UNPKG

@auth0/auth0-spa-js

Version:

Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE

3 lines 230 kB
!function(e,t){"object"==typeof exports&&"undefined"!=typeof module?t(exports):"function"==typeof define&&define.amd?define(["exports"],t):t((e="undefined"!=typeof globalThis?globalThis:e||self).auth0={})}(this,function(e){"use strict";function t(e,t){var n={};for(var o in e)Object.prototype.hasOwnProperty.call(e,o)&&t.indexOf(o)<0&&(n[o]=e[o]);if(null!=e&&"function"==typeof Object.getOwnPropertySymbols){var i=0;for(o=Object.getOwnPropertySymbols(e);i<o.length;i++)t.indexOf(o[i])<0&&Object.prototype.propertyIsEnumerable.call(e,o[i])&&(n[o[i]]=e[o[i]])}return n}function n(e,t,n,o){if("a"===n&&!o)throw new TypeError("Private accessor was defined without a getter");if("function"==typeof t?e!==t||!o:!t.has(e))throw new TypeError("Cannot read private member from an object whose class did not declare it");return"m"===n?o:"a"===n?o.call(e):o?o.value:t.get(e)}function o(e,t,n,o,i){if("m"===o)throw new TypeError("Private method is not writable");if("a"===o&&!i)throw new TypeError("Private accessor was defined without a setter");if("function"==typeof t?e!==t||!i:!t.has(e))throw new TypeError("Cannot write private member to an object whose class did not declare it");return"a"===o?i.call(e,n):i?i.value=n:t.set(e,n),n}function i(e,t){this.v=e,this.k=t}function r(e,t){(null==t||t>e.length)&&(t=e.length);for(var n=0,o=Array(t);n<t;n++)o[n]=e[n];return o}function s(e,t,n){if("function"==typeof e?e===t:e.has(t))return arguments.length<3?t:n;throw new TypeError("Private element is not present on this object")}function a(e){return new i(e,0)}function c(e,t){if(t.has(e))throw new TypeError("Cannot initialize the same private elements twice on an object")}function u(e,t){return e.get(s(e,t))}function l(e,t,n){c(e,t),t.set(e,n)}function d(e,t,n){return e.set(s(e,t),n),n}function h(e,t){c(e,t),t.add(e)}function p(e,t,n){return(t=function(e){var t=function(e,t){if("object"!=typeof e||!e)return e;var n=e[Symbol.toPrimitive];if(void 0!==n){var o=n.call(e,t||"default");if("object"!=typeof o)return o;throw new TypeError("@@toPrimitive must return a primitive value.")}return("string"===t?String:Number)(e)}(e,"string");return"symbol"==typeof t?t:t+""}(t))in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function f(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);t&&(o=o.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,o)}return n}function m(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?f(Object(n),!0).forEach(function(t){p(e,t,n[t])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):f(Object(n)).forEach(function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))})}return e}function y(e,t){if(null==e)return{};var n,o,i=function(e,t){if(null==e)return{};var n={};for(var o in e)if({}.hasOwnProperty.call(e,o)){if(-1!==t.indexOf(o))continue;n[o]=e[o]}return n}(e,t);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);for(o=0;o<r.length;o++)n=r[o],-1===t.indexOf(n)&&{}.propertyIsEnumerable.call(e,n)&&(i[n]=e[n])}return i}function w(e,t){return function(e){if(Array.isArray(e))return e}(e)||function(e,t){var n=null==e?null:"undefined"!=typeof Symbol&&e[Symbol.iterator]||e["@@iterator"];if(null!=n){var o,i,r,s,a=[],c=!0,u=!1;try{if(r=(n=n.call(e)).next,0===t){if(Object(n)!==n)return;c=!1}else for(;!(c=(o=r.call(n)).done)&&(a.push(o.value),a.length!==t);c=!0);}catch(e){u=!0,i=e}finally{try{if(!c&&null!=n.return&&(s=n.return(),Object(s)!==s))return}finally{if(u)throw i}}return a}}(e,t)||function(e,t){if(e){if("string"==typeof e)return r(e,t);var n={}.toString.call(e).slice(8,-1);return"Object"===n&&e.constructor&&(n=e.constructor.name),"Map"===n||"Set"===n?Array.from(e):"Arguments"===n||/^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(n)?r(e,t):void 0}}(e,t)||function(){throw new TypeError("Invalid attempt to destructure non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method.")}()}function g(e){return function(){return new v(e.apply(this,arguments))}}function v(e){var t,n;function o(t,n){try{var s=e[t](n),a=s.value,c=a instanceof i;Promise.resolve(c?a.v:a).then(function(n){if(c){var i="return"===t&&a.k?t:"next";if(!a.k||n.done)return o(i,n);n=e[i](n).value}r(!!s.done,n)},function(e){o("throw",e)})}catch(e){r(2,e)}}function r(e,i){2===e?t.reject(i):t.resolve({value:i,done:e}),(t=t.next)?o(t.key,t.arg):n=null}this._invoke=function(e,i){return new Promise(function(r,s){var a={key:e,arg:i,resolve:r,reject:s,next:null};n?n=n.next=a:(t=n=a,o(e,i))})},"function"!=typeof e.return&&(this.return=void 0)}"function"==typeof SuppressedError&&SuppressedError,v.prototype["function"==typeof Symbol&&Symbol.asyncIterator||"@@asyncIterator"]=function(){return this},v.prototype.next=function(e){return this._invoke("next",e)},v.prototype.throw=function(e){return this._invoke("throw",e)},v.prototype.return=function(e){return this._invoke("return",e)};const b={timeoutInSeconds:60},_=1e4,k="memory",S="Multifactor authentication required",T="online_access",E={name:"auth0-spa-js",version:"2.27.0"},P=()=>Date.now(),C="default";class A extends Error{constructor(e,t){super(t),this.error=e,this.error_description=t,Object.setPrototypeOf(this,A.prototype)}static fromPayload(e){let t=e.error,n=e.error_description;return new A(t,n)}}class R extends A{constructor(e,t){super("invalid_configuration","".concat(e," ").concat(t)),this.suggestion=t,Object.setPrototypeOf(this,R.prototype)}}class x extends A{constructor(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:null;super(e,t),this.state=n,this.appState=o,Object.setPrototypeOf(this,x.prototype)}}class I extends A{constructor(e,t,n,o){let i=arguments.length>4&&void 0!==arguments[4]?arguments[4]:null;super(e,t),this.connection=n,this.state=o,this.appState=i,Object.setPrototypeOf(this,I.prototype)}}class O extends A{constructor(){super("timeout","Timeout"),Object.setPrototypeOf(this,O.prototype)}}class j extends O{constructor(e){super(),this.popup=e,Object.setPrototypeOf(this,j.prototype)}}class W extends A{constructor(e){super("cancelled","Popup closed"),this.popup=e,Object.setPrototypeOf(this,W.prototype)}}class M extends A{constructor(){super("popup_open","Unable to open a popup for loginWithPopup - window.open returned `null`"),Object.setPrototypeOf(this,M.prototype)}}class N extends A{constructor(e,t,n,o){super(e,t),this.mfa_token=n,this.mfa_requirements=o,Object.setPrototypeOf(this,N.prototype)}}class K extends A{constructor(e,t){super("missing_refresh_token","Missing Refresh Token (audience: '".concat(z(e,["default"]),"', scope: '").concat(z(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,K.prototype)}}class U extends A{constructor(e,t){super("missing_scopes","Missing requested scopes after refresh (audience: '".concat(z(e,["default"]),"', missing scope: '").concat(z(t),"')")),this.audience=e,this.scope=t,Object.setPrototypeOf(this,U.prototype)}}class L extends A{constructor(e){super("use_dpop_nonce","Server rejected DPoP proof: wrong nonce"),this.newDpopNonce=e,Object.setPrototypeOf(this,L.prototype)}}function z(e){return e&&!(arguments.length>1&&void 0!==arguments[1]?arguments[1]:[]).includes(e)?e:""}const J=()=>window.crypto,D=()=>{const e="0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-_~.";let t="";for(;t.length<43;){const n=J().getRandomValues(new Uint8Array(43-t.length));for(const o of n)t.length<43&&o<198&&(t+=e[o%66])}return t},Z=e=>btoa(e),H=[{key:"name",type:["string"]},{key:"version",type:["string","number"]},{key:"env",type:["object"]}],F=function(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return Object.keys(e).reduce((n,o)=>{if(t&&"env"===o)return n;const i=H.find(e=>e.key===o);return i&&i.type.includes(typeof e[o])&&(n[o]=e[o]),n},{})},V=e=>{var n=e.clientId,o=t(e,["clientId"]);return new URLSearchParams((e=>Object.keys(e).filter(t=>void 0!==e[t]).reduce((t,n)=>Object.assign(Object.assign({},t),{[n]:e[n]}),{}))(Object.assign({client_id:n},o))).toString()},G=async e=>{const t=J().subtle.digest({name:"SHA-256"},(new TextEncoder).encode(e));return await t},X=e=>(e=>decodeURIComponent(atob(e).split("").map(e=>"%"+("00"+e.charCodeAt(0).toString(16)).slice(-2)).join("")))(e.replace(/_/g,"/").replace(/-/g,"+")),q=e=>{const t=new Uint8Array(e);return(e=>{const t={"+":"-","/":"_","=":""};return e.replace(/[+/=]/g,e=>t[e])})(window.btoa(String.fromCharCode(...Array.from(t))))};var Y="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{},B={},Q={};Object.defineProperty(Q,"__esModule",{value:!0});var $=function(){function e(){var e=this;this.locked=new Map,this.addToLocked=function(t,n){var o=e.locked.get(t);void 0===o?void 0===n?e.locked.set(t,[]):e.locked.set(t,[n]):void 0!==n&&(o.unshift(n),e.locked.set(t,o))},this.isLocked=function(t){return e.locked.has(t)},this.lock=function(t){return new Promise(function(n,o){e.isLocked(t)?e.addToLocked(t,n):(e.addToLocked(t),n())})},this.unlock=function(t){var n=e.locked.get(t);if(void 0!==n&&0!==n.length){var o=n.pop();e.locked.set(t,n),void 0!==o&&setTimeout(o,0)}else e.locked.delete(t)}}return e.getInstance=function(){return void 0===e.instance&&(e.instance=new e),e.instance},e}();Q.default=function(){return $.getInstance()};var ee=Y&&Y.__awaiter||function(e,t,n,o){return new(n||(n=Promise))(function(i,r){function s(e){try{c(o.next(e))}catch(e){r(e)}}function a(e){try{c(o.throw(e))}catch(e){r(e)}}function c(e){e.done?i(e.value):new n(function(t){t(e.value)}).then(s,a)}c((o=o.apply(e,t||[])).next())})},te=Y&&Y.__generator||function(e,t){var n,o,i,r,s={label:0,sent:function(){if(1&i[0])throw i[1];return i[1]},trys:[],ops:[]};return r={next:a(0),throw:a(1),return:a(2)},"function"==typeof Symbol&&(r[Symbol.iterator]=function(){return this}),r;function a(r){return function(a){return function(r){if(n)throw new TypeError("Generator is already executing.");for(;s;)try{if(n=1,o&&(i=2&r[0]?o.return:r[0]?o.throw||((i=o.return)&&i.call(o),0):o.next)&&!(i=i.call(o,r[1])).done)return i;switch(o=0,i&&(r=[2&r[0],i.value]),r[0]){case 0:case 1:i=r;break;case 4:return s.label++,{value:r[1],done:!1};case 5:s.label++,o=r[1],r=[0];continue;case 7:r=s.ops.pop(),s.trys.pop();continue;default:if(!(i=s.trys,(i=i.length>0&&i[i.length-1])||6!==r[0]&&2!==r[0])){s=0;continue}if(3===r[0]&&(!i||r[1]>i[0]&&r[1]<i[3])){s.label=r[1];break}if(6===r[0]&&s.label<i[1]){s.label=i[1],i=r;break}if(i&&s.label<i[2]){s.label=i[2],s.ops.push(r);break}i[2]&&s.ops.pop(),s.trys.pop();continue}r=t.call(e,s)}catch(e){r=[6,e],o=0}finally{n=i=0}if(5&r[0])throw r[1];return{value:r[0]?r[1]:void 0,done:!0}}([r,a])}}},ne=Y;Object.defineProperty(B,"__esModule",{value:!0});var oe=Q,ie="browser-tabs-lock-key",re={key:function(e){return ee(ne,void 0,void 0,function(){return te(this,function(e){throw new Error("Unsupported")})})},getItem:function(e){return ee(ne,void 0,void 0,function(){return te(this,function(e){throw new Error("Unsupported")})})},clear:function(){return ee(ne,void 0,void 0,function(){return te(this,function(e){return[2,window.localStorage.clear()]})})},removeItem:function(e){return ee(ne,void 0,void 0,function(){return te(this,function(e){throw new Error("Unsupported")})})},setItem:function(e,t){return ee(ne,void 0,void 0,function(){return te(this,function(e){throw new Error("Unsupported")})})},keySync:function(e){return window.localStorage.key(e)},getItemSync:function(e){return window.localStorage.getItem(e)},clearSync:function(){return window.localStorage.clear()},removeItemSync:function(e){return window.localStorage.removeItem(e)},setItemSync:function(e,t){return window.localStorage.setItem(e,t)}};function se(e){return new Promise(function(t){return setTimeout(t,e)})}function ae(e){for(var t="0123456789ABCDEFGHIJKLMNOPQRSTUVWXTZabcdefghiklmnopqrstuvwxyz",n="",o=0;o<e;o++){n+=t[Math.floor(61*Math.random())]}return n}var ce=function(){function e(t){this.acquiredIatSet=new Set,this.storageHandler=void 0,this.id=Date.now().toString()+ae(15),this.acquireLock=this.acquireLock.bind(this),this.releaseLock=this.releaseLock.bind(this),this.releaseLock__private__=this.releaseLock__private__.bind(this),this.waitForSomethingToChange=this.waitForSomethingToChange.bind(this),this.refreshLockWhileAcquired=this.refreshLockWhileAcquired.bind(this),this.storageHandler=t,void 0===e.waiters&&(e.waiters=[])}return e.prototype.acquireLock=function(t,n){return void 0===n&&(n=5e3),ee(this,void 0,void 0,function(){var o,i,r,s,a,c,u;return te(this,function(l){switch(l.label){case 0:o=Date.now()+ae(4),i=Date.now()+n,r=ie+"-"+t,s=void 0===this.storageHandler?re:this.storageHandler,l.label=1;case 1:return Date.now()<i?[4,se(30)]:[3,8];case 2:return l.sent(),null!==s.getItemSync(r)?[3,5]:(a=this.id+"-"+t+"-"+o,[4,se(Math.floor(25*Math.random()))]);case 3:return l.sent(),s.setItemSync(r,JSON.stringify({id:this.id,iat:o,timeoutKey:a,timeAcquired:Date.now(),timeRefreshed:Date.now()})),[4,se(30)];case 4:return l.sent(),null!==(c=s.getItemSync(r))&&(u=JSON.parse(c)).id===this.id&&u.iat===o?(this.acquiredIatSet.add(o),this.refreshLockWhileAcquired(r,o),[2,!0]):[3,7];case 5:return e.lockCorrector(void 0===this.storageHandler?re:this.storageHandler),[4,this.waitForSomethingToChange(i)];case 6:l.sent(),l.label=7;case 7:return o=Date.now()+ae(4),[3,1];case 8:return[2,!1]}})})},e.prototype.refreshLockWhileAcquired=function(e,t){return ee(this,void 0,void 0,function(){var n=this;return te(this,function(o){return setTimeout(function(){return ee(n,void 0,void 0,function(){var n,o,i;return te(this,function(r){switch(r.label){case 0:return[4,oe.default().lock(t)];case 1:return r.sent(),this.acquiredIatSet.has(t)?(n=void 0===this.storageHandler?re:this.storageHandler,null===(o=n.getItemSync(e))?(oe.default().unlock(t),[2]):((i=JSON.parse(o)).timeRefreshed=Date.now(),n.setItemSync(e,JSON.stringify(i)),oe.default().unlock(t),this.refreshLockWhileAcquired(e,t),[2])):(oe.default().unlock(t),[2])}})})},1e3),[2]})})},e.prototype.waitForSomethingToChange=function(t){return ee(this,void 0,void 0,function(){return te(this,function(n){switch(n.label){case 0:return[4,new Promise(function(n){var o=!1,i=Date.now(),r=!1;function s(){if(r||(window.removeEventListener("storage",s),e.removeFromWaiting(s),clearTimeout(a),r=!0),!o){o=!0;var t=50-(Date.now()-i);t>0?setTimeout(n,t):n(null)}}window.addEventListener("storage",s),e.addToWaiting(s);var a=setTimeout(s,Math.max(0,t-Date.now()))})];case 1:return n.sent(),[2]}})})},e.addToWaiting=function(t){this.removeFromWaiting(t),void 0!==e.waiters&&e.waiters.push(t)},e.removeFromWaiting=function(t){void 0!==e.waiters&&(e.waiters=e.waiters.filter(function(e){return e!==t}))},e.notifyWaiters=function(){void 0!==e.waiters&&e.waiters.slice().forEach(function(e){return e()})},e.prototype.releaseLock=function(e){return ee(this,void 0,void 0,function(){return te(this,function(t){switch(t.label){case 0:return[4,this.releaseLock__private__(e)];case 1:return[2,t.sent()]}})})},e.prototype.releaseLock__private__=function(t){return ee(this,void 0,void 0,function(){var n,o,i,r;return te(this,function(s){switch(s.label){case 0:return n=void 0===this.storageHandler?re:this.storageHandler,o=ie+"-"+t,null===(i=n.getItemSync(o))?[2]:(r=JSON.parse(i)).id!==this.id?[3,2]:[4,oe.default().lock(r.iat)];case 1:s.sent(),this.acquiredIatSet.delete(r.iat),n.removeItemSync(o),oe.default().unlock(r.iat),e.notifyWaiters(),s.label=2;case 2:return[2]}})})},e.lockCorrector=function(t){for(var n=Date.now()-5e3,o=t,i=[],r=0;;){var s=o.keySync(r);if(null===s)break;i.push(s),r++}for(var a=!1,c=0;c<i.length;c++){var u=i[c];if(u.includes(ie)){var l=o.getItemSync(u);if(null!==l){var d=JSON.parse(l);(void 0===d.timeRefreshed&&d.timeAcquired<n||void 0!==d.timeRefreshed&&d.timeRefreshed<n)&&(o.removeItemSync(u),a=!0)}}}a&&e.notifyWaiters()},e.waiters=void 0,e}(),ue=B.default=ce;class le{async runWithLock(e,t,n){const o=new AbortController,i=setTimeout(()=>o.abort(),t);try{return await navigator.locks.request(e,{mode:"exclusive",signal:o.signal},async e=>{if(clearTimeout(i),!e)throw new Error("Lock not available");return await n()})}catch(e){if(clearTimeout(i),"AbortError"===(null==e?void 0:e.name))throw new O;throw e}}}class de{constructor(){this.activeLocks=new Set,this.lock=new ue,this.pagehideHandler=()=>{this.activeLocks.forEach(e=>this.lock.releaseLock(e)),this.activeLocks.clear()}}async runWithLock(e,t,n){let o=!1;for(let n=0;n<10&&!o;n++)o=await this.lock.acquireLock(e,t);if(!o)throw new O;this.activeLocks.add(e),1===this.activeLocks.size&&"undefined"!=typeof window&&window.addEventListener("pagehide",this.pagehideHandler);try{return await n()}finally{this.activeLocks.delete(e),await this.lock.releaseLock(e),0===this.activeLocks.size&&"undefined"!=typeof window&&window.removeEventListener("pagehide",this.pagehideHandler)}}}function he(){return"undefined"!=typeof navigator&&"function"==typeof(null===(e=navigator.locks)||void 0===e?void 0:e.request)?new le:new de;var e}let pe=null;function fe(){return pe||(pe=he()),pe}const me=new TextEncoder,ye=new TextDecoder;function we(e){return"string"==typeof e?me.encode(e):ye.decode(e)}function ge(e){if("number"!=typeof e.modulusLength||e.modulusLength<2048)throw new Se(`${e.name} modulusLength must be at least 2048 bits`)}async function ve(e,t,n){if(!1===n.usages.includes("sign"))throw new TypeError('private CryptoKey instances used for signing assertions must include "sign" in their "usages"');const o=`${_e(we(JSON.stringify(e)))}.${_e(we(JSON.stringify(t)))}`;return`${o}.${_e(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:"SHA-256"};case"RSA-PSS":return ge(e.algorithm),{name:e.algorithm.name,saltLength:32};case"RSASSA-PKCS1-v1_5":return ge(e.algorithm),{name:e.algorithm.name};case"Ed25519":return{name:e.algorithm.name}}throw new ke}(n),n,we(o)))}`}let be;if(Uint8Array.prototype.toBase64)be=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;be=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function _e(e){return be(e)}class ke extends Error{constructor(e){var t;super(null!=e?e:"operation not supported"),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}class Se extends Error{constructor(e){var t;super(e),this.name=this.constructor.name,null===(t=Error.captureStackTrace)||void 0===t||t.call(Error,this,this.constructor)}}function Te(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){if("SHA-256"===e.algorithm.hash.name)return"PS256";throw new ke("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"RSASSA-PKCS1-v1_5":return function(e){if("SHA-256"===e.algorithm.hash.name)return"RS256";throw new ke("unsupported RsaHashedKeyAlgorithm hash name")}(e);case"ECDSA":return function(e){if("P-256"===e.algorithm.namedCurve)return"ES256";throw new ke("unsupported EcKeyAlgorithm namedCurve")}(e);case"Ed25519":return"Ed25519";default:throw new ke("unsupported CryptoKey algorithm name")}}function Ee(e){return e instanceof CryptoKey}function Pe(e){return Ee(e)&&"public"===e.type}async function Ce(e,t,n,o,i,r){const s=null==e?void 0:e.privateKey,a=null==e?void 0:e.publicKey;if(!Ee(c=s)||"private"!==c.type)throw new TypeError('"keypair.privateKey" must be a private CryptoKey');var c;if(!Pe(a))throw new TypeError('"keypair.publicKey" must be a public CryptoKey');if(!0!==a.extractable)throw new TypeError('"keypair.publicKey.extractable" must be true');if("string"!=typeof t)throw new TypeError('"htu" must be a string');if("string"!=typeof n)throw new TypeError('"htm" must be a string');if(void 0!==o&&"string"!=typeof o)throw new TypeError('"nonce" must be a string or undefined');if(void 0!==i&&"string"!=typeof i)throw new TypeError('"accessToken" must be a string or undefined');if(void 0!==r&&("object"!=typeof r||null===r||Array.isArray(r)))throw new TypeError('"additional" must be an object');const u=Object.assign(Object.create(null),r,{iat:Math.floor(Date.now()/1e3),jti:crypto.randomUUID(),htm:n,nonce:o,htu:t,ath:i?_e(await crypto.subtle.digest("SHA-256",we(i))):void 0});return ve({alg:Te(s),typ:"dpop+jwt",jwk:await Ae(a)},u,s)}async function Ae(e){const{kty:t,e:n,n:o,x:i,y:r,crv:s}=await crypto.subtle.exportKey("jwk",e);return{kty:t,crv:s,e:n,n:o,x:i,y:r}}const Re="dpop-nonce",xe=["authorization_code","refresh_token","urn:ietf:params:oauth:grant-type:token-exchange","urn:okta:params:oauth:grant-type:webauthn","http://auth0.com/oauth/grant-type/mfa-oob","http://auth0.com/oauth/grant-type/mfa-otp","http://auth0.com/oauth/grant-type/mfa-recovery-code"];function Ie(){return async function(e,t){var n;let o;if("string"!=typeof e||0===e.length)throw new TypeError('"alg" must be a non-empty string');switch(e){case"PS256":o={name:"RSA-PSS",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"RS256":o={name:"RSASSA-PKCS1-v1_5",hash:"SHA-256",modulusLength:2048,publicExponent:new Uint8Array([1,0,1])};break;case"ES256":o={name:"ECDSA",namedCurve:"P-256"};break;case"Ed25519":o={name:"Ed25519"};break;default:throw new ke}return crypto.subtle.generateKey(o,null!==(n=null==t?void 0:t.extractable)&&void 0!==n&&n,["sign","verify"])}("ES256",{extractable:!1})}function Oe(e){return async function(e){if(!Pe(e))throw new TypeError('"publicKey" must be a public CryptoKey');if(!0!==e.extractable)throw new TypeError('"publicKey.extractable" must be true');const t=await Ae(e);let n;switch(t.kty){case"EC":n={crv:t.crv,kty:t.kty,x:t.x,y:t.y};break;case"OKP":n={crv:t.crv,kty:t.kty,x:t.x};break;case"RSA":n={e:t.e,kty:t.kty,n:t.n};break;default:throw new ke("unsupported JWK kty")}return _e(await crypto.subtle.digest({name:"SHA-256"},we(JSON.stringify(n))))}(e.publicKey)}function je(e){let t=e.keyPair,n=e.url,o=e.method,i=e.nonce,r=e.accessToken;const s=function(e){const t=new URL(e);return t.search="",t.hash="",t.href}(n);return Ce(t,s,o,i,r)}const We=(e,t)=>new Promise(function(n,o){const i=new MessageChannel;i.port1.onmessage=function(e){e.data.error?o(new Error(e.data.error)):n(e.data),i.port1.close()},t.postMessage(e,[i.port2])}),Me=(e,t,n)=>{const o=new AbortController;let i;return t.signal=o.signal,Promise.race([fetch(e,t),new Promise((e,t)=>{i=setTimeout(()=>{o.abort(),t(new Error("Timeout when executing 'fetch'"))},n)})]).finally(()=>{clearTimeout(i)})},Ne=async function(e,t,n,o,i,r){let s=arguments.length>6&&void 0!==arguments[6]?arguments[6]:_;return i?(async(e,t,n,o,i,r,s,a,c,u)=>We({type:"refresh",auth:{audience:t,scope:n},timeout:i,fetchUrl:e,fetchOptions:o,useFormData:s,useMrrt:a,skipTokenStorage:c,preserveRefreshToken:u},r))(e,t,n,o,s,i,r,arguments.length>7?arguments[7]:void 0,arguments.length>8?arguments[8]:void 0,arguments.length>9?arguments[9]:void 0):(async(e,t,n)=>{const o=await Me(e,t,n);return{ok:o.ok,json:await o.json(),headers:(i=o.headers,[...i].reduce((e,t)=>{let n=w(t,2),o=n[0],i=n[1];return e[o]=i,e},{}))};var i})(e,o,s)};async function Ke(e,n,o,i,r,s,a,c,u,l,d,h){if(u){const t=await u.generateProof({url:e,method:r.method||"GET",nonce:await u.getNonce()});r.headers=Object.assign(Object.assign({},r.headers),{dpop:t})}let p,f=null;for(let t=0;t<3;t++)try{p=await Ne(e,o,i,r,s,a,n,c,d,h),f=null;break}catch(e){f=e}if(f)throw f;const m=p.json,y=m.error,w=m.error_description,g=t(m,["error","error_description"]),v=p,b=v.headers,_=v.ok;let k;if(u&&(k=b[Re],k&&await u.setNonce(k)),!_){const t=w||"HTTP error. Unable to fetch ".concat(e);if("mfa_required"===y)throw new N(y,t,g.mfa_token,g.mfa_requirements);if("missing_refresh_token"===y)throw new K(o,i);if("use_dpop_nonce"===y){if(!u||!k||l)throw new L(k);return Ke(e,n,o,i,r,s,a,c,u,!0,d,h)}throw new A(y||"request_error",t)}return g}async function Ue(e,n,o){var i=e.baseUrl,r=e.timeout,s=e.audience,a=e.scope,c=e.auth0Client,u=e.useFormData,l=e.useMrrt,d=e.dpop,h=e.preserveRefreshToken,p=t(e,["baseUrl","timeout","audience","scope","auth0Client","useFormData","useMrrt","dpop","preserveRefreshToken"]);const f="urn:ietf:params:oauth:grant-type:token-exchange"===p.grant_type,m="urn:okta:params:oauth:grant-type:webauthn"===p.grant_type,y="refresh_token"===p.grant_type&&l,w=f||m||y,g=Object.assign(Object.assign(Object.assign({},p),w&&s&&{audience:s}),w&&a&&{scope:a}),v=m||!u,b=v?JSON.stringify(g):V(g),_=(k=p.grant_type,xe.includes(k));var k;return await Ke("".concat(i,"/oauth/token"),r,s||C,a,{method:"POST",body:b,headers:{"Content-Type":v?"application/json":"application/x-www-form-urlencoded","Auth0-Client":btoa(JSON.stringify(F(c||E)))}},n,u,l,_?d:void 0,void 0,o,h)}const Le=function(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];return(o=t.filter(Boolean).join(" ").trim().split(/\s+/),Array.from(new Set(o))).join(" ");var o},ze=(e,t,n)=>{let o;return n&&(o=e[n]),o||(o=e[C]),Le(o,t)},Je="@@auth0spajs@@",De="@@user@@";class Ze{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:Je,n=arguments.length>2?arguments[2]:void 0;this.prefix=t,this.suffix=n,this.clientId=e.clientId,this.scope=e.scope,this.audience=e.audience}toKey(){return[this.prefix,this.clientId,this.audience,this.scope,this.suffix].filter(Boolean).join("::")}static fromKey(e){const t=w(e.split("::"),4),n=t[0],o=t[1],i=t[2],r=t[3];return new Ze({clientId:o,scope:r,audience:i},n)}static fromCacheEntry(e){const t=e.scope,n=e.audience,o=e.client_id;return new Ze({scope:t,audience:n,clientId:o})}}class He{set(e,t){localStorage.setItem(e,JSON.stringify(t))}get(e){const t=window.localStorage.getItem(e);if(t)try{return JSON.parse(t)}catch(e){return}}remove(e){localStorage.removeItem(e)}allKeys(){return Object.keys(window.localStorage).filter(e=>e.startsWith(Je))}}class Fe{constructor(){this.enclosedCache=function(){let e={};return{set(t,n){e[t]=n},get(t){const n=e[t];if(n)return n},remove(t){delete e[t]},allKeys:()=>Object.keys(e)}}()}}class Ve{constructor(e,t,n){this.cache=e,this.keyManifest=t,this.nowProvider=n||P}async setIdToken(e,t,n){var o;const i=this.getIdTokenCacheKey(e);await this.cache.set(i,{id_token:t,decodedToken:n}),await(null===(o=this.keyManifest)||void 0===o?void 0:o.add(i))}async getIdToken(e){const t=await this.cache.get(this.getIdTokenCacheKey(e.clientId));if(!t&&e.scope&&e.audience){const t=await this.get(e);if(!t)return;if(!t.id_token||!t.decodedToken)return;return{id_token:t.id_token,decodedToken:t.decodedToken}}if(t)return{id_token:t.id_token,decodedToken:t.decodedToken}}async get(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:0,n=arguments.length>2&&void 0!