntries:100}}var Fc=class{static createDiscoveryCache(e){const t=(n=e.maxEntries,o=e.ttlMs,"".concat(n,":").concat(o));var n,o;let i=(r=t,Zc.get(r));var r;return i||(i=new Dc(e.maxEntries,e.ttlMs),Zc.set(t,i)),i}static createJwksCache(){return{}}},Vc="openid profile email offline_access",Gc=Object.freeze(new Set(["grant_type","client_id","client_secret","client_assertion","client_assertion_type","subject_token","subject_token_type","requested_token_type","actor_token","actor_token_type","audience","aud","resource","resources","resource_indicator","scope","connection","login_hint","organization","assertion"]));function Xc(e){if(null==e)throw new Oa("subject_token is required");if("string"!=typeof e)throw new Oa("subject_token must be a string");if(0===e.trim().length)throw new Oa("subject_token cannot be blank or whitespace");if(e!==e.trim())throw new Oa("subject_token must not include leading or trailing whitespace");if(/^bearer\s+/i.test(e))throw new Oa("subject_token must not include the 'Bearer ' prefix")}function qc(e,t){if(t)for(const o of Object.entries(t)){var n=w(o,2);const t=n[0],i=n[1];if(!Gc.has(t))if(Array.isArray(i)){if(i.length>20)throw new Oa("Parameter '".concat(t,"' exceeds maximum array size of ").concat(20));i.forEach(n=>{e.append(t,n)})}else e.append(t,i)}}var Yc="urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token",Bc="urn:ietf:params:oauth:grant-type:token-exchange",Qc="urn:ietf:params:oauth:token-type:access_token";function $c(e,t){return(n,o)=>{const i=null==o?void 0:o.body;if(t!==fc||!(i instanceof URLSearchParams))return e(n,o);const r={};for(const e of i){var s=w(e,2);const t=s[0],n=s[1];r[t]="authn_response"===t?JSON.parse(n):n}const a=new Headers(null==o?void 0:o.headers);return a.set("Content-Type","application/json"),e(n,m(m({},o),{},{headers:a,body:JSON.stringify(r)}))}}var eu=(da=new WeakMap,ha=new WeakMap,pa=new WeakMap,fa=new WeakMap,ma=new WeakMap,ya=new WeakMap,wa=new WeakMap,ga=new WeakMap,va=new WeakMap,ba=new WeakMap,_a=new WeakMap,ka=new WeakSet,class{constructor(e){var t;if(h(this,ka),l(this,da,void 0),l(this,ha,void 0),l(this,pa,void 0),l(this,fa,void 0),l(this,ma,void 0),l(this,ya,void 0),l(this,wa,void 0),l(this,ga,void 0),l(this,va,void 0),l(this,ba,void 0),l(this,_a,void 0),p(this,"mfa",void 0),p(this,"passkey",void 0),p(this,"passwordless",void 0),p(this,"database",void 0),p(this,"anonymous",void 0),d(ma,this,e),e.useMtls&&!e.customFetch)throw new Pa("mtls_without_custom_fetch_not_supported","Using mTLS without a custom fetch implementation is not supported");d(wa,this,oc(e.telemetry)),d(ya,this,nc(null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)},u(wa,this)));const n=Hc(e.discoveryCache);d(va,this,Fc.createDiscoveryCache(n)),d(ba,this,new Map),d(_a,this,Fc.createJwksCache()),this.mfa=new ac({domain:u(ma,this).domain,clientId:u(ma,this).clientId,clientSecret:u(ma,this).clientSecret,customFetch:u(ya,this),telemetryConfig:u(wa,this),getConfiguration:async e=>(await s(ka,this,iu).call(this,e)).configuration,createCaptureConfiguration:async e=>{const t=(await s(ka,this,ru).call(this)).serverMetadata;return s(ka,this,nu).call(this,t,e)}}),this.passkey=new mc({domain:u(ma,this).domain,clientId:u(ma,this).clientId,clientSecret:u(ma,this).clientSecret,useMtls:u(ma,this).useMtls,customFetch:u(ya,this),telemetryConfig:u(wa,this),grantRequest:async(e,t,n,o)=>{const i=(await s(ka,this,ru).call(this)).serverMetadata,r=s(ka,this,ou).call(this,n);if(o){const n=ic(r),o=await s(ka,this,nu).call(this,i,n);o[Fi]=$c(n,e);const a=await vr(o,e,t),c=tc.fromTokenEndpointResponse(a),u=n.getCapturedResponse();if(!u)throw new Da;return{data:c,response:u}}const a=await s(ka,this,nu).call(this,i);a[Fi]=$c(r,e);const c=await vr(a,e,t);return tc.fromTokenEndpointResponse(c)}}),this.passwordless=new Pc({domain:u(ma,this).domain,clientId:u(ma,this).clientId,customFetch:u(ya,this),telemetryConfig:u(wa,this),clientSecret:u(ma,this).clientSecret,clientAssertionSigningKey:u(ma,this).clientAssertionSigningKey,clientAssertionSigningAlg:u(ma,this).clientAssertionSigningAlg,useMtls:u(ma,this).useMtls,grantRequest:async(e,t,n,o)=>{const i=(await s(ka,this,iu).call(this,n)).configuration;if(o){var r;const n=ic(null!==(r=i[Fi])&&void 0!==r?r:u(ya,this)),o=await s(ka,this,nu).call(this,i.serverMetadata(),n),a=await vr(o,e,t),c=tc.fromTokenEndpointResponse(a),l=n.getCapturedResponse();if(!l)throw new Da;return{data:c,response:l}}try{const n=await vr(i,e,t);return tc.fromTokenEndpointResponse(n)}catch(e){const t=e,n={};throw Ha(n,e),t._statusCode=n.statusCode,t._headers=n.headers,e}}}),this.database=new Wc({domain:u(ma,this).domain,clientId:u(ma,this).clientId,customFetch:u(ya,this),telemetryConfig:u(wa,this)}),this.anonymous=new Lc({domain:u(ma,this).domain,clientId:u(ma,this).clientId,clientSecret:u(ma,this).clientSecret,clientAssertionSigningKey:u(ma,this).clientAssertionSigningKey,clientAssertionSigningAlg:u(ma,this).clientAssertionSigningAlg,useMtls:u(ma,this).useMtls,customFetch:u(ya,this)})}async getServerMetadata(){return(await s(ka,this,ru).call(this)).serverMetadata}async buildAuthorizationUrl(e){const t=(await s(ka,this,ru).call(this)).serverMetadata;if(null!=e&&e.pushedAuthorizationRequests&&!t.pushed_authorization_request_endpoint)throw new Pa("par_not_supported_error","The Auth0 tenant does not have pushed authorization requests enabled. Learn how to enable it here: https://auth0.com/docs/get-started/applications/configure-par");try{return await s(ka,this,hu).call(this,e)}catch(e){throw new Ka(e)}}async buildLinkUserUrl(e){try{const t=await s(ka,this,hu).call(this,{authorizationParams:m(m({},e.authorizationParams),{},{requested_connection:e.connection,requested_connection_scope:e.connectionScope,scope:"openid link_account offline_access",id_token_hint:e.idToken})});return{linkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new Ua(e)}}async buildUnlinkUserUrl(e){try{const t=await s(ka,this,hu).call(this,{authorizationParams:m(m({},e.authorizationParams),{},{requested_connection:e.connection,scope:"openid unlink_account",id_token_hint:e.idToken})});return{unlinkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new La(e)}}async backchannelAuthentication(e,t){var n;const o=await s(ka,this,iu).call(this,t),i=o.configuration,r=o.serverMetadata,a=Fa(m(m({},u(ma,this).authorizationParams),null==e?void 0:e.authorizationParams)),c=new URLSearchParams(m(m({scope:Vc},a),{},{client_id:u(ma,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:r.issuer,sub:e.loginHint.sub})}));if(e.requestedExpiry&&c.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&c.append("authorization_details",JSON.stringify(e.authorizationDetails)),e.fullResponse){var l;const e=ic(null!==(l=i[Fi])&&void 0!==l?l:u(ya,this)),t=await s(ka,this,nu).call(this,i.serverMetadata(),e);try{const n=await sr(i,c),o=await ar(t,n),r=e.getCapturedResponse();if(!r)throw new Da;return{data:tc.fromTokenEndpointResponse(o),response:r}}catch(t){if(t instanceof Da)throw t;const n=new Na(t);throw Ha(n,t,e.getCapturedResponse()),n}}const d=ic(null!==(n=i[Fi])&&void 0!==n?n:u(ya,this)),h=await s(ka,this,nu).call(this,i.serverMetadata(),d);try{const e=await sr(i,c),t=await ar(h,e);return tc.fromTokenEndpointResponse(t)}catch(e){const t=new Na(e);throw Ha(t,e,d.getCapturedResponse()),t}}async initiateBackchannelAuthentication(e,t){var n;const o=await s(ka,this,iu).call(this,t),i=o.configuration,r=o.serverMetadata,a=Fa(m(m({},u(ma,this).authorizationParams),null==e?void 0:e.authorizationParams)),c=new URLSearchParams(m(m({scope:Vc},a),{},{client_id:u(ma,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:r.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&c.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&c.append("authorization_details",JSON.stringify(e.authorizationDetails));const l=ic(null!==(n=i[Fi])&&void 0!