==arguments[2]&&arguments[2],o=arguments.length>3?arguments[3]:void 0;var i;let r=await this.cache.get(e.toKey()),s=e;if(!r){const t=await this.getCacheKeys();if(!t)return;const i=this.matchExistingCacheKey(e,t);if(i&&(r=await this.cache.get(i),s=Ze.fromKey(i)),!r&&n&&"cache-only"!==o)return this.getEntryWithRefreshToken(e,t)}if(!r)return;const a=await this.nowProvider(),c=Math.floor(a/1e3);return r.expiresAt-t<c?r.body.refresh_token?this.modifiedCachedEntry(r,s):(await this.cache.remove(s.toKey()),void await(null===(i=this.keyManifest)||void 0===i?void 0:i.remove(s.toKey()))):r.body}async modifiedCachedEntry(e,t){const n={refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope},o={body:n,expiresAt:e.expiresAt};return await this.cache.set(t.toKey(),o),{refresh_token:n.refresh_token,audience:n.audience,scope:n.scope}}async set(e){var t;const n=new Ze({clientId:e.client_id,scope:e.scope,audience:e.audience}),o=await this.wrapCacheEntry(e);await this.cache.set(n.toKey(),o),await(null===(t=this.keyManifest)||void 0===t?void 0:t.add(n.toKey()))}async remove(e,t,n){const o=new Ze({clientId:e,scope:n,audience:t});await this.cache.remove(o.toKey())}async stripRefreshToken(e){var t;const n=await this.getCacheKeys();if(n)for(const o of n){const n=await this.cache.get(o);(null===(t=null==n?void 0:n.body)||void 0===t?void 0:t.refresh_token)===e&&(delete n.body.refresh_token,await this.cache.set(o,n))}}async clear(e){var t;const n=await this.getCacheKeys();n&&(await n.filter(t=>!e||t.includes(e)).reduce(async(e,t)=>{await e,await this.cache.remove(t)},Promise.resolve()),await(null===(t=this.keyManifest)||void 0===t?void 0:t.clear()))}async wrapCacheEntry(e){const t=await this.nowProvider();return{body:e,expiresAt:Math.floor(t/1e3)+e.expires_in}}async getCacheKeys(){var e;return this.keyManifest?null===(e=await this.keyManifest.get())||void 0===e?void 0:e.keys:this.cache.allKeys?this.cache.allKeys():void 0}getIdTokenCacheKey(e){return new Ze({clientId:e},Je,De).toKey()}matchExistingCacheKey(e,t){return t.filter(t=>{var n;const o=Ze.fromKey(t),i=new Set(o.scope&&o.scope.split(" ")),r=(null===(n=e.scope)||void 0===n?void 0:n.split(" "))||[],s=o.scope&&r.reduce((e,t)=>e&&i.has(t),!0);return o.prefix===Je&&o.clientId===e.clientId&&o.audience===e.audience&&s})[0]}async getEntryWithRefreshToken(e,t){var n;for(const o of t){const t=Ze.fromKey(o);if(t.prefix===Je&&t.clientId===e.clientId){const e=await this.cache.get(o);if(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)return{refresh_token:e.body.refresh_token,audience:e.body.audience,scope:e.body.scope}}}}async getRefreshTokensByAudience(e,t){var n;const o=await this.getCacheKeys();if(!o)return[];const i=new Set;for(const r of o){const o=Ze.fromKey(r);if(o.prefix===Je&&o.clientId===t&&o.audience===e){const e=await this.cache.get(r);(null===(n=null==e?void 0:e.body)||void 0===n?void 0:n.refresh_token)&&i.add(e.body.refresh_token)}}return Array.from(i)}async updateEntry(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const i=await this.getCacheKeys();if(i)for(const r of i){if(Ze.fromKey(r).clientId!==n)continue;const i=await this.cache.get(r);if(!(null==i?void 0:i.body))continue;const s=i.body.refresh_token;s&&(o||s===e)&&(i.body.refresh_token=t,await this.cache.set(r,i))}}}class Ge{constructor(e,t,n){this.storage=e,this.clientId=t,this.cookieDomain=n,this.storageKey="".concat("a0.spajs.txs",".").concat(this.clientId)}create(e){this.storage.save(this.storageKey,e,{daysUntilExpire:1,cookieDomain:this.cookieDomain})}get(){return this.storage.get(this.storageKey)}remove(){this.storage.remove(this.storageKey,{cookieDomain:this.cookieDomain})}}const Xe=e=>"number"==typeof e,qe=["iss","aud","exp","nbf","iat","jti","azp","nonce","auth_time","at_hash","c_hash","acr","amr","sub_jwk","cnf","sip_from_tag","sip_date","sip_callid","sip_cseq_num","sip_via_branch","orig","dest","mky","events","toe","txn","rph","sid","vot","vtm"],Ye=e=>{if(!e.id_token)throw new Error("ID token is required but missing");const t=(e=>{const t=e.split("."),n=w(t,3),o=n[0],i=n[1],r=n[2];if(3!==t.length||!o||!i||!r)throw new Error("ID token could not be decoded");const s=JSON.parse(X(i)),a={__raw:e},c={};return Object.keys(s).forEach(e=>{a[e]=s[e],qe.includes(e)||(c[e]=s[e])}),{encoded:{header:o,payload:i,signature:r},header:JSON.parse(X(o)),claims:a,user:c}})(e.id_token);if(!t.claims.iss)throw new Error("Issuer (iss) claim must be a string present in the ID token");if(t.claims.iss!==e.iss)throw new Error('Issuer (iss) claim mismatch in the ID token; expected "'.concat(e.iss,'", found "').concat(t.claims.iss,'"'));if(!t.user.sub)throw new Error("Subject (sub) claim must be a string present in the ID token");if("RS256"!==t.header.alg)throw new Error('Signature algorithm of "'.concat(t.header.alg,'" is not supported. Expected the ID token to be signed with "RS256".'));if(!t.claims.aud||"string"!=typeof t.claims.aud&&!Array.isArray(t.claims.aud))throw new Error("Audience (aud) claim must be a string or array of strings present in the ID token");if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e.aud))throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but was not one of "').concat(t.claims.aud.join(", "),'"'));if(t.claims.aud.length>1){if(!t.claims.azp)throw new Error("Authorized Party (azp) claim must be a string present in the ID token when Audience (aud) claim has multiple values");if(t.claims.azp!==e.aud)throw new Error('Authorized Party (azp) claim mismatch in the ID token; expected "'.concat(e.aud,'", found "').concat(t.claims.azp,'"'))}}else if(t.claims.aud!==e.aud)throw new Error('Audience (aud) claim mismatch in the ID token; expected "'.concat(e.aud,'" but found "').concat(t.claims.aud,'"'));if(e.nonce){if(!t.claims.nonce)throw new Error("Nonce (nonce) claim must be a string present in the ID token");if(t.claims.nonce!==e.nonce)throw new Error('Nonce (nonce) claim mismatch in the ID token; expected "'.concat(e.nonce,'", found "').concat(t.claims.nonce,'"'))}if(e.max_age&&!Xe(t.claims.auth_time))throw new Error("Authentication Time (auth_time) claim must be a number present in the ID token when Max Age (max_age) is specified");if(null==t.claims.exp||!Xe(t.claims.exp))throw new Error("Expiration Time (exp) claim must be a number present in the ID token");if(!Xe(t.claims.iat))throw new Error("Issued At (iat) claim must be a number present in the ID token");const n=e.leeway||60,o=new Date(e.now||Date.now()),i=new Date(0);if(i.setUTCSeconds(t.claims.exp+n),o>i)throw new Error("Expiration Time (exp) claim error in the ID token; current time (".concat(o,") is after expiration time (").concat(i,")"));if(null!=t.claims.nbf&&Xe(t.claims.nbf)){const e=new Date(0);if(e.setUTCSeconds(t.claims.nbf-n),o<e)throw new Error("Not Before time (nbf) claim in the ID token indicates that this token can't be used just yet. Current time (".concat(o,") is before ").concat(e))}if(null!=t.claims.auth_time&&Xe(t.claims.auth_time)){const i=new Date(0);if(i.setUTCSeconds(parseInt(t.claims.auth_time)+e.max_age+n),o>i)throw new Error("Authentication Time (auth_time) claim in the ID token indicates that too much time has passed since the last end-user authentication. Current time (".concat(o,") is after last auth at ").concat(i))}if(e.organization){const n=e.organization.trim();if(n.startsWith("org_")){const e=n;if(!t.claims.org_id)throw new Error("Organization ID (org_id) claim must be a string present in the ID token");if(e!==t.claims.org_id)throw new Error('Organization ID (org_id) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_id,'"'))}else{const e=n.toLowerCase();if(!t.claims.org_name)throw new Error("Organization Name (org_name) claim must be a string present in the ID token");if(e!==t.claims.org_name)throw new Error('Organization Name (org_name) claim mismatch in the ID token; expected "'.concat(e,'", found "').concat(t.claims.org_name,'"'))}}return t};var Be=Y&&Y.__assign||function(){return Be=Object.assign||function(e){for(var t,n=1,o=arguments.length;n<o;n++)for(var i in t=arguments[n])Object.prototype.hasOwnProperty.call(t,i)&&(e[i]=t[i]);return e},Be.apply(this,arguments)};function Qe(e,t){if(!t)return"";var n="; "+e;return!0===t?n:n+"="+t}function $e(e,t,n){return encodeURIComponent(e).replace(/%(23|24|26|2B|5E|60|7C)/g,decodeURIComponent).replace(/\(/g,"%28").replace(/\)/g,"%29")+"="+encodeURIComponent(t).replace(/%(23|24|26|2B|3A|3C|3E|3D|2F|3F|40|5B|5D|5E|60|7B|7D|7C)/g,decodeURIComponent)+function(e){if("number"==typeof e.expires){var t=new Date;t.setMilliseconds(t.getMilliseconds()+864e5*e.expires),e.expires=t}return Qe("Expires",e.expires?e.expires.toUTCString():"")+Qe("Domain",e.domain)+Qe("Path",e.path)+Qe("Secure",e.secure)+Qe("SameSite",e.sameSite)}(n)}function et(){return function(e){for(var t={},n=e?e.split("; "):[],o=/(%[\dA-F]{2})+/gi,i=0;i<n.length;i++){var r=n[i].split("="),s=r.slice(1).join("=");'"'===s.charAt(0)&&(s=s.slice(1,-1));try{t[r[0].replace(o,decodeURIComponent)]=s.replace(o,decodeURIComponent)}catch(e){}}return t}(document.cookie)}var tt=function(e){return et()[e]};function nt(e,t,n){document.cookie=$e(e,t,Be({path:"/"},n))}var ot=nt;var it=function(e,t){nt(e,"",Be(Be({},t),{expires:-1}))};const rt={get(e){const t=tt(e);if(void 0!==t)return JSON.parse(t)},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0,sameSite:"none"}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),ot(e,JSON.stringify(t),o)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),it(e,n)}},st="_legacy_",at={get(e){const t=rt.get(e);return t||rt.get("".concat(st).concat(e))},save(e,t,n){let o={};"https:"===window.location.protocol&&(o={secure:!0}),(null==n?void 0:n.daysUntilExpire)&&(o.expires=n.daysUntilExpire),(null==n?void 0:n.cookieDomain)&&(o.domain=n.cookieDomain),ot("".concat(st).concat(e),JSON.stringify(t),o),rt.save(e,t,n)},remove(e,t){let n={};(null==t?void 0:t.cookieDomain)&&(n.domain=t.cookieDomain),it(e,n),rt.remove(e,t),rt.remove("".concat(st).concat(e),t)}},ct={get(e){if("undefined"==typeof sessionStorage)return;const t=sessionStorage.getItem(e);return null!=t?JSON.parse(t):void 0},save(e,t){sessionStorage.setItem(e,JSON.stringify(t))},remove(e){sessionStorage.removeItem(e)}};var ut;e.ResponseType=void 0,(ut=e.ResponseType||(e.ResponseType={})).Code="code",ut.ConnectCode="connect_code";function lt(e,t,n){var o=void 0===t?null:t,i=function(e,t){var n=atob(e);if(t){for(var o=new Uint8Array(n.length),i=0,r=n.length;i<r;++i)o[i]=n.charCodeAt(i);return String.fromCharCode.apply(null,new Uint16Array(o.buffer))}return n}(e,void 0!==n&&n),r=i.indexOf("\n",10)+1,s=i.substring(r)+(o?"//# sourceMappingURL="+o:""),a=new Blob([s],{type:"application/javascript"});return URL.createObjectURL(a)}var dt,ht,pt,ft,mt=(dt="Lyogcm9sbHVwLXBsdWdpbi13ZWItd29ya2VyLWxvYWRlciAqLwohZnVuY3Rpb24oKXsidXNlIHN0cmljdCI7ZnVuY3Rpb24gZShlLHQpeyhudWxsPT10fHx0PmUubGVuZ3RoKSYmKHQ9ZS5sZW5ndGgpO2Zvcih2YXIgcj0wLG89QXJyYXkodCk7cjx0O3IrKylvW3JdPWVbcl07cmV0dXJuIG99ZnVuY3Rpb24gdCh0LHIpe3JldHVybiBmdW5jdGlvbihlKXtpZihBcnJheS5pc0FycmF5KGUpKXJldHVybiBlfSh0KXx8ZnVuY3Rpb24oZSx0KXt2YXIgcj1udWxsPT1lP251bGw6InVuZGVmaW5lZCIhPXR5cGVvZiBTeW1ib2wmJmVbU3ltYm9sLml0ZXJhdG9yXXx8ZVsiQEBpdGVyYXRvciJdO2lmKG51bGwhPXIpe3ZhciBvLG4scyxhLGk9W10sYz0hMCxsPSExO3RyeXtpZihzPShyPXIuY2FsbChlKSkubmV4dCwwPT09dCl7aWYoT2JqZWN0KHIpIT09cilyZXR1cm47Yz0hMX1lbHNlIGZvcig7IShjPShvPXMuY2FsbChyKSkuZG9uZSkmJihpLnB1c2goby52YWx1ZSksaS5sZW5ndGghPT10KTtjPSEwKTt9Y2F0Y2goZSl7bD0hMCxuPWV9ZmluYWxseXt0cnl7aWYoIWMmJm51bGwhPXIucmV0dXJuJiYoYT1yLnJldHVybigpLE9iamVjdChhKSE9PWEpKXJldHVybn1maW5hbGx5e2lmKGwpdGhyb3cgbn19cmV0dXJuIGl9fSh0LHIpfHxmdW5jdGlvbih0LHIpe2lmKHQpe2lmKCJzdHJpbmciPT10eXBlb2YgdClyZXR1cm4gZSh0LHIpO3ZhciBvPXt9LnRvU3RyaW5nLmNhbGwodCkuc2xpY2UoOCwtMSk7cmV0dXJuIk9iamVjdCI9PT1vJiZ0LmNvbnN0cnVjdG9yJiYobz10LmNvbnN0cnVjdG9yLm5hbWUpLCJNYXAiPT09b3x8IlNldCI9PT1vP0FycmF5LmZyb20odCk6IkFyZ3VtZW50cyI9PT1vfHwvXig/OlVpfEkpbnQoPzo4fDE2fDMyKSg/OkNsYW1wZWQpP0FycmF5JC8udGVzdChvKT9lKHQscik6dm9pZCAwfX0odCxyKXx8ZnVuY3Rpb24oKXt0aHJvdyBuZXcgVHlwZUVycm9yKCJJbnZhbGlkIGF0dGVtcHQgdG8gZGVzdHJ1Y3R1cmUgbm9uLWl0ZXJhYmxlIGluc3RhbmNlLlxuSW4gb3JkZXIgdG8gYmUgaXRlcmFibGUsIG5vbi1hcnJheSBvYmplY3RzIG11c3QgaGF2ZSBhIFtTeW1ib2wuaXRlcmF0b3JdKCkgbWV0aG9kLiIpfSgpfWNsYXNzIHIgZXh0ZW5kcyBFcnJvcntjb25zdHJ1Y3RvcihlLHQpe3N1cGVyKHQpLHRoaXMuZXJyb3I9ZSx0aGlzLmVycm9yX2Rlc2NyaXB0aW9uPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsci5wcm90b3R5cGUpfXN0YXRpYyBmcm9tUGF5bG9hZChlKXtsZXQgdD1lLmVycm9yLG89ZS5lcnJvcl9kZXNjcmlwdGlvbjtyZXR1cm4gbmV3IHIodCxvKX19Y2xhc3MgbyBleHRlbmRzIHJ7Y29uc3RydWN0b3IoZSx0KXtzdXBlcigibWlzc2luZ19yZWZyZXNoX3Rva2VuIiwiTWlzc2luZyBSZWZyZXNoIFRva2VuIChhdWRpZW5jZTogJyIuY29uY2F0KG4oZSxbImRlZmF1bHQiXSksIicsIHNjb3BlOiAnIikuY29uY2F0KG4odCksIicpIikpLHRoaXMuYXVkaWVuY2U9ZSx0aGlzLnNjb3BlPXQsT2JqZWN0LnNldFByb3RvdHlwZU9mKHRoaXMsby5wcm90b3R5cGUpfX1mdW5jdGlvbiBuKGUpe3JldHVybiBlJiYhKGFyZ3VtZW50cy5sZW5ndGg+MSYmdm9pZCAwIT09YXJndW1lbnRzWzFdP2FyZ3VtZW50c1sxXTpbXSkuaW5jbHVkZXMoZSk/ZToiIn0iZnVuY3Rpb24iPT10eXBlb2YgU3VwcHJlc3NlZEVycm9yJiZTdXBwcmVzc2VkRXJyb3I7Y29uc3Qgcz1lPT57dmFyIHQ9ZS5jbGllbnRJZCxyPWZ1bmN0aW9uKGUsdCl7dmFyIHI9e307Zm9yKHZhciBvIGluIGUpT2JqZWN0LnByb3RvdHlwZS5oYXNPd25Qcm9wZXJ0eS5jYWxsKGUsbykmJnQuaW5kZXhPZihvKTwwJiYocltvXT1lW29dKTtpZihudWxsIT1lJiYiZnVuY3Rpb24iPT10eXBlb2YgT2JqZWN0LmdldE93blByb3BlcnR5U3ltYm9scyl7dmFyIG49MDtmb3Iobz1PYmplY3QuZ2V0T3duUHJvcGVydHlTeW1ib2xzKGUpO248by5sZW5ndGg7bisrKXQuaW5kZXhPZihvW25dKTwwJiZPYmplY3QucHJvdG90eXBlLnByb3BlcnR5SXNFbnVtZXJhYmxlLmNhbGwoZSxvW25dKSYmKHJbb1tuXV09ZVtvW25dXSl9cmV0dXJuIHJ9KGUsWyJjbGllbnRJZCJdKTtyZXR1cm4gbmV3IFVSTFNlYXJjaFBhcmFtcygoZT0+T2JqZWN0LmtleXMoZSkuZmlsdGVyKHQ9PnZvaWQgMCE9PWVbdF0pLnJlZHVjZSgodCxyKT0+T2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHQpLHtbcl06ZVtyXX0pLHt9KSkoT2JqZWN0LmFzc2lnbih7Y2xpZW50X2lkOnR9LHIpKSkudG9TdHJpbmcoKX07bGV0IGE9e30saT1udWxsO2NvbnN0IGM9KGUsdCk9PiIiLmNvbmNhdChlLCJ8IikuY29uY2F0KHQpLGw9KGUsdCk9PnQuc3RhcnRzV2l0aCgiIi5jb25jYXQoZSwifCIpKSx1PShlLHQpPT5hW2MoZSx0KV0sZj1lPT57T2JqZWN0LmVudHJpZXMoYSkuZm9yRWFjaChyPT57bGV0IG89dChyLDIpLG49b1swXTtvWzFdPT09ZSYmZGVsZXRlIGFbbl19KX0saD1lPT57Y29uc3QgdD1uZXcgVVJMU2VhcmNoUGFyYW1zKGUpLHI9e307cmV0dXJuIHQuZm9yRWFjaCgoZSx0KT0+e3JbdF09ZX0pLHJ9LGQ9YXN5bmMgZT0+e2xldCByLG4saT1lLmRhdGEsZj1pLnRpbWVvdXQsZD1pLmF1dGgscD1pLmZldGNoVXJsLHk9aS5mZXRjaE9wdGlvbnMsZz1pLnVzZUZvcm1EYXRhLGI9aS51c2VNcnJ0LE89aS5za2lwVG9rZW5TdG9yYWdlLGs9aS5wcmVzZXJ2ZVJlZnJlc2hUb2tlbixtPXQoZS5wb3J0cywxKVswXSxqPXt9O2NvbnN0IHY9ZHx8e30sXz12LmF1ZGllbmNlLHc9di5zY29wZTt0cnl7Y29uc3QgZT1nP2goeS5ib2R5KTpKU09OLnBhcnNlKHkuYm9keSk7aWYoZS5yZWZyZXNoX3Rva2VufHwicmVmcmVzaF90b2tlbiIhPT1lLmdyYW50X3R5cGUpZS5tZmFfdG9rZW4mJihuPXUoXyx3KSwhbiYmYiYmKG49YS5sYXRlc3RfcmVmcmVzaF90b2tlbikpO2Vsc2V7aWYobj11KF8sdyksIW4mJmIpe2NvbnN0IGU9YS5sYXRlc3RfcmVmcmVzaF90b2tlbix0PSgoZSx0KT0+ISFPYmplY3Qua2V5cyhhKS5maW5kKHI9PntpZigibGF0ZXN0X3JlZnJlc2hfdG9rZW4iIT09cil7Y29uc3Qgbz1sKHQsciksbj1yLnNwbGl0KCJ8IilbMV0uc3BsaXQoIiAiKSxzPWUuc3BsaXQoIiAiKS5ldmVyeShlPT5uLmluY2x1ZGVzKGUpKTtyZXR1cm4gbyYmc319KSkodyxfKTtlJiYhdCYmKG49ZSl9aWYoIW4pdGhyb3cgbmV3IG8oXyx3KTt5LmJvZHk9Zz9zKE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxlKSx7cmVmcmVzaF90b2tlbjpufSkpfWxldCBpLGQ7ImZ1bmN0aW9uIj09dHlwZW9mIEFib3J0Q29udHJvbGxlciYmKGk9bmV3IEFib3J0Q29udHJvbGxlcix5LnNpZ25hbD1pLnNpZ25hbCk7dHJ5e2Q9YXdhaXQgUHJvbWlzZS5yYWNlKFsoUD1mLG5ldyBQcm9taXNlKGU9PnNldFRpbWVvdXQoZSxQKSkpLGZldGNoKHAsT2JqZWN0LmFzc2lnbih7fSx5KSldKX1jYXRjaChlKXtyZXR1cm4gdm9pZCBtLnBvc3RNZXNzYWdlKHtlcnJvcjplLm1lc3NhZ2V9KX1pZighZClyZXR1cm4gaSYmaS5hYm9ydCgpLHZvaWQgbS5wb3N0TWVzc2FnZSh7ZXJyb3I6IlRpbWVvdXQgd2hlbiBleGVjdXRpbmcgJ2ZldGNoJyJ9KTtpZihVPWQuaGVhZGVycyxqPVsuLi5VXS5yZWR1Y2UoKGUscik9PntsZXQgbz10KHIsMiksbj1vWzBdLHM9b1sxXTtyZXR1cm4gZVtuXT1zLGV9LHt9KSxyPWF3YWl0IGQuanNvbigpLE8pcmV0dXJuIGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4sdm9pZCBtLnBvc3RNZXNzYWdlKHtvazpkLm9rLGpzb246cixoZWFkZXJzOmp9KTtyLnJlZnJlc2hfdG9rZW4/KGImJihhLmxhdGVzdF9yZWZyZXNoX3Rva2VuPXIucmVmcmVzaF90b2tlbixTPW4sTT1yLnJlZnJlc2hfdG9rZW4sT2JqZWN0LmVudHJpZXMoYSkuZm9yRWFjaChlPT57bGV0IHI9dChlLDIpLG89clswXTtyWzFdPT09UyYmKGFbb109TSl9KSksKChlLHQscik9PnthW2ModCxyKV09ZX0pKHIucmVmcmVzaF90b2tlbixfLHcpLGRlbGV0ZSByLnJlZnJlc2hfdG9rZW4pOmt8fCgoZSx0KT0+e2RlbGV0ZSBhW2MoZSx0KV19KShfLHcpLG0ucG9zdE1lc3NhZ2Uoe29rOmQub2ssanNvbjpyLGhlYWRlcnM6an0pfWNhdGNoKGUpe20ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOmUuZXJyb3IsZXJyb3JfZGVzY3JpcHRpb246ZS5tZXNzYWdlfSxoZWFkZXJzOmp9KX12YXIgUyxNLFUsUH0scD1hc3luYyBlPT57bGV0IHI9ZS5kYXRhLG89ci50aW1lb3V0LG49ci5hdXRoLGk9ci5mZXRjaFVybCxjPXIuZmV0Y2hPcHRpb25zLHU9ci51c2VGb3JtRGF0YSxkPXQoZS5wb3J0cywxKVswXTtjb25zdCBwPShufHx7fSkuYXVkaWVuY2U7dHJ5e2NvbnN0IGU9KGU9Pntjb25zdCByPW5ldyBTZXQ7cmV0dXJuIE9iamVjdC5lbnRyaWVzKGEpLmZvckVhY2gobz0+e2xldCBuPXQobywyKSxzPW5bMF0sYT1uWzFdO2woZSxzKSYmci5hZGQoYSl9KSxBcnJheS5mcm9tKHIpfSkocCk7aWYoMD09PWUubGVuZ3RoKXJldHVybiB2b2lkIGQucG9zdE1lc3NhZ2Uoe29rOiEwfSk7Y29uc3Qgcj11P2goYy5ib2R5KTpKU09OLnBhcnNlKGMuYm9keSk7Zm9yKGNvbnN0IHQgb2YgZSl7Y29uc3QgZT11P3MoT2JqZWN0LmFzc2lnbihPYmplY3QuYXNzaWduKHt9LHIpLHt0b2tlbjp0fSkpOkpTT04uc3RyaW5naWZ5KE9iamVjdC5hc3NpZ24oT2JqZWN0LmFzc2lnbih7fSxyKSx7dG9rZW46dH0pKTtsZXQgbixhLGwsaDsiZnVuY3Rpb24iPT10eXBlb2YgQWJvcnRDb250cm9sbGVyJiYobj1uZXcgQWJvcnRDb250cm9sbGVyLGE9bi5zaWduYWwpO3RyeXtoPWF3YWl0IFByb21pc2UucmFjZShbbmV3IFByb21pc2UoZT0+e2w9c2V0VGltZW91dChlLG8pfSksZmV0Y2goaSxPYmplY3QuYXNzaWduKE9iamVjdC5hc3NpZ24oe30sYykse2JvZHk6ZSxzaWduYWw6YX0pKV0pLmZpbmFsbHkoKCk9PmNsZWFyVGltZW91dChsKSl9Y2F0Y2goZSl7cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZS5tZXNzYWdlfSl9aWYoIWgpcmV0dXJuIG4mJm4uYWJvcnQoKSx2b2lkIGQucG9zdE1lc3NhZ2Uoe2Vycm9yOiJUaW1lb3V0IHdoZW4gZXhlY3V0aW5nICdmZXRjaCcifSk7aWYoIWgub2spe2xldCBlO3RyeXtjb25zdCB0PUpTT04ucGFyc2UoYXdhaXQgaC50ZXh0KCkpO2U9dC5lcnJvcl9kZXNjcmlwdGlvbn1jYXRjaChlKXt9cmV0dXJuIHZvaWQgZC5wb3N0TWVzc2FnZSh7ZXJyb3I6ZXx8IkhUVFAgZXJyb3IgIi5jb25jYXQoaC5zdGF0dXMpfSl9Zih0KX1kLnBvc3RNZXNzYWdlKHtvazohMH0pfWNhdGNoKGUpe2QucG9zdE1lc3NhZ2Uoe2Vycm9yOmUubWVzc2FnZXx8IlVua25vd24gZXJyb3IgZHVyaW5nIHRva2VuIHJldm9jYXRpb24ifSl9fSx5PShlLHQpPT57aWYoIWkpcmV0dXJuITE7dHJ5e2NvbnN0IHI9bmV3IFVSTChpKS5vcmlnaW4sbz1uZXcgVVJMKGUuZmV0Y2hVcmwpO3JldHVybiBvLm9yaWdpbj09PXImJm8ucGF0aG5hbWU9PT10fWNhdGNoKGUpe3JldHVybiExfX07YWRkRXZlbnRMaXN0ZW5lcigibWVzc2FnZSIsZT0+e2NvbnN0IHI9ZS5kYXRhLG89dChlLnBvcnRzLDEpWzBdO2lmKCEoInR5cGUiaW4gcil8fCJpbml0IiE9PXIudHlwZSlyZXR1cm4idHlwZSJpbiByJiYiY2xlYXIiPT09ci50eXBlPyhhPXt9LHZvaWQobnVsbD09b3x8by5wb3N0TWVzc2FnZSh7b2s6ITB9KSkpOiJ0eXBlImluIHImJiJyZXZva2UiPT09ci50eXBlP3kociwiL29hdXRoL3Jldm9rZSIpP3ZvaWQgcChlKTp2b2lkKG51bGw9PW98fG8ucG9zdE1lc3NhZ2Uoe29rOiExLGpzb246e2Vycm9yOiJpbnZhbGlkX2ZldGNoX3VybCIsZXJyb3JfZGVzY3JpcHRpb246IlVuYXV0aG9yaXplZCBmZXRjaCBVUkwifSxoZWFkZXJzOnt9fSkpOnZvaWQoImZldGNoVXJsImluIHImJnkociwiL29hdXRoL3Rva2VuIik/ZChlKTpudWxsPT1vfHxvLnBvc3RNZXNzYWdlKHtvazohMSxqc29uOntlcnJvcjoiaW52YWxpZF9mZXRjaF91cmwiLGVycm9yX2Rlc2NyaXB0aW9uOiJVbmF1dGhvcml6ZWQgZmV0Y2ggVVJMIn0saGVhZGVyczp7fX0pKTtpZihudWxsPT09aSl0cnl7bmV3IFVSTChyLmFsbG93ZWRCYXNlVXJsKSxpPXIuYWxsb3dlZEJhc2VVcmx9Y2F0Y2goZSl7cmV0dXJufX0pfSgpOwoK",ht=null,pt=!1,function(e){return ft=ft||lt(dt,ht,pt),new Worker(ft,e)});class yt{constructor(e,t){this.cache=e,this.clientId=t,this.manifestKey=this.createManifestKeyFrom(this.clientId)}async add(e){var t;const n=new Set((null===(t=await this.cache.get(this.manifestKey))||void 0===t?void 0:t.keys)||[]);n.add(e),await this.cache.set(this.manifestKey,{keys:[...n]})}async remove(e){const t=await this.cache.get(this.manifestKey);if(t){const n=new Set(t.keys);return n.delete(e),n.size>0?await this.cache.set(this.manifestKey,{keys:[...n]}):await this.cache.remove(this.manifestKey)}}get(){return this.cache.get(this.manifestKey)}clear(){return this.cache.remove(this.manifestKey)}createManifestKeyFrom(e){return"".concat(Je,"::").concat(e)}}const wt="auth0.is.authenticated",gt={memory:()=>(new Fe).enclosedCache,localstorage:()=>new He},vt=e=>gt[e],bt=e=>{const n=e.openUrl,o=e.onRedirect,i=t(e,["openUrl","onRedirect"]);return Object.assign(Object.assign({},i),{openUrl:!1===n||n?n:o})},_t=(e,t,n)=>{const o=(null==e?void 0:e.split(" "))||[],i=n?o.filter(e=>e!==T):o;const r=(null==t?void 0:t.split(" "))||[];return i.filter(e=>-1==r.indexOf(e)).join(",")},kt={NONCE:"nonce",KEYPAIR:"keypair"};class St{constructor(e){this.clientId=e}getVersion(){return 1}createDbHandle(){const e=window.indexedDB.open("auth0-spa-js",this.getVersion());return new Promise((t,n)=>{e.onupgradeneeded=()=>Object.values(kt).forEach(t=>e.result.createObjectStore(t)),e.onerror=()=>n(e.error),e.onsuccess=()=>t(e.result)})}async getDbHandle(){return this.dbHandle||(this.dbHandle=await this.createDbHandle()),this.dbHandle}async executeDbRequest(e,t,n){const o=n((await this.getDbHandle()).transaction(e,t).objectStore(e));return new Promise((e,t)=>{o.onsuccess=()=>e(o.result),o.onerror=()=>t(o.error)})}buildKey(e){const t=e?"_".concat(e):"auth0";return"".concat(this.clientId,"::").concat(t)}setNonce(e,t){return this.save(kt.NONCE,this.buildKey(t),e)}setKeyPair(e){return this.save(kt.KEYPAIR,this.buildKey(),e)}async save(e,t,n){await this.executeDbRequest(e,"readwrite",e=>e.put(n,t))}findNonce(e){return this.find(kt.NONCE,this.buildKey(e))}findKeyPair(){return this.find(kt.KEYPAIR,this.buildKey())}find(e,t){return this.executeDbRequest(e,"readonly",e=>e.get(t))}async deleteBy(e,t){const n=await this.executeDbRequest(e,"readonly",e=>e.getAllKeys());await Promise.all((null==n?void 0:n.filter(t).map(t=>this.executeDbRequest(e,"readwrite",e=>e.delete(t))))||[])}deleteByClientId(e,t){return this.deleteBy(e,e=>"string"==typeof e&&e.startsWith("".concat(t,"::")))}clearNonces(){return this.deleteByClientId(kt.NONCE,this.clientId)}clearKeyPairs(){return this.deleteByClientId(kt.KEYPAIR,this.clientId)}}class Tt{constructor(e){this.storage=new St(e)}getNonce(e){return this.storage.findNonce(e)}setNonce(e,t){return this.storage.setNonce(e,t)}async getOrGenerateKeyPair(){let e=await this.storage.findKeyPair();return e||(e=await Ie(),await this.storage.setKeyPair(e)),e}async generateProof(e){const t=await this.getOrGenerateKeyPair();return je(Object.assign({keyPair:t},e))}async calculateThumbprint(){return Oe(await this.getOrGenerateKeyPair())}async clear(){await Promise.all([this.storage.clearNonces(),this.storage.clearKeyPairs()])}}var Et;!function(e){e.Bearer="Bearer",e.DPoP="DPoP"}(Et||(Et={}));class Pt{constructor(e,t){this.hooks=t,this.config=Object.assign(Object.assign({},e),{fetch:e.fetch||("undefined"==typeof window?fetch:window.fetch.bind(window))})}isAbsoluteUrl(e){return/^(https?:)?\/\//i.test(e)}buildUrl(e,t){if(t){if(this.isAbsoluteUrl(t))return t;if(e)return"".concat(e.replace(/\/?\/$/,""),"/").concat(t.replace(/^\/+/,""))}throw new TypeError("`url` must be absolute or `baseUrl` non-empty.")}getAccessToken(e){return this.config.getAccessToken?this.config.getAccessToken(e):this.hooks.getAccessToken(e)}extractUrl(e){return"string"==typeof e?e:e instanceof URL?e.href:e.url}buildBaseRequest(e,t){if(!this.config.baseUrl)return new Request(e,t);const n=this.buildUrl(this.config.baseUrl,this.extractUrl(e)),o=e instanceof Request?new Request(n,e):n;return new Request(o,t)}setAuthorizationHeader(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:Et.Bearer;e.headers.set("authorization","".concat(n," ").concat(t))}async setDpopProofHeader(e,t){if(!this.config.dpopNonceId)return;const n=await this.hooks.getDpopNonce(),o=await this.hooks.generateDpopProof({accessToken:t,method:e.method,nonce:n,url:e.url});e.headers.set("dpop",o)}async prepareRequest(e,t){const n=await this.getAccessToken(t);if(void 0===n)throw new A("missing_access_token","No access token available");let o,i;"string"==typeof n?(o=this.config.dpopNonceId?Et.DPoP:Et.Bearer,i=n):(o=n.token_type,i=n.access_token),this.setAuthorizationHeader(e,i,o),o===Et.DPoP&&await this.setDpopProofHeader(e,i)}getHeader(e,t){return Array.isArray(e)?new Headers(e).get(t)||"":"function"==typeof e.get?e.get(t)||"":e[t]||""}hasUseDpopNonceError(e){if(401!==e.status)return!1;const t=this.getHeader(e.headers,"www-authenticate");return t.includes("invalid_dpop_nonce")||t.includes("use_dpop_nonce")}async handleResponse(e,t){const n=this.getHeader(e.headers,Re);if(n&&await this.hooks.setDpopNonce(n),!this.hasUseDpopNonceError(e))return e;if(!n||!t.onUseDpopNonceError)throw new L(n);return t.onUseDpopNonceError()}async internalFetchWithAuth(e,t,n,o){const i=this.buildBaseRequest(e,t);await this.prepareRequest(i,o);const r=await this.config.fetch(i);return this.handleResponse(r,n)}fetchWithAuth(e,t,n){const o={onUseDpopNonceError:()=>this.internalFetchWithAuth(e,t,Object.assign(Object.assign({},o),{onUseDpopNonceError:void 0}),n)};return this.internalFetchWithAuth(e,t,o,n)}}class Ct{constructor(e,t){this.myAccountFetcher=e,this.apiBase=t}async connectAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/connect"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:connected_accounts"]});return this._handleResponse(t)}async completeAccount(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/connected-accounts/complete"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:connected_accounts"]});return this._handleResponse(t)}async getFactors(){const e=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/factors"),{method:"GET"},{scope:["read:me:factors"]});return(await this._handleResponse(e)).factors}async getAuthenticationMethods(e){const t=e?"?".concat(new URLSearchParams({type:e})):"",n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods").concat(t),{method:"GET"},{scope:["read:me:authentication_methods"]});return(await this._handleResponse(n)).authentication_methods}async getAuthenticationMethod(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"GET"},{scope:["read:me:authentication_methods"]});return this._handleResponse(t)}async deleteAuthenticationMethod(e){const t=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"DELETE"},{scope:["delete:me:authentication_methods"]});t.ok||await this._handleResponse(t)}async updateAuthenticationMethod(e,t){const n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods/").concat(encodeURIComponent(e)),{method:"PATCH",headers:{"Content-Type":"application/json"},body:JSON.stringify(t)},{scope:["update:me:authentication_methods"]});return this._handleResponse(n)}async enrollmentChallenge(e){var t;const n=await this.myAccountFetcher.fetchWithAuth("".concat(this.apiBase,"v1/authentication-methods"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(e)},{scope:["create:me:authentication_methods"]}),o=await this._handleResponse(n),i=null!==(t=n.headers.get("location"))&&void 0!==t?t:"",r=decodeURIComponent(i.split("/").pop()||"");return Object.assign(Object.assign({},o),{id:r,location:i})}async enrollmentVerify(e){const n=e,o=n.location;n.type;const i=t(n,["location","type"]),r=await this.myAccountFetcher.fetchWithAuth("".concat(o,"/verify"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(i)},{scope:["create:me:authentication_methods"]});return this._handleResponse(r)}async _handleResponse(e){let t;try{t=await e.text(),t=JSON.parse(t)}catch(n){throw new At({type:"invalid_json",status:e.status,title:"Invalid JSON response",detail:t||String(n)})}if(e.ok)return t;throw new At(t)}}class At extends Error{constructor(e){let t=e.type,n=e.status,o=e.title,i=e.detail,r=e.validation_errors;super(i),this.name="MyAccountApiError",this.type=t,this.status=n,this.title=o,this.detail=i,this.validation_errors=r,Object.setPrototypeOf(this,At.prototype)}}const Rt={otp:{authenticatorTypes:["otp"]},sms:{authenticatorTypes:["oob"],oobChannels:["sms"]},email:{authenticatorTypes:["oob"],oobChannels:["email"]},push:{authenticatorTypes:["oob"],oobChannels:["auth0"]},voice:{authenticatorTypes:["oob"],oobChannels:["voice"]}},xt="http://auth0.com/oauth/grant-type/mfa-otp",It="http://auth0.com/oauth/grant-type/mfa-oob",Ot="http://auth0.com/oauth/grant-type/mfa-recovery-code";var jt,Wt;let Mt;if("undefined"==typeof navigator||null===(jt=navigator.userAgent)||void 0===jt||null===(Wt=jt.startsWith)||void 0===Wt||!Wt.call(jt,"Mozilla/5.0 ")){const e="v3.8.6";Mt="".concat("oauth4webapi","/").concat(e)}function Nt(e,t){if(null==e)return!1;try{return e instanceof t||Object.getPrototypeOf(e)[Symbol.toStringTag]===t.prototype[Symbol.toStringTag]}catch(e){return!1}}const Kt="ERR_INVALID_ARG_VALUE",Ut="ERR_INVALID_ARG_TYPE";function Lt(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}const zt=Symbol(),Jt=Symbol(),Dt=Symbol(),Zt=Symbol(),Ht=Symbol(),Ft=Symbol(),Vt=new TextEncoder,Gt=new TextDecoder;function Xt(e){return"string"==typeof e?Vt.encode(e):Gt.decode(e)}let qt,Yt;if(Uint8Array.prototype.toBase64)qt=e=>(e instanceof ArrayBuffer&&(e=new Uint8Array(e)),e.toBase64({alphabet:"base64url",omitPadding:!0}));else{const e=32768;qt=t=>{t instanceof ArrayBuffer&&(t=new Uint8Array(t));const n=[];for(let o=0;o<t.byteLength;o+=e)n.push(String.fromCharCode.apply(null,t.subarray(o,o+e)));return btoa(n.join("")).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}}function Bt(e){return"string"==typeof e?Yt(e):qt(e)}Yt=Uint8Array.fromBase64?e=>{try{return Uint8Array.fromBase64(e,{alphabet:"base64url"})}catch(e){throw Lt("The input to be decoded is not correctly encoded.",Kt,e)}}:e=>{try{const t=atob(e.replace(/-/g,"+").replace(/_/g,"/").replace(/\s/g,"")),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}catch(e){throw Lt("The input to be decoded is not correctly encoded.",Kt,e)}};class Qt extends Error{constructor(e,t){var n;super(e,t),p(this,"code",void 0),this.name=this.constructor.name,this.code=so,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class $t extends Error{constructor(e,t){var n;super(e,t),p(this,"code",void 0),this.name=this.constructor.name,null!=t&&t.code&&(this.code=null==t?void 0:t.code),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function en(e,t,n){return new $t(e,{code:t,cause:n})}function tn(e,t){if(function(e,t){if(!(e instanceof CryptoKey))throw Lt("".concat(t," must be a CryptoKey"),Ut)}(e,t),"private"!==e.type)throw Lt("".concat(t," must be a private CryptoKey"),Kt)}function nn(e){return null!==e&&"object"==typeof e&&!Array.isArray(e)}function on(e){Nt(e,Headers)&&(e=Object.fromEntries(e.entries()));const t=new Headers(null!=e?e:{});if(Mt&&!t.has("user-agent")&&t.set("user-agent",Mt),t.has("authorization"))throw Lt('"options.headers" must not include the "authorization" header name',Kt);return t}function rn(e,t){if(void 0!==t){if("function"==typeof t&&(t=t(e.href)),!(t instanceof AbortSignal))throw Lt('"options.signal" must return or be an instance of AbortSignal',Ut);return t}}function sn(e){return e.includes("//")?e.replace("//","/"):e}async function an(e,t){return async function(e,t,n,o){if(!(e instanceof URL))throw Lt('"'.concat(t,'" must be an instance of URL'),Ut);_n(e,!0!==(null==o?void 0:o[zt]));const i=n(new URL(e.href)),r=on(null==o?void 0:o.headers);return r.set("accept","application/json"),((null==o?void 0:o[Zt])||fetch)(i.href,{body:void 0,headers:Object.fromEntries(r.entries()),method:"GET",redirect:"manual",signal:rn(i,null==o?void 0:o.signal)})}(e,"issuerIdentifier",e=>{switch(null==t?void 0:t.algorithm){case void 0:case"oidc":!function(e,t){e.pathname=sn("".concat(e.pathname,"/").concat(t))}(e,".well-known/openid-configuration");break;case"oauth2":!function(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];"/"===e.pathname?e.pathname=t:e.pathname=sn("".concat(t,"/").concat(n?e.pathname:e.pathname.replace(/(\/)$/,"")))}(e,".well-known/oauth-authorization-server");break;default:throw Lt('"options.algorithm" must be "oidc" (default), or "oauth2"',Kt)}return e},t)}function cn(e,t,n,o,i){try{if("number"!=typeof e||!Number.isFinite(e))throw Lt("".concat(n," must be a number"),Ut,i);if(e>0)return;if(t){if(0!==e)throw Lt("".concat(n," must be a non-negative number"),Kt,i);return}throw Lt("".concat(n," must be a positive number"),Kt,i)}catch(e){if(o)throw en(e.message,o,i);throw e}}function un(e,t,n,o){try{if("string"!=typeof e)throw Lt("".concat(t," must be a string"),Ut,o);if(0===e.length)throw Lt("".concat(t," must not be empty"),Kt,o)}catch(e){if(n)throw en(e.message,n,o);throw e}}function ln(e){!function(e,t){if(Un(e)!==t)throw function(e){let t='"response" content-type must be ';for(var n=arguments.length,o=new Array(n>1?n-1:0),i=1;i<n;i++)o[i-1]=arguments[i];if(o.length>2){const e=o.pop();t+="".concat(o.join(", "),", or ").concat(e)}else 2===o.length?t+="".concat(o[0]," or ").concat(o[1]):t+=o[0];return en(t,ho,e)}(e,t)}(e,"application/json")}function dn(){return Bt(crypto.getRandomValues(new Uint8Array(32)))}function hn(e){switch(e.algorithm.name){case"RSA-PSS":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"PS256";case"SHA-384":return"PS384";case"SHA-512":return"PS512";default:throw new Qt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"RSASSA-PKCS1-v1_5":return function(e){switch(e.algorithm.hash.name){case"SHA-256":return"RS256";case"SHA-384":return"RS384";case"SHA-512":return"RS512";default:throw new Qt("unsupported RsaHashedKeyAlgorithm hash name",{cause:e})}}(e);case"ECDSA":return function(e){switch(e.algorithm.namedCurve){case"P-256":return"ES256";case"P-384":return"ES384";case"P-521":return"ES512";default:throw new Qt("unsupported EcKeyAlgorithm namedCurve",{cause:e})}}(e);case"Ed25519":case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":return e.algorithm.name;case"EdDSA":return"Ed25519";default:throw new Qt("unsupported CryptoKey algorithm name",{cause:e})}}function pn(e){const t=null==e?void 0:e[Jt];return"number"==typeof t&&Number.isFinite(t)?t:0}function fn(e){const t=null==e?void 0:e[Dt];return"number"==typeof t&&Number.isFinite(t)&&-1!==Math.sign(t)?t:30}function mn(){return Math.floor(Date.now()/1e3)}function yn(e){if("object"!=typeof e||null===e)throw Lt('"as" must be an object',Ut);un(e.issuer,'"as.issuer"')}function wn(e){if("object"!=typeof e||null===e)throw Lt('"client" must be an object',Ut);un(e.client_id,'"client.client_id"')}function gn(e){return un(e,'"clientSecret"'),(t,n,o,i)=>{o.set("client_id",n.client_id),o.set("client_secret",e)}}function vn(e,t){const n=(r=e)instanceof CryptoKey?{key:r}:(null==r?void 0:r.key)instanceof CryptoKey?(void 0!==r.kid&&un(r.kid,'"kid"'),{key:r.key,kid:r.kid}):{},o=n.key,i=n.kid;var r;return tn(o,'"clientPrivateKey.key"'),async(e,n,r,s)=>{var a;const c={alg:hn(o),kid:i},u=function(e,t){const n=mn()+pn(t);return{jti:dn(),aud:e.issuer,exp:n+60,iat:n,nbf:n,iss:t.client_id,sub:t.client_id}}(e,n);null==t||null===(a=t[Ht])||void 0===a||a.call(t,c,u),r.set("client_id",n.client_id),r.set("client_assertion_type","urn:ietf:params:oauth:client-assertion-type:jwt-bearer"),r.set("client_assertion",await async function(e,t,n){if(!n.usages.includes("sign"))throw Lt('CryptoKey instances used for signing assertions must include "sign" in their "usages"',Kt);const o="".concat(Bt(Xt(JSON.stringify(e))),".").concat(Bt(Xt(JSON.stringify(t)))),i=Bt(await crypto.subtle.sign(function(e){switch(e.algorithm.name){case"ECDSA":return{name:e.algorithm.name,hash:To(e)};case"RSA-PSS":switch(So(e),e.algorithm.hash.name){case"SHA-256":case"SHA-384":case"SHA-512":return{name:e.algorithm.name,saltLength:parseInt(e.algorithm.hash.name.slice(-3),10)>>3};default:throw new Qt("unsupported RSA-PSS hash name",{cause:e})}case"RSASSA-PKCS1-v1_5":return So(e),e.algorithm.name;case"ML-DSA-44":case"ML-DSA-65":case"ML-DSA-87":case"Ed25519":return e.algorithm.name}throw new Qt("unsupported CryptoKey algorithm name",{cause:e})}(n),n,Xt(o)));return"".concat(o,".").concat(i)}(c,u,o))}}const bn=URL.parse?(e,t)=>URL.parse(e,t):(e,t)=>{try{return new URL(e,t)}catch(e){return null}};function _n(e,t){if(t&&"https:"!==e.protocol)throw en("only requests to HTTPS are allowed",fo,e);if("https:"!==e.protocol&&"http:"!==e.protocol)throw en("only HTTP and HTTPS requests are allowed",mo,e)}function kn(e,t,n,o){let i;if("string"!=typeof e||!(i=bn(e)))throw en("authorization server metadata does not contain a valid ".concat(n?'"as.mtls_endpoint_aliases.'.concat(t,'"'):'"as.'.concat(t,'"')),void 0===e?vo:bo,{attribute:n?"mtls_endpoint_aliases.".concat(t):t});return _n(i,o),i}function Sn(e,t,n,o){return n&&e.mtls_endpoint_aliases&&t in e.mtls_endpoint_aliases?kn(e.mtls_endpoint_aliases[t],t,n,o):kn(e[t],t,n,o)}class Tn extends Error{constructor(e,t){var n;super(e,t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"error",void 0),p(this,"status",void 0),p(this,"error_description",void 0),p(this,"response",void 0),this.name=this.constructor.name,this.code=ro,this.cause=t.cause,this.error=t.cause.error,this.status=t.response.status,this.error_description=t.cause.error_description,Object.defineProperty(this,"response",{enumerable:!1,value:t.response}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}class En extends Error{constructor(e,t){var n,o;super(e,t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"error",void 0),p(this,"error_description",void 0),this.name=this.constructor.name,this.code=ao,this.cause=t.cause,this.error=t.cause.get("error"),this.error_description=null!==(n=t.cause.get("error_description"))&&void 0!==n?n:void 0,null===(o=Error.captureStackTrace)||void 0===o||o.call(Error,this,this.constructor)}}class Pn extends Error{constructor(e,t){var n;super(e,t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"response",void 0),p(this,"status",void 0),this.name=this.constructor.name,this.code=io,this.cause=t.cause,this.status=t.response.status,this.response=t.response,Object.defineProperty(this,"response",{enumerable:!1}),null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}const Cn="[a-zA-Z0-9!#$%&\\'\\*\\+\\-\\.\\^_`\\|~]+",An="("+Cn+')\\s*=\\s*"((?:[^"\\\\]|\\\\[\\s\\S])*)"',Rn="("+Cn+")\\s*=\\s*("+Cn+")",xn=new RegExp("^[,\\s]*("+Cn+")"),In=new RegExp("^[,\\s]*"+An+"[,\\s]*(.*)"),On=new RegExp("^[,\\s]*"+Rn+"[,\\s]*(.*)"),jn=new RegExp("^([a-zA-Z0-9\\-\\._\\~\\+\\/]+={0,2})(?:$|[,\\s])(.*)");async function Wn(e,t,n){if(e.status!==t){let t;var o;if(Vn(e),t=await async function(e){if(e.status>399&&e.status<500){ko(e),ln(e);try{const t=await e.clone().json();if(nn(t)&&"string"==typeof t.error&&t.error.length)return t}catch(e){}}}(e))throw await(null===(o=e.body)||void 0===o?void 0:o.cancel()),new Tn("server responded with an error in the response body",{cause:t,response:e});throw en('"response" is not a conform '.concat(n," response (unexpected HTTP status code)"),po,e)}}function Mn(e){if(!Bn.has(e))throw Lt('"options.DPoP" is not a valid DPoPHandle',Kt)}async function Nn(e,t,n,o){yn(e),wn(t);const i=Sn(e,"userinfo_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==o?void 0:o[zt])),r=on(null==o?void 0:o.headers);return t.userinfo_signed_response_alg?r.set("accept","application/jwt"):(r.set("accept","application/json"),r.append("accept","application/jwt")),async function(e,t,n,o,i,r){var s;if(un(e,'"accessToken"'),!(n instanceof URL))throw Lt('"url" must be an instance of URL',Ut);_n(n,!0!==(null==r?void 0:r[zt])),o=on(o),null!=r&&r.DPoP&&(Mn(r.DPoP),await r.DPoP.addProof(n,o,t.toUpperCase(),e)),o.set("authorization","".concat(o.has("dpop")?"DPoP":"Bearer"," ").concat(e));const a=await((null==r?void 0:r[Zt])||fetch)(n.href,{duplex:Nt(i,ReadableStream)?"half":void 0,body:i,headers:Object.fromEntries(o.entries()),method:t,redirect:"manual",signal:rn(n,null==r?void 0:r.signal)});return null==r||null===(s=r.DPoP)||void 0===s||s.cacheNonce(a,n),a}(n,"GET",i,r,null,m(m({},o),{},{[Jt]:pn(t)}))}const Kn=Symbol();function Un(e){var t;return null===(t=e.headers.get("content-type"))||void 0===t?void 0:t.split(";")[0]}async function Ln(e,t,n,o,i){if(yn(e),wn(t),!Nt(o,Response))throw Lt('"response" must be an instance of Response',Ut);if(Vn(o),200!==o.status)throw en('"response" is not a conform UserInfo Endpoint response (unexpected HTTP status code)',po,o);let r;if(ko(o),"application/jwt"===Un(o)){const n=await Eo(await o.text(),Co.bind(void 0,t.userinfo_signed_response_alg,e.userinfo_signing_alg_values_supported,void 0),pn(t),fn(t),null==i?void 0:i[Ft]).then(Gn.bind(void 0,t.client_id)).then(qn.bind(void 0,e)),s=n.claims,a=n.jwt;Zn.set(o,a),r=s}else{if(t.userinfo_signed_response_alg)throw en("JWT UserInfo Response expected",co,o);r=await Oo(o)}if(un(r.sub,'"response" body "sub" property',lo,{body:r}),n===Kn);else if(un(n,'"expectedSubject"'),r.sub!==n)throw en('unexpected "response" body "sub" property value',go,{expected:n,body:r,attribute:"sub"});return r}async function zn(e,t,n,o,i,r,s){return await n(e,t,i,r),r.set("content-type","application/x-www-form-urlencoded;charset=UTF-8"),((null==s?void 0:s[Zt])||fetch)(o.href,{body:i,headers:Object.fromEntries(r.entries()),method:"POST",redirect:"manual",signal:rn(o,null==s?void 0:s.signal)})}async function Jn(e,t,n,o,i,r){var s;const a=Sn(e,"token_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==r?void 0:r[zt]));i.set("grant_type",o);const c=on(null==r?void 0:r.headers);c.set("accept","application/json"),void 0!==(null==r?void 0:r.DPoP)&&(Mn(r.DPoP),await r.DPoP.addProof(a,c,"POST"));const u=await zn(e,t,n,a,i,c,r);return null==r||null===(s=r.DPoP)||void 0===s||s.cacheNonce(u,a),u}const Dn=new WeakMap,Zn=new WeakMap;function Hn(e){if(!e.id_token)return;const t=Dn.get(e);if(!t)throw Lt('"ref" was already garbage collected or did not resolve from the proper sources',Kt);return t}async function Fn(e,t,n,o,i,r){if(yn(e),wn(t),!Nt(n,Response))throw Lt('"response" must be an instance of Response',Ut);await Wn(n,200,"Token Endpoint"),ko(n);const s=await Oo(n);if(un(s.access_token,'"response" body "access_token" property',lo,{body:s}),un(s.token_type,'"response" body "token_type" property',lo,{body:s}),s.token_type=s.token_type.toLowerCase(),void 0!==s.expires_in){let e="number"!=typeof s.expires_in?parseFloat(s.expires_in):s.expires_in;cn(e,!0,'"response" body "expires_in" property',lo,{body:s}),s.expires_in=e}if(void 0!==s.refresh_token&&un(s.refresh_token,'"response" body "refresh_token" property',lo,{body:s}),void 0!==s.scope&&"string"!=typeof s.scope)throw en('"response" body "scope" property must be a string',lo,{body:s});if(void 0!==s.id_token){un(s.id_token,'"response" body "id_token" property',lo,{body:s});const r=["aud","exp","iat","iss","sub"];!0===t.require_auth_time&&r.push("auth_time"),void 0!==t.default_max_age&&(cn(t.default_max_age,!0,'"client.default_max_age"'),r.push("auth_time")),null!=o&&o.length&&r.push(...o);const a=await Eo(s.id_token,Co.bind(void 0,t.id_token_signed_response_alg,e.id_token_signing_alg_values_supported,"RS256"),pn(t),fn(t),i).then(eo.bind(void 0,r)).then(Yn.bind(void 0,e)).then(Xn.bind(void 0,t.client_id)),c=a.claims,u=a.jwt;if(Array.isArray(c.aud)&&1!==c.aud.length){if(void 0===c.azp)throw en('ID Token "aud" (audience) claim includes additional untrusted audiences',wo,{claims:c,claim:"aud"});if(c.azp!==t.client_id)throw en('unexpected ID Token "azp" (authorized party) claim value',wo,{expected:t.client_id,claims:c,claim:"azp"})}void 0!==c.auth_time&&cn(c.auth_time,!0,'ID Token "auth_time" (authentication time)',lo,{claims:c}),Zn.set(n,u),Dn.set(s,c)}if(void 0!==(null==r?void 0:r[s.token_type]))r[s.token_type](n,s);else if("dpop"!==s.token_type&&"bearer"!==s.token_type)throw new Qt("unsupported `token_type` value",{cause:{body:s}});return s}function Vn(e){let t;if(t=function(e){if(!Nt(e,Response))throw Lt('"response" must be an instance of Response',Ut);const t=e.headers.get("www-authenticate");if(null===t)return;const n=[];let o=t;for(;o;){var i;let e=o.match(xn);const t=null===(i=e)||void 0===i?void 0:i[1].toLowerCase();if(!t)return;const c=o.substring(e[0].length);if(c&&!c.match(/^[\s,]/))return;const u=c.match(/^\s+(.*)$/),l=!!u;o=u?u[1]:void 0;const d={};let h;if(l)for(;o;){let t,n;if(e=o.match(In)){var r=w(e,4);if(t=r[1],n=r[2],o=r[3],n.includes("\\"))try{n=JSON.parse('"'.concat(n,'"'))}catch(e){}d[t.toLowerCase()]=n}else{if(!(e=o.match(On))){if(e=o.match(jn)){if(Object.keys(d).length)break;var s=w(e,3);h=s[1],o=s[2];break}return}var a=w(e,4);t=a[1],n=a[2],o=a[3],d[t.toLowerCase()]=n}}else o=c||void 0;const p={scheme:t,parameters:d};h&&(p.token68=h),n.push(p)}return n.length?n:void 0}(e))throw new Pn("server responded with a challenge in the WWW-Authenticate HTTP Header",{cause:t,response:e})}function Gn(e,t){return void 0!==t.claims.aud?Xn(e,t):t}function Xn(e,t){if(Array.isArray(t.claims.aud)){if(!t.claims.aud.includes(e))throw en('unexpected JWT "aud" (audience) claim value',wo,{expected:e,claims:t.claims,claim:"aud"})}else if(t.claims.aud!==e)throw en('unexpected JWT "aud" (audience) claim value',wo,{expected:e,claims:t.claims,claim:"aud"});return t}function qn(e,t){return void 0!==t.claims.iss?Yn(e,t):t}function Yn(e,t){var n,o;const i=null!==(n=null===(o=e[Wo])||void 0===o?void 0:o.call(e,t))&&void 0!==n?n:e.issuer;if(t.claims.iss!==i)throw en('unexpected JWT "iss" (issuer) claim value',wo,{expected:i,claims:t.claims,claim:"iss"});return t}const Bn=new WeakSet;const Qn=Symbol();const $n={aud:"audience",c_hash:"code hash",client_id:"client id",exp:"expiration time",iat:"issued at",iss:"issuer",jti:"jwt id",nonce:"nonce",s_hash:"state hash",sub:"subject",ath:"access token hash",htm:"http method",htu:"http uri",cnf:"confirmation",auth_time:"authentication time"};function eo(e,t){for(const n of e)if(void 0===t.claims[n])throw en('JWT "'.concat(n,'" (').concat($n[n],") claim missing"),lo,{claims:t.claims});return t}const to=Symbol(),no=Symbol();async function oo(e,t,n,o){return"string"==typeof(null==o?void 0:o.expectedNonce)||"number"==typeof(null==o?void 0:o.maxAge)||null!=o&&o.requireIdToken?async function(e,t,n,o,i,r,s){const a=[];switch(o){case void 0:o=to;break;case to:break;default:un(o,'"expectedNonce" argument'),a.push("nonce")}switch(null!=i||(i=t.default_max_age),i){case void 0:i=no;break;case no:break;default:cn(i,!0,'"maxAge" argument'),a.push("auth_time")}const c=await Fn(e,t,n,a,r,s);un(c.id_token,'"response" body "id_token" property',lo,{body:c});const u=Hn(c);if(i!==no){const e=mn()+pn(t),n=fn(t);if(u.auth_time+i<e-n)throw en("too much time has elapsed since the last End-User authentication",yo,{claims:u,now:e,tolerance:n,claim:"auth_time"})}if(o===to){if(void 0!==u.nonce)throw en('unexpected ID Token "nonce" claim value',wo,{expected:void 0,claims:u,claim:"nonce"})}else if(u.nonce!==o)throw en('unexpected ID Token "nonce" claim value',wo,{expected:o,claims:u,claim:"nonce"});return c}(e,t,n,o.expectedNonce,o.maxAge,o[Ft],o.recognizedTokenTypes):async function(e,t,n,o,i){const r=await Fn(e,t,n,void 0,o,i),s=Hn(r);if(s){if(void 0!==t.default_max_age){cn(t.default_max_age,!0,'"client.default_max_age"');const e=mn()+pn(t),n=fn(t);if(s.auth_time+t.default_max_age<e-n)throw en("too much time has elapsed since the last End-User authentication",yo,{claims:s,now:e,tolerance:n,claim:"auth_time"})}if(void 0!==s.nonce)throw en('unexpected ID Token "nonce" claim value',wo,{expected:void 0,claims:s,claim:"nonce"})}return r}(e,t,n,null==o?void 0:o[Ft],null==o?void 0:o.recognizedTokenTypes)}const io="OAUTH_WWW_AUTHENTICATE_CHALLENGE",ro="OAUTH_RESPONSE_BODY_ERROR",so="OAUTH_UNSUPPORTED_OPERATION",ao="OAUTH_AUTHORIZATION_RESPONSE_ERROR",co="OAUTH_JWT_USERINFO_EXPECTED",uo="OAUTH_PARSE_ERROR",lo="OAUTH_INVALID_RESPONSE",ho="OAUTH_RESPONSE_IS_NOT_JSON",po="OAUTH_RESPONSE_IS_NOT_CONFORM",fo="OAUTH_HTTP_REQUEST_FORBIDDEN",mo="OAUTH_REQUEST_PROTOCOL_FORBIDDEN",yo="OAUTH_JWT_TIMESTAMP_CHECK_FAILED",wo="OAUTH_JWT_CLAIM_COMPARISON_FAILED",go="OAUTH_JSON_ATTRIBUTE_COMPARISON_FAILED",vo="OAUTH_MISSING_SERVER_METADATA",bo="OAUTH_INVALID_SERVER_METADATA";async function _o(e){if(!Nt(e,Response))throw Lt('"response" must be an instance of Response',Ut);await Wn(e,200,"Revocation Endpoint")}function ko(e){if(e.bodyUsed)throw Lt('"response" body has been used already',Kt)}function So(e){const t=e.algorithm;if("number"!=typeof t.modulusLength||t.modulusLength<2048)throw new Qt("unsupported ".concat(t.name," modulusLength"),{cause:e})}function To(e){switch(e.algorithm.namedCurve){case"P-256":return"SHA-256";case"P-384":return"SHA-384";case"P-521":return"SHA-512";default:throw new Qt("unsupported ECDSA namedCurve",{cause:e})}}async function Eo(e,t,n,o,i){let r,s,a=e.split("."),c=a[0],u=a[1],l=a.length;if(5===l){if(void 0===i)throw new Qt("JWE decryption is not configured",{cause:e});var d=(e=await i(e)).split(".");c=d[0],u=d[1],l=d.length}if(3!==l)throw en("Invalid JWT",lo,e);try{r=JSON.parse(Xt(Bt(c)))}catch(e){throw en("failed to parse JWT Header body as base64url encoded JSON",uo,e)}if(!nn(r))throw en("JWT Header must be a top level object",lo,e);if(t(r),void 0!==r.crit)throw new Qt('no JWT "crit" header parameter extensions are supported',{cause:{header:r}});try{s=JSON.parse(Xt(Bt(u)))}catch(e){throw en("failed to parse JWT Payload body as base64url encoded JSON",uo,e)}if(!nn(s))throw en("JWT Payload must be a top level object",lo,e);const h=mn()+n;if(void 0!==s.exp){if("number"!