==n?n:u(ya,this)),d=await s(ka,this,nu).call(this,i.serverMetadata(),l);try{const e=await sr(d,c);return{authReqId:e.auth_req_id,expiresIn:e.expires_in,interval:e.interval}}catch(e){const t=new Na(e),n=l.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async backchannelAuthenticationGrant(e,t){var n;let o=e.authReqId;const i=(await s(ka,this,iu).call(this,t)).configuration,r=new URLSearchParams({auth_req_id:o}),a=ic(null!==(n=i[Fi])&&void 0!==n?n:u(ya,this)),c=await s(ka,this,nu).call(this,i.serverMetadata(),a);try{const e=await vr(c,"urn:openid:params:grant-type:ciba",r);return tc.fromTokenEndpointResponse(e)}catch(e){const t=new Na(e),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async getTokenForConnection(e,t){var n;if(e.refreshToken&&e.accessToken)throw new Ia("Either a refresh or access token should be specified, but not both.");const o=null!==(n=e.accessToken)&&void 0!==n?n:e.refreshToken;if(!o)throw new Ia("Either a refresh or access token must be specified.");try{return await this.exchangeToken(m({connection:e.connection,subjectToken:o,subjectTokenType:e.accessToken?Qc:"urn:ietf:params:oauth:token-type:refresh_token",loginHint:e.loginHint},e.fullResponse?{fullResponse:!0}:{}),t)}catch(e){if(e instanceof Oa){const t=new Ia(e.message,e.cause);throw t.statusCode=e.statusCode,t.headers=e.headers,t}throw e}}async exchangeToken(e,t){return e.fullResponse?"connection"in e?s(ka,this,au).call(this,e,t,!0):s(ka,this,uu).call(this,e,t,!0):"connection"in e?s(ka,this,au).call(this,e,t):s(ka,this,uu).call(this,e,t)}async getTokenByCode(e,t,n){var o;const i=(await s(ka,this,iu).call(this,n)).configuration;if(void 0!==t.organization&&Va(t.organization),t.fullResponse){var r;const n=ic(null!==(r=i[Fi])&&void 0!==r?r:u(ya,this)),o=await s(ka,this,nu).call(this,i.serverMetadata(),n);let a,c;try{const i=await ur(o,e,{pkceCodeVerifier:t.codeVerifier});if(a=tc.fromTokenEndpointResponse(i),c=n.getCapturedResponse(),!c)throw new Da}catch(e){if(e instanceof Da)throw e;const t=new Ca("There was an error while trying to request a token.",Ta(e)),o=n.getCapturedResponse();throw t.statusCode=null==o?void 0:o.status,t.headers=o?Za(o.headers):void 0,t}return t.organization&&Ga(a.claims,t.organization),{data:a,response:c}}const a=ic(null!==(o=i[Fi])&&void 0!==o?o:u(ya,this)),c=await s(ka,this,nu).call(this,i.serverMetadata(),a);let l;try{const n=await ur(c,e,{pkceCodeVerifier:t.codeVerifier});l=tc.fromTokenEndpointResponse(n)}catch(e){const t=new Ca("There was an error while trying to request a token.",Ta(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}return t.organization&&Ga(l.claims,t.organization),l}async getTokenByMagicLinkCode(e,t,n){var o;const i=(await s(ka,this,iu).call(this,n)).configuration;if(null!=t&&t.fullResponse){var r;const n=ic(null!==(r=i[Fi])&&void 0!==r?r:u(ya,this)),o=await s(ka,this,nu).call(this,i.serverMetadata(),n);try{const i=await ur(o,e,{expectedState:null==t?void 0:t.expectedState}),r=tc.fromTokenEndpointResponse(i),s=n.getCapturedResponse();if(!s)throw new Da;return{data:r,response:s}}catch(e){if(e instanceof Da)throw e;const t=e instanceof Error&&e.message?e.message:"There was an error while trying to request a token.",o=new Ca(t,e),i=n.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Za(i.headers):void 0,o}}const a=ic(null!==(o=i[Fi])&&void 0!==o?o:u(ya,this)),c=await s(ka,this,nu).call(this,i.serverMetadata(),a);try{const n=await ur(c,e,{expectedState:null==t?void 0:t.expectedState});return tc.fromTokenEndpointResponse(n)}catch(e){const t=e instanceof Error&&e.message?e.message:"There was an error while trying to request a token.",n=new Ca(t,e),o=a.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}}async getTokenByRefreshToken(e,t){var n;const o=(await s(ka,this,iu).call(this,t)).configuration,i=new URLSearchParams;if(e.audience&&i.append("audience",e.audience),e.scope&&i.append("scope",e.scope),e.fullResponse){var r;const t=ic(null!==(r=o[Fi])&&void 0!==r?r:u(ya,this)),n=await s(ka,this,nu).call(this,o.serverMetadata(),t);try{const o=await lr(n,e.refreshToken,i),r=tc.fromTokenEndpointResponse(o),s=t.getCapturedResponse();if(!s)throw new Da;return{data:r,response:s}}catch(e){if(e instanceof Da)throw e;const n=new Aa("The access token has expired and there was an error while trying to refresh it.",Ta(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}}const a=ic(null!==(n=o[Fi])&&void 0!==n?n:u(ya,this)),c=await s(ka,this,nu).call(this,o.serverMetadata(),a);try{const t=await lr(c,e.refreshToken,i);return tc.fromTokenEndpointResponse(t)}catch(e){const t=new Aa("The access token has expired and there was an error while trying to refresh it.",Ta(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async revokeToken(e,t){var n;const o=(await s(ka,this,iu).call(this,t)).configuration,i={};e.tokenTypeHint&&(i.token_type_hint=e.tokenTypeHint);const r=ic(null!==(n=o[Fi])&&void 0!==n?n:u(ya,this)),a=await s(ka,this,nu).call(this,o.serverMetadata(),r);try{await br(a,e.token,i)}catch(e){const t=new ja("An error occurred while trying to revoke the token.",Ta(e)),n=r.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async getUserInfo(e,t){const n=(await s(ka,this,iu).call(this,t,!0)).configuration;try{var o;return await yr(n,e.accessToken,null!==(o=e.expectedSubject)&&void 0!==o?o:Hi)}catch(e){throw new Wa("There was an error while trying to retrieve the user info.",Ta(e))}}async getTokenByPassword(e,t){var n;const o=(await s(ka,this,iu).call(this,t)).configuration,i=new URLSearchParams({username:e.username,password:e.password});e.audience&&i.append("audience",e.audience),e.scope&&i.append("scope",e.scope),e.realm&&i.append("realm",e.realm);let r=o;if(e.auth0ForwardedFor){const t=await s(ka,this,du).call(this);r=new nr(o.serverMetadata(),u(ma,this).clientId,{client_secret:u(ma,this).clientSecret,use_mtls_endpoint_aliases:u(ma,this).useMtls},t);const n=o[Fi];r[Fi]=(t,o)=>n(t,m(m({},o),{},{headers:m(m({},o.headers),{},{"auth0-forwarded-for":e.auth0ForwardedFor})}))}if(e.fullResponse){var a;const e=ic(null!==(a=r[Fi])&&void 0!==a?a:u(ya,this)),t=await s(ka,this,nu).call(this,r.serverMetadata(),e);try{const n=await vr(t,"password",i),o=tc.fromTokenEndpointResponse(n),r=e.getCapturedResponse();if(!r)throw new Da;return{data:o,response:r}}catch(t){if(t instanceof Da)throw t;const n=new xa("There was an error while trying to request a token.",Ta(t)),o=e.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}}const c=ic(null!==(n=r[Fi])&&void 0!==n?n:u(ya,this)),l=await s(ka,this,nu).call(this,r.serverMetadata(),c);try{const e=await vr(l,"password",i);return tc.fromTokenEndpointResponse(e)}catch(e){const t=new xa("There was an error while trying to request a token.",Ta(e)),n=c.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async getTokenByPasswordlessEmail(e,t){const n=new URLSearchParams({username:e.email,otp:e.code,realm:"email"});return e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),s(ka,this,lu).call(this,n,t,e.fullResponse)}async getTokenByPasswordlessSms(e,t){if(!Sc(e.phoneNumber))throw new bc("Phone number must be in E.164 format (e.g. +14155550100).");const n=new URLSearchParams({username:e.phoneNumber,otp:e.code,realm:"sms"});return e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),s(ka,this,lu).call(this,n,t,e.fullResponse)}async getTokenByClientCredentials(e,t){var n;const o=(await s(ka,this,iu).call(this,t)).configuration;if(e.fullResponse){var i;const t=ic(null!==(i=o[Fi])&&void 0!==i?i:u(ya,this)),n=await s(ka,this,nu).call(this,o.serverMetadata(),t),r=new URLSearchParams({audience:e.audience});e.organization&&r.append("organization",e.organization);try{const e=await dr(n,r),o=tc.fromTokenEndpointResponse(e),i=t.getCapturedResponse();if(!i)throw new Da;return{data:o,response:i}}catch(e){if(e instanceof Da)throw e;const n=new Ra("There was an error while trying to request a token.",Ta(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}}const r=ic(null!