=typeof s.exp)throw en('unexpected JWT "exp" (expiration time) claim type',lo,{claims:s});if(s.exp<=h-o)throw en('unexpected JWT "exp" (expiration time) claim value, expiration is past current timestamp',yo,{claims:s,now:h,tolerance:o,claim:"exp"})}if(void 0!==s.iat&&"number"!=typeof s.iat)throw en('unexpected JWT "iat" (issued at) claim type',lo,{claims:s});if(void 0!==s.iss&&"string"!=typeof s.iss)throw en('unexpected JWT "iss" (issuer) claim type',lo,{claims:s});if(void 0!==s.nbf){if("number"!=typeof s.nbf)throw en('unexpected JWT "nbf" (not before) claim type',lo,{claims:s});if(s.nbf>h+o)throw en('unexpected JWT "nbf" (not before) claim value',yo,{claims:s,now:h,tolerance:o,claim:"nbf"})}if(void 0!==s.aud&&"string"!=typeof s.aud&&!Array.isArray(s.aud))throw en('unexpected JWT "aud" (audience) claim type',lo,{claims:s});return{header:r,claims:s,jwt:e}}async function Po(e){if("POST"!==e.method)throw Lt("form_post responses are expected to use the POST method",Kt,{cause:e});if("application/x-www-form-urlencoded"!==Un(e))throw Lt("form_post responses are expected to use the application/x-www-form-urlencoded content-type",Kt,{cause:e});return async function(e){if(e.bodyUsed)throw Lt("form_post Request instances must contain a readable body",Kt,{cause:e});return e.text()}(e)}function Co(e,t,n,o){if(void 0===e)if(Array.isArray(t)){if(!t.includes(o.alg))throw en('unexpected JWT "alg" header parameter',lo,{header:o,expected:t,reason:"authorization server metadata"})}else{if(void 0===n)throw en('missing client or server configuration to verify used JWT "alg" header parameter',void 0,{client:e,issuer:t,fallback:n});if("string"==typeof n?o.alg!==n:"function"==typeof n?!n(o.alg):!n.includes(o.alg))throw en('unexpected JWT "alg" header parameter',lo,{header:o,expected:n,reason:"default value"})}else if("string"==typeof e?o.alg!==e:!e.includes(o.alg))throw en('unexpected JWT "alg" header parameter',lo,{header:o,expected:e,reason:"client configuration"})}function Ao(e,t){const n=e.getAll(t),o=n[0];if(n.length>1)throw en('"'.concat(t,'" parameter must be provided only once'),lo);return o}const Ro=Symbol(),xo=Symbol();function Io(e,t,n,o){if(yn(e),wn(t),n instanceof URL&&(n=n.searchParams),!(n instanceof URLSearchParams))throw Lt('"parameters" must be an instance of URLSearchParams, or URL',Ut);if(Ao(n,"response"))throw en('"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()',lo,{parameters:n});const i=Ao(n,"iss"),r=Ao(n,"state");if(!i&&e.authorization_response_iss_parameter_supported)throw en('response parameter "iss" (issuer) missing',lo,{parameters:n});if(i&&i!==e.issuer)throw en('unexpected "iss" (issuer) response parameter value',lo,{expected:e.issuer,parameters:n});switch(o){case void 0:case xo:if(void 0!==r)throw en('unexpected "state" response parameter encountered',lo,{expected:void 0,parameters:n});break;case Ro:break;default:if(un(o,'"expectedState" argument'),r!==o)throw en(void 0===r?'response parameter "state" missing':'unexpected "state" response parameter value',lo,{expected:o,parameters:n})}if(Ao(n,"error"))throw new En("authorization response from the server is an error",{cause:n});const s=Ao(n,"id_token"),a=Ao(n,"token");if(void 0!==s||void 0!==a)throw new Qt("implicit and hybrid flows are not supported");return c=new URLSearchParams(n),Bn.add(c),c;var c}async function Oo(e){let t,n=arguments.length>1&&void 0!==arguments[1]?arguments[1]:ln;try{t=await e.json()}catch(t){throw n(e),en('failed to parse "response" body as JSON',uo,t)}if(!nn(t))throw en('"response" body must be a top level object',lo,{body:t});return t}const jo=Symbol(),Wo=Symbol(),Mo=new TextEncoder,No=new TextDecoder,Ko=new TextDecoder("utf-8",{fatal:!0});function Uo(){for(var e=arguments.length,t=new Array(e),n=0;n<e;n++)t[n]=arguments[n];const o=t.reduce((e,t)=>e+t.length,0),i=new Uint8Array(o);let r=0;for(const e of t)i.set(e,r),r+=e.length;return i}function Lo(e){const t=new Uint8Array(e.length);for(let n=0;n<e.length;n++){const o=e.charCodeAt(n);if(o>127)throw new TypeError("non-ASCII string encountered in encode()");t[n]=o}return t}const zo=function(e){return new TypeError("CryptoKey does not support this operation, its ".concat(arguments.length>1&&void 0!==arguments[1]?arguments[1]:"algorithm.name"," must be ").concat(e))};function Jo(e,t,n){var o;const i=e.algorithm;if(i.name!==t.name)throw zo(t.name);if(t.hash&&(null===(o=i.hash)||void 0===o?void 0:o.name)!==t.hash)throw zo(t.hash,"algorithm.hash");if(t.namedCurve&&i.namedCurve!==t.namedCurve)throw zo(t.namedCurve,"algorithm.namedCurve");if(void 0!==t.length&&i.length!==t.length)throw zo(t.length,"algorithm.length");!function(e,t){if(t&&!e.usages.includes(t))throw new TypeError("CryptoKey does not support this operation, its usages must include ".concat(t,"."))}(e,n)}const Do=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];return function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];if(o.length>2){const t=o.pop();e+="one of type ".concat(o.join(", "),", or ").concat(t,".")}else 2===o.length?e+="one of type ".concat(o[0]," or ").concat(o[1],"."):e+="of type ".concat(o[0],".");if(null==t)e+=" Received ".concat(t);else if("function"==typeof t&&t.name)e+=" Received function ".concat(t.name);else if("object"==typeof t&&null!=t){var r;null!==(r=t.constructor)&&void 0!==r&&r.name&&(e+=" Received an instance of ".concat(t.constructor.name))}return e}("Key for the ".concat(e," algorithm must be "),t,...o)};class Zo extends Error{constructor(e,t){var n;super(e,t),p(this,"code","ERR_JOSE_GENERIC"),this.name=this.constructor.name,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}p(Zo,"code","ERR_JOSE_GENERIC");class Ho extends Zo{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),p(this,"code","ERR_JWT_CLAIM_VALIDATION_FAILED"),p(this,"claim",void 0),p(this,"reason",void 0),p(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}p(Ho,"code","ERR_JWT_CLAIM_VALIDATION_FAILED");class Fo extends Zo{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"unspecified",o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:"unspecified";super(e,{cause:{claim:n,reason:o,payload:t}}),p(this,"code","ERR_JWT_EXPIRED"),p(this,"claim",void 0),p(this,"reason",void 0),p(this,"payload",void 0),this.claim=n,this.reason=o,this.payload=t}}p(Fo,"code","ERR_JWT_EXPIRED");class Vo extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JOSE_ALG_NOT_ALLOWED")}}p(Vo,"code","ERR_JOSE_ALG_NOT_ALLOWED");class Go extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JOSE_NOT_SUPPORTED")}}p(Go,"code","ERR_JOSE_NOT_SUPPORTED");p(class extends Zo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"decryption operation failed",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWE_DECRYPTION_FAILED")}},"code","ERR_JWE_DECRYPTION_FAILED");p(class extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JWE_INVALID")}},"code","ERR_JWE_INVALID");class Xo extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JWS_INVALID")}}p(Xo,"code","ERR_JWS_INVALID");class qo extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JWT_INVALID")}}p(qo,"code","ERR_JWT_INVALID");p(class extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JWK_INVALID")}},"code","ERR_JWK_INVALID");class Yo extends Zo{constructor(){super(...arguments),p(this,"code","ERR_JWKS_INVALID")}}p(Yo,"code","ERR_JWKS_INVALID");class Bo extends Zo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"no applicable key found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWKS_NO_MATCHING_KEY")}}p(Bo,"code","ERR_JWKS_NO_MATCHING_KEY");class Qo extends Zo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"multiple matching keys found in the JSON Web Key Set",arguments.length>1?arguments[1]:void 0),p(this,Symbol.asyncIterator,g(function*(){})),p(this,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS")}}p(Qo,"code","ERR_JWKS_MULTIPLE_MATCHING_KEYS");class $o extends Zo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"request timed out",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWKS_TIMEOUT")}}p($o,"code","ERR_JWKS_TIMEOUT");class ei extends Zo{constructor(){super(arguments.length>0&&void 0!==arguments[0]?arguments[0]:"signature verification failed",arguments.length>1?arguments[1]:void 0),p(this,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED")}}p(ei,"code","ERR_JWS_SIGNATURE_VERIFICATION_FAILED");const ti=e=>{if("CryptoKey"===(null==e?void 0:e[Symbol.toStringTag]))return!0;try{return e instanceof CryptoKey}catch(e){return!1}},ni=e=>ti(e)||(e=>"KeyObject"===(null==e?void 0:e[Symbol.toStringTag]))(e);function oi(e){if(Uint8Array.fromBase64)return Uint8Array.fromBase64(e);const t=atob(e),n=new Uint8Array(t.length);for(let e=0;e<t.length;e++)n[e]=t.charCodeAt(e);return n}const ii="The input to be decoded is not correctly encoded.";function ri(e){if(Uint8Array.fromBase64)try{return Uint8Array.fromBase64("string"==typeof e?e:No.decode(e),{alphabet:"base64url"})}catch(e){throw new TypeError(ii,{cause:e})}let t=e;if(t instanceof Uint8Array&&(t=No.decode(t)),t.includes("+")||t.includes("/"))throw new TypeError(ii);t=t.replace(/-/g,"+").replace(/_/g,"/");try{return oi(t)}catch(e){throw new TypeError(ii)}}function si(e){let t=e;return"string"==typeof t&&(t=Mo.encode(t)),Uint8Array.prototype.toBase64?t.toBase64({alphabet:"base64url",omitPadding:!0}):function(e){if(Uint8Array.prototype.toBase64)return e.toBase64();const t=[];for(let n=0;n<e.length;n+=32768)t.push(String.fromCharCode.apply(null,e.subarray(n,n+32768)));return btoa(t.join(""))}(t).replace(/=/g,"").replace(/\+/g,"-").replace(/\//g,"_")}function ai(e){if("object"!=typeof e||null===e||"[object Object]"!==Object.prototype.toString.call(e))return!1;const t=Object.getPrototypeOf(e);return null===t||null===Object.getPrototypeOf(t)}function ci(e){return ai(e)&&Array.isArray(e.keys)&&Array.from(e.keys).every(ai)}function ui(e,t,n){try{return ri(e)}catch(e){throw new n("Failed to base64url decode the ".concat(t))}}async function li(e,t){var n,o,i,r;if("RSA"===t.kty&&"oth"in t&&void 0!==t.oth)throw new Go('RSA JWK "oth" (Other Primes Info) Parameter value is not supported');if(!e.kty.includes(t.kty))throw new Go('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');const s=null!==(n=null===(o=e.resolve)||void 0===o?void 0:o.call(e,{kty:t.kty,crv:t.crv}))&&void 0!==n?n:e.subtle,a=!(!t.d&&!t.priv),c=m({},t);return"AKP"!==c.kty&&delete c.alg,delete c.use,crypto.subtle.importKey("jwk",c,s,null!==(i=t.ext)&&void 0!==i?i:!a,null!==(r=t.key_ops)&&void 0!==r?r:e.usages[a?1:0])}function di(e){return m({__proto__:null},e)}const hi=e=>e[Symbol.toStringTag];function pi(e,t,n){const o=e.alg,i=e.secret,r="decrypt"===n||"sign"===n;if(i&&t instanceof Uint8Array)return[fi,t];if(ai(t)){const s=function(e){const t=di(e);if(void 0!==t.ext&&"boolean"!=typeof t.ext)throw new TypeError('"ext" (Extractable) Parameter must be a boolean');if(void 0!==t.key_ops){const e=t.key_ops,n=Array.isArray(e)?[...e]:void 0;if(!n||n.some(e=>"string"!=typeof e)||new Set(n).size!==n.length)throw new TypeError('"key_ops" (Key Operations) Parameter must be an array of unique strings');t.key_ops=n}return t}(t);if("string"!=typeof s.kty)throw new TypeError(i?Do(o,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"):Do(o,t,"CryptoKey","KeyObject","JSON Web Key"));if(!(i?"oct"===s.kty&&"string"==typeof s.k:"oct"!==s.kty&&(r?"AKP"===s.kty&&"string"==typeof s.priv||"string"==typeof s.d:void 0===s.d&&void 0===s.priv)))throw new TypeError(i?'JSON Web Key for symmetric algorithms must have JWK "kty" (Key Type) equal to "oct" and the JWK "k" (Key Value) present':"JSON Web Key for this operation must be a ".concat(r?"private":"public"," JWK"));return((e,t,n)=>{const o=e.alg;if(void 0!==t.use){const e="sign"===n||"verify"===n?"sig":"enc";if(t.use!==e)throw new TypeError('Invalid key for this operation, its "use" must be "'.concat(e,'" when present'))}if(void 0!==t.alg&&t.alg!==o)throw new TypeError('Invalid key for this operation, its "alg" must be "'.concat(o,'" when present'));if(Array.isArray(t.key_ops)){var i;const o="encrypt"===n||"decrypt"===n?null===(i=e.ops)||void 0===i?void 0:i["encrypt"===n?0:1]:n;if(o&&!t.key_ops.includes(o))throw new TypeError('Invalid key for this operation, its "key_ops" must include "'.concat(o,'" when present'))}})(e,s,n),[wi,t,s]}if(!ni(t))throw new TypeError(i?Do(o,t,"CryptoKey","KeyObject","JSON Web Key","Uint8Array"):Do(o,t,"CryptoKey","KeyObject","JSON Web Key"));if(i){if("secret"!==t.type)throw new TypeError("".concat(hi(t),' instances for symmetric algorithms must be of type "secret"'))}else{if("secret"===t.type)throw new TypeError("".concat(hi(t),' instances for asymmetric algorithms must not be of type "secret"'));const e=r?"private":"public";if(("public"===t.type||"private"===t.type)&&t.type!==e){const o="sign"===n?"signing":"verify"===n?"verifying":"".concat(n.slice(0,-1),"tion");throw new TypeError("".concat(hi(t)," instances for asymmetric algorithm ").concat(o,' must be of type "').concat(e,'"'))}}return ti(t)?[mi,t]:[yi,t]}const fi=0,mi=1,yi=2,wi=3;let gi;const vi={__proto__:null,prime256v1:"P-256",secp384r1:"P-384",secp521r1:"P-521"};function bi(e,t,n){gi||(gi=new WeakMap);const o=gi.get(e);return n&&(o?o[t]=n:gi.set(e,{[t]:n})),null!=n?n:null==o?void 0:o[t]}const _i=async(e,t,n)=>{var o;return null!==(o=bi(e,n.alg))&&void 0!==o?o:bi(e,n.alg,await li(n,m(m({},t),{},{alg:n.alg})))};async function ki(e,t,n){const o=pi(e,t,n);switch(o[0]){case fi:case mi:return o[1];case wi:{const t=o[1],n=o[2];if("oct"===n.kty)return ri(n.k);if(!Object.isFrozen(t)){const e=t.key_ops;Array.isArray(e)&&Object.freeze(e),Object.freeze(t)}return _i(t,n,e)}case yi:{const t=o[1];return"secret"===t.type?t.export():"toCryptoKey"in t&&"function"==typeof t.toCryptoKey?((e,t)=>{var n,o,i;const r=bi(e,t.alg);if(r)return r;const s="public"===e.type,a=t.usages[s?0:1],c=e.asymmetricKeyType,u=vi[null===(n=e.asymmetricKeyDetails)||void 0===n?void 0:n.namedCurve],l=null!==(o=null===(i=t.resolve)||void 0===i?void 0:i.call(t,{crv:u,asymmetricKeyType:c}))&&void 0!==o?o:t.subtle;return bi(e,t.alg,e.toCryptoKey(l,s,a))})(t,e):_i(t,t.export({format:"jwk"}),e)}}}function Si(e){const t={__proto__:null};for(const n in e)t[n]=m(m({},e[n]),{},{alg:n});return t}const Ti=[["encrypt","wrapKey"],["decrypt","unwrapKey"]],Ei=[[],["deriveBits"]],Pi=[[],[]];function Ci(e){return{kty:["RSA"],subtle:{name:"RSA-OAEP",hash:"SHA-".concat(e)},usages:Ti,ops:["wrapKey","unwrapKey"]}}function Ai(){return{kty:["EC","OKP"],subtle:{name:"ECDH"},resolve:e=>{let t=e.kty,n=e.crv,o=e.asymmetricKeyType;if("X25519"===n||"x25519"===o)return{name:"X25519"};if("OKP"===t)throw new Go('Invalid or unsupported JWK "alg" (Algorithm) Parameter value');return{name:"ECDH",namedCurve:n}},usages:Ei,ops:[void 0,"deriveBits"]}}function Ri(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return{kty:["oct"],secret:!0,subtle:{name:t?"AES-GCM":"AES-KW",length:e},usages:Pi,ops:t?["encrypt","decrypt"]:["wrapKey","unwrapKey"]}}function xi(){return{kty:["oct"],secret:!0,subtle:{name:"PBKDF2"},usages:Pi,ops:["deriveBits","deriveBits"]}}const Ii=Si({dir:{kty:["oct"],secret:!0,subtle:{name:"AES-GCM"},usages:Pi,ops:["encrypt","decrypt"]},"RSA-OAEP":Ci(1),"RSA-OAEP-256":Ci(256),"RSA-OAEP-384":Ci(384),"RSA-OAEP-512":Ci(512),"ECDH-ES":Ai(),"ECDH-ES+A128KW":Ai(),"ECDH-ES+A192KW":Ai(),"ECDH-ES+A256KW":Ai(),A128KW:Ri(128),A192KW:Ri(192),A256KW:Ri(256),A128GCMKW:Ri(128,!0),A192GCMKW:Ri(192,!0),A256GCMKW:Ri(256,!0),"PBES2-HS256+A128KW":xi(),"PBES2-HS384+A192KW":xi(),"PBES2-HS512+A256KW":xi()}),Oi=["encrypt","decrypt"];function ji(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];return{kty:["oct"],secret:!0,subtle:{name:t?"AES-CBC":"AES-GCM",length:e},usages:Pi,ops:Oi,cekBits:e,ivBits:t?128:96,cbc:t}}Si({A128GCM:ji(128),A192GCM:ji(192),A256GCM:ji(256),"A128CBC-HS256":ji(256,!0),"A192CBC-HS384":ji(384,!0),"A256CBC-HS512":ji(512,!0)});const Wi={__proto__:null,b64:!0};function Mi(e,t){if(void 0!==t&&(!Array.isArray(t)||t.some(e=>"string"!=typeof e)))throw new TypeError('"'.concat(e,'" option must be an array of strings'));if(t)return new Set(t)}function Ni(e,t,n,o,i){if(void 0!==i.crit&&void 0===(null==o?void 0:o.crit))throw new e('"crit" (Critical) Header Parameter MUST be integrity protected');if(!o||void 0===o.crit)return[];if(!Array.isArray(o.crit)||0===o.crit.length||o.crit.some(e=>"string"!=typeof e||0===e.length))throw new e('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');const r=void 0===n?t:m(m({__proto__:null},n),t);for(const t of o.crit){if(!(t in r))throw new Go('Extension Header Parameter "'.concat(t,'" is not recognized'));if(!Object.hasOwn(i,t)||void 0===i[t])throw new e('Extension Header Parameter "'.concat(t,'" is missing'));if(r[t]&&(!Object.hasOwn(o,t)||void 0===o[t]))throw new e('Extension Header Parameter "'.concat(t,'" MUST be integrity protected'))}return o.crit}function Ki(e,t){if(t.includes("b64")){const t=e.b64;if("boolean"!=typeof t)throw new Xo('The "b64" (base64url-encode payload) Header Parameter must be a boolean');return t}return!0}var Ui,Li;let zi,Ji;if("undefined"==typeof navigator||null===(Ui=navigator.userAgent)||void 0===Ui||null===(Li=Ui.startsWith)||void 0===Li||!Li.call(Ui,"Mozilla/5.0 ")){const e="v6.8.4";Ji="".concat("openid-client","/").concat(e),zi={"user-agent":Ji}}const Di=e=>Zi.get(e);let Zi,Hi;function Fi(e){return void 0!==e?gn(e):(Hi||(Hi=new WeakMap),(e,t,n,o)=>{let i;return(i=Hi.get(t))||(!function(e,t){if("string"!=typeof e)throw Yi("".concat(t," must be a string"),qi);if(0===e.length)throw Yi("".concat(t," must not be empty"),Xi)}(t.client_secret,'"metadata.client_secret"'),i=gn(t.client_secret),Hi.set(t,i)),i(e,t,n,o)})}const Vi=Kn,Gi=Zt,Xi="ERR_INVALID_ARG_VALUE",qi="ERR_INVALID_ARG_TYPE";function Yi(e,t,n){const o=new TypeError(e,{cause:n});return Object.assign(o,{code:t}),o}function Bi(e){return async function(e){return un(e,"codeVerifier"),Bt(await crypto.subtle.digest("SHA-256",Xt(e)))}(e)}function Qi(){return dn()}class $i extends Error{constructor(e,t){var n;super(e,t),p(this,"code",void 0),this.name=this.constructor.name,this.code=null==t?void 0:t.code,null===(n=Error.captureStackTrace)||void 0===n||n.call(Error,this,this.constructor)}}function er(e,t,n){return new $i(e,{cause:t,code:n})}function tr(e){if(e instanceof TypeError||e instanceof $i||e instanceof Tn||e instanceof En||e instanceof Pn)throw e;if(e instanceof $t)switch(e.code){case fo:throw er("only requests to HTTPS are allowed",e,e.code);case mo:throw er("only requests to HTTP or HTTPS are allowed",e,e.code);case po:throw er("unexpected HTTP response status code",e.cause,e.code);case ho:throw er("unexpected response content-type",e.cause,e.code);case uo:throw er("parsing error occured",e,e.code);case lo:throw er("invalid response encountered",e,e.code);case wo:throw er("unexpected JWT claim value encountered",e,e.code);case go:throw er("unexpected JSON attribute value encountered",e,e.code);case yo:throw er("JWT timestamp claim value failed validation",e,e.code);default:throw er(e.message,e,e.code)}if(e instanceof Qt)throw er("unsupported operation",e,e.code);if(e instanceof DOMException)switch(e.name){case"OperationError":throw er("runtime operation error",e,so);case"NotSupportedError":throw er("runtime unsupported operation",e,so);case"TimeoutError":throw er("operation timed out",e,"OAUTH_TIMEOUT");case"AbortError":throw er("operation aborted",e,"OAUTH_ABORT")}throw new $i("something went wrong",{cause:e})}async function nr(e,t,n,o,i){const r=await async function(e,t){var n,o;if(!(e instanceof URL))throw Yi('"server" must be an instance of URL',qi);const i=!e.href.includes("/.well-known/"),r=null!==(n=null==t?void 0:t.timeout)&&void 0!==n?n:30,s=AbortSignal.timeout(1e3*r),a=await(i?an(e,{algorithm:null==t?void 0:t.algorithm,[Zt]:null==t?void 0:t[Gi],[zt]:null==t||null===(o=t.execute)||void 0===o?void 0:o.includes(lr),signal:s,headers:new Headers(zi)}):((null==t?void 0:t[Gi])||fetch)((_n(e,null==t||null===(c=t.execute)||void 0===c||!c.includes(lr)),e.href),{headers:Object.fromEntries(new Headers(m({accept:"application/json"},zi)).entries()),body:void 0,method:"GET",redirect:"manual",signal:s})).then(e=>async function(e,t){const n=e;if(!(n instanceof URL)&&n!==jo)throw Lt('"expectedIssuerIdentifier" must be an instance of URL',Ut);if(!Nt(t,Response))throw Lt('"response" must be an instance of Response',Ut);if(200!==t.status)throw en('"response" is not a conform Authorization Server Metadata response (unexpected HTTP status code)',po,t);ko(t);const o=await Oo(t);if(un(o.issuer,'"response" body "issuer" property',lo,{body:o}),n!==jo&&new URL(o.issuer).href!==n.href)throw en('"response" body "issuer" property does not match the expected value',go,{expected:n.href,body:o,attribute:"issuer"});return o}(jo,e)).catch(tr);var c;i&&new URL(a.issuer).href!==e.href&&(function(e,t,n){return!("https://login.microsoftonline.com"!==e.origin||null!=n&&n.algorithm&&"oidc"!==n.algorithm||(t[or]=!0,0))}(e,a,t)||function(e,t){return!(!e.hostname.endsWith(".b2clogin.com")||null!=t&&t.algorithm&&"oidc"!==t.algorithm)}(e,t)||(()=>{throw new $i("discovered metadata issuer does not match the expected issuer",{code:go,cause:{expected:e.href,body:a,attribute:"issuer"}})})());return a}(e,i),s=new ir(r,t,n,o);let a=Di(s);if(null!=i&&i[Gi]&&(a.fetch=i[Gi]),null!=i&&i.timeout&&(a.timeout=i.timeout),null!=i&&i.execute)for(const e of i.execute)e(s);return s}new TextDecoder;const or=Symbol();class ir{constructor(e,t,n,o){var i,r,s,a,c;if("string"!=typeof t||!t.length)throw Yi('"clientId" must be a non-empty string',qi);if("string"==typeof n&&(n={client_secret:n}),void 0!==(null===(i=n)||void 0===i?void 0:i.client_id)&&t!==n.client_id)throw Yi('"clientId" and "metadata.client_id" must be the same',Xi);const u=m(m({},structuredClone(n)),{},{client_id:t});let l;u[Jt]=null!==(r=null===(s=n)||void 0===s?void 0:s[Jt])&&void 0!==r?r:0,u[Dt]=null!==(a=null===(c=n)||void 0===c?void 0:c[Dt])&&void 0!==a?a:30,l=o||("string"==typeof u.client_secret&&u.client_secret.length?Fi(u.client_secret):(e,t,n,o)=>{n.set("client_id",t.client_id)});let d=Object.freeze(u);const h=structuredClone(e);or in e&&(h[Wo]=t=>{let n=t.claims.tid;return e.issuer.replace("{tenantid}",n)});let p=Object.freeze(h);Zi||(Zi=new WeakMap),Zi.set(this,{__proto__:null,as:p,c:d,auth:l,tlsOnly:!0,jwksCache:{}})}serverMetadata(){const e=structuredClone(Di(this).as);return function(e){Object.defineProperties(e,function(e){return{supportsPKCE:{__proto__:null,value(){var t;let n=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"S256";return!0===(null===(t=e.code_challenge_methods_supported)||void 0===t?void 0:t.includes(n))}}}}(e))}(e),e}clientMetadata(){return structuredClone(Di(this).c)}get timeout(){return Di(this).timeout}set timeout(e){Di(this).timeout=e}get[Gi](){return Di(this).fetch}set[Gi](e){Di(this).fetch=e}}function rr(e){Object.defineProperties(e,function(e){let t;if(void 0!==e.expires_in){const n=new Date;n.setSeconds(n.getSeconds()+e.expires_in),t=n.getTime()}return{expiresIn:{__proto__:null,value(){if(t){const e=Date.now();return t>e?Math.floor((t-e)/1e3):0}}},claims:{__proto__:null,value(){try{return Hn(this)}catch(e){return}}}}}(e))}async function sr(e,t,n){var o;let i=arguments.length>3&&void 0!==arguments[3]&&arguments[3];const r=null===(o=e.headers.get("retry-after"))||void 0===o?void 0:o.trim();if(void 0===r)return;let s;if(/^\d+$/.test(r))s=parseInt(r,10);else{const e=new Date(r);if(Number.isFinite(e.getTime())){const t=new Date,n=e.getTime()-t.getTime();n>0&&(s=Math.ceil(n/1e3))}}if(i&&!Number.isFinite(s))throw new $t("invalid Retry-After header value",{cause:e});s>t&&await ar(s-t,n)}function ar(e,t){return new Promise((n,o)=>{const i=e=>{try{t.throwIfAborted()}catch(e){return void o(e)}if(e<=0)return void n();const r=Math.min(e,5);setTimeout(()=>i(e-r),1e3*r)};i(e)})}async function cr(e,t){yr(e);const n=Di(e),o=n.as,i=n.c,r=n.auth,s=n.fetch,a=n.tlsOnly,c=n.timeout;return async function(e,t,n,o,i){yn(e),wn(t);const r=Sn(e,"backchannel_authentication_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[zt])),s=new URLSearchParams(o);s.set("client_id",t.client_id);const a=on(null==i?void 0:i.headers);return a.set("accept","application/json"),zn(e,t,n,r,s,a,i)}(o,i,r,t,{[Zt]:s,[zt]:!a,headers:new Headers(zi),signal:wr(c)}).then(e=>async function(e,t,n){if(yn(e),wn(t),!Nt(n,Response))throw Lt('"response" must be an instance of Response',Ut);await Wn(n,200,"Backchannel Authentication Endpoint"),ko(n);const o=await Oo(n);un(o.auth_req_id,'"response" body "auth_req_id" property',lo,{body:o});let i="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return cn(i,!0,'"response" body "expires_in" property',lo,{body:o}),o.expires_in=i,void 0!==o.interval&&cn(o.interval,!1,'"response" body "interval" property',lo,{body:o}),o}(o,i,e)).catch(tr)}async function ur(e,t,n,o){var i,r;yr(e),n=new URLSearchParams(n);let s=null!==(i=t.interval)&&void 0!==i?i:5;const a=null!==(r=null==o?void 0:o.signal)&&void 0!==r?r:AbortSignal.timeout(1e3*t.expires_in);try{await ar(s,a)}catch(e){tr(e)}const c=Di(e),u=c.as,l=c.c,d=c.auth,h=c.fetch,p=c.tlsOnly,f=c.nonRepudiation,y=c.timeout,w=c.decrypt,g=(i,r)=>ur(e,m(m({},t),{},{interval:i}),n,m(m({},o),{},{signal:a,flag:r})),v=function(e,t){const n=wr(t);if(!n)return{signal:e,cleanup(){}};const o=new AbortController,i=e=>{const t=e.target;o.abort(t.reason)};return e.aborted?o.abort(e.reason):n.aborted?o.abort(n.reason):(e.addEventListener("abort",i,{once:!0}),n.addEventListener("abort",i,{once:!0})),{signal:o.signal,cleanup(){e.removeEventListener("abort",i),n.removeEventListener("abort",i)}}}(a,y),b=await async function(e,t,n,o,i){yn(e),wn(t),un(o,'"authReqId"');const r=new URLSearchParams(null==i?void 0:i.additionalParameters);return r.set("auth_req_id",o),Jn(e,t,n,"urn:openid:params:grant-type:ciba",r,i)}(u,l,d,t.auth_req_id,{[Zt]:h,[zt]:!p,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(zi),signal:v.signal}).catch(tr).finally(v.cleanup);var _;if(503===b.status&&b.headers.has("retry-after"))return await sr(b,s,a,!0),await(null===(_=b.body)||void 0===_?void 0:_.cancel()),g(s);const k=async function(e,t,n,o){return Fn(e,t,n,void 0,null==o?void 0:o[Ft],null==o?void 0:o.recognizedTokenTypes)}(u,l,b,{[Ft]:w});let S;try{S=await k}catch(e){if(vr(e,o))return g(s,br);if(e instanceof Tn)switch(e.error){case"slow_down":s+=5;case"authorization_pending":return await sr(e.response,s,a),g(s)}tr(e)}return S.id_token&&await(null==f?void 0:f(b)),rr(S),S}function lr(e){Di(e).tlsOnly=!1}async function dr(e,t,n,o,i){if(yr(e),!((null==i?void 0:i.flag)===br||t instanceof URL||function(e,t){try{return Object.getPrototypeOf(e)[Symbol.toStringTag]===t}catch(e){return!1}}(t,"Request")))throw Yi('"currentUrl" must be an instance of URL, or Request',qi);let r,s;const a=Di(e),c=a.as,u=a.c,l=a.auth,d=a.fetch,h=a.tlsOnly,p=a.jarm,f=a.hybrid,y=a.nonRepudiation,g=a.timeout,v=a.decrypt,b=a.implicit;if((null==i?void 0:i.flag)===br)r=i.authResponse,s=i.redirectUri;else{if(!(t instanceof URL)){const e=t;switch(t=new URL(t.url),e.method){case"GET":break;case"POST":const n=new URLSearchParams(await Po(e));if(f)t.hash=n.toString();else for(const e of n.entries()){var _=w(e,2);const n=_[0],o=_[1];t.searchParams.append(n,o)}break;default:throw Yi("unexpected Request HTTP method",Xi)}}switch(s=function(e){return(e=new URL(e)).search="",e.hash="",e.href}(t),!0){case!!p:r=await p(t,null==n?void 0:n.expectedState);break;case!!f:r=await f(t,null==n?void 0:n.expectedNonce,null==n?void 0:n.expectedState,null==n?void 0:n.maxAge);break;case!!b:throw new TypeError("authorizationCodeGrant() cannot be used by response_type=id_token clients");default:try{r=Io(c,u,t.searchParams,null==n?void 0:n.expectedState)}catch(e){tr(e)}}}const k=await async function(e,t,n,o,i,r,s){if(yn(e),wn(t),!Bn.has(o))throw Lt('"callbackParameters" must be an instance of URLSearchParams obtained from "validateAuthResponse()", or "validateJwtAuthResponse()',Kt);un(i,'"redirectUri"');const a=Ao(o,"code");if(!a)throw en('no authorization code in "callbackParameters"',lo);const c=new URLSearchParams(null==s?void 0:s.additionalParameters);return c.set("redirect_uri",i),c.set("code",a),r!==Qn&&(un(r,'"codeVerifier"'),c.set("code_verifier",r)),Jn(e,t,n,"authorization_code",c,s)}(c,u,l,r,s,(null==n?void 0:n.pkceCodeVerifier)||Qn,{additionalParameters:o,[Zt]:d,[zt]:!h,DPoP:null==i?void 0:i.DPoP,headers:new Headers(zi),signal:wr(g)}).catch(tr);"string"!=typeof(null==n?void 0:n.expectedNonce)&&"number"!=typeof(null==n?void 0:n.maxAge)||(n.idTokenExpected=!0);const S=oo(c,u,k,{expectedNonce:null==n?void 0:n.expectedNonce,maxAge:null==n?void 0:n.maxAge,requireIdToken:null==n?void 0:n.idTokenExpected,[Ft]:v});let T;try{T=await S}catch(t){if(vr(t,i))return dr(e,void 0,n,o,m(m({},i),{},{flag:br,authResponse:r,redirectUri:s}));tr(t)}return T.id_token&&await(null==y?void 0:y(k)),rr(T),T}async function hr(e,t,n,o){yr(e),n=new URLSearchParams(n);const i=Di(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.nonRepudiation,d=i.timeout,h=i.decrypt,p=await async function(e,t,n,o,i){yn(e),wn(t),un(o,'"refreshToken"');const r=new URLSearchParams(null==i?void 0:i.additionalParameters);return r.set("refresh_token",o),Jn(e,t,n,"refresh_token",r,i)}(r,s,a,t,{[Zt]:c,[zt]:!u,additionalParameters:n,DPoP:null==o?void 0:o.DPoP,headers:new Headers(zi),signal:wr(d)}).catch(tr),f=async function(e,t,n,o){return Fn(e,t,n,void 0,null==o?void 0:o[Ft],null==o?void 0:o.recognizedTokenTypes)}(r,s,p,{[Ft]:h});let y;try{y=await f}catch(i){if(vr(i,o))return hr(e,t,n,m(m({},o),{},{flag:br}));tr(i)}return y.id_token&&await(null==l?void 0:l(p)),rr(y),y}async function pr(e,t,n){yr(e),t=new URLSearchParams(t);const o=Di(e),i=o.as,r=o.c,s=o.auth,a=o.fetch,c=o.tlsOnly,u=o.timeout,l=await async function(e,t,n,o,i){return yn(e),wn(t),Jn(e,t,n,"client_credentials",new URLSearchParams(o),i)}(i,r,s,t,{[Zt]:a,[zt]:!c,DPoP:null==n?void 0:n.DPoP,headers:new Headers(zi),signal:wr(u)}).catch(tr),d=async function(e,t,n,o){return Fn(e,t,n,void 0,null==o?void 0:o[Ft],null==o?void 0:o.recognizedTokenTypes)}(i,r,l);let h;try{h=await d}catch(o){if(vr(o,n))return pr(e,t,m(m({},n),{},{flag:br}));tr(o)}return rr(h),h}function fr(e,t){yr(e);const n=Di(e),o=n.as,i=n.c,r=n.tlsOnly,s=n.hybrid,a=n.jarm,c=n.implicit,u=Sn(o,"authorization_endpoint",!1,r);if((t=new URLSearchParams(t)).has("client_id")||t.set("client_id",i.client_id),!t.has("request_uri")&&!t.has("request")){if(t.has("response_type")||t.set("response_type",s?"code id_token":c?"id_token":"code"),c&&!t.has("nonce"))throw Yi("response_type=id_token clients must provide a nonce parameter in their authorization request parameters",Xi);a&&t.set("response_mode","jwt")}for(const e of t.entries()){var l=w(e,2);const t=l[0],n=l[1];u.searchParams.append(t,n)}return u}async function mr(e,t,n){yr(e);const o=fr(e,t),i=Di(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.timeout,d=await async function(e,t,n,o,i){var r;yn(e),wn(t);const s=Sn(e,"pushed_authorization_request_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[zt])),a=new URLSearchParams(o);a.set("client_id",t.client_id);const c=on(null==i?void 0:i.headers);c.set("accept","application/json"),void 0!==(null==i?void 0:i.DPoP)&&(Mn(i.DPoP),await i.DPoP.addProof(s,c,"POST"));const u=await zn(e,t,n,s,a,c,i);return null==i||null===(r=i.DPoP)||void 0===r||r.cacheNonce(u,s),u}(r,s,a,o.searchParams,{[Zt]:c,[zt]:!u,DPoP:null==n?void 0:n.DPoP,headers:new Headers(zi),signal:wr(l)}).catch(tr),h=async function(e,t,n){if(yn(e),wn(t),!Nt(n,Response))throw Lt('"response" must be an instance of Response',Ut);await Wn(n,201,"Pushed Authorization Request Endpoint"),ko(n);const o=await Oo(n);un(o.request_uri,'"response" body "request_uri" property',lo,{body:o});let i="number"!=typeof o.expires_in?parseFloat(o.expires_in):o.expires_in;return cn(i,!0,'"response" body "expires_in" property',lo,{body:o}),o.expires_in=i,o}(r,s,d);let p;try{p=await h}catch(o){if(vr(o,n))return mr(e,t,m(m({},n),{},{flag:br}));tr(o)}return fr(e,{request_uri:p.request_uri})}function yr(e){if(!(e instanceof ir))throw Yi('"config" must be an instance of Configuration',qi);if(Object.getPrototypeOf(e)!==ir.prototype)throw Yi("subclassing Configuration is not allowed",Xi)}function wr(e){return e?AbortSignal.timeout(1e3*e):void 0}async function gr(e,t,n,o){yr(e);const i=Di(e),r=i.as,s=i.c,a=i.fetch,c=i.tlsOnly,u=i.nonRepudiation,l=i.timeout,d=i.decrypt,h=await Nn(r,s,t,{[Zt]:a,[zt]:!c,DPoP:null==o?void 0:o.DPoP,headers:new Headers(zi),signal:wr(l)}).catch(tr);let p,f=Ln(r,s,n,h,{[Ft]:d});try{p=await f}catch(i){if(vr(i,o))return gr(e,t,n,m(m({},o),{},{flag:br}));tr(i)}return"application/jwt"===Un(h)&&await(null==u?void 0:u(h)),p}function vr(e,t){return!(null==t||!t.DPoP||t.flag===br)&&function(e){if(e instanceof Pn){const t=e.cause,n=t[0];return 1===t.length&&"dpop"===n.scheme&&"use_dpop_nonce"===n.parameters.error}return e instanceof Tn&&"use_dpop_nonce"===e.error}(e)}Object.freeze(ir.prototype);const br=Symbol();async function _r(e,t,n,o){yr(e);const i=Di(e),r=i.as,s=i.c,a=i.auth,c=i.fetch,u=i.tlsOnly,l=i.timeout,d=i.decrypt,h=i.nonRepudiation,p=await async function(e,t,n,o,i,r){return yn(e),wn(t),un(o,'"grantType"'),Jn(e,t,n,o,new URLSearchParams(i),r)}(r,s,a,t,new URLSearchParams(n),{[Zt]:c,[zt]:!u,DPoP:null==o?void 0:o.DPoP,headers:new Headers(zi),signal:wr(l)}).catch(tr);let f;"urn:ietf:params:oauth:grant-type:token-exchange"===t&&(f={n_a:()=>{}});const y=async function(e,t,n,o){return Fn(e,t,n,void 0,null==o?void 0:o[Ft],null==o?void 0:o.recognizedTokenTypes)}(r,s,p,{[Ft]:d,recognizedTokenTypes:f});let w;try{w=await y}catch(i){if(vr(i,o))return _r(e,t,n,m(m({},o),{},{flag:br}));tr(i)}return w.id_token&&await(null==h?void 0:h(p)),rr(w),w}async function kr(e,t,n){yr(e);const o=Di(e),i=o.as,r=o.c,s=o.auth,a=o.fetch,c=o.tlsOnly,u=o.timeout;return async function(e,t,n,o,i){yn(e),wn(t),un(o,'"token"');const r=Sn(e,"revocation_endpoint",t.use_mtls_endpoint_aliases,!0!==(null==i?void 0:i[zt])),s=new URLSearchParams(null==i?void 0:i.additionalParameters);s.set("token",o);const a=on(null==i?void 0:i.headers);return a.delete("accept"),zn(e,t,n,r,s,a,i)}(i,r,s,t,{[Zt]:a,[zt]:!c,additionalParameters:new URLSearchParams(n),headers:new Headers(zi),signal:wr(u)}).then(_o).catch(tr)}async function Sr(e,t,n){return t instanceof Uint8Array?crypto.subtle.importKey("raw",t,e.subtle,!1,[n]):(Jo(t,e.subtle,n),e.minRsaBits&&function(e,t){const n=t.algorithm.modulusLength;if("number"!=typeof n||n<2048)throw new TypeError("".concat(e," requires key modulusLength to be 2048 bits or larger"))}(e.alg,t),t)}const Tr=[["verify"],["sign"]];function Er(e){const t={name:"HMAC",hash:"SHA-".concat(e)};return{kty:["oct"],secret:!0,subtle:t,signing:t,usages:Tr}}function Pr(e,t){const n={name:t?"RSA-PSS":"RSASSA-PKCS1-v1_5",hash:"SHA-".concat(e)};return{kty:["RSA"],subtle:n,signing:t?m(m({},n),{},{saltLength:t}):n,usages:Tr,minRsaBits:2048}}function Cr(e,t){return{kty:["EC"],crv:e,subtle:{name:"ECDSA",namedCurve:e},signing:{name:"ECDSA",hash:"SHA-".concat(t)},usages:Tr}}function Ar(){const e={name:"Ed25519"};return{kty:["OKP"],crv:"Ed25519",subtle:e,signing:e,usages:Tr}}function Rr(e){const t={name:"ML-DSA-".concat(e)};return{kty:["AKP"],subtle:t,signing:t,usages:Tr}}const xr=Si({HS256:Er(256),HS384:Er(384),HS512:Er(512),RS256:Pr(256),RS384:Pr(384),RS512:Pr(512),PS256:Pr(256,32),PS384:Pr(384,48),PS512:Pr(512,64),ES256:Cr("P-256",256),ES384:Cr("P-384",384),ES512:Cr("P-521",512),EdDSA:Ar(),Ed25519:Ar(),"ML-DSA-44":Rr(44),"ML-DSA-65":Rr(65),"ML-DSA-87":Rr(87)});function Ir(e){const t="string"==typeof e?xr[e]:void 0;if(!t)throw new Go("alg ".concat(e," is not supported either by JOSE or your javascript runtime"));return t}function Or(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:void 0===e?{}:function(e,t,n){let o;try{o=JSON.parse(Ko.decode(ri(e)))}catch(e){throw new t(n)}if(!ai(o))throw new t(n);return o}(e,Xo,"JWS Protected Header is invalid");return t}async function jr(e,t,n,o,i,r,s){var a;let c=!1;"function"==typeof n&&(n=await n(i,e),c=!0);const u="string"==typeof s,l=Ir(r),d=Uo(void 0!==o?Lo(o):new Uint8Array,Lo("."),u?null!==(a=t[2])&&void 0!==a?a:t[2]=function(e,t,n){try{return Lo(e)}catch(e){throw new n("The ".concat(t," is not a valid base64url string"))}}(s,"payload",Xo):s),h=ui(e.signature,"signature",Xo),p=await ki(l,n,"verify");if(!await async function(e,t,n,o){const i=await Sr(e,t,"verify");try{return await crypto.subtle.verify(e.signing,i,n,o)}catch(e){return!1}}(l,p,h,d))throw new ei;return[u?ui(s,"payload",Xo):s,i,u,p,c]}async function Wr(e,t,n){if(e instanceof Uint8Array&&(e=No.decode(e)),"string"!=typeof e)throw new Xo("Compact JWS must be a string or Uint8Array");const o=e.split("."),i=o[0],r=o[1],s=o[2];if(3!==o.length)throw new Xo("Invalid Compact JWS");const a={payload:r,protected:i,signature:s},c=Or(i),u=function(e,t,n){const o=Ki(e,Ni(Xo,Wi,n[1],e,t)),i=t.alg;if("string"!=typeof i||!i)throw new Xo('JWS "alg" (Algorithm) Header Parameter missing or invalid');if(n[0]&&!n[0].has(i))throw new Vo('"alg" (Algorithm) Header Parameter value not allowed');return[o,i]}(c,c,t),l=w(u,2),d=l[0],h=l[1],p=d?r:function(e){try{return Lo(e)}catch(e){throw new Xo("JWS Compact Serialization payload must use only ASCII characters")}}(r);return jr(a,t,n,i,c,h,p)}const Mr=e=>Math.floor(e.getTime()/1e3),Nr={s:1,m:60,h:3600,d:86400,w:604800,y:31557600},Kr=/^(\+|\-)? ?(\d+|\d+\.\d+) ?(seconds?|secs?|s|minutes?|mins?|m|hours?|hrs?|h|days?|d|weeks?|w|years?|yrs?|y)(?: (ago|from now))?$/i,Ur="check_failed";function Lr(){throw new TypeError("Invalid time period format")}function zr(e){"string"!=typeof e&&Lr();const t=Kr.exec(e);(!t||t[4]&&t[1])&&Lr();const n=parseFloat(t[2]),o=Math.round(n*Nr[t[3][0].toLowerCase()]);return Number.isFinite(o)||Lr(),"-"===t[1]||"ago"===t[4]?-o:o}function Jr(e,t){if(!Number.isFinite(t))throw new TypeError("Invalid ".concat(e," input"));return t}function Dr(e,t){if("string"!=typeof t)throw new TypeError('"'.concat(e,'" claim must be a string'))}function Zr(e,t){return"number"==typeof e?Jr(t,e):e instanceof Date?Jr(t,Mr(e)):Mr(new Date)+zr(e)}const Hr=e=>{const t=e.toLowerCase();return e.includes("/")?t:"application/".concat(t)};function Fr(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];const o=e[t];if(void 0!==o||n){if("number"!=typeof o)throw new Ho('"'.concat(t,'" claim must be a number'),e,t,"invalid");return o}}function Vr(e,t){throw new Ho('unexpected "'.concat(t,'" claim value'),e,t,Ur)}function Gr(e,t){let n,o=arguments.length>2&&void 0!==arguments[2]?arguments[2]:{};try{n=JSON.parse(Ko.decode(t))}catch(e){}if(!ai(n))throw new qo("JWT Claims Set must be a top-level JSON object");const i=o.typ;if(void 0!==i&&("string"!=typeof e.typ||Hr(e.typ)!==Hr(i)))throw new Ho('unexpected "typ" JWT header value',n,"typ",Ur);const r=o.requiredClaims,s=void 0===r?[]:r,a=o.issuer,c=o.subject,u=o.audience,l=o.maxTokenAge,d=[...s];void 0!==l&&d.push("iat"),void 0!==u&&d.push("aud"),void 0!==c&&d.push("sub"),void 0!==a&&d.push("iss");for(const e of new Set(d.reverse()))if(!Object.hasOwn(n,e))throw new Ho('missing required "'.concat(e,'" claim'),n,e,"missing");var h,p;void 0===a||(Array.isArray(a)?a:[a]).includes(n.iss)||Vr(n,"iss"),void 0!==c&&n.sub!==c&&Vr(n,"sub"),void 0===u||(h=n.aud,p="string"==typeof u?[u]:u,"string"==typeof h?p.includes(h):Array.isArray(h)&&p.some(e=>h.includes(e)))||Vr(n,"aud");const f=o.clockTolerance;let m=0;if("string"==typeof f)m=zr(f);else if(void 0!==f){if("number"!=typeof f)throw new TypeError("Invalid clockTolerance option type");m=f}Jr("clockTolerance option",m);const y=o.currentDate,w=Jr("currentDate option",Mr(void 0===y?new Date:y)),g=Fr(n,"iat",void 0!==l),v=Fr(n,"nbf");if(void 0!==v&&v>w+m)throw new Ho('"nbf" claim timestamp check failed',n,"nbf",Ur);const b=Fr(n,"exp");if(void 0!==b&&b<=w-m)throw new Fo('"exp" claim timestamp check failed',n,"exp",Ur);if(void 0!==l){const e=w-g;if(e-m>Jr("maxTokenAge option","number"==typeof l?l:zr(l)))throw new Fo('"iat" claim timestamp check failed (too far in the past)',n,"iat",Ur);if(e<-m)throw new Ho('"iat" claim timestamp check failed (it should be in the past)',n,"iat",Ur)}return n}let Xr;function qr(e){return Xr.get(e)}async function Yr(e,t,n){const o=await Wr(e,function(e){return[e&&Mi("algorithms",e.algorithms),null==e?void 0:e.crit]}(n),t);if(!o[2])throw new qo("JWTs MUST NOT use unencoded payload");const i={payload:Gr(o[1],o[0],n),protectedHeader:o[1]};return"function"==typeof t?m(m({},i),{},{key:o[3]}):i}function Br(e){if(void 0===e)return[void 0,""];const t=function(e,t){let n,o;try{n=JSON.stringify(t),o=JSON.parse(n)}catch(t){throw new e("JOSE Header is not valid JSON",{cause:t})}if(!ai(o))throw new e("JOSE Header is not a JSON object");return[o,n]}(Xo,e);return[t[0],si(t[1])]}function Qr(e,t,n){return function(e,t){const n=(null!=t?t:{}).crit;if(Array.isArray(n)&&new Set(n).size!==n.length)throw new e('"crit" (Critical) Header Parameter MUST NOT contain duplicate values')}(Xo,e),Ki(e,Ni(Xo,Wi,n,e,t))}async function $r(e,t,n,o){const i=Uo(Lo(e),Lo("."),t),r=await ki(n,o,"sign");return si(await async function(e,t,n){const o=await Sr(e,t,"sign"),i=await crypto.subtle.sign(e.signing,o,n);return new Uint8Array(i)}(n,r,i))}async function es(e,t,n,o,i){const r=w(Br(t),2),s=r[0],a=r[1];if(!s)throw new Xo("either setProtectedHeader or setUnprotectedHeader must be called before #sign()");Qr(s,s,n)||i();const c=function(e){const t=e.alg;if("string"!=typeof t||!t)throw new Xo('JWS "alg" (Algorithm) Header Parameter missing or invalid');return Ir(t)}(s),u=si(e),l=await $r(a,Lo(u),c,o);return"".concat(a,".").concat(u,".").concat(l)}const ts=class{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!ai(e))throw new TypeError("JWT Claims Set MUST be an object");(Xr||(Xr=new WeakMap)).set(this,structuredClone(e))}setIssuer(e){return Dr("iss",e),qr(this).iss=e,this}setSubject(e){return Dr("sub",e),qr(this).sub=e,this}setAudience(e){return function(e){if("string"!=typeof e&&(!Array.isArray(e)||Array.from(e).some(e=>"string"!=typeof e)))throw new TypeError('"aud" claim must be a string or an array of strings')}(e),qr(this).aud=e,this}setJti(e){return Dr("jti",e),qr(this).jti=e,this}setNotBefore(e){return qr(this).nbf=Zr(e,"setNotBefore"),this}setExpirationTime(e){return qr(this).exp=Zr(e,"setExpirationTime"),this}setIssuedAt(e){const t=qr(this);return t.iat=void 0===e?Mr(new Date):"string"==typeof e?Jr("setIssuedAt",Mr(new Date)+zr(e)):Zr(e,"setIssuedAt"),this}};var ns=new WeakMap;class os extends ts{constructor(){super(...arguments),l(this,ns,void 0)}setProtectedHeader(e){return function(e,t){if(void 0!==e)throw new TypeError("".concat(t," can only be called once"))}(u(ns,this),"setProtectedHeader"),d(ns,this,e),this}async sign(e,t){return es(function(e){const t=qr(e);for(const e of["iat","nbf","exp"]){const n=t[e];if("number"==typeof n&&!Number.isFinite(n))throw new TypeError('"'.concat(e,'" claim must be a finite number'))}return Mo.encode(JSON.stringify(t))}(this),u(ns,this),null==t?void 0:t.crit,e,()=>{throw new qo("JWTs MUST NOT use unencoded payload")})}}const is='"alg" (Algorithm)';function rs(){throw new Go("Invalid or unsupported ".concat(arguments.length>0&&void 0!==arguments[0]?arguments[0]:'JWK "alg" (Algorithm) Parameter'," value"))}const ss=(e,t)=>{if(e.byteLength!==t.length)return!1;for(let n=0;n<e.byteLength;n++)if(e[n]!==t[n])return!1;return!0},as=e=>{const t=e.data[e.pos++];if(void 0===t)throw new Error("Unexpected end of ASN.1 input");return t},cs=e=>{const t=as(e);if(128&t){const n=127&t;let o=0;for(let t=0;t<n;t++)o=o<<8|as(e);return o}return t},us=(e,t,n)=>{if(as(e)!==t)throw new Error(n)},ls=(e,t)=>{if(t<0||e.pos+t>e.data.length)throw new Error("Unexpected end of ASN.1 input");const n=e.data.subarray(e.pos,e.pos+t);return e.pos+=t,n};const ds=e=>{const t=(e=>{us(e,6,"Expected algorithm OID");const t=cs(e);return ls(e,t)})(e);if(ss(t,[43,101,110]))return"X25519";if(!ss(t,[42,134,72,206,61,2,1]))throw new Error("Unsupported key algorithm");us(e,6,"Expected curve OID");const n=cs(e),o=ls(e,n);if(ss(o,[42,134,72,206,61,3,1,7]))return"P-256";if(ss(o,[43,129,4,0,34]))return"P-384";if(ss(o,[43,129,4,0,35]))return"P-521";throw new Error("Unsupported named curve")},hs=async(e,t,n,o)=>{const i=function(e){if(void 0!==e&&"boolean"!=typeof e)throw new TypeError('"extractable" option must be a boolean');return e}(null==o?void 0:o.extractable),r=function(e,t){var n,o;return null!==(n="string"==typeof e?null!==(o=xr[e])&&void 0!==o?o:Ii[e]:void 0)&&void 0!==n?n:rs(t)}(n,is);r.secret&&rs(is);const s="spki"===e;let a;if(r.resolve)try{const n={data:t,pos:0};!function(e,t){if(us(e,48,"Invalid ".concat("spki"===t?"SPKI":"PKCS#8"," structure")),cs(e),"pkcs8"===t){us(e,2,"Expected version field");const t=cs(e);e.pos+=t}us(e,48,"Expected algorithm identifier"),cs(e)}(n,e),a=r.resolve({crv:ds(n)})}catch(e){throw new Go("Invalid or unsupported key format")}else a=r.subtle;return crypto.subtle.importKey(e,t,a,null!=i?i:s,r.usages[s?0:1])},ps=(e,t,n)=>{const o=((e,t)=>oi(e.replace(t,"")))(e,/(?:-----(?:BEGIN|END) PRIVATE KEY-----|\s)/g);return hs("pkcs8",o,t,n)};async function fs(e,t,n){const o=e.get(t)||e.set(t,{}).get(t),i=n.alg;if(void 0===o[i]){const e=await li(n,m(m({},t),{},{alg:i,ext:!0}));if("public"!==e.type)throw new Yo("JSON Web Key Set members must be public keys");o[i]=e}return o[i]}function ms(e){let t;try{t=structuredClone(e)}catch(e){}if(!ci(t))throw new Yo("JSON Web Key Set malformed");const n=new WeakMap;return Object.defineProperty(async(e,o)=>{const i=m(m({},e),null==o?void 0:o.header),r=i.alg,s=i.kid,c="string"==typeof r?xr[r]:void 0;if(!c||c.secret)throw new Go('Unsupported "alg" value for a JSON Web Key Set');const u=t.keys.filter(e=>function(e,t,n,o){const i=di(e),r=i.kty,s=i.key_ops,a=i.ext,c=i.kid,u=i.alg,l=i.use,d=i.crv,h=Array.isArray(s)?[...s]:s;return(void 0===a||"boolean"==typeof a)&&(void 0===h||Array.isArray(h)&&h.every((e,t)=>"string"==typeof e&&h.indexOf(e)===t)&&h.includes("verify"))&&t.kty.includes(r)&&(void 0===o||"string"==typeof o&&o===c)&&(void 0===u?"AKP"!==r:n===u)&&(void 0===l||"sig"===l)&&(!t.crv||d===t.crv)}(e,c,r,s)),l=u[0],d=u.length;if(!d)throw new Bo;if(1!==d){const e=new Qo;throw e[Symbol.asyncIterator]=g(function*(){for(const e of u)try{yield yield a(fs(n,e,c))}catch(e){}}),e}return fs(n,l,c)},"jwks",{value:()=>structuredClone(t)})}var ys,ws;let gs;if("undefined"==typeof navigator||null===(ys=navigator.userAgent)||void 0===ys||null===(ws=ys.startsWith)||void 0===ws||!ws.call(ys,"Mozilla/5.0 ")){const e="v6.2.10";gs="".concat("jose","/").concat(e)}const vs=Symbol();const bs=Symbol();function _s(e,t){return Number.isFinite(e)&&Date.now()<e+t}function ks(e,t,n){if(Number.isNaN(e))throw new TypeError('"'.concat(n,'" option must not be NaN'));return"number"==typeof e?e:t}function Ss(e,t){if(!(e instanceof URL))throw new TypeError("url must be an instance of URL");const n=new URL(e.href).href,o=null!=t?t:{},i=o.timeoutDuration;if("number"==typeof i&&(!Number.isInteger(i)||i<0))throw new TypeError('"timeoutDuration" option must be a non-negative integer');const r="number"==typeof i?i:5e3,s=ks(o.cooldownDuration,3e4,"cooldownDuration"),a=ks(o.cacheMaxAge,6e5,"cacheMaxAge"),c=new Headers(o.headers);gs&&!c.has("User-Agent")&&c.set("User-Agent",gs),c.has("accept")||c.set("accept","application/json, application/jwk-set+json");const u=o[vs],l=o[bs];let d,h,p,f=0,m=0;if(l&&"object"==typeof l){const e=l.uat,t=l.jwks;_s(e,a)&&ci(t)&&(d=e,p=ms(t))}const y=async()=>{if(h&&("undefined"!=typeof WebSocketPair||"undefined"!=typeof navigator&&"Cloudflare-Workers"===navigator.userAgent||"undefined"!=typeof EdgeRuntime&&"vercel"===EdgeRuntime)&&(h=void 0),!h){const e=++f,t=h=async function(e,t,n){let o=arguments.length>3&&void 0!==arguments[3]?arguments[3]:fetch;const i=await o(e,{method:"GET",signal:n,redirect:"manual",headers:t}).catch(e=>{if("TimeoutError"===e.name)throw new $o;throw e});if(200!==i.status)throw new Zo("Expected 200 OK from the JSON Web Key Set HTTP response");try{return await i.json()}catch(e){throw new Zo("Failed to parse the JSON Web Key Set HTTP response as JSON")}}(n,c,AbortSignal.timeout(r),u).then(t=>{const n=ms(t);if(e<=m)return;p=n;const o=Date.now();l&&(l.uat=o,l.jwks=t),d=o,m=e}).finally(()=>{h===t&&(h=void 0)})}await h};return Object.defineProperties(async(e,t)=>{p&&_s(d,a)||await y();try{return await p(e,t)}catch(n){if(n instanceof Bo&&!_s(d,s))return await y(),p(e,t);throw n}},{coolingDown:{get:()=>_s(d,s),enumerable:!0},fresh:{get:()=>_s(d,a),enumerable:!0},reload:{value:y,enumerable:!0},reloading:{get:()=>!!h,enumerable:!0},jwks:{value:()=>{var e;return null===(e=p)||void 0===e?void 0:e.jwks()},enumerable:!0}})}async function Ts(e,t,n){if("string"!=typeof e||0!==e.indexOf("-----BEGIN PRIVATE KEY-----"))throw new TypeError('"pkcs8" must be PKCS#8 formatted string');return ps(e,t,n)}const Es=["mfaToken"],Ps=["mfaToken"];var Cs,As,Rs,xs,Is,Os,js,Ws,Ms,Ns,Ks,Us,Ls,zs,Js,Ds,Zs,Hs,Fs,Vs,Gs,Xs,qs,Ys,Bs,Qs,$s,ea,ta,na,oa,ia,ra,sa,aa,ca,ua,la,da,ha,pa,fa,ma,ya,wa,ga,va,ba,_a,ka,Sa,Ta;function Ea(e){if("object"!=typeof e||null===e)return{};const t=e;return{statusCode:"number"==typeof t.statusCode?t.statusCode:void 0,headers:t.headers instanceof Headers?t.headers:void 0,body:"string"==typeof t.body?t.body:void 0}}function Pa(e){var t,n;if("object"!=typeof e||null===e)return{error:"unknown_error",error_description:String(e)};const o=e;let i;if(o.response instanceof Response)try{i=new Headers(o.response.headers),i.delete("set-cookie")}catch(e){i=void 0}const r={error:null!==(t=o.error)&&void 0!==t?t:"",error_description:null!==(n=o.error_description)&&void 0!==n?n:"",message:o.message,statusCode:"number"==typeof o.status?o.status:void 0,headers:i};if("mfa_required"===o.error&&o.cause){r.mfa_token="string"==typeof o.cause.mfa_token?o.cause.mfa_token:void 0;const e=o.cause.mfa_requirements;"object"==typeof e&&null!