==(n=o[Fi])&&void 0!==n?n:u(ya,this)),a=await s(ka,this,nu).call(this,o.serverMetadata(),r);try{const t=new URLSearchParams({audience:e.audience});e.organization&&t.append("organization",e.organization);const n=await dr(a,t);return tc.fromTokenEndpointResponse(n)}catch(e){const t=new Ra("There was an error while trying to request a token.",Ta(e)),n=r.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async buildLogoutUrl(e){const t=await s(ka,this,ru).call(this),n=t.configuration;if(!t.serverMetadata.end_session_endpoint){const t=new URL("https://".concat(u(ma,this).domain,"/v2/logout"));return t.searchParams.set("returnTo",e.returnTo),t.searchParams.set("client_id",u(ma,this).clientId),e.federated&&t.searchParams.set("federated",""),t}const o={post_logout_redirect_uri:e.returnTo};return e.federated&&(o.federated=""),function(e,t){fr(e);const n=zi(e),o=n.as,i=n.c,r=_n(o,"end_session_endpoint",!1,n.tlsOnly);(t=new URLSearchParams(t)).has("client_id")||t.set("client_id",i.client_id);for(const e of t.entries()){var s=w(e,2);const t=s[0],n=s[1];r.searchParams.append(t,n)}return r}(n,o)}async verifyLogoutToken(e){const t=(await s(ka,this,ru).call(this)).serverMetadata,n=Hc(u(ma,this).discoveryCache),o=t.jwks_uri;u(ga,this)||d(ga,this,_s(new URL(o),{cacheMaxAge:n.ttlMs,[ws]:u(ya,this),[gs]:u(_a,this)}));const i=(await Xr(e.logoutToken,u(ga,this),{issuer:t.issuer,audience:u(ma,this).clientId,algorithms:["RS256"],requiredClaims:["iat"]})).payload;if(!("sid"in i)&&!("sub"in i))throw new Ma('either "sid" or "sub" (or both) claims must be present');if("sid"in i&&"string"!=typeof i.sid)throw new Ma('"sid" claim must be a string');if("sub"in i&&"string"!=typeof i.sub)throw new Ma('"sub" claim must be a string');if("nonce"in i)throw new Ma('"nonce" claim is prohibited');if(!("events"in i))throw new Ma('"events" claim is missing');if("object"!=typeof i.events||null===i.events)throw new Ma('"events" claim must be an object');if(!("http://schemas.openid.net/event/backchannel-logout"in i.events))throw new Ma('"http://schemas.openid.net/event/backchannel-logout" member is missing in the "events" claim');if("object"!=typeof i.events["http://schemas.openid.net/event/backchannel-logout"])throw new Ma('"http://schemas.openid.net/event/backchannel-logout" member in the "events" claim must be an object');return{sid:i.sid,sub:i.sub}}});function tu(){const e=u(ma,this).domain.toLowerCase();return"".concat(e,"|mtls:").concat(u(ma,this).useMtls?"1":"0")}async function nu(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];const o=await s(ka,this,du).call(this,n),i=new nr(e,u(ma,this).clientId,{client_secret:u(ma,this).clientSecret,use_mtls_endpoint_aliases:u(ma,this).useMtls},o);return i[Fi]=null!=t?t:u(ya,this),i}function ou(e){return rc(u(ya,this),e,u(wa,this))}async function iu(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];const n=await s(ka,this,ru).call(this,t),o=n.configuration,i=n.serverMetadata;if(!e)return{configuration:o,serverMetadata:i};const r=s(ka,this,ou).call(this,e);return{configuration:await s(ka,this,nu).call(this,i,r,t),serverMetadata:i}}async function ru(){let e=arguments.length>0&&void 0!==arguments[0]&&arguments[0];const t=u(e?ha:da,this);if(t&&u(pa,this))return{configuration:t,serverMetadata:u(pa,this)};const n=s(ka,this,tu).call(this);e||await s(ka,this,du).call(this,!1);const o=u(va,this).get(n);if(o)return s(ka,this,su).call(this,o.serverMetadata,e);const i=u(ba,this).get(n);if(i){const t=await i;return s(ka,this,su).call(this,t.serverMetadata,e)}const r=(async()=>{const e=(await er(new URL("https://".concat(u(ma,this).domain)),u(ma,this).clientId,{use_mtls_endpoint_aliases:u(ma,this).useMtls},(e,t,n,o)=>{n.set("client_id",t.client_id)},{[Fi]:u(ya,this)})).serverMetadata();return u(va,this).set(n,{serverMetadata:e}),{serverMetadata:e}})();r.catch(()=>{}),u(ba,this).set(n,r);try{const t=(await r).serverMetadata;return s(ka,this,su).call(this,t,e)}finally{u(ba,this).delete(n)}}async function su(e,t){const n=await s(ka,this,nu).call(this,e,void 0,t);return d(pa,this,e),d(t?ha:da,this,n),{configuration:n,serverMetadata:e}}async function au(e,t,n){var o,i,r;const a=(await s(ka,this,iu).call(this,t)).configuration;if("audience"in e||"resource"in e)throw new Oa("audience and resource parameters are not supported for Token Vault exchanges");Xc(e.subjectToken);const c=new URLSearchParams({connection:e.connection,subject_token:e.subjectToken,subject_token_type:null!==(o=e.subjectTokenType)&&void 0!==o?o:Qc,requested_token_type:null!==(i=e.requestedTokenType)&&void 0!==i?i:"http://auth0.com/oauth/token-type/federated-connection-access-token"});if(e.loginHint&&c.append("login_hint",e.loginHint),e.scope&&c.append("scope",e.scope),qc(c,e.extra),n){var l;const t=ic(null!==(l=a[Fi])&&void 0!==l?l:u(ya,this)),n=await s(ka,this,nu).call(this,a.serverMetadata(),t);try{const e=await vr(n,Yc,c),o=tc.fromTokenEndpointResponse(e),i=t.getCapturedResponse();if(!i)throw new Da;return{data:o,response:i}}catch(n){if(n instanceof Da)throw n;const o=new Oa("Failed to exchange token for connection '".concat(e.connection,"'."),Ta(n)),i=t.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Za(i.headers):void 0,o}}const d=ic(null!==(r=a[Fi])&&void 0!==r?r:u(ya,this)),h=await s(ka,this,nu).call(this,a.serverMetadata(),d);try{const e=await vr(h,Yc,c);return tc.fromTokenEndpointResponse(e)}catch(t){const n=new Oa("Failed to exchange token for connection '".concat(e.connection,"'."),Ta(t)),o=d.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}}function cu(e,t,n){var o;if(n.organization&&Ga(e.claims,n.organization),n.actorToken)if(null!==(o=e.claims)&&void 0!==o&&o.act)e.act=e.claims.act;else try{e.act=function(e){if("string"!=typeof e)throw new Go("JWTs must use Compact JWS serialization, JWT must be a string");const t=e.split("."),n=t[1],o=t.length;if(5===o)throw new Go("Only JWTs using Compact JWS serialization can be decoded");if(3!==o)throw new Go("Invalid JWT");if(!n)throw new Go("JWTs must contain a payload");let i,r;try{i=oi(n)}catch(e){throw new Go("Failed to base64url decode the payload")}try{r=JSON.parse(Mo.decode(i))}catch(e){throw new Go("Failed to parse the decoded payload as JSON")}if(!ri(r))throw new Go("Invalid JWT Claims Set");return r}(t.access_token).act}catch(e){}return e}async function uu(e,t,n){var o;const i=(await s(ka,this,iu).call(this,t)).configuration;if(Xc(e.subjectToken),void 0!==e.organization&&Va(e.organization),void 0!==e.actorToken&&void 0===e.actorTokenType)throw new Oa("actorTokenType is required when actorToken is provided");const r=new URLSearchParams({subject_token_type:e.subjectTokenType,subject_token:e.subjectToken});if(e.audience&&r.append("audience",e.audience),e.scope&&r.append("scope",e.scope),e.requestedTokenType&&r.append("requested_token_type",e.requestedTokenType),e.organization&&r.append("organization",e.organization),e.actorToken&&r.append("actor_token",e.actorToken),e.actorTokenType&&r.append("actor_token_type",e.actorTokenType),qc(r,e.extra),n){var a;const t=ic(null!==(a=i[Fi])&&void 0!==a?a:u(ya,this)),n=await s(ka,this,nu).call(this,i.serverMetadata(),t);let o,c,l;try{if(c=await vr(n,Bc,r),o=tc.fromTokenEndpointResponse(c),l=t.getCapturedResponse(),!l)throw new Da}catch(n){if(n instanceof Da)throw n;const o=new Oa("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),Ta(n)),i=t.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Za(i.headers):void 0,o}return s(ka,this,cu).call(this,o,c,e),{data:o,response:l}}const c=ic(null!==(o=i[Fi])&&void 0!==o?o:u(ya,this)),l=await s(ka,this,nu).call(this,i.serverMetadata(),c);let d,h;try{h=await vr(l,Bc,r),d=tc.fromTokenEndpointResponse(h)}catch(t){const n=new Oa("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),Ta(t)),o=c.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}return s(ka,this,cu).call(this,d,h,e),d}async function lu(e,t,n){var o;const i=(await s(ka,this,iu).call(this,t)).configuration;if(n){var r;const t=ic(null!