==e&&(r.mfa_requirements=e)}return r}var Ca=class extends Error{constructor(e,t){super(t),p(this,"code",void 0),this.name="NotSupportedError",this.code=e}},Aa=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements};const o=Ea(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},Ra=class extends Aa{constructor(e,t){super("token_by_code_error",e,t),this.name="TokenByCodeError"}},xa=class extends Aa{constructor(e,t){super("token_by_client_credentials_error",e,t),this.name="TokenByClientCredentialsError"}},Ia=class extends Aa{constructor(e,t){super("token_by_refresh_token_error",e,t),this.name="TokenByRefreshTokenError"}},Oa=class extends Aa{constructor(e,t){super("token_by_password_error",e,t),this.name="TokenByPasswordError"}},ja=class extends Aa{constructor(e,t){super("token_for_connection_error",e,t),this.name="TokenForConnectionErrorCode"}},Wa=class extends Aa{constructor(e,t){super("token_exchange_error",e,t),this.name="TokenExchangeError"}},Ma=class extends Aa{constructor(e,t){super("token_revocation_error",e,t),this.name="TokenRevocationError"}},Na=class extends Aa{constructor(e,t){super("user_info_error",e,t),this.name="UserInfoError"}},Ka=class extends Error{constructor(e){super(e),p(this,"code","verify_logout_token_error"),this.name="VerifyLogoutTokenError"}},Ua=class extends Aa{constructor(e){super("backchannel_authentication_error","There was an error when trying to use Client-Initiated Backchannel Authentication.",e),p(this,"code","backchannel_authentication_error"),this.name="BackchannelAuthenticationError"}},La=class extends Aa{constructor(e){super("build_authorization_url_error","There was an error when trying to build the authorization URL.",e),this.name="BuildAuthorizationUrlError"}},za=class extends Aa{constructor(e){super("build_link_user_url_error","There was an error when trying to build the Link User URL.",e),this.name="BuildLinkUserUrlError"}},Ja=class extends Aa{constructor(e){super("build_unlink_user_url_error","There was an error when trying to build the Unlink User URL.",e),this.name="BuildUnlinkUserUrlError"}},Da=class extends Error{constructor(){super("The client secret or client assertion signing key must be provided."),p(this,"code","missing_client_auth_error"),this.name="MissingClientAuthError"}},Za=class extends Error{constructor(e){super(e),p(this,"code","organization_validation_error"),this.name="OrganizationValidationError"}},Ha=class extends Error{constructor(e){super(e||"fullResponse: true requested but no HTTP Response was captured. This is a bug in CapturingFetch."),p(this,"code","missing_captured_response_error"),this.name="MissingCapturedResponseError"}};function Fa(e){try{const t=new Headers(e);return t.delete("set-cookie"),t}catch(e){return new Headers}}function Va(e,t,n){var o;const i="object"==typeof t&&null!==t?t:void 0,r=null!==(o=null==i?void 0:i.response)&&void 0!==o?o:n,s="number"==typeof(null==i?void 0:i.status)?i.status:null==r?void 0:r.status;"number"==typeof s&&(e.statusCode=s),null!=r&&r.headers&&(e.headers=Fa(r.headers))}function Ga(e){return Object.entries(e).filter(e=>void 0!==w(e,2)[1]).reduce((e,t)=>m(m({},e),{},{[t[0]]:t[1]}),{})}function Xa(e){if(!e.trim())throw new Za("organization must not be blank")}function qa(e,t){if(!e)return;const n=t.trim();if(n.startsWith("org_")){const t=e.org_id;if("string"!=typeof t)throw new Za("Organization Id (org_id) claim must be a string present in the ID token");if(t!==n)throw new Za('Organization Id (org_id) claim value mismatch in the ID token; expected "'.concat(n,'", found "').concat(t,'"'))}else{const t=e.org_name;if("string"!=typeof t)throw new Za("Organization Name (org_name) claim must be a string present in the ID token");if(t.toLowerCase()!==n.toLowerCase())throw new Za('Organization Name (org_name) claim value mismatch in the ID token; expected "'.concat(n,'", found "').concat(t,'"'))}}var Ya=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Ea(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},Ba=class extends Ya{constructor(e,t){super("mfa_list_authenticators_error",e,t),this.name="MfaListAuthenticatorsError"}},Qa=class extends Ya{constructor(e,t){super("mfa_enrollment_error",e,t),this.name="MfaEnrollmentError"}},$a=class extends Ya{constructor(e,t){super("mfa_delete_authenticator_error",e,t),this.name="MfaDeleteAuthenticatorError"}},ec=class extends Ya{constructor(e,t){super("mfa_challenge_error",e,t),this.name="MfaChallengeError"}},tc=class extends Ya{constructor(e,t){super("mfa_verify_error",e,t),this.name="MfaVerifyError"}};function nc(e){return{id:e.id,authenticatorType:e.authenticator_type,active:e.active,name:e.name,oobChannels:e.oob_channels,type:e.type}}var oc=class e{constructor(e,t,n,o,i,r,s){p(this,"accessToken",void 0),p(this,"idToken",void 0),p(this,"refreshToken",void 0),p(this,"expiresAt",void 0),p(this,"scope",void 0),p(this,"claims",void 0),p(this,"authorizationDetails",void 0),p(this,"tokenType",void 0),p(this,"issuedTokenType",void 0),p(this,"recoveryCode",void 0),p(this,"act",void 0),this.accessToken=e,this.idToken=n,this.refreshToken=o,this.expiresAt=t,this.scope=i,this.claims=r,this.authorizationDetails=s}static fromTokenEndpointResponse(t){const n=t.id_token?t.claims():void 0,o=new e(t.access_token,Math.floor(Date.now()/1e3)+Number(t.expires_in),t.id_token,t.refresh_token,t.scope,n,t.authorization_details);return o.tokenType=t.token_type,o.issuedTokenType=t.issued_token_type,o}};function ic(e,t){if(!1===t.enabled)return e;const n={name:t.name,version:t.version},o=btoa(JSON.stringify(n));return async(t,n)=>{const i=t instanceof Request?new Headers(t.headers):new Headers;if(null!=n&&n.headers){new Headers(n.headers).forEach((e,t)=>{i.set(t,e)})}return i.set("Auth0-Client",o),e(t,m(m({},n),{},{headers:i}))}}function rc(e){var t,n;return!1===(null==e?void 0:e.enabled)?e:{enabled:!0,name:null!==(t=null==e?void 0:e.name)&&void 0!==t?t:"@auth0/auth0-auth-js",version:null!==(n=null==e?void 0:e.version)&&void 0!==n?n:"1.15.0"}}function sc(e){let t;const n=async(n,o)=>{const i=await e(n,o);return t=i.clone(),i};return n.getCapturedResponse=()=>t,n}function ac(e,t,n){if(!t)return e;const o=t.signal,i=t.headers,r=t.customFetch,s=r?ic(r,n):e;return o||i?async(e,t)=>{const n=i?new Headers(e instanceof Request?e.headers:void 0):void 0;if(n&&null!=t&&t.headers&&new Headers(t.headers).forEach((e,t)=>n.set(t,e)),i)for(const e of Object.entries(i)){var r=w(e,2);const t=r[0],o=r[1],i=t.toLowerCase();"authorization"!==i&&"auth0-client"!==i&&n.set(t,o)}const a=function(e,t){if(!e)return{signal:null!=t?t:void 0};if(!t)return{signal:e};if("undefined"!=typeof AbortSignal&&"function"==typeof AbortSignal.any)return{signal:AbortSignal.any([e,t])};const n=new AbortController,o=[e,t],i=o.find(e=>e.aborted);if(i)return n.abort(i.reason),{signal:n.signal};const r=[],s=()=>{o.forEach((e,t)=>{const n=r[t];n&&e.removeEventListener("abort",n)})};return o.forEach((e,t)=>{const o=()=>{s(),n.abort(e.reason)};r[t]=o,e.addEventListener("abort",o,{once:!0})}),{signal:n.signal,cleanup:s}}(o,null==t?void 0:t.signal);try{return await s(e,m(m(m({},t),n&&{headers:n}),{},{signal:a.signal}))}finally{var c;null===(c=a.cleanup)||void 0===c||c.call(a)}}:s}var cc={otp:"http://auth0.com/oauth/grant-type/mfa-otp",oob:"http://auth0.com/oauth/grant-type/mfa-oob","recovery-code":"http://auth0.com/oauth/grant-type/mfa-recovery-code"},uc=(Cs=new WeakMap,As=new WeakMap,Rs=new WeakMap,xs=new WeakMap,Is=new WeakMap,Os=new WeakMap,js=new WeakMap,Ws=new WeakSet,class{constructor(e){var t,n;h(this,Ws),l(this,Cs,void 0),l(this,As,void 0),l(this,Rs,void 0),l(this,xs,void 0),l(this,Is,void 0),l(this,Os,void 0),l(this,js,void 0),d(Cs,this,"https://".concat(e.domain)),d(As,this,e.clientId),d(Rs,this,e.clientSecret),d(xs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(Is,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:rc()),d(Os,this,e.getConfiguration),d(js,this,e.createCaptureConfiguration)}async listAuthenticators(e,t){const n="".concat(u(Cs,this),"/mfa/authenticators"),o=e.mfaToken,i=await s(Ws,this,lc).call(this,t)(n,{method:"GET",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"}});if(!i.ok){const e=await i.clone().text(),t=i.status,n=Fa(i.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Ba("Failed to list authenticators",{error:"unknown_error",error_description:"Failed to list authenticators",statusCode:t,headers:n,body:e})}throw new Ba(o.error_description||"Failed to list authenticators",m(m({},o),{},{statusCode:t,headers:n,body:e}))}return(await i.json()).map(nc)}async enrollAuthenticator(e,t){const n="".concat(u(Cs,this),"/mfa/associate"),o=e.mfaToken,i=y(e,Es),r={authenticator_types:i.authenticatorTypes};"oobChannels"in i&&(r.oob_channels=i.oobChannels),"phoneNumber"in i&&i.phoneNumber&&(r.phone_number=i.phoneNumber),"email"in i&&i.email&&(r.email=i.email);const a=await s(Ws,this,lc).call(this,t)(n,{method:"POST",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"},body:JSON.stringify(r)});if(!a.ok){const e=await a.clone().text(),t=a.status,n=Fa(a.headers);let o;try{o=JSON.parse(e)}catch(o){throw new Qa("Failed to enroll authenticator",{error:"unknown_error",error_description:"Failed to enroll authenticator",statusCode:t,headers:n,body:e})}throw new Qa(o.error_description||"Failed to enroll authenticator",m(m({},o),{},{statusCode:t,headers:n,body:e}))}return function(e){if("otp"===e.authenticator_type)return{authenticatorType:"otp",secret:e.secret,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes,id:e.id};if("oob"===e.authenticator_type)return{authenticatorType:"oob",oobChannel:e.oob_channel,oobCode:e.oob_code,bindingMethod:e.binding_method,id:e.id,barcodeUri:e.barcode_uri,recoveryCodes:e.recovery_codes};throw new Error("Unexpected authenticator type: ".concat(e.authenticator_type))}(await a.json())}async deleteAuthenticator(e,t){const n=e.authenticatorId,o=e.mfaToken,i="".concat(u(Cs,this),"/mfa/authenticators/").concat(encodeURIComponent(n)),r=await s(Ws,this,lc).call(this,t)(i,{method:"DELETE",headers:{Authorization:"Bearer ".concat(o),"Content-Type":"application/json"}});if(!r.ok){const e=await r.clone().text(),t=r.status,n=Fa(r.headers);let o;try{o=JSON.parse(e)}catch(o){throw new $a("Failed to delete authenticator",{error:"unknown_error",error_description:"Failed to delete authenticator",statusCode:t,headers:n,body:e})}throw new $a(o.error_description||"Failed to delete authenticator",m(m({},o),{},{statusCode:t,headers:n,body:e}))}}async challengeAuthenticator(e,t){const n="".concat(u(Cs,this),"/mfa/challenge"),o=e.mfaToken,i=y(e,Ps),r={mfa_token:o,client_id:u(As,this),challenge_type:i.challengeType};u(Rs,this)&&(r.client_secret=u(Rs,this)),i.authenticatorId&&(r.authenticator_id=i.authenticatorId);const a=await s(Ws,this,lc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(r)});if(!a.ok){const e=await a.clone().text(),t=a.status,n=Fa(a.headers);let o;try{o=JSON.parse(e)}catch(o){throw new ec("Failed to challenge authenticator",{error:"unknown_error",error_description:"Failed to challenge authenticator",statusCode:t,headers:n,body:e})}throw new ec(o.error_description||"Failed to challenge authenticator",m(m({},o),{},{statusCode:t,headers:n,body:e}))}return function(e){const t={challengeType:e.challenge_type};return void 0!==e.oob_code&&(t.oobCode=e.oob_code),void 0!==e.binding_method&&(t.bindingMethod=e.binding_method),t}(await a.json())}async verify(e,t){if(!u(Os,this))throw new Error("MFA verify requires a configuration provider (getConfiguration was not set)");const n={mfa_token:e.mfaToken};if(e.audience&&(n.audience=e.audience),"otp"===e.factorType?n.otp=e.otp:"oob"===e.factorType?(n.oob_code=e.oobCode,e.bindingCode&&(n.binding_code=e.bindingCode)):"recovery-code"===e.factorType&&(n.recovery_code=e.recoveryCode),e.fullResponse){var o;if(!u(js,this))throw new Error("MFA verify fullResponse requires a capture-config factory (createCaptureConfiguration was not set)");const a=sc(null!==(o=(await u(Os,this).call(this,t))[Gi])&&void 0!==o?o:fetch),c=await u(js,this).call(this,a);try{const t=await _r(c,cc[e.factorType],n),o=oc.fromTokenEndpointResponse(t);t.recovery_code&&(o.recoveryCode=t.recovery_code);const i=a.getCapturedResponse();if(!i)throw new Ha;return{data:o,response:i}}catch(e){var i,r,s;if(e instanceof Ha)throw e;if(e instanceof tc)throw e;const t=e,n=new tc(t.error_description||t.message||"Failed to verify MFA challenge",{error:null!==(i=t.error)&&void 0!==i?i:"mfa_verify_error",error_description:null!==(r=null!==(s=t.error_description)&&void 0!==s?s:t.message)&&void 0!==r?r:"Failed to verify MFA challenge"});throw Va(n,e,a.getCapturedResponse()),n}}const a=await u(Os,this).call(this,t);try{const t=await _r(a,cc[e.factorType],n),o=oc.fromTokenEndpointResponse(t);return t.recovery_code&&(o.recoveryCode=t.recovery_code),o}catch(e){var c,l,d;if(e instanceof tc)throw e;const t=e,n=new tc(t.error_description||t.message||"Failed to verify MFA challenge",{error:null!==(c=t.error)&&void 0!==c?c:"mfa_verify_error",error_description:null!==(l=null!==(d=t.error_description)&&void 0!==d?d:t.message)&&void 0!==l?l:"Failed to verify MFA challenge"});throw Va(n,e),n}}});function lc(e){return ac(u(xs,this),e,u(Is,this))}var dc=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Ea(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},hc=class extends dc{constructor(e,t){super("passkey_register_error",e,t),this.name="PasskeyRegisterError"}},pc=class extends dc{constructor(e,t){super("passkey_challenge_error",e,t),this.name="PasskeyChallengeError"}},fc=class extends dc{constructor(e,t){super("passkey_get_token_error",e,t),this.name="PasskeyGetTokenError",this.cause=t&&{error:t.error,error_description:t.error_description,message:t.message,mfa_token:t.mfa_token,mfa_requirements:t.mfa_requirements}}};function mc(e){return e.useMtls?{}:e.clientSecret?{client_secret:e.clientSecret}:{}}var yc="urn:okta:params:oauth:grant-type:webauthn",wc=(Ms=new WeakMap,Ns=new WeakMap,Ks=new WeakMap,Us=new WeakMap,Ls=new WeakMap,zs=new WeakMap,Js=new WeakSet,class{constructor(e){var t,n;h(this,Js),l(this,Ms,void 0),l(this,Ns,void 0),l(this,Ks,void 0),l(this,Us,void 0),l(this,Ls,void 0),l(this,zs,void 0),d(Ms,this,"https://".concat(e.domain)),d(Ns,this,e.clientId),d(Ks,this,{clientSecret:e.clientSecret,useMtls:e.useMtls}),d(Us,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(Ls,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:rc()),d(zs,this,e.grantRequest)}async register(e,t){const n="".concat(u(Ms,this),"/passkey/register"),o=m(m(m(m(m(m(m(m({},e.email&&{email:e.email}),e.name&&{name:e.name}),e.phoneNumber&&{phone_number:e.phoneNumber}),e.username&&{username:e.username}),e.givenName&&{given_name:e.givenName}),e.familyName&&{family_name:e.familyName}),e.nickname&&{nickname:e.nickname}),e.picture&&{picture:e.picture}),i=m(m({client_id:u(Ns,this)},mc(u(Ks,this))),{},{user_profile:o});e.realm&&(i.realm=e.realm),e.organization&&(i.organization=e.organization),e.userMetadata&&(i.user_metadata=e.userMetadata);const r=await s(Js,this,gc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(i)});if(!r.ok){const e=await s(Js,this,vc).call(this,r),t=new hc(e.error_description||"Failed to request signup challenge",e);throw t.statusCode=r.status,t.headers=Fa(r.headers),t}const a=await r.json();return{authSession:(c=a).auth_session,authnParamsPublicKey:m({},c.authn_params_public_key)};var c}async challenge(e,t){const n="".concat(u(Ms,this),"/passkey/challenge"),o=m({client_id:u(Ns,this)},mc(u(Ks,this)));null!=e&&e.realm&&(o.realm=e.realm),null!=e&&e.organization&&(o.organization=e.organization);const i=await s(Js,this,gc).call(this,t)(n,{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(o)});if(!i.ok){const e=await s(Js,this,vc).call(this,i),t=new pc(e.error_description||"Failed to request login challenge",e);throw t.statusCode=i.status,t.headers=Fa(i.headers),t}const r=await i.json();return{authSession:(a=r).auth_session,authnParamsPublicKey:m({},a.authn_params_public_key)};var a}async getTokenByPasskey(e,t){void 0!==e.organization&&Xa(e.organization);const n=new URLSearchParams({auth_session:e.authSession,authn_response:JSON.stringify(e.credential)});let o;e.realm&&n.append("realm",e.realm),e.scope&&n.append("scope",e.scope),e.audience&&n.append("audience",e.audience),e.organization&&n.append("organization",e.organization);try{o=await u(zs,this).call(this,yc,n,t,e.fullResponse)}catch(e){if(e instanceof Ha)throw e;const t=Pa(e),n=new fc(t.error_description||"Failed to exchange passkey credential for tokens.",t);throw Va(n,e),n}if(e.fullResponse){const t=o;return e.organization&&qa(t.data.claims,e.organization),t}const i=o;return e.organization&&qa(i.claims,e.organization),i}});function gc(e){return ac(u(Us,this),e,u(Ls,this))}async function vc(e){const t=await e.clone().text();try{return m(m({},JSON.parse(t)),{},{statusCode:e.status,headers:e.headers,body:t})}catch(n){return{error:"unknown_error",error_description:"HTTP ".concat(e.status," ").concat(e.statusText),statusCode:e.status,headers:e.headers,body:t}}}var bc=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&(n.error||n.error_description)?{error:n.error,error_description:n.error_description,message:n.message,mfa_token:n.mfa_token,mfa_requirements:n.mfa_requirements}:void 0;const o=Ea(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},_c=class extends bc{constructor(e,t){super("passwordless_start_error",e,t),this.name="PasswordlessStartError"}},kc=class extends bc{constructor(e,t){super("passwordless_verify_error",e,t),this.name="PasswordlessVerifyError"}},Sc=class extends bc{constructor(e,t){super("passwordless_db_get_token_error",e,t),this.name="PasswordlessDbGetTokenError"}},Tc=class extends bc{constructor(e,t,n,o,i){super("passwordless_challenge_error",e,n),p(this,"statusCode",void 0),p(this,"validationErrors",void 0),this.name="PasswordlessChallengeError",this.statusCode=t,this.validationErrors=o,this.headers=null!=i?i:this.headers}};function Ec(e){return/^\+[1-9]\d{1,14}$/.test(e)}async function Pc(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){var o;const i=null!==(o=e.clientAssertionSigningAlg)&&void 0!==o?o:"RS256",r=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await Ts(e.clientAssertionSigningKey,i);return{client_assertion:await new os({}).setProtectedHeader({alg:i}).setIssuer(t).setSubject(t).setAudience("https://".concat(n,"/")).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime("".concat(120,"s")).sign(r),client_assertion_type:"urn:ietf:params:oauth:client-assertion-type:jwt-bearer"}}if(e.clientSecret)return{client_secret:e.clientSecret};throw new Da}var Cc=(Ds=new WeakMap,Zs=new WeakMap,Hs=new WeakMap,Fs=new WeakMap,Vs=new WeakMap,Gs=new WeakMap,Xs=new WeakMap,qs=new WeakSet,class{constructor(e){var t,n;h(this,qs),l(this,Ds,void 0),l(this,Zs,void 0),l(this,Hs,void 0),l(this,Fs,void 0),l(this,Vs,void 0),l(this,Gs,void 0),l(this,Xs,void 0),d(Zs,this,e.domain),d(Ds,this,"https://".concat(e.domain)),d(Hs,this,e.clientId),d(Fs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d(Vs,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:rc()),d(Gs,this,{clientSecret:e.clientSecret,clientAssertionSigningKey:e.clientAssertionSigningKey,clientAssertionSigningAlg:e.clientAssertionSigningAlg,useMtls:e.useMtls}),d(Xs,this,e.grantRequest)}async sendEmail(e,t){const n=await s(qs,this,Rc).call(this,function(e){var t;const n=null!==(t=e.send)&&void 0!==t?t:"code",o={email:e.email,connection:"email",send:n};return"link"===n&&e.authParams&&(o.authParams=e.authParams),o}(e),"Failed to send passwordless email",e.language,t);if(e.fullResponse)return{data:void 0,response:n}}async sendSms(e,t){if(!Ec(e.phoneNumber))throw new _c("Phone number must be in E.164 format (e.g. +14155550100).");const n=await s(qs,this,Rc).call(this,function(e){return{phone_number:e.phoneNumber,connection:"sms"}}(e),"Failed to send passwordless SMS",e.language,t);if(e.fullResponse)return{data:void 0,response:n}}async challengeWithEmail(e,t){const n=function(e){var t;return{email:e.email,connection:e.connection,allow_signup:null!==(t=e.allowSignup)&&void 0!==t&&t}}(e);return s(qs,this,xc).call(this,n,"Failed to request email OTP challenge",t)}async challengeWithPhoneNumber(e,t){if(!Ec(e.phoneNumber))throw new Tc("Phone number must be in E.164 format (e.g. +14155550100).",0,void 0,void 0);const n=function(e){var t;const n={phone_number:e.phoneNumber,connection:e.connection,allow_signup:null!==(t=e.allowSignup)&&void 0!==t&&t};return e.deliveryMethod&&(n.delivery_method=e.deliveryMethod),n}(e);return s(qs,this,xc).call(this,n,"Failed to request phone OTP challenge",t)}async getTokenByPasswordlessDbConnection(e,t){const n=new URLSearchParams({auth_session:e.authSession,otp:e.otp});if(e.scope&&n.append("scope",e.scope),e.audience&&n.append("audience",e.audience),!u(Xs,this))throw new Sc("Missing grant request delegate.",Pa(new Error("missing grantRequest")));try{return await u(Xs,this).call(this,"http://auth0.com/oauth/grant-type/passwordless/otp",n,t,e.fullResponse)}catch(e){if(e instanceof Ha)throw e;const t=new Sc("There was an error while trying to request a token.",Pa(e)),n=e;throw t.statusCode=n._statusCode,t.headers=n._headers,t}}});function Ac(e){return ac(u(Fs,this),e,u(Vs,this))}async function Rc(e,t,n,o){var i;const r=await Pc(u(Gs,this),u(Hs,this),u(Zs,this)),a=m(m({client_id:u(Hs,this)},e),r);let c;try{c=await s(qs,this,Ac).call(this,o)("".concat(u(Ds,this),"/passwordless/start"),{method:"POST",headers:m({"Content-Type":"application/json"},n?{"x-request-language":n}:{}),body:JSON.stringify(a)})}catch(e){throw new _c("".concat(t,": a network error occurred."))}if(c.ok)return c;const l=await c.clone().text();let d;if(204!==c.status)try{d=JSON.parse(l)}catch(e){d=void 0}const h=new _c((null===(i=d)||void 0===i?void 0:i.error_description)||t,d);throw h.statusCode=c.status,h.headers=Fa(c.headers),h.body=l,h}async function xc(e,t,n){var o,i;const r=await Pc(u(Gs,this),u(Hs,this),u(Zs,this)),a=m(m({client_id:u(Hs,this)},e),r);let c;try{c=await s(qs,this,Ac).call(this,n)("".concat(u(Ds,this),"/otp/challenge"),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(a)})}catch(e){throw new Tc("challenge error: a network error occurred.",0,void 0,void 0)}if(c.ok){let e;try{e=await c.json()}catch(e){throw new Tc("".concat(t,": could not parse the response body."),c.status,void 0,void 0,Fa(c.headers))}return{authSession:e.auth_session}}const l=await c.clone().text();let d;try{d=JSON.parse(l)}catch(e){d=void 0}const h=d?m(m({},d),{},{statusCode:c.status,headers:c.headers,body:l}):{error:"",error_description:"",statusCode:c.status,headers:c.headers,body:l};throw new Tc((null===(o=d)||void 0===o?void 0:o.error_description)||t,c.status,h,null===(i=d)||void 0===i?void 0:i.validation_errors,Fa(c.headers))}var Ic=class extends Error{constructor(e,t,n){super(t),p(this,"cause",void 0),p(this,"code",void 0),p(this,"statusCode",void 0),p(this,"headers",void 0),p(this,"body",void 0),Object.setPrototypeOf(this,new.target.prototype),this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message};const o=Ea(n);this.statusCode=o.statusCode,this.headers=o.headers,this.body=o.body}},Oc=class extends Ic{constructor(e,t){super("signup_error",e,t),this.name="SignUpError"}},jc=class extends Ic{constructor(e,t){super("change_password_error",e,t),this.name="ChangePasswordError"}};function Wc(e,t,n){for(const o of t)if(null===e[o]||void 0===e[o]||""===e[o])throw new n('Required parameter "'.concat(String(o),'" was null, undefined, or empty.'))}function Mc(e){var t,n;return{id:null!==(t=null!==(n=e._id)&&void 0!==n?n:e.user_id)&&void 0!==t?t:e.id,email:"string"==typeof e.email?e.email:"",emailVerified:Boolean(e.email_verified),username:e.username,givenName:e.given_name,familyName:e.family_name,name:e.name,nickname:e.nickname,picture:e.picture,userMetadata:e.user_metadata}}var Nc=(Ys=new WeakMap,Bs=new WeakMap,Qs=new WeakMap,$s=new WeakMap,ea=new WeakSet,class{constructor(e){var t,n;h(this,ea),l(this,Ys,void 0),l(this,Bs,void 0),l(this,Qs,void 0),l(this,$s,void 0),d(Ys,this,"https://".concat(e.domain)),d(Bs,this,e.clientId),d(Qs,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)}),d($s,this,null!==(n=e.telemetryConfig)&&void 0!==n?n:rc())}async signUp(e,t){var n;Wc(e,["email","password","connection"],Oc);const o=m({client_id:null!==(n=e.clientId)&&void 0!==n?n:u(Bs,this)},function(e){const t={email:e.email,password:e.password,connection:e.connection};return void 0!==e.username&&(t.username=e.username),void 0!==e.givenName&&(t.given_name=e.givenName),void 0!==e.familyName&&(t.family_name=e.familyName),void 0!==e.name&&(t.name=e.name),void 0!==e.nickname&&(t.nickname=e.nickname),void 0!==e.picture&&(t.picture=e.picture),void 0!==e.userMetadata&&(t.user_metadata=e.userMetadata),t}(e)),i=await s(ea,this,Kc).call(this,"/dbconnections/signup",o,Oc,"Failed to sign up",t);if(e.fullResponse){const e=i.clone();return{data:Mc(await i.json()),response:e}}return Mc(await i.json())}async changePassword(e,t){var n;if(Wc(e,["connection"],jc),!e.email&&!e.username)throw new jc('Either "email" or "username" is required.');const o=m({client_id:null!