==(r=i[Fi])&&void 0!==r?r:u(ya,this)),n=await s(ka,this,nu).call(this,i.serverMetadata(),t);try{const o=await vr(n,"http://auth0.com/oauth/grant-type/passwordless/otp",e),i=tc.fromTokenEndpointResponse(o),r=t.getCapturedResponse();if(!r)throw new Da;return{data:i,response:r}}catch(e){if(e instanceof Da)throw e;const n=new bc("There was an error while trying to request a token.",Ta(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Za(o.headers):void 0,n}}const a=ic(null!==(o=i[Fi])&&void 0!==o?o:u(ya,this)),c=await s(ka,this,nu).call(this,i.serverMetadata(),a);try{const t=await vr(c,"http://auth0.com/oauth/grant-type/passwordless/otp",e);return tc.fromTokenEndpointResponse(t)}catch(e){const t=new bc("There was an error while trying to request a token.",Ta(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Za(n.headers):void 0,t}}async function du(){let e=arguments.length>0&&void 0!==arguments[0]&&arguments[0];const t=!!u(ma,this).clientSecret||!!u(ma,this).clientAssertionSigningKey||!!u(ma,this).useMtls;return e&&!t?(e,t,n,o)=>{n.set("client_id",t.client_id)}:(u(fa,this)||d(fa,this,(async()=>{if(!u(ma,this).clientSecret&&!u(ma,this).clientAssertionSigningKey&&!u(ma,this).useMtls)throw new za;if(u(ma,this).useMtls)return(e,t,n,o)=>{n.set("client_id",t.client_id)};let e=u(ma,this).clientAssertionSigningKey;return!e||e instanceof CryptoKey||(e=await ks(e,u(ma,this).clientAssertionSigningAlg||"RS256")),e?function(e,t){return wn(e,t)}(e):Zi(u(ma,this).clientSecret)})().catch(e=>{throw d(fa,this,void 0),e})),u(fa,this))}async function hu(e){const t=(await s(ka,this,ru).call(this)).configuration,n=Yi(),o=await qi(n),i=Fa(m(m({},u(ma,this).authorizationParams),null==e?void 0:e.authorizationParams)),r=new URLSearchParams(m(m({scope:Vc},i),{},{client_id:u(ma,this).clientId,code_challenge:o,code_challenge_method:"S256"}));return{authorizationUrl:null!=e&&e.pushedAuthorizationRequests?await pr(t,r):await hr(t,r),codeVerifier:n}}var pu=new Dc(1e3,6e4);class fu extends C{constructor(e,t){super(e,t),Object.setPrototypeOf(this,fu.prototype)}static fromPayload(e){let t=e.error,n=e.error_description;return new fu(t,n)}}class mu extends fu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,mu.prototype)}}class yu extends fu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,yu.prototype)}}class wu extends fu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,wu.prototype)}}class gu extends fu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,gu.prototype)}}class vu extends fu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,vu.prototype)}}class bu{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:6e5;this.contexts=new Map,this.ttlMs=e}set(e,t){this.cleanup(),this.contexts.set(e,Object.assign(Object.assign({},t),{createdAt:Date.now()}))}get(e){const t=this.contexts.get(e);if(t){if(!(Date.now()-t.createdAt>this.ttlMs))return t;this.contexts.delete(e)}}remove(e){this.contexts.delete(e)}cleanup(){const e=Date.now();for(const n of this.contexts){var t=w(n,2);const o=t[0];e-t[1].createdAt>this.ttlMs&&this.contexts.delete(o)}}get size(){return this.contexts.size}}class _u{constructor(e,t){this.authJsMfaClient=e,this.auth0Client=t,this.contextManager=new bu}setMFAAuthDetails(e,t,n,o){this.contextManager.set(e,{scope:t,audience:n,mfaRequirements:o})}async getAuthenticators(e){var t,n,o;const i=this.contextManager.get(e);if(!i)throw new mu("invalid_request","MFA context not found for this MFA token");const r=null===(n=null===(t=i.mfaRequirements)||void 0===t?void 0:t.challenge)||void 0===n?void 0:n.map(e=>e.type);try{const t=await this.authJsMfaClient.listAuthenticators({mfaToken:e});return r&&0!==r.length?t.filter(e=>!!e.type&&r.includes(e.type)):t}catch(e){if(e instanceof qa)throw new mu(null===(o=e.cause)||void 0===o?void 0:o.error,e.message);throw e}}async enroll(e){var t;const n=function(e){const t=Ct[e.factorType];return Object.assign(Object.assign(Object.assign({mfaToken:e.mfaToken,authenticatorTypes:t.authenticatorTypes},t.oobChannels&&{oobChannels:t.oobChannels}),"phoneNumber"in e&&{phoneNumber:e.phoneNumber}),"email"in e&&{email:e.email})}(e);try{return await this.authJsMfaClient.enrollAuthenticator(n)}catch(e){if(e instanceof Ya)throw new yu(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async challenge(e){var t;try{const t={challengeType:e.challengeType,mfaToken:e.mfaToken};return e.authenticatorId&&(t.authenticatorId=e.authenticatorId),await this.authJsMfaClient.challengeAuthenticator(t)}catch(e){if(e instanceof Qa)throw new wu(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async getEnrollmentFactors(e){const t=this.contextManager.get(e);if(!t||!t.mfaRequirements)throw new vu("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");return t.mfaRequirements.enroll&&0!==t.mfaRequirements.enroll.length?t.mfaRequirements.enroll:[]}async verify(e){const t=this.contextManager.get(e.mfaToken);if(!t)throw new gu("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");const n=function(e){return"otp"in e&&e.otp?Rt:"oobCode"in e&&e.oobCode?At:"recoveryCode"in e&&e.recoveryCode?xt:void 0}(e);if(!n)throw new gu("invalid_request","Unable to determine grant type. Provide one of: otp, oobCode, or recoveryCode.");const o=t.scope,i=t.audience;try{const t=await this.auth0Client._requestTokenForMfa({grant_type:n,mfaToken:e.mfaToken,scope:o,audience:i,otp:e.otp,oob_code:e.oobCode,binding_code:e.bindingCode,recovery_code:e.recoveryCode});return this.contextManager.remove(e.mfaToken),t}catch(e){if(e instanceof gu)throw new gu(e.error,e.error_description);throw e}}}class ku extends Error{constructor(e,t,n){super(t),this.name="PasskeyError",this.code=e,this.cause=n,Object.setPrototypeOf(this,ku.prototype)}}var Su,Tu;class Pu{constructor(e,t){Su.set(this,void 0),Tu.set(this,void 0),o(this,Su,e,"f"),o(this,Tu,t,"f")}async signup(e){if(!window.PublicKeyCredential)throw new ku("passkey_not_supported","WebAuthn is not supported in this browser.");const o=e.scope,i=e.audience,r=t(e,["scope","audience"]),s=await n(this,Su,"f").register(r),a=Ru(s.authnParamsPublicKey),c=await navigator.credentials.create({publicKey:a});if(!c)throw new ku("passkey_cancelled","Passkey creation was cancelled or no credential was returned.");const u=xu(c);return n(this,Tu,"f")._requestTokenForPasskey({authSession:s.authSession,credential:u,realm:r.realm,organization:r.organization,scope:o,audience:i})}async login(e){if(!window.PublicKeyCredential)throw new ku("passkey_not_supported","WebAuthn is not supported in this browser.");const o=e||{},i=o.scope,r=o.audience,s=t(o,["scope","audience"]),a=await n(this,Su,"f").challenge(Object.keys(s).length>0?s:void 0),c=Au(a.authnParamsPublicKey),u=await navigator.credentials.get({publicKey:c});if(!u)throw new ku("passkey_cancelled","Passkey authentication was cancelled or no credential was returned.");const l=Iu(u);return n(this,Tu,"f")._requestTokenForPasskey({authSession:a.authSession,credential:l,realm:s.realm,organization:s.organization,scope:i,audience:r})}async getSignupChallenge(e){if(!window.PublicKeyCredential)throw new ku("passkey_not_supported","WebAuthn is not supported in this browser.");const t=await n(this,Su,"f").register(e);return{authSession:t.authSession,publicKey:Ru(t.authnParamsPublicKey)}}async getLoginChallenge(e){if(!window.PublicKeyCredential)throw new ku("passkey_not_supported","WebAuthn is not supported in this browser.");const t=await n(this,Su,"f").challenge(e);return{authSession:t.authSession,publicKey:Au(t.authnParamsPublicKey)}}async getTokenWithPasskey(e){if(!window.PublicKeyCredential)throw new ku("passkey_not_supported","WebAuthn is not supported in this browser.");const t=e.authSession,o=e.credential,i=e.realm,r=e.organization,s=e.scope,a=e.audience,c=o.response;let u;if(c instanceof AuthenticatorAttestationResponse)u=xu(o);else{if(!(c instanceof AuthenticatorAssertionResponse))throw new ku("passkey_invalid_credential","The provided credential is not a valid attestation or assertion response.");u=Iu(o)}return n(this,Tu,"f")._requestTokenForPasskey({authSession:t,credential:u,realm:i,organization:r,scope:s,audience:a})}}function Eu(e){const t=new Uint8Array(e),n=Array.from(t,e=>String.fromCharCode(e)).join("");return btoa(n).replace(/\+/g,"-").replace(/\//g,"_").replace(/=+$/,"")}function Cu(e){const t=e.replace(/-/g,"+").replace(/_/g,"/"),n=t+"=".repeat((4-t.length%4)%4),o=atob(n),i=new Uint8Array(o.length);for(let e=0;e<o.length;e++)i[e]=o.charCodeAt(e);return i.buffer}function Ru(e){return Object.assign(Object.assign({},e),{challenge:Cu(e.challenge),user:Object.assign(Object.assign({},e.user),{id:Cu(e.user.id)}),pubKeyCredParams:e.pubKeyCredParams,authenticatorSelection:e.authenticatorSelection})}function Au(e){return Object.assign(Object.assign({},e),{challenge:Cu(e.challenge)})}function xu(e){var t;const n=e.response;return{id:e.id,rawId:Eu(e.rawId),type:e.type,authenticatorAttachment:null!==(t=e.authenticatorAttachment)&&void 0!==t?t:void 0,response:{clientDataJSON:Eu(n.clientDataJSON),attestationObject:Eu(n.attestationObject)},clientExtensionResults:e.getClientExtensionResults()}}function Iu(e){var t;const n=e.response;return{id:e.id,rawId:Eu(e.rawId),type:e.type,authenticatorAttachment:null!==(t=e.authenticatorAttachment)&&void 0!==t?t:void 0,response:{clientDataJSON:Eu(n.clientDataJSON),authenticatorData:Eu(n.authenticatorData),signature:Eu(n.signature),userHandle:n.userHandle?Eu(n.userHandle):void 0},clientExtensionResults:e.getClientExtensionResults()}}Su=new WeakMap,Tu=new WeakMap;class Ou{resolveOnlineAccess(e){if("online"!==e.refreshTokenMode)return!1;if(!0!==e.useRefreshTokens)throw new R('`refreshTokenMode: "online"` requires the refresh-token grant.',"Set `useRefreshTokens: true`.");if(!0!==e.useDpop)throw new R('`refreshTokenMode: "online"` requires DPoP, which is missing or disabled.',"Set `useDpop: true` (DPoP is mandatory for online access).");return!0}warnEnterpriseConnectConfig(e){var t,n;if(!0!==e.enterpriseConnect)return;const o=null===(t=e.authorizationParams)||void 0===t?void 0:t.scope;(!0===e.useRefreshTokens||"string"==typeof o&&o.includes("offline_access"))&&console.warn("Enterprise Connect issues no refresh token; `useRefreshTokens` and `offline_access` in `scope` have no effect."),(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)&&console.warn("Enterprise Connect resolves the organization from the email domain (Home Realm Discovery); a static `organization` breaks multi-customer setups.")}constructor(e){let t,n;if(this.userCache=(new Ze).enclosedCache,this.defaultOptions={authorizationParams:{scope:"openid profile email"},useRefreshTokensFallback:!1,useFormData:!0,refreshTokenMode:"offline"},this.onlineAccess=this.resolveOnlineAccess(e),this.warnEnterpriseConnectConfig(e),this.options=Object.assign(Object.assign(Object.assign({},this.defaultOptions),e),{authorizationParams:Object.assign(Object.assign({},this.defaultOptions.authorizationParams),e.authorizationParams)}),"undefined"!=typeof window&&(()=>{if(!z())throw new Error("For security reasons, `window.crypto` is required to run `auth0-spa-js`.");if(void 0===z().subtle)throw new Error("\n auth0-spa-js must run on a secure origin. See https://github.com/auth0/auth0-spa-js/blob/main/FAQ.md#why-do-i-get-auth0-spa-js-must-run-on-a-secure-origin for more information.\n ")})(),this.lockManager=(he||(he=de()),he),e.cache&&e.cacheLocation&&console.warn("Both `cache` and `cacheLocation` options have been specified in the Auth0Client configuration; ignoring `cacheLocation` and using `cache`."),e.cache)n=e.cache;else{if(t=e.cacheLocation||k,!wt(t))throw new Error('Invalid cache location "'.concat(t,'"'));n=wt(t)()}var o;this.httpTimeoutMs=e.httpTimeoutInSeconds?1e3*e.httpTimeoutInSeconds:_,this.cookieStorage=!1===e.legacySameSiteCookie?ot:rt,this.orgHintCookieName=(o=this.options.clientId,"auth0.".concat(o,".organization_hint")),this.isAuthenticatedCookieName=(e=>"auth0.".concat(e,".is.authenticated"))(this.options.clientId),this.sessionCheckExpiryDays=e.sessionCheckExpiryDays||1;const i=e.useCookiesForTransactions?this.cookieStorage:st;let r="";var s;this.onlineAccess?r=S:this.options.useRefreshTokens&&(r="offline_access"),this.scope=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];if("object"!=typeof e)return{[E]:Ke(t,e,...o)};let r={[E]:Ke(t,...o)};return Object.keys(e).forEach(n=>{const i=e[n];r[n]=Ke(t,i,...o)}),r}(this.options.authorizationParams.scope,"openid",r),this.transactionManager=new Fe(i,this.options.clientId,this.options.cookieDomain),this.nowProvider=this.options.nowProvider||P,this.cacheManager=new He(n,n.allKeys?void 0:new ft(n,this.options.clientId),this.nowProvider),this.dpop=this.options.useDpop?new kt(this.options.clientId):void 0,this.domainUrl=(s=this.options.domain,/^https?:\/\//.test(s)?s:"https://".concat(s)),this.tokenIssuer=((e,t)=>e?e.startsWith("https://")?e:"https://".concat(e,"/"):"".concat(t,"/"))(this.options.issuer,this.domainUrl);const a="".concat(this.domainUrl,"/me/"),c=this.createFetcher(Object.assign(Object.assign({},this.options.useDpop&&{dpopNonceId:"__auth0_my_account_api__"}),{getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:a},detailedResponse:!0})}}));this.myAccount=new Pt(c,a),this.authJsClient=new eu({domain:this.options.domain,clientId:this.options.clientId}),this.mfa=new _u(this.authJsClient.mfa,this),this.passkey=new Pu(this.authJsClient.passkey,this),"undefined"!=typeof window&&window.Worker&&this.options.useRefreshTokens&&t===k&&(this.options.workerUrl?this.worker=new Worker(this.options.workerUrl):this.worker=new pt,this.worker.postMessage({type:"init",allowedBaseUrl:this.domainUrl}))}getConfiguration(){return Object.freeze({domain:this.options.domain,clientId:this.options.clientId})}_url(e){const t=this.options.auth0Client||T,n=H(t,!0),o=encodeURIComponent(btoa(JSON.stringify(n)));return"".concat(this.domainUrl).concat(e,"&auth0Client=").concat(o)}_authorizeUrl(e){return this._url("/authorize?".concat(F(e)))}async _verifyIdToken(e,t,n){const o=await this.nowProvider();return Xe({iss:this.tokenIssuer,aud:this.options.clientId,id_token:e,nonce:t,organization:n,leeway:this.options.leeway,max_age:(i=this.options.authorizationParams.max_age,"string"!=typeof i?i:parseInt(i,10)||void 0),now:o});var i}_processOrgHint(e){e?this.cookieStorage.save(this.orgHintCookieName,e,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}):this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain})}_extractSessionTransferToken(e){return new URLSearchParams(window.location.search).get(e)||void 0}_clearSessionTransferTokenFromUrl(e){try{const t=new URL(window.location.href);t.searchParams.has(e)&&(t.searchParams.delete(e),window.history.replaceState({},"",t.toString()))}catch(e){}}_applySessionTransferToken(e){const t=this.options.sessionTransferTokenQueryParamName;if(!t||e.session_transfer_token)return e;const n=this._extractSessionTransferToken(t);return n?(this._clearSessionTransferTokenFromUrl(t),Object.assign(Object.assign({},e),{session_transfer_token:n})):e}async _prepareAuthorizeUrl(e,t,n){var o;const i=D(J()),r=D(J()),s=J(),a=await V(s),c=X(a),u=await(null===(o=this.dpop)||void 0===o?void 0:o.calculateThumbprint()),l=((e,t,n,o,i,r,s,a,c)=>Object.assign(Object.assign(Object.assign({client_id:e.clientId},e.authorizationParams),n),{scope:Ue(t,n.scope,n.audience),response_type:"code",response_mode:a||"query",state:o,nonce:i,redirect_uri:s||e.authorizationParams.redirect_uri,code_challenge:r,code_challenge_method:"S256",dpop_jkt:c}))(this.options,this.scope,e,i,r,c,e.redirect_uri||this.options.authorizationParams.redirect_uri||n,null==t?void 0:t.response_mode,u),d=this._authorizeUrl(l);return{nonce:r,code_verifier:s,scope:l.scope,audience:l.audience||E,redirect_uri:l.redirect_uri,state:i,url:d}}async loginWithPopup(e,t){var n;if(e=e||{},!