==(n=e.clientId)&&void 0!==n?n:u(Bs,this)},function(e){const t={connection:e.connection};return void 0!==e.email&&(t.email=e.email),void 0!==e.username&&(t.username=e.username),void 0!==e.organization&&(t.organization=e.organization),t}(e)),i=await s(ea,this,Kc).call(this,"/dbconnections/change_password",o,jc,"Failed to request a password change",t);if(e.fullResponse){const e=i.clone();return{data:await i.text(),response:e}}return i.text()}});async function Kc(e,t,n,o,i){const r=ac(u(Qs,this),i,u($s,this));let s;try{s=await r("".concat(u(Ys,this)).concat(e),{method:"POST",headers:{"Content-Type":"application/json"},body:JSON.stringify(t)})}catch(e){throw new n("".concat(o,": a network error occurred."))}if(s.ok)return s;const a=await s.clone().text(),c=await async function(e){let t;try{t=await e.json()}catch(e){return}return"string"==typeof t.error?t:"string"==typeof t.code?{error:t.code,error_description:"string"==typeof t.description?t.description:""}:void 0}(s.clone()),l=new n((null==c?void 0:c.error_description)||o,null!=c?c:{error:"unknown_error",error_description:o});throw l.statusCode=s.status,l.headers=Fa(s.headers),l.body=a,l}var Uc=class extends Error{constructor(e,t,n){super(t),p(this,"code",void 0),p(this,"cause",void 0),this.name="AnonymousSessionError",this.code=e,this.cause=n&&{error:n.error,error_description:n.error_description,message:n.message}}};var Lc=new Set(["session_expired","invalid_session_token"]);async function zc(e){const t="Request failed with status ".concat(e.status);let n={};try{n=await e.json()}catch(e){}return{error:"string"==typeof n.error?n.error:"server_error",error_description:"string"==typeof n.error_description?n.error_description:t}}var Jc=(ta=new WeakMap,na=new WeakMap,oa=new WeakMap,ia=new WeakMap,ra=new WeakMap,sa=new WeakMap,aa=new WeakMap,ca=new WeakMap,ua=new WeakSet,class{constructor(e){var t;h(this,ua),l(this,ta,void 0),l(this,na,void 0),l(this,oa,void 0),l(this,ia,void 0),l(this,ra,void 0),l(this,sa,void 0),l(this,aa,void 0),l(this,ca,void 0),d(ta,this,e.domain),d(na,this,"https://".concat(e.domain)),d(oa,this,e.clientId),d(ia,this,e.clientSecret),d(ra,this,e.clientAssertionSigningKey),d(sa,this,e.clientAssertionSigningAlg),d(aa,this,e.useMtls),d(ca,this,null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)})}async createSession(e){const t={client_id:u(oa,this)};null!=e&&e.audience&&(t.audience=e.audience),null!=e&&e.scope&&(t.scope=e.scope),null!=e&&e.metadata&&(t.metadata=e.metadata);const n=await s(ua,this,Zc).call(this,t);if(!n.sessionToken)throw new Uc("server_error","session_token missing from create session response");return{sessionToken:n.sessionToken,accessToken:n.accessToken,expiresAt:n.expiresAt,sessionTokenExpiresAt:n.sessionTokenExpiresAt,scope:n.scope}}async getAccessToken(e){if(null==e||!e.sessionToken)return this.createSession({audience:null==e?void 0:e.audience,scope:null==e?void 0:e.scope});try{return await s(ua,this,Dc).call(this,e.sessionToken,e)}catch(t){if(t instanceof Uc&&Lc.has(t.code)){return m(m({},await this.createSession({audience:null==e?void 0:e.audience,scope:null==e?void 0:e.scope})),{},{sessionReplaced:!0})}throw t}}async logout(){const e="".concat(u(na,this),"/anonymous/logout"),t={client_id:u(oa,this)},n=await u(ca,this).call(this,e,{method:"POST",headers:{"Content-Type":"application/json"},credentials:"include",redirect:"error",body:JSON.stringify(t)});if(!n.ok){const e=await zc(n);throw new Uc(e.error,e.error_description||"Failed to end anonymous session",e)}}});async function Dc(e,t){const n={client_id:u(oa,this),session_token:e};null!=t&&t.audience&&(n.audience=t.audience),null!=t&&t.scope&&(n.scope=t.scope);const o=await s(ua,this,Zc).call(this,n);return{sessionToken:e,accessToken:o.accessToken,expiresAt:o.expiresAt,sessionTokenExpiresAt:o.sessionTokenExpiresAt,scope:o.scope,sessionReplaced:!1}}async function Zc(e){const t="".concat(u(na,this),"/anonymous/token"),n=await async function(e,t,n){if(e.useMtls)return{};if(e.clientAssertionSigningKey){var o;const i=null!==(o=e.clientAssertionSigningAlg)&&void 0!==o?o:"RS256",r=e.clientAssertionSigningKey instanceof CryptoKey?e.clientAssertionSigningKey:await Ts(e.clientAssertionSigningKey,i);return{client_assertion:await new os({}).setProtectedHeader({alg:i}).setIssuer(t).setSubject(t).setAudience("https://".concat(n,"/")).setJti(crypto.randomUUID()).setIssuedAt().setExpirationTime("".concat(120,"s")).sign(r),client_assertion_type:"urn:ietf:params:oauth:client-assertion-type:jwt-bearer"}}return e.clientSecret?{client_secret:e.clientSecret}:{}}({clientSecret:u(ia,this),clientAssertionSigningKey:u(ra,this),clientAssertionSigningAlg:u(sa,this),useMtls:u(aa,this)},u(oa,this),u(ta,this));Object.assign(e,n);const o=await u(ca,this).call(this,t,{method:"POST",headers:{"Content-Type":"application/json"},credentials:"include",redirect:"error",body:JSON.stringify(e)});if(!o.ok){const e=await zc(o);throw new Uc(e.error,e.error_description||"Anonymous token request failed",e)}let i;try{i=await o.json()}catch(e){throw new Uc("server_error","Invalid response from anonymous token endpoint")}return function(e){const t=Math.floor(Date.now()/1e3);if("string"!=typeof e.access_token||!e.access_token)throw new Uc("server_error","access_token missing or invalid in anonymous token response");const n=e.expires_in;if("number"!=typeof n||!Number.isFinite(n))throw new Uc("server_error","expires_in missing or invalid in anonymous token response");return{accessToken:e.access_token,expiresAt:t+n,scope:e.scope,sessionToken:e.session_token,sessionTokenExpiresAt:"number"==typeof e.session_expires_in&&Number.isFinite(e.session_expires_in)?t+e.session_expires_in:void 0}}(i)}var Hc=(la=new WeakMap,da=new WeakMap,ha=new WeakMap,class{constructor(e,t){l(this,la,new Map),l(this,da,void 0),l(this,ha,void 0),d(ha,this,Math.max(1,Math.floor(e))),d(da,this,Math.max(0,Math.floor(t)))}get(e){const t=u(la,this).get(e);if(t){if(!(Date.now()>=t.expiresAt))return u(la,this).delete(e),u(la,this).set(e,t),t.value;u(la,this).delete(e)}}set(e,t,n){u(la,this).has(e)&&u(la,this).delete(e);const o=null!=n&&Number.isFinite(n)&&n>0?n:u(da,this);for(u(la,this).set(e,{value:t,expiresAt:Date.now()+o});u(la,this).size>u(ha,this);){const e=u(la,this).keys().next().value;if(void 0===e)break;u(la,this).delete(e)}}}),Fc=new Map;function Vc(e){return{ttlMs:1e3*("number"==typeof(null==e?void 0:e.ttl)?e.ttl:600),maxEntries:"number"==typeof(null==e?void 0:e.maxEntries)&&e.maxEntries>0?e.maxEntries:100}}var Gc=class{static createDiscoveryCache(e){const t=(n=e.maxEntries,o=e.ttlMs,"".concat(n,":").concat(o));var n,o;let i=(r=t,Fc.get(r));var r;return i||(i=new Hc(e.maxEntries,e.ttlMs),Fc.set(t,i)),i}static createJwksCache(){return{}}},Xc="openid profile email offline_access",qc=Object.freeze(new Set(["grant_type","client_id","client_secret","client_assertion","client_assertion_type","subject_token","subject_token_type","requested_token_type","actor_token","actor_token_type","audience","aud","resource","resources","resource_indicator","scope","connection","login_hint","organization","assertion"]));function Yc(e){if(null==e)throw new Wa("subject_token is required");if("string"!=typeof e)throw new Wa("subject_token must be a string");if(0===e.trim().length)throw new Wa("subject_token cannot be blank or whitespace");if(e!==e.trim())throw new Wa("subject_token must not include leading or trailing whitespace");if(/^bearer\s+/i.test(e))throw new Wa("subject_token must not include the 'Bearer ' prefix")}function Bc(e,t){if(t)for(const o of Object.entries(t)){var n=w(o,2);const t=n[0],i=n[1];if(!qc.has(t))if(Array.isArray(i)){if(i.length>20)throw new Wa("Parameter '".concat(t,"' exceeds maximum array size of ").concat(20));i.forEach(n=>{e.append(t,n)})}else e.append(t,i)}}var Qc="urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token",$c="urn:ietf:params:oauth:grant-type:token-exchange",eu="urn:ietf:params:oauth:token-type:access_token";function tu(e,t){return(n,o)=>{const i=null==o?void 0:o.body;if(t!==yc||!(i instanceof URLSearchParams))return e(n,o);const r={};for(const e of i){var s=w(e,2);const t=s[0],n=s[1];r[t]="authn_response"===t?JSON.parse(n):n}const a=new Headers(null==o?void 0:o.headers);return a.set("Content-Type","application/json"),e(n,m(m({},o),{},{headers:a,body:JSON.stringify(r)}))}}var nu=(pa=new WeakMap,fa=new WeakMap,ma=new WeakMap,ya=new WeakMap,wa=new WeakMap,ga=new WeakMap,va=new WeakMap,ba=new WeakMap,_a=new WeakMap,ka=new WeakMap,Sa=new WeakMap,Ta=new WeakSet,class{constructor(e){var t;if(h(this,Ta),l(this,pa,void 0),l(this,fa,void 0),l(this,ma,void 0),l(this,ya,void 0),l(this,wa,void 0),l(this,ga,void 0),l(this,va,void 0),l(this,ba,void 0),l(this,_a,void 0),l(this,ka,void 0),l(this,Sa,void 0),p(this,"mfa",void 0),p(this,"passkey",void 0),p(this,"passwordless",void 0),p(this,"database",void 0),p(this,"anonymous",void 0),d(wa,this,e),e.useMtls&&!e.customFetch)throw new Ca("mtls_without_custom_fetch_not_supported","Using mTLS without a custom fetch implementation is not supported");d(va,this,rc(e.telemetry)),d(ga,this,ic(null!==(t=e.customFetch)&&void 0!==t?t:function(){return fetch(...arguments)},u(va,this)));const n=Vc(e.discoveryCache);d(_a,this,Gc.createDiscoveryCache(n)),d(ka,this,new Map),d(Sa,this,Gc.createJwksCache()),this.mfa=new uc({domain:u(wa,this).domain,clientId:u(wa,this).clientId,clientSecret:u(wa,this).clientSecret,customFetch:u(ga,this),telemetryConfig:u(va,this),getConfiguration:async e=>(await s(Ta,this,su).call(this,e)).configuration,createCaptureConfiguration:async e=>{const t=(await s(Ta,this,au).call(this)).serverMetadata;return s(Ta,this,iu).call(this,t,e)}}),this.passkey=new wc({domain:u(wa,this).domain,clientId:u(wa,this).clientId,clientSecret:u(wa,this).clientSecret,useMtls:u(wa,this).useMtls,customFetch:u(ga,this),telemetryConfig:u(va,this),grantRequest:async(e,t,n,o)=>{const i=(await s(Ta,this,au).call(this)).serverMetadata,r=s(Ta,this,ru).call(this,n);if(o){const n=sc(r),o=await s(Ta,this,iu).call(this,i,n);o[Gi]=tu(n,e);const a=await _r(o,e,t),c=oc.fromTokenEndpointResponse(a),u=n.getCapturedResponse();if(!u)throw new Ha;return{data:c,response:u}}const a=await s(Ta,this,iu).call(this,i);a[Gi]=tu(r,e);const c=await _r(a,e,t);return oc.fromTokenEndpointResponse(c)}}),this.passwordless=new Cc({domain:u(wa,this).domain,clientId:u(wa,this).clientId,customFetch:u(ga,this),telemetryConfig:u(va,this),clientSecret:u(wa,this).clientSecret,clientAssertionSigningKey:u(wa,this).clientAssertionSigningKey,clientAssertionSigningAlg:u(wa,this).clientAssertionSigningAlg,useMtls:u(wa,this).useMtls,grantRequest:async(e,t,n,o)=>{const i=(await s(Ta,this,su).call(this,n)).configuration;if(o){var r;const n=sc(null!==(r=i[Gi])&&void 0!==r?r:u(ga,this)),o=await s(Ta,this,iu).call(this,i.serverMetadata(),n),a=await _r(o,e,t),c=oc.fromTokenEndpointResponse(a),l=n.getCapturedResponse();if(!l)throw new Ha;return{data:c,response:l}}try{const n=await _r(i,e,t);return oc.fromTokenEndpointResponse(n)}catch(e){const t=e,n={};throw Va(n,e),t._statusCode=n.statusCode,t._headers=n.headers,e}}}),this.database=new Nc({domain:u(wa,this).domain,clientId:u(wa,this).clientId,customFetch:u(ga,this),telemetryConfig:u(va,this)}),this.anonymous=new Jc({domain:u(wa,this).domain,clientId:u(wa,this).clientId,clientSecret:u(wa,this).clientSecret,clientAssertionSigningKey:u(wa,this).clientAssertionSigningKey,clientAssertionSigningAlg:u(wa,this).clientAssertionSigningAlg,useMtls:u(wa,this).useMtls,customFetch:u(ga,this)})}async getServerMetadata(){return(await s(Ta,this,au).call(this)).serverMetadata}async buildAuthorizationUrl(e){const t=(await s(Ta,this,au).call(this)).serverMetadata;if(null!=e&&e.pushedAuthorizationRequests&&!t.pushed_authorization_request_endpoint)throw new Ca("par_not_supported_error","The Auth0 tenant does not have pushed authorization requests enabled. Learn how to enable it here: https://auth0.com/docs/get-started/applications/configure-par");try{return await s(Ta,this,fu).call(this,e)}catch(e){throw new La(e)}}async buildLinkUserUrl(e){try{const t=await s(Ta,this,fu).call(this,{authorizationParams:m(m({},e.authorizationParams),{},{requested_connection:e.connection,requested_connection_scope:e.connectionScope,scope:"openid link_account offline_access",id_token_hint:e.idToken})});return{linkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new za(e)}}async buildUnlinkUserUrl(e){try{const t=await s(Ta,this,fu).call(this,{authorizationParams:m(m({},e.authorizationParams),{},{requested_connection:e.connection,scope:"openid unlink_account",id_token_hint:e.idToken})});return{unlinkUserUrl:t.authorizationUrl,codeVerifier:t.codeVerifier}}catch(e){throw new Ja(e)}}async backchannelAuthentication(e,t){var n;const o=await s(Ta,this,su).call(this,t),i=o.configuration,r=o.serverMetadata,a=Ga(m(m({},u(wa,this).authorizationParams),null==e?void 0:e.authorizationParams)),c=new URLSearchParams(m(m({scope:Xc},a),{},{client_id:u(wa,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:r.issuer,sub:e.loginHint.sub})}));if(e.requestedExpiry&&c.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&c.append("authorization_details",JSON.stringify(e.authorizationDetails)),e.fullResponse){var l;const e=sc(null!==(l=i[Gi])&&void 0!==l?l:u(ga,this)),t=await s(Ta,this,iu).call(this,i.serverMetadata(),e);try{const n=await cr(i,c),o=await ur(t,n),r=e.getCapturedResponse();if(!r)throw new Ha;return{data:oc.fromTokenEndpointResponse(o),response:r}}catch(t){if(t instanceof Ha)throw t;const n=new Ua(t);throw Va(n,t,e.getCapturedResponse()),n}}const d=sc(null!==(n=i[Gi])&&void 0!==n?n:u(ga,this)),h=await s(Ta,this,iu).call(this,i.serverMetadata(),d);try{const e=await cr(i,c),t=await ur(h,e);return oc.fromTokenEndpointResponse(t)}catch(e){const t=new Ua(e);throw Va(t,e,d.getCapturedResponse()),t}}async initiateBackchannelAuthentication(e,t){var n;const o=await s(Ta,this,su).call(this,t),i=o.configuration,r=o.serverMetadata,a=Ga(m(m({},u(wa,this).authorizationParams),null==e?void 0:e.authorizationParams)),c=new URLSearchParams(m(m({scope:Xc},a),{},{client_id:u(wa,this).clientId,binding_message:e.bindingMessage,login_hint:JSON.stringify({format:"iss_sub",iss:r.issuer,sub:e.loginHint.sub})}));e.requestedExpiry&&c.append("requested_expiry",e.requestedExpiry.toString()),e.authorizationDetails&&c.append("authorization_details",JSON.stringify(e.authorizationDetails));const l=sc(null!==(n=i[Gi])&&void 0!==n?n:u(ga,this)),d=await s(Ta,this,iu).call(this,i.serverMetadata(),l);try{const e=await cr(d,c);return{authReqId:e.auth_req_id,expiresIn:e.expires_in,interval:e.interval}}catch(e){const t=new Ua(e),n=l.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async backchannelAuthenticationGrant(e,t){var n;let o=e.authReqId;const i=(await s(Ta,this,su).call(this,t)).configuration,r=new URLSearchParams({auth_req_id:o}),a=sc(null!==(n=i[Gi])&&void 0!==n?n:u(ga,this)),c=await s(Ta,this,iu).call(this,i.serverMetadata(),a);try{const e=await _r(c,"urn:openid:params:grant-type:ciba",r);return oc.fromTokenEndpointResponse(e)}catch(e){const t=new Ua(e),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async getTokenForConnection(e,t){var n;if(e.refreshToken&&e.accessToken)throw new ja("Either a refresh or access token should be specified, but not both.");const o=null!==(n=e.accessToken)&&void 0!==n?n:e.refreshToken;if(!o)throw new ja("Either a refresh or access token must be specified.");try{return await this.exchangeToken(m({connection:e.connection,subjectToken:o,subjectTokenType:e.accessToken?eu:"urn:ietf:params:oauth:token-type:refresh_token",loginHint:e.loginHint},e.fullResponse?{fullResponse:!0}:{}),t)}catch(e){if(e instanceof Wa){const t=new ja(e.message,e.cause);throw t.statusCode=e.statusCode,t.headers=e.headers,t}throw e}}async exchangeToken(e,t){return e.fullResponse?"connection"in e?s(Ta,this,uu).call(this,e,t,!0):s(Ta,this,du).call(this,e,t,!0):"connection"in e?s(Ta,this,uu).call(this,e,t):s(Ta,this,du).call(this,e,t)}async getTokenByCode(e,t,n){var o;const i=(await s(Ta,this,su).call(this,n)).configuration;if(void 0!==t.organization&&Xa(t.organization),t.fullResponse){var r;const n=sc(null!==(r=i[Gi])&&void 0!==r?r:u(ga,this)),o=await s(Ta,this,iu).call(this,i.serverMetadata(),n);let a,c;try{const i=await dr(o,e,{pkceCodeVerifier:t.codeVerifier});if(a=oc.fromTokenEndpointResponse(i),c=n.getCapturedResponse(),!c)throw new Ha}catch(e){if(e instanceof Ha)throw e;const t=new Ra("There was an error while trying to request a token.",Pa(e)),o=n.getCapturedResponse();throw t.statusCode=null==o?void 0:o.status,t.headers=o?Fa(o.headers):void 0,t}return t.organization&&qa(a.claims,t.organization),{data:a,response:c}}const a=sc(null!==(o=i[Gi])&&void 0!==o?o:u(ga,this)),c=await s(Ta,this,iu).call(this,i.serverMetadata(),a);let l;try{const n=await dr(c,e,{pkceCodeVerifier:t.codeVerifier});l=oc.fromTokenEndpointResponse(n)}catch(e){const t=new Ra("There was an error while trying to request a token.",Pa(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}return t.organization&&qa(l.claims,t.organization),l}async getTokenByMagicLinkCode(e,t,n){var o;const i=(await s(Ta,this,su).call(this,n)).configuration;if(null!=t&&t.fullResponse){var r;const n=sc(null!==(r=i[Gi])&&void 0!==r?r:u(ga,this)),o=await s(Ta,this,iu).call(this,i.serverMetadata(),n);try{const i=await dr(o,e,{expectedState:null==t?void 0:t.expectedState}),r=oc.fromTokenEndpointResponse(i),s=n.getCapturedResponse();if(!s)throw new Ha;return{data:r,response:s}}catch(e){if(e instanceof Ha)throw e;const t=e instanceof Error&&e.message?e.message:"There was an error while trying to request a token.",o=new Ra(t,e),i=n.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Fa(i.headers):void 0,o}}const a=sc(null!==(o=i[Gi])&&void 0!==o?o:u(ga,this)),c=await s(Ta,this,iu).call(this,i.serverMetadata(),a);try{const n=await dr(c,e,{expectedState:null==t?void 0:t.expectedState});return oc.fromTokenEndpointResponse(n)}catch(e){const t=e instanceof Error&&e.message?e.message:"There was an error while trying to request a token.",n=new Ra(t,e),o=a.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}}async getTokenByRefreshToken(e,t){var n;const o=(await s(Ta,this,su).call(this,t)).configuration,i=new URLSearchParams;if(e.audience&&i.append("audience",e.audience),e.scope&&i.append("scope",e.scope),e.fullResponse){var r;const t=sc(null!==(r=o[Gi])&&void 0!==r?r:u(ga,this)),n=await s(Ta,this,iu).call(this,o.serverMetadata(),t);try{const o=await hr(n,e.refreshToken,i),r=oc.fromTokenEndpointResponse(o),s=t.getCapturedResponse();if(!s)throw new Ha;return{data:r,response:s}}catch(e){if(e instanceof Ha)throw e;const n=new Ia("The access token has expired and there was an error while trying to refresh it.",Pa(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}}const a=sc(null!==(n=o[Gi])&&void 0!==n?n:u(ga,this)),c=await s(Ta,this,iu).call(this,o.serverMetadata(),a);try{const t=await hr(c,e.refreshToken,i);return oc.fromTokenEndpointResponse(t)}catch(e){const t=new Ia("The access token has expired and there was an error while trying to refresh it.",Pa(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async revokeToken(e,t){var n;const o=(await s(Ta,this,su).call(this,t)).configuration,i={};e.tokenTypeHint&&(i.token_type_hint=e.tokenTypeHint);const r=sc(null!==(n=o[Gi])&&void 0!==n?n:u(ga,this)),a=await s(Ta,this,iu).call(this,o.serverMetadata(),r);try{await kr(a,e.token,i)}catch(e){const t=new Ma("An error occurred while trying to revoke the token.",Pa(e)),n=r.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async getUserInfo(e,t){const n=(await s(Ta,this,su).call(this,t,!0)).configuration;try{var o;return await gr(n,e.accessToken,null!==(o=e.expectedSubject)&&void 0!==o?o:Vi)}catch(e){throw new Na("There was an error while trying to retrieve the user info.",Pa(e))}}async getTokenByPassword(e,t){var n;const o=(await s(Ta,this,su).call(this,t)).configuration,i=new URLSearchParams({username:e.username,password:e.password});e.audience&&i.append("audience",e.audience),e.scope&&i.append("scope",e.scope),e.realm&&i.append("realm",e.realm);let r=o;if(e.auth0ForwardedFor){const t=await s(Ta,this,pu).call(this);r=new ir(o.serverMetadata(),u(wa,this).clientId,{client_secret:u(wa,this).clientSecret,use_mtls_endpoint_aliases:u(wa,this).useMtls},t);const n=o[Gi];r[Gi]=(t,o)=>n(t,m(m({},o),{},{headers:m(m({},o.headers),{},{"auth0-forwarded-for":e.auth0ForwardedFor})}))}if(e.fullResponse){var a;const e=sc(null!==(a=r[Gi])&&void 0!==a?a:u(ga,this)),t=await s(Ta,this,iu).call(this,r.serverMetadata(),e);try{const n=await _r(t,"password",i),o=oc.fromTokenEndpointResponse(n),r=e.getCapturedResponse();if(!r)throw new Ha;return{data:o,response:r}}catch(t){if(t instanceof Ha)throw t;const n=new Oa("There was an error while trying to request a token.",Pa(t)),o=e.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}}const c=sc(null!==(n=r[Gi])&&void 0!==n?n:u(ga,this)),l=await s(Ta,this,iu).call(this,r.serverMetadata(),c);try{const e=await _r(l,"password",i);return oc.fromTokenEndpointResponse(e)}catch(e){const t=new Oa("There was an error while trying to request a token.",Pa(e)),n=c.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async getTokenByPasswordlessEmail(e,t){const n=new URLSearchParams({username:e.email,otp:e.code,realm:"email"});return e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),s(Ta,this,hu).call(this,n,t,e.fullResponse)}async getTokenByPasswordlessSms(e,t){if(!Ec(e.phoneNumber))throw new kc("Phone number must be in E.164 format (e.g. +14155550100).");const n=new URLSearchParams({username:e.phoneNumber,otp:e.code,realm:"sms"});return e.audience&&n.append("audience",e.audience),e.scope&&n.append("scope",e.scope),s(Ta,this,hu).call(this,n,t,e.fullResponse)}async getTokenByClientCredentials(e,t){var n;const o=(await s(Ta,this,su).call(this,t)).configuration;if(e.fullResponse){var i;const t=sc(null!==(i=o[Gi])&&void 0!==i?i:u(ga,this)),n=await s(Ta,this,iu).call(this,o.serverMetadata(),t),r=new URLSearchParams({audience:e.audience});e.organization&&r.append("organization",e.organization);try{const e=await pr(n,r),o=oc.fromTokenEndpointResponse(e),i=t.getCapturedResponse();if(!i)throw new Ha;return{data:o,response:i}}catch(e){if(e instanceof Ha)throw e;const n=new xa("There was an error while trying to request a token.",Pa(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}}const r=sc(null!==(n=o[Gi])&&void 0!==n?n:u(ga,this)),a=await s(Ta,this,iu).call(this,o.serverMetadata(),r);try{const t=new URLSearchParams({audience:e.audience});e.organization&&t.append("organization",e.organization);const n=await pr(a,t);return oc.fromTokenEndpointResponse(n)}catch(e){const t=new xa("There was an error while trying to request a token.",Pa(e)),n=r.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async buildLogoutUrl(e){const t=await s(Ta,this,au).call(this),n=t.configuration;if(!t.serverMetadata.end_session_endpoint){const t=new URL("https://".concat(u(wa,this).domain,"/v2/logout"));return t.searchParams.set("returnTo",e.returnTo),t.searchParams.set("client_id",u(wa,this).clientId),e.federated&&t.searchParams.set("federated",""),t}const o={post_logout_redirect_uri:e.returnTo};return e.federated&&(o.federated=""),function(e,t){yr(e);const n=Di(e),o=n.as,i=n.c,r=Sn(o,"end_session_endpoint",!1,n.tlsOnly);(t=new URLSearchParams(t)).has("client_id")||t.set("client_id",i.client_id);for(const e of t.entries()){var s=w(e,2);const t=s[0],n=s[1];r.searchParams.append(t,n)}return r}(n,o)}async verifyLogoutToken(e){const t=(await s(Ta,this,au).call(this)).serverMetadata,n=Vc(u(wa,this).discoveryCache),o=t.jwks_uri;u(ba,this)||d(ba,this,Ss(new URL(o),{cacheMaxAge:n.ttlMs,[vs]:u(ga,this),[bs]:u(Sa,this)}));const i=(await Yr(e.logoutToken,u(ba,this),{issuer:t.issuer,audience:u(wa,this).clientId,algorithms:["RS256"],requiredClaims:["iat"]})).payload;if(!("sid"in i)&&!("sub"in i))throw new Ka('either "sid" or "sub" (or both) claims must be present');if("sid"in i&&"string"!=typeof i.sid)throw new Ka('"sid" claim must be a string');if("sub"in i&&"string"!=typeof i.sub)throw new Ka('"sub" claim must be a string');if("nonce"in i)throw new Ka('"nonce" claim is prohibited');if(!("events"in i))throw new Ka('"events" claim is missing');if("object"!=typeof i.events||null===i.events)throw new Ka('"events" claim must be an object');if(!("http://schemas.openid.net/event/backchannel-logout"in i.events))throw new Ka('"http://schemas.openid.net/event/backchannel-logout" member is missing in the "events" claim');if("object"!=typeof i.events["http://schemas.openid.net/event/backchannel-logout"])throw new Ka('"http://schemas.openid.net/event/backchannel-logout" member in the "events" claim must be an object');return{sid:i.sid,sub:i.sub}}});function ou(){const e=u(wa,this).domain.toLowerCase();return"".concat(e,"|mtls:").concat(u(wa,this).useMtls?"1":"0")}async function iu(e,t){let n=arguments.length>2&&void 0!