(t=t||{}).popup&&(t.popup=(e=>{const t=window.screenX+(window.innerWidth-400)/2,n=window.screenY+(window.innerHeight-600)/2;return window.open(e,"auth0:authorize:popup","left=".concat(t,",top=").concat(n,",width=").concat(400,",height=").concat(600,",resizable,scrollbars=yes,status=1"))})(""),!t.popup))throw new W;const o=this._applySessionTransferToken(e.authorizationParams||{}),i=await this._prepareAuthorizeUrl(o,{response_mode:"web_message"},window.location.origin);t.popup.location.href=i.url;const r=await((e,t)=>new Promise((n,o)=>{let i;const r=setInterval(()=>{e.popup&&e.popup.closed&&(clearInterval(r),clearTimeout(s),window.removeEventListener("message",i,!1),o(new j(e.popup)))},1e3),s=setTimeout(()=>{clearInterval(r),o(new O(e.popup)),window.removeEventListener("message",i,!1)},1e3*(e.timeoutInSeconds||60));i=function(a){if(a.origin===t&&a.data&&"authorization_response"===a.data.type){if(clearTimeout(s),clearInterval(r),window.removeEventListener("message",i,!1),!1!==e.closePopup&&e.popup.close(),a.data.response.error)return o(C.fromPayload(a.data.response));n(a.data.response)}},window.addEventListener("message",i)}))(Object.assign(Object.assign({},t),{timeoutInSeconds:t.timeoutInSeconds||this.options.authorizeTimeoutInSeconds||60}),new URL(i.url).origin);if(i.state!==r.state)throw new C("state_mismatch","Invalid state");const s=(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization;await this._requestToken({audience:i.audience,scope:i.scope,code_verifier:i.code_verifier,grant_type:"authorization_code",code:r.code,redirect_uri:i.redirect_uri},{nonceIn:i.nonce,organization:s})}async getUser(){var e;if(await this._isSessionCeilingReached())return;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.user}async getIdTokenClaims(){var e;if(await this._isSessionCeilingReached())return;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.claims}async loginWithRedirect(){var n;const o=gt(arguments.length>0&&void 0!==arguments[0]?arguments[0]:{}),i=o.openUrl,r=o.fragment,s=o.appState,a=t(o,["openUrl","fragment","appState"]),c=(null===(n=a.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization,u=this._applySessionTransferToken(a.authorizationParams||{}),l=await this._prepareAuthorizeUrl(u),d=l.url,h=t(l,["url"]);this.transactionManager.create(Object.assign(Object.assign(Object.assign({},h),{appState:s,response_type:e.ResponseType.Code}),c&&{organization:c}));const p=r?"".concat(d,"#").concat(r):d;i?await i(p):window.location.assign(p)}async handleRedirectCallback(){const t=(arguments.length>0&&void 0!==arguments[0]?arguments[0]:window.location.href).split("?").slice(1);if(0===t.length)throw new Error("There are no query params available for parsing.");const n=this.transactionManager.get();if(!n)throw new C("missing_transaction","Invalid state");this.transactionManager.remove();const o=(e=>{e.indexOf("#")>-1&&(e=e.substring(0,e.indexOf("#")));const t=new URLSearchParams(e);return{state:t.get("state"),code:t.get("code")||void 0,connect_code:t.get("connect_code")||void 0,error:t.get("error")||void 0,error_description:t.get("error_description")||void 0}})(t.join(""));return n.response_type===e.ResponseType.ConnectCode?this._handleConnectAccountRedirectCallback(o,n):this._handleLoginRedirectCallback(o,n)}async _handleLoginRedirectCallback(t,n){const o=t.code,i=t.state,r=t.error,s=t.error_description;if(r)throw new A(r,s||r,i,n.appState);if(!n.code_verifier||n.state&&n.state!==i)throw new C("state_mismatch","Invalid state");const a=n.organization,c=n.nonce,u=n.redirect_uri;return await this._requestToken(Object.assign({audience:n.audience,scope:n.scope,code_verifier:n.code_verifier,grant_type:"authorization_code",code:o},u?{redirect_uri:u}:{}),{nonceIn:c,organization:a}),{appState:n.appState,response_type:e.ResponseType.Code}}async _handleConnectAccountRedirectCallback(t,n){const o=t.connect_code,i=t.state,r=t.error,s=t.error_description;if(r)throw new x(r,s||r,n.connection,i,n.appState);if(!o)throw new C("missing_connect_code","Missing connect code");if(!(n.code_verifier&&n.state&&n.auth_session&&n.redirect_uri&&n.state===i))throw new C("state_mismatch","Invalid state");const a=await this.myAccount.completeAccount({auth_session:n.auth_session,connect_code:o,redirect_uri:n.redirect_uri,code_verifier:n.code_verifier});return Object.assign(Object.assign({},a),{appState:n.appState,response_type:e.ResponseType.ConnectCode})}async checkSession(e){if(!this.cookieStorage.get(this.isAuthenticatedCookieName)){if(!this.cookieStorage.get(mt))return;this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(mt)}try{await this.getTokenSilently(e)}catch(e){}}async getTokenSilently(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var t,n;const o=Object.assign(Object.assign({cacheMode:"on"},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:Ue(this.scope,null===(t=e.authorizationParams)||void 0===t?void 0:t.scope,(null===(n=e.authorizationParams)||void 0===n?void 0:n.audience)||this.options.authorizationParams.audience)})}),i=await this._getTokenSilently(o);return e.detailedResponse?i:null==i?void 0:i.access_token}async _getTokenSilently(e){const n=e.cacheMode,o=t(e,["cacheMode"]);if(await this._isSessionCeilingReached())return;if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||E,clientId:this.options.clientId,cacheMode:n});if(e)return e}if("cache-only"===n)return;const i=(r=this.options.clientId,s=o.authorizationParams.audience||"default","".concat("auth0.lock.getTokenSilently",".").concat(r,".").concat(s));var r,s;try{return await this.lockManager.runWithLock(i,5e3,async()=>{if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||E,clientId:this.options.clientId});if(e)return e}const e=this.options.useRefreshTokens?await this._getTokenUsingRefreshToken(o):await this._getTokenFromIFrame(o),t=e.id_token,i=e.token_type,r=e.access_token,s=e.oauthTokenScope,a=e.expires_in;return Object.assign(Object.assign({id_token:t,token_type:i,access_token:r},s?{scope:s}:null),{expires_in:a})})}catch(e){if(this._isInteractiveError(e)&&"popup"===this.options.interactiveErrorHandler)return await this._handleInteractiveErrorWithPopup(o);throw e}}_isInteractiveError(e){return e instanceof M||e instanceof C&&this._isIframeMfaError(e)}_isIframeMfaError(e){return"login_required"===e.error&&"Multifactor authentication required"===e.error_description}async _handleInteractiveErrorWithPopup(e){try{await this.loginWithPopup({authorizationParams:e.authorizationParams});const t=await this._getEntryFromCache({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||E,clientId:this.options.clientId});if(!t)throw new C("interactive_handler_cache_miss","Token not found in cache after interactive authentication");return t}catch(e){throw e}}async getTokenWithPopup(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{};var n,o;const i=Object.assign(Object.assign({},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:Ue(this.scope,null===(n=e.authorizationParams)||void 0===n?void 0:n.scope,(null===(o=e.authorizationParams)||void 0===o?void 0:o.audience)||this.options.authorizationParams.audience)})});t=Object.assign(Object.assign({},b),t),await this.loginWithPopup(i,t);return(await this.cacheManager.get(new Je({scope:i.authorizationParams.scope,audience:i.authorizationParams.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt)).access_token}async isAuthenticated(){return!!await this.getUser()}_buildLogoutUrl(e){null!==e.clientId?e.clientId=e.clientId||this.options.clientId:delete e.clientId;const n=e.logoutParams||{},o=n.federated,i=t(n,["federated"]),r=o?"&federated":"";return this._url("/v2/logout?".concat(F(Object.assign({clientId:e.clientId},i))))+r}async revokeRefreshToken(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!this.options.useRefreshTokens)return;const t=e.audience||this.options.authorizationParams.audience||E,n=await this.cacheManager.getRefreshTokensByAudience(t,this.options.clientId);await async function(e,t){let n=e.baseUrl,o=e.timeout,i=e.auth0Client,r=e.useFormData,s=e.refreshTokens,a=e.audience,c=e.client_id,u=e.onRefreshTokenRevoked;const l=o||_,d="refresh_token",h="".concat(n,"/oauth/revoke"),p={"Content-Type":r?"application/x-www-form-urlencoded":"application/json","Auth0-Client":btoa(JSON.stringify(H(i||T)))};if(t){const e={client_id:c,token_type_hint:d},n=r?F(e):JSON.stringify(e);try{return await Oe({type:"revoke",timeout:l,fetchUrl:h,fetchOptions:{method:"POST",body:n,headers:p},useFormData:r,auth:{audience:null!=a?a:E}},t)}catch(e){throw new C("revoke_error",e.message)}}for(const e of s){const t={client_id:c,token_type_hint:d,token:e},n=r?F(t):JSON.stringify(t),o=await je(h,{method:"POST",body:n,headers:p},l);if(!o.ok){let e,t;try{var f=JSON.parse(await o.text());e=f.error,t=f.error_description}catch(e){}throw new C(e||"revoke_error",t||"HTTP error ".concat(o.status))}await(null==u?void 0:u(e))}}({baseUrl:this.domainUrl,timeout:this.httpTimeoutMs,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,client_id:this.options.clientId,refreshTokens:n,audience:t,onRefreshTokenRevoked:e=>this.cacheManager.stripRefreshToken(e)},this.worker),this.onlineAccess&&await this._clearLocalSession()}async logout(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var n;this.options.enterpriseConnect&&!0!==(null===(n=e.logoutParams)||void 0===n?void 0:n.federated)&&console.warn("Enterprise Connect logout without `federated: true` leaves the enterprise IdP session alive; the next login may silently reuse the previous user.");const o=gt(e),i=o.openUrl,r=t(o,["openUrl"]);await this._clearLocalSession(e.clientId);const s=this._buildLogoutUrl(r);i?await i(s):!1!==i&&window.location.assign(s)}async _getTokenFromIFrame(e){const t=(n=this.options.clientId,"".concat("auth0.lock.getTokenFromIFrame",".").concat(n));var n;try{return await this.lockManager.runWithLock(t,5e3,async()=>{const t=Object.assign(Object.assign({},e.authorizationParams),{prompt:"none"}),n=this.cookieStorage.get(this.orgHintCookieName);n&&!t.organization&&(t.organization=n);const o=await this._prepareAuthorizeUrl(t,{response_mode:"web_message"},window.location.origin),i=o.url,r=o.state,s=o.nonce,a=o.code_verifier,c=o.redirect_uri,u=o.scope,l=o.audience;if(window.crossOriginIsolated)throw new C("login_required","The application is running in a Cross-Origin Isolated context, silently retrieving a token without refresh token is not possible.");const d=e.timeoutInSeconds||this.options.authorizeTimeoutInSeconds;let h;try{h=new URL(this.domainUrl).origin}catch(e){h=this.domainUrl}const p=await function(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:60;return new Promise((o,i)=>{const r=window.document.createElement("iframe");r.setAttribute("width","0"),r.setAttribute("height","0"),r.style.display="none";const s=()=>{window.document.body.contains(r)&&(window.document.body.removeChild(r),window.removeEventListener("message",a,!1))};let a;const c=setTimeout(()=>{i(new I),s()},1e3*n);a=function(e){if(e.origin!=t)return;if(!e.data||"authorization_response"!==e.data.type)return;const n=e.source;n&&n.close(),e.data.response.error?i(C.fromPayload(e.data.response)):o(e.data.response),clearTimeout(c),window.removeEventListener("message",a,!1),setTimeout(s,2e3)},window.addEventListener("message",a,!1),window.document.body.appendChild(r),r.setAttribute("src",e)})}(i,h,d);if(r!==p.state)throw new C("state_mismatch","Invalid state");const f=await this._requestToken(Object.assign(Object.assign({},e.authorizationParams),{code_verifier:a,code:p.code,grant_type:"authorization_code",redirect_uri:c,timeout:e.authorizationParams.timeout||this.httpTimeoutMs}),{nonceIn:s,organization:t.organization});return Object.assign(Object.assign({},f),{scope:u,oauthTokenScope:f.scope,audience:l})})}catch(e){if("login_required"===e.error){e instanceof C&&this._isIframeMfaError(e)&&"popup"===this.options.interactiveErrorHandler||this.logout({openUrl:!1})}throw e}}async _getTokenUsingRefreshToken(e){const t=await this.cacheManager.get(new Je({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt);if(!(t&&t.refresh_token||this.worker)){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw new N(e.authorizationParams.audience||E,e.authorizationParams.scope)}const n=e.authorizationParams.redirect_uri||this.options.authorizationParams.redirect_uri||window.location.origin,o="number"==typeof e.timeoutInSeconds?1e3*e.timeoutInSeconds:null,i=((e,t,n,o)=>{var i;if(e&&n&&o){if(t.audience!==n)return t.scope;const e=o.split(" "),r=(null===(i=t.scope)||void 0===i?void 0:i.split(" "))||[],s=r.every(t=>e.includes(t));return e.length>=r.length&&s?o:t.scope}return t.scope})(this.options.useMrrt,e.authorizationParams,null==t?void 0:t.audience,null==t?void 0:t.scope);try{const u=await this._requestToken(Object.assign(Object.assign(Object.assign({},e.authorizationParams),{grant_type:"refresh_token",refresh_token:t&&t.refresh_token,redirect_uri:n}),o&&{timeout:o}),{scopesToRequest:i});if(await this._propagateRotatedRefreshToken(null==t?void 0:t.refresh_token,u.refresh_token),this.options.useMrrt){if(r=null==t?void 0:t.audience,s=null==t?void 0:t.scope,a=e.authorizationParams.audience,c=e.authorizationParams.scope,r!==a||!((e,t)=>{const n=(null==t?void 0:t.split(" "))||[];return((null==e?void 0:e.split(" "))||[]).every(e=>n.includes(e))})(c,s)){const t=vt(i,u.scope,this.onlineAccess);if(t){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw await this.cacheManager.remove(this.options.clientId,e.authorizationParams.audience,e.authorizationParams.scope),new K(e.authorizationParams.audience||"default",t)}}}return Object.assign(Object.assign({},u),{scope:e.authorizationParams.scope,oauthTokenScope:u.scope,audience:e.authorizationParams.audience||E})}catch(t){if(t.message){if(t.message.includes("user is blocked"))throw await this.logout({openUrl:!1}),t;if((t.message.includes("Missing Refresh Token")||t.message.includes("invalid refresh token"))&&this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e)}throw t}var r,s,a,c}async _propagateRotatedRefreshToken(e,t){!this.onlineAccess&&t&&e&&await this.cacheManager.updateEntry(e,t,this.options.clientId,this.options.useMrrt)}async _saveEntryInCache(e){const n=e.decodedToken.claims,o=n.session_expiry,i=n.iat;if(void 0!==o){if("number"!=typeof o)throw new C("invalid_token","Invalid session_expiry: value must be a number.");if(o>=1e10)throw new C("invalid_token","Invalid session_expiry: value appears to be in milliseconds; expected a Unix timestamp in seconds.");if(void 0===i||o<=i)throw new C("invalid_token","Invalid session_expiry: session ceiling is before or at the token issue time.")}const r=e.id_token,s=e.decodedToken,a=t(e,["id_token","decodedToken"]);this.userCache.set(ze,{id_token:r,decodedToken:s}),await this.cacheManager.setIdToken(this.options.clientId,e.id_token,e.decodedToken),await this.cacheManager.set(a)}async _clearLocalSession(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:this.options.clientId;var t;null===e?await this.cacheManager.clear():await this.cacheManager.clear(e),this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(this.isAuthenticatedCookieName,{cookieDomain:this.options.cookieDomain}),this.userCache.remove(ze);try{await(null===(t=this.dpop)||void 0===t?void 0:t.clear())}catch(e){}if(this.worker)try{await Oe({type:"clear"},this.worker)}catch(e){}}async _isSessionCeilingReached(){var e,t;const n=this.userCache.get(ze),o=null!=n?n:await this.cacheManager.getIdToken(new Je({clientId:this.options.clientId})),i=null===(t=null===(e=null==o?void 0:o.decodedToken)||void 0===e?void 0:e.claims)||void 0===t?void 0:t.session_expiry;if(void 0===i)return!1;const r=await this.nowProvider();return Math.floor(r/1e3)>=i-30&&(await this._clearLocalSession(),!0)}async _getIdTokenFromCache(){const e=this.options.authorizationParams.audience||E,t=this.scope[e],n=await this.cacheManager.getIdToken(new Je({clientId:this.options.clientId,audience:e,scope:t})),o=this.userCache.get(ze);return n&&n.id_token===(null==o?void 0:o.id_token)?o:(this.userCache.set(ze,n),n)}async _getEntryFromCache(e){let t=e.scope,n=e.audience,o=e.clientId,i=e.cacheMode;const r=await this.cacheManager.get(new Je({scope:t,audience:n,clientId:o}),60,this.options.useMrrt,i);if(r&&r.access_token){const e=r.token_type,t=r.access_token,n=r.oauthTokenScope,o=r.expires_in,i=await this._getIdTokenFromCache();return i&&Object.assign(Object.assign({id_token:i.id_token,token_type:e||"Bearer",access_token:t},n?{scope:n}:null),{expires_in:o})}}_storeMfaContext(e,t,n){e instanceof M&&this.mfa.setMFAAuthDetails(e.mfa_token,t,n,e.mfa_requirements)}async _requestToken(e,t){var n,o,i,r,s,a;const c=t||{},u=c.nonceIn,l=c.organization,d=c.scopesToRequest;try{const t=await Ne(Object.assign(Object.assign({baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,useMrrt:this.options.useMrrt,dpop:this.dpop,preserveRefreshToken:this.onlineAccess},e),{scope:d||e.scope}),this.worker);let c=await this._verifyIdToken(t.id_token,u,l);if("authorization_code"===e.grant_type){const e=await this._getIdTokenFromCache();(null===(o=null===(n=null==e?void 0:e.decodedToken)||void 0===n?void 0:n.claims)||void 0===o?void 0:o.sub)&&e.decodedToken.claims.sub!==c.claims.sub&&(await this.cacheManager.clear(this.options.clientId),this.userCache.remove(ze))}if("authorization_code"!==e.grant_type){const e=await this._getIdTokenFromCache(),t=null===(r=null===(i=null==e?void 0:e.decodedToken)||void 0===i?void 0:i.claims)||void 0===r?void 0:r.session_expiry;void 0!==t&&(c=Object.assign(Object.assign({},c),{claims:Object.assign(Object.assign({},c.claims),{session_expiry:t})}))}return!t.refresh_token&&this.onlineAccess&&(t.refresh_token=null!==(s=e.refresh_token)&&void 0!==s?s:null===(a=await this.cacheManager.get(new Je({scope:d||e.scope,audience:e.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt))||void 0===a?void 0:a.refresh_token),await this._saveEntryInCache(Object.assign(Object.assign(Object.assign(Object.assign({},t),{decodedToken:c,scope:e.scope,audience:e.audience||E}),t.scope?{oauthTokenScope:t.scope}:null),{client_id:this.options.clientId})),this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this._processOrgHint(l||c.claims.org_id),Object.assign(Object.assign({},t),{decodedToken:c})}catch(t){throw"authorization_code"!==e.grant_type&&this._storeMfaContext(t,d||e.scope,e.audience),t}}_buildTokenExchangeParams(e){return Object.assign(Object.assign(Object.assign(Object.assign(Object.assign({},e),{grant_type:"urn:ietf:params:oauth:grant-type:token-exchange",subject_token:e.subject_token,subject_token_type:e.subject_token_type}),e.actor_token&&{actor_token:e.actor_token}),e.actor_token_type&&{actor_token_type:e.actor_token_type}),{scope:Ue(this.scope,e.scope,e.audience||this.options.authorizationParams.audience),audience:e.audience||this.options.authorizationParams.audience,organization:e.organization||this.options.authorizationParams.organization})}async loginWithCustomTokenExchange(e){return this._requestToken(this._buildTokenExchangeParams(e))}async customTokenExchange(e){const t=this._buildTokenExchangeParams(e);try{const n=await Ne(Object.assign(Object.assign({},t),{baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,dpop:this.dpop}),this.worker,!0);return n.id_token&&await this._verifyIdToken(n.id_token,void 0,e.organization),n}catch(e){throw this._storeMfaContext(e,t.scope,t.audience),e}}async exchangeToken(e){return this.loginWithCustomTokenExchange(e)}_assertDpop(e){if(!e)throw new Error("`useDpop` option must be enabled before using DPoP.")}getDpopNonce(e){return this._assertDpop(this.dpop),this.dpop.getNonce(e)}setDpopNonce(e,t){return this._assertDpop(this.dpop),this.dpop.setNonce(e,t)}generateDpopProof(e){return this._assertDpop(this.dpop),this.dpop.generateProof(e)}createFetcher(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};return new Tt(e,{isDpopEnabled:()=>!!this.options.useDpop,getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:null==e?void 0:e.audience},detailedResponse:!0})},getDpopNonce:()=>this.getDpopNonce(e.dpopNonceId),setDpopNonce:t=>this.setDpopNonce(t,e.dpopNonceId),generateDpopProof:e=>this.generateDpopProof(e)})}async connectAccountWithRedirect(t){const n=t.openUrl,o=t.appState,i=t.connection,r=t.scopes,s=t.authorization_params,a=t.redirectUri,c=void 0===a?this.options.authorizationParams.redirect_uri||window.location.origin:a;if(!i)throw new Error("connection is required");const u=D(J()),l=J(),d=await V(l),h=X(d),p=await this.myAccount.connectAccount({connection:i,scopes:r,redirect_uri:c,state:u,code_challenge:h,code_challenge_method:"S256",authorization_params:s}),f=p.connect_uri,m=p.connect_params,y=p.auth_session;this.transactionManager.create({state:u,code_verifier:l,auth_session:y,redirect_uri:c,appState:o,connection:i,response_type:e.ResponseType.ConnectCode});const w=new URL(f);w.searchParams.set("ticket",m.ticket),n?await n(w.toString()):window.location.assign(w)}async _requestTokenForPasskey(e){const t=e.audience||this.options.authorizationParams.audience,n=e.organization||this.options.authorizationParams.organization;return this._requestToken(Object.assign(Object.assign(Object.assign({grant_type:"urn:okta:params:oauth:grant-type:webauthn",auth_session:e.authSession,authn_response:e.credential},e.realm&&{realm:e.realm}),n&&{organization:n}),{scope:Ue(this.scope,e.scope,t),audience:t}))}async _requestTokenForMfa(e,n){const o=e.mfaToken,i=t(e,["mfaToken"]),r=await this.cacheManager.get(new Je({scope:i.scope,audience:i.audience||E,clientId:this.options.clientId}),void 0,this.options.useMrrt),s=await this._requestToken(Object.assign(Object.assign({},i),{mfa_token:o}),n);return await this._propagateRotatedRefreshToken(null==r?void 0:r.refresh_token,s.refresh_token),s}}e.Auth0Client=Ou,e.AuthenticationError=A,e.CacheKey=Je,e.ConnectError=x,e.GenericError=C,e.InMemoryCache=Ze,e.InvalidConfigurationError=R,e.LocalStorageCache=De,e.MfaApiClient=_u,e.MfaChallengeError=wu,e.MfaEnrollmentError=yu,e.MfaEnrollmentFactorsError=vu,e.MfaError=fu,e.MfaListAuthenticatorsError=mu,e.MfaRequiredError=M,e.MfaVerifyError=gu,e.MissingRefreshTokenError=N,e.MissingScopesError=K,e.MyAccountApiClient=Pt,e.MyAccountApiError=Et,e.PasskeyApiClient=Pu,e.PasskeyChallengeError=dc,e.PasskeyError=ku,e.PasskeyGetTokenError=hc,e.PasskeyRegisterError=lc,e.PopupCancelledError=j,e.PopupOpenError=W,e.PopupTimeoutError=O,e.RefreshTokenMode={Offline:"offline",Online:"online"},e.TimeoutError=I,e.UseDpopNonceError=U,e.User=class{},e.createAuth0Client=async function(e){const t=new Ou(e);return await t.checkSession(),t},e.isFederatedDomain=function(e,t,n){var o;return async function(e,t,n){const o=t.toLowerCase(),i=e.replace(/^https?:\/\//,""),r="".concat(i,"|").concat(o),s=pu.get(r);if(void 0!==s)return s;try{var a;const e=new URL("https://".concat(i,"/.well-known/webfinger"));e.searchParams.set("resource","urn:auth0:discovery:domain:".concat(o)),e.searchParams.set("rel","http://openid.net/specs/connect/1.0/issuer");let t=null!==(a=null==n?void 0:n.customFetch)&&void 0!==a?a:globalThis.fetch;null!=n&&n.telemetry&&!1!==n.telemetry.enabled&&(t=nc(t,n.telemetry));const s=await t(e.toString());return s.ok?(pu.set(r,!0),!0):404===s.status?(pu.set(r,!1,15e3),!1):429===s.status&&(console.warn("[Auth0] isFederatedDomain: rate limit hit (429)"),!1)}catch(e){return!1}}(e.replace(/^https?:\/\//i,"").toLowerCase(),t.toLowerCase(),Object.assign(Object.assign({},n),{telemetry:null!==(o=null==n?void 0:n.telemetry)&&void 0!==o?o:T}))},Object.defineProperty(e,"__esModule",{value:!0})});
//# sourceMappingURL=auth0-spa-js.production.js.map