==arguments[2]&&arguments[2];const o=await s(Ta,this,pu).call(this,n),i=new ir(e,u(wa,this).clientId,{client_secret:u(wa,this).clientSecret,use_mtls_endpoint_aliases:u(wa,this).useMtls},o);return i[Gi]=null!=t?t:u(ga,this),i}function ru(e){return ac(u(ga,this),e,u(va,this))}async function su(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1];const n=await s(Ta,this,au).call(this,t),o=n.configuration,i=n.serverMetadata;if(!e)return{configuration:o,serverMetadata:i};const r=s(Ta,this,ru).call(this,e);return{configuration:await s(Ta,this,iu).call(this,i,r,t),serverMetadata:i}}async function au(){let e=arguments.length>0&&void 0!==arguments[0]&&arguments[0];const t=u(e?fa:pa,this);if(t&&u(ma,this))return{configuration:t,serverMetadata:u(ma,this)};const n=s(Ta,this,ou).call(this);e||await s(Ta,this,pu).call(this,!1);const o=u(_a,this).get(n);if(o)return s(Ta,this,cu).call(this,o.serverMetadata,e);const i=u(ka,this).get(n);if(i){const t=await i;return s(Ta,this,cu).call(this,t.serverMetadata,e)}const r=(async()=>{const e=(await nr(new URL("https://".concat(u(wa,this).domain)),u(wa,this).clientId,{use_mtls_endpoint_aliases:u(wa,this).useMtls},(e,t,n,o)=>{n.set("client_id",t.client_id)},{[Gi]:u(ga,this)})).serverMetadata();return u(_a,this).set(n,{serverMetadata:e}),{serverMetadata:e}})();r.catch(()=>{}),u(ka,this).set(n,r);try{const t=(await r).serverMetadata;return s(Ta,this,cu).call(this,t,e)}finally{u(ka,this).delete(n)}}async function cu(e,t){const n=await s(Ta,this,iu).call(this,e,void 0,t);return d(ma,this,e),d(t?fa:pa,this,n),{configuration:n,serverMetadata:e}}async function uu(e,t,n){var o,i,r;const a=(await s(Ta,this,su).call(this,t)).configuration;if("audience"in e||"resource"in e)throw new Wa("audience and resource parameters are not supported for Token Vault exchanges");Yc(e.subjectToken);const c=new URLSearchParams({connection:e.connection,subject_token:e.subjectToken,subject_token_type:null!==(o=e.subjectTokenType)&&void 0!==o?o:eu,requested_token_type:null!==(i=e.requestedTokenType)&&void 0!==i?i:"http://auth0.com/oauth/token-type/federated-connection-access-token"});if(e.loginHint&&c.append("login_hint",e.loginHint),e.scope&&c.append("scope",e.scope),Bc(c,e.extra),n){var l;const t=sc(null!==(l=a[Gi])&&void 0!==l?l:u(ga,this)),n=await s(Ta,this,iu).call(this,a.serverMetadata(),t);try{const e=await _r(n,Qc,c),o=oc.fromTokenEndpointResponse(e),i=t.getCapturedResponse();if(!i)throw new Ha;return{data:o,response:i}}catch(n){if(n instanceof Ha)throw n;const o=new Wa("Failed to exchange token for connection '".concat(e.connection,"'."),Pa(n)),i=t.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Fa(i.headers):void 0,o}}const d=sc(null!==(r=a[Gi])&&void 0!==r?r:u(ga,this)),h=await s(Ta,this,iu).call(this,a.serverMetadata(),d);try{const e=await _r(h,Qc,c);return oc.fromTokenEndpointResponse(e)}catch(t){const n=new Wa("Failed to exchange token for connection '".concat(e.connection,"'."),Pa(t)),o=d.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}}function lu(e,t,n){var o;if(n.organization&&qa(e.claims,n.organization),n.actorToken)if(null!==(o=e.claims)&&void 0!==o&&o.act)e.act=e.claims.act;else try{e.act=function(e){if("string"!=typeof e)throw new qo("JWTs must use Compact JWS serialization, JWT must be a string");const t=e.split("."),n=t[1],o=t.length;if(5===o)throw new qo("Only JWTs using Compact JWS serialization can be decoded");if(3!==o)throw new qo("Invalid JWT");if(!n)throw new qo("JWTs must contain a payload");let i,r;try{i=ri(n)}catch(e){throw new qo("Failed to base64url decode the payload")}try{r=JSON.parse(Ko.decode(i))}catch(e){throw new qo("Failed to parse the decoded payload as JSON")}if(!ai(r))throw new qo("Invalid JWT Claims Set");return r}(t.access_token).act}catch(e){}return e}async function du(e,t,n){var o;const i=(await s(Ta,this,su).call(this,t)).configuration;if(Yc(e.subjectToken),void 0!==e.organization&&Xa(e.organization),void 0!==e.actorToken&&void 0===e.actorTokenType)throw new Wa("actorTokenType is required when actorToken is provided");const r=new URLSearchParams({subject_token_type:e.subjectTokenType,subject_token:e.subjectToken});if(e.audience&&r.append("audience",e.audience),e.scope&&r.append("scope",e.scope),e.requestedTokenType&&r.append("requested_token_type",e.requestedTokenType),e.organization&&r.append("organization",e.organization),e.actorToken&&r.append("actor_token",e.actorToken),e.actorTokenType&&r.append("actor_token_type",e.actorTokenType),Bc(r,e.extra),n){var a;const t=sc(null!==(a=i[Gi])&&void 0!==a?a:u(ga,this)),n=await s(Ta,this,iu).call(this,i.serverMetadata(),t);let o,c,l;try{if(c=await _r(n,$c,r),o=oc.fromTokenEndpointResponse(c),l=t.getCapturedResponse(),!l)throw new Ha}catch(n){if(n instanceof Ha)throw n;const o=new Wa("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),Pa(n)),i=t.getCapturedResponse();throw o.statusCode=null==i?void 0:i.status,o.headers=i?Fa(i.headers):void 0,o}return s(Ta,this,lu).call(this,o,c,e),{data:o,response:l}}const c=sc(null!==(o=i[Gi])&&void 0!==o?o:u(ga,this)),l=await s(Ta,this,iu).call(this,i.serverMetadata(),c);let d,h;try{h=await _r(l,$c,r),d=oc.fromTokenEndpointResponse(h)}catch(t){const n=new Wa("Failed to exchange token of type '".concat(e.subjectTokenType,"'").concat(e.audience?" for audience '".concat(e.audience,"'"):"","."),Pa(t)),o=c.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}return s(Ta,this,lu).call(this,d,h,e),d}async function hu(e,t,n){var o;const i=(await s(Ta,this,su).call(this,t)).configuration;if(n){var r;const t=sc(null!==(r=i[Gi])&&void 0!==r?r:u(ga,this)),n=await s(Ta,this,iu).call(this,i.serverMetadata(),t);try{const o=await _r(n,"http://auth0.com/oauth/grant-type/passwordless/otp",e),i=oc.fromTokenEndpointResponse(o),r=t.getCapturedResponse();if(!r)throw new Ha;return{data:i,response:r}}catch(e){if(e instanceof Ha)throw e;const n=new kc("There was an error while trying to request a token.",Pa(e)),o=t.getCapturedResponse();throw n.statusCode=null==o?void 0:o.status,n.headers=o?Fa(o.headers):void 0,n}}const a=sc(null!==(o=i[Gi])&&void 0!==o?o:u(ga,this)),c=await s(Ta,this,iu).call(this,i.serverMetadata(),a);try{const t=await _r(c,"http://auth0.com/oauth/grant-type/passwordless/otp",e);return oc.fromTokenEndpointResponse(t)}catch(e){const t=new kc("There was an error while trying to request a token.",Pa(e)),n=a.getCapturedResponse();throw t.statusCode=null==n?void 0:n.status,t.headers=n?Fa(n.headers):void 0,t}}async function pu(){let e=arguments.length>0&&void 0!==arguments[0]&&arguments[0];const t=!!u(wa,this).clientSecret||!!u(wa,this).clientAssertionSigningKey||!!u(wa,this).useMtls;return e&&!t?(e,t,n,o)=>{n.set("client_id",t.client_id)}:(u(ya,this)||d(ya,this,(async()=>{if(!u(wa,this).clientSecret&&!u(wa,this).clientAssertionSigningKey&&!u(wa,this).useMtls)throw new Da;if(u(wa,this).useMtls)return(e,t,n,o)=>{n.set("client_id",t.client_id)};let e=u(wa,this).clientAssertionSigningKey;return!e||e instanceof CryptoKey||(e=await Ts(e,u(wa,this).clientAssertionSigningAlg||"RS256")),e?function(e,t){return vn(e,t)}(e):Fi(u(wa,this).clientSecret)})().catch(e=>{throw d(ya,this,void 0),e})),u(ya,this))}async function fu(e){const t=(await s(Ta,this,au).call(this)).configuration,n=Qi(),o=await Bi(n),i=Ga(m(m({},u(wa,this).authorizationParams),null==e?void 0:e.authorizationParams)),r=new URLSearchParams(m(m({scope:Xc},i),{},{client_id:u(wa,this).clientId,code_challenge:o,code_challenge_method:"S256"}));return{authorizationUrl:null!=e&&e.pushedAuthorizationRequests?await mr(t,r):await fr(t,r),codeVerifier:n}}var mu=new Hc(1e3,6e4);class yu extends A{constructor(e,t){super(e,t),Object.setPrototypeOf(this,yu.prototype)}static fromPayload(e){let t=e.error,n=e.error_description;return new yu(t,n)}}class wu extends yu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,wu.prototype)}}class gu extends yu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,gu.prototype)}}class vu extends yu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,vu.prototype)}}class bu extends yu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,bu.prototype)}}class _u extends yu{constructor(e,t){super(e,t),Object.setPrototypeOf(this,_u.prototype)}}class ku{constructor(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:6e5;this.contexts=new Map,this.ttlMs=e}set(e,t){this.cleanup(),this.contexts.set(e,Object.assign(Object.assign({},t),{createdAt:Date.now()}))}get(e){const t=this.contexts.get(e);if(t){if(!(Date.now()-t.createdAt>this.ttlMs))return t;this.contexts.delete(e)}}remove(e){this.contexts.delete(e)}cleanup(){const e=Date.now();for(const n of this.contexts){var t=w(n,2);const o=t[0];e-t[1].createdAt>this.ttlMs&&this.contexts.delete(o)}}get size(){return this.contexts.size}}class Su{constructor(e,t){this.authJsMfaClient=e,this.auth0Client=t,this.contextManager=new ku}setMFAAuthDetails(e,t,n,o){this.contextManager.set(e,{scope:t,audience:n,mfaRequirements:o})}async getAuthenticators(e){var t,n,o;const i=this.contextManager.get(e);if(!i)throw new wu("invalid_request","MFA context not found for this MFA token");const r=null===(n=null===(t=i.mfaRequirements)||void 0===t?void 0:t.challenge)||void 0===n?void 0:n.map(e=>e.type);try{const t=await this.authJsMfaClient.listAuthenticators({mfaToken:e});return r&&0!==r.length?t.filter(e=>!!e.type&&r.includes(e.type)):t}catch(e){if(e instanceof Ba)throw new wu(null===(o=e.cause)||void 0===o?void 0:o.error,e.message);throw e}}async enroll(e){var t;const n=function(e){const t=Rt[e.factorType];return Object.assign(Object.assign(Object.assign({mfaToken:e.mfaToken,authenticatorTypes:t.authenticatorTypes},t.oobChannels&&{oobChannels:t.oobChannels}),"phoneNumber"in e&&{phoneNumber:e.phoneNumber}),"email"in e&&{email:e.email})}(e);try{return await this.authJsMfaClient.enrollAuthenticator(n)}catch(e){if(e instanceof Qa)throw new gu(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async challenge(e){var t;try{const t={challengeType:e.challengeType,mfaToken:e.mfaToken};return e.authenticatorId&&(t.authenticatorId=e.authenticatorId),await this.authJsMfaClient.challengeAuthenticator(t)}catch(e){if(e instanceof ec)throw new vu(null===(t=e.cause)||void 0===t?void 0:t.error,e.message);throw e}}async getEnrollmentFactors(e){const t=this.contextManager.get(e);if(!t||!t.mfaRequirements)throw new _u("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");return t.mfaRequirements.enroll&&0!==t.mfaRequirements.enroll.length?t.mfaRequirements.enroll:[]}async verify(e){const t=this.contextManager.get(e.mfaToken);if(!t)throw new bu("mfa_context_not_found","MFA context not found for this MFA token. Please retry the original request to get a new MFA token.");const n=function(e){return"otp"in e&&e.otp?xt:"oobCode"in e&&e.oobCode?It:"recoveryCode"in e&&e.recoveryCode?Ot:void 0}(e);if(!n)throw new bu("invalid_request","Unable to determine grant type. Provide one of: otp, oobCode, or recoveryCode.");const o=t.scope,i=t.audience;try{const t=await this.auth0Client._requestTokenForMfa({grant_type:n,mfaToken:e.mfaToken,scope:o,audience:i,otp:e.otp,oob_code:e.oobCode,binding_code:e.bindingCode,recovery_code:e.recoveryCode});return this.contextManager.remove(e.mfaToken),t}catch(e){if(e instanceof bu)throw new bu(e.error,e.error_description);throw e}}}class Tu extends Error{constructor(e,t,n){super(t),this.name="PasskeyError",this.code=e,this.cause=n,Object.setPrototypeOf(this,Tu.prototype)}}var Eu,Pu;class Cu{constructor(e,t){Eu.set(this,void 0),Pu.set(this,void 0),o(this,Eu,e,"f"),o(this,Pu,t,"f")}async signup(e){if(!window.PublicKeyCredential)throw new Tu("passkey_not_supported","WebAuthn is not supported in this browser.");const o=e.scope,i=e.audience,r=t(e,["scope","audience"]),s=await n(this,Eu,"f").register(r),a=xu(s.authnParamsPublicKey),c=await navigator.credentials.create({publicKey:a});if(!c)throw new Tu("passkey_cancelled","Passkey creation was cancelled or no credential was returned.");const u=Ou(c);return n(this,Pu,"f")._requestTokenForPasskey({authSession:s.authSession,credential:u,realm:r.realm,organization:r.organization,scope:o,audience:i})}async login(e){if(!window.PublicKeyCredential)throw new Tu("passkey_not_supported","WebAuthn is not supported in this browser.");const o=e||{},i=o.scope,r=o.audience,s=t(o,["scope","audience"]),a=await n(this,Eu,"f").challenge(Object.keys(s).length>0?s:void 0),c=Iu(a.authnParamsPublicKey),u=await navigator.credentials.get({publicKey:c});if(!u)throw new Tu("passkey_cancelled","Passkey authentication was cancelled or no credential was returned.");const l=ju(u);return n(this,Pu,"f")._requestTokenForPasskey({authSession:a.authSession,credential:l,realm:s.realm,organization:s.organization,scope:i,audience:r})}async getSignupChallenge(e){if(!window.PublicKeyCredential)throw new Tu("passkey_not_supported","WebAuthn is not supported in this browser.");const t=await n(this,Eu,"f").register(e);return{authSession:t.authSession,publicKey:xu(t.authnParamsPublicKey)}}async getLoginChallenge(e){if(!window.PublicKeyCredential)throw new Tu("passkey_not_supported","WebAuthn is not supported in this browser.");const t=await n(this,Eu,"f").challenge(e);return{authSession:t.authSession,publicKey:Iu(t.authnParamsPublicKey)}}async getTokenWithPasskey(e){if(!window.PublicKeyCredential)throw new Tu("passkey_not_supported","WebAuthn is not supported in this browser.");const t=e.authSession,o=e.credential,i=e.realm,r=e.organization,s=e.scope,a=e.audience,c=o.response;let u;if(c instanceof AuthenticatorAttestationResponse)u=Ou(o);else{if(!(c instanceof AuthenticatorAssertionResponse))throw new Tu("passkey_invalid_credential","The provided credential is not a valid attestation or assertion response.");u=ju(o)}return n(this,Pu,"f")._requestTokenForPasskey({authSession:t,credential:u,realm:i,organization:r,scope:s,audience:a})}}function Au(e){const t=new Uint8Array(e),n=Array.from(t,e=>String.fromCharCode(e)).join("");return btoa(n).replace(/\+/g,"-").replace(/\//g,"_").replace(/=+$/,"")}function Ru(e){const t=e.replace(/-/g,"+").replace(/_/g,"/"),n=t+"=".repeat((4-t.length%4)%4),o=atob(n),i=new Uint8Array(o.length);for(let e=0;e<o.length;e++)i[e]=o.charCodeAt(e);return i.buffer}function xu(e){return Object.assign(Object.assign({},e),{challenge:Ru(e.challenge),user:Object.assign(Object.assign({},e.user),{id:Ru(e.user.id)}),pubKeyCredParams:e.pubKeyCredParams,authenticatorSelection:e.authenticatorSelection})}function Iu(e){return Object.assign(Object.assign({},e),{challenge:Ru(e.challenge)})}function Ou(e){var t;const n=e.response;return{id:e.id,rawId:Au(e.rawId),type:e.type,authenticatorAttachment:null!==(t=e.authenticatorAttachment)&&void 0!==t?t:void 0,response:{clientDataJSON:Au(n.clientDataJSON),attestationObject:Au(n.attestationObject)},clientExtensionResults:e.getClientExtensionResults()}}function ju(e){var t;const n=e.response;return{id:e.id,rawId:Au(e.rawId),type:e.type,authenticatorAttachment:null!==(t=e.authenticatorAttachment)&&void 0!==t?t:void 0,response:{clientDataJSON:Au(n.clientDataJSON),authenticatorData:Au(n.authenticatorData),signature:Au(n.signature),userHandle:n.userHandle?Au(n.userHandle):void 0},clientExtensionResults:e.getClientExtensionResults()}}Eu=new WeakMap,Pu=new WeakMap;function Wu(e){return{get(){try{const t=window.localStorage.getItem(e);return t?JSON.parse(t):null}catch(e){return null}},set(t){try{window.localStorage.setItem(e,JSON.stringify(t))}catch(e){}},remove(){try{window.localStorage.removeItem(e)}catch(e){}}}}function Mu(){let e=null;return{get:()=>e,set:t=>{e=t},remove:()=>{e=null}}}class Nu{constructor(e,t){this.slots=new Map,this.baseKey="".concat("@@auth0spajs@@","::").concat(e,"::anonymous"),this.useLocalStorage="localStorage"===t&&"undefined"!=typeof window&&!!window.localStorage,this.sessionKey="".concat(this.baseKey,"::").concat("session"),this.sessionStore=this.useLocalStorage?Wu(this.sessionKey):Mu()}getStore(e,t){const n="".concat(this.baseKey,"::").concat(JSON.stringify([null!=e?e:"",null!=t?t:""]));return this.slots.has(n)||this.slots.set(n,this.useLocalStorage?Wu(n):Mu()),this.slots.get(n)}getSessionToken(){return this.sessionStore.get()}setSessionToken(e){this.sessionStore.set(e)}removeAll(){if(this.sessionStore.remove(),this.slots.forEach(e=>e.remove()),this.slots.clear(),this.useLocalStorage)try{const e=this.baseKey+"::",t=[];for(let n=0;n<window.localStorage.length;n++){const o=window.localStorage.key(n);(null==o?void 0:o.startsWith(e))&&t.push(o)}t.forEach(e=>window.localStorage.removeItem(e))}catch(e){}}}class Ku{constructor(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:"localStorage",o=arguments.length>3?arguments[3]:void 0;this.authJsClient=e,this.clientId=t,this.cache=new Nu(t,n),this.lockManager=null!=o?o:fe()}async createSession(e){const t=await this.authJsClient.createSession(e);return this.cache.setSessionToken(Object.assign({sessionToken:t.sessionToken},void 0!==t.sessionTokenExpiresAt&&{sessionTokenExpiresAt:t.sessionTokenExpiresAt})),this.cache.getStore(null==e?void 0:e.audience,null==e?void 0:e.scope).set(Object.assign({accessToken:t.accessToken,expiresAt:t.expiresAt},void 0!==t.scope&&{scope:t.scope})),t}async getTokenSilently(e){const t=this.cache.getStore(null==e?void 0:e.audience,null==e?void 0:e.scope),n=t.get();return n&&n.expiresAt-60>Date.now()/1e3?n:this.lockManager.runWithLock("anonymous::".concat(this.clientId),5e3,async()=>{var n;const o=t.get();if(o&&o.expiresAt-60>Date.now()/1e3)return o;const i=null===(n=this.cache.getSessionToken())||void 0===n?void 0:n.sessionToken,r=await this.authJsClient.getAccessToken(Object.assign(Object.assign({},e),{sessionToken:i}));return this.cache.getStore(null==e?void 0:e.audience,null==e?void 0:e.scope).set(Object.assign({accessToken:r.accessToken,expiresAt:r.expiresAt},void 0!==r.scope&&{scope:r.scope})),!r.sessionReplaced&&this.cache.getSessionToken()||this.cache.setSessionToken(Object.assign({sessionToken:r.sessionToken},void 0!==r.sessionTokenExpiresAt&&{sessionTokenExpiresAt:r.sessionTokenExpiresAt})),Object.assign({accessToken:r.accessToken,expiresAt:r.expiresAt},void 0!==r.scope&&{scope:r.scope})})}async logout(){await this.authJsClient.logout(),this.cache.removeAll()}hasSession(){var e;return!!(null===(e=this.cache.getSessionToken())||void 0===e?void 0:e.sessionToken)}getClaims(){return null}}class Uu{resolveOnlineAccess(e){if("online"!==e.refreshTokenMode)return!1;if(!0!==e.useRefreshTokens)throw new R('`refreshTokenMode: "online"` requires the refresh-token grant.',"Set `useRefreshTokens: true`.");if(!0!==e.useDpop)throw new R('`refreshTokenMode: "online"` requires DPoP, which is missing or disabled.',"Set `useDpop: true` (DPoP is mandatory for online access).");return!0}warnEnterpriseConnectConfig(e){var t,n;if(!0!==e.enterpriseConnect)return;const o=null===(t=e.authorizationParams)||void 0===t?void 0:t.scope;(!0===e.useRefreshTokens||"string"==typeof o&&o.includes("offline_access"))&&console.warn("Enterprise Connect issues no refresh token; `useRefreshTokens` and `offline_access` in `scope` have no effect."),(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)&&console.warn("Enterprise Connect resolves the organization from the email domain (Home Realm Discovery); a static `organization` breaks multi-customer setups.")}constructor(e){let t,n;if(this.userCache=(new Fe).enclosedCache,this.defaultOptions={authorizationParams:{scope:"openid profile email"},useRefreshTokensFallback:!1,useFormData:!0,refreshTokenMode:"offline",anonymousSessionsCacheMode:"localStorage"},this.onlineAccess=this.resolveOnlineAccess(e),this.warnEnterpriseConnectConfig(e),this.options=Object.assign(Object.assign(Object.assign({},this.defaultOptions),e),{authorizationParams:Object.assign(Object.assign({},this.defaultOptions.authorizationParams),e.authorizationParams)}),"undefined"!=typeof window&&(()=>{if(!J())throw new Error("For security reasons, `window.crypto` is required to run `auth0-spa-js`.");if(void 0===J().subtle)throw new Error("\n      auth0-spa-js must run on a secure origin. See https://github.com/auth0/auth0-spa-js/blob/main/FAQ.md#why-do-i-get-auth0-spa-js-must-run-on-a-secure-origin for more information.\n    ")})(),this.lockManager=fe(),e.cache&&e.cacheLocation&&console.warn("Both `cache` and `cacheLocation` options have been specified in the Auth0Client configuration; ignoring `cacheLocation` and using `cache`."),e.cache)n=e.cache;else{if(t=e.cacheLocation||k,!vt(t))throw new Error('Invalid cache location "'.concat(t,'"'));n=vt(t)()}var o;this.httpTimeoutMs=e.httpTimeoutInSeconds?1e3*e.httpTimeoutInSeconds:_,this.cookieStorage=!1===e.legacySameSiteCookie?rt:at,this.orgHintCookieName=(o=this.options.clientId,"auth0.".concat(o,".organization_hint")),this.isAuthenticatedCookieName=(e=>"auth0.".concat(e,".is.authenticated"))(this.options.clientId),this.sessionCheckExpiryDays=e.sessionCheckExpiryDays||1;const i=e.useCookiesForTransactions?this.cookieStorage:ct;let r="";var s;this.onlineAccess?r=T:this.options.useRefreshTokens&&(r="offline_access"),this.scope=function(e,t){for(var n=arguments.length,o=new Array(n>2?n-2:0),i=2;i<n;i++)o[i-2]=arguments[i];if("object"!=typeof e)return{[C]:Le(t,e,...o)};let r={[C]:Le(t,...o)};return Object.keys(e).forEach(n=>{const i=e[n];r[n]=Le(t,i,...o)}),r}(this.options.authorizationParams.scope,"openid",r),this.transactionManager=new Ge(i,this.options.clientId,this.options.cookieDomain),this.nowProvider=this.options.nowProvider||P,this.cacheManager=new Ve(n,n.allKeys?void 0:new yt(n,this.options.clientId),this.nowProvider),this.dpop=this.options.useDpop?new Tt(this.options.clientId):void 0,this.domainUrl=(s=this.options.domain,/^https?:\/\//.test(s)?s:"https://".concat(s)),this.tokenIssuer=((e,t)=>e?e.startsWith("https://")?e:"https://".concat(e,"/"):"".concat(t,"/"))(this.options.issuer,this.domainUrl);const a="".concat(this.domainUrl,"/me/"),c=this.createFetcher(Object.assign(Object.assign({},this.options.useDpop&&{dpopNonceId:"__auth0_my_account_api__"}),{getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:a},detailedResponse:!0})}}));this.myAccount=new Ct(c,a),this.authJsClient=new nu({domain:this.options.domain,clientId:this.options.clientId}),this.mfa=new Su(this.authJsClient.mfa,this),this.anonymous=new Ku(this.authJsClient.anonymous,this.options.clientId,this.options.anonymousSessionsCacheMode,this.lockManager),this.passkey=new Cu(this.authJsClient.passkey,this),"undefined"!=typeof window&&window.Worker&&this.options.useRefreshTokens&&t===k&&(this.options.workerUrl?this.worker=new Worker(this.options.workerUrl):this.worker=new mt,this.worker.postMessage({type:"init",allowedBaseUrl:this.domainUrl}))}getConfiguration(){return Object.freeze({domain:this.options.domain,clientId:this.options.clientId})}_url(e){const t=this.options.auth0Client||E,n=F(t,!0),o=encodeURIComponent(btoa(JSON.stringify(n)));return"".concat(this.domainUrl).concat(e,"&auth0Client=").concat(o)}_authorizeUrl(e){return this._url("/authorize?".concat(V(e)))}async _verifyIdToken(e,t,n){const o=await this.nowProvider();return Ye({iss:this.tokenIssuer,aud:this.options.clientId,id_token:e,nonce:t,organization:n,leeway:this.options.leeway,max_age:(i=this.options.authorizationParams.max_age,"string"!=typeof i?i:parseInt(i,10)||void 0),now:o});var i}_processOrgHint(e){e?this.cookieStorage.save(this.orgHintCookieName,e,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}):this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain})}_extractSessionTransferToken(e){return new URLSearchParams(window.location.search).get(e)||void 0}_clearSessionTransferTokenFromUrl(e){try{const t=new URL(window.location.href);t.searchParams.has(e)&&(t.searchParams.delete(e),window.history.replaceState({},"",t.toString()))}catch(e){}}_applySessionTransferToken(e){const t=this.options.sessionTransferTokenQueryParamName;if(!t||e.session_transfer_token)return e;const n=this._extractSessionTransferToken(t);return n?(this._clearSessionTransferTokenFromUrl(t),Object.assign(Object.assign({},e),{session_transfer_token:n})):e}async _prepareAuthorizeUrl(e,t,n){var o;const i=Z(D()),r=Z(D()),s=D(),a=await G(s),c=q(a),u=await(null===(o=this.dpop)||void 0===o?void 0:o.calculateThumbprint()),l=((e,t,n,o,i,r,s,a,c)=>Object.assign(Object.assign(Object.assign({client_id:e.clientId},e.authorizationParams),n),{scope:ze(t,n.scope,n.audience),response_type:"code",response_mode:a||"query",state:o,nonce:i,redirect_uri:s||e.authorizationParams.redirect_uri,code_challenge:r,code_challenge_method:"S256",dpop_jkt:c}))(this.options,this.scope,e,i,r,c,e.redirect_uri||this.options.authorizationParams.redirect_uri||n,null==t?void 0:t.response_mode,u),d=this._authorizeUrl(l);return{nonce:r,code_verifier:s,scope:l.scope,audience:l.audience||C,redirect_uri:l.redirect_uri,state:i,url:d}}async loginWithPopup(e,t){var n;if(e=e||{},!(t=t||{}).popup&&(t.popup=(e=>{const t=window.screenX+(window.innerWidth-400)/2,n=window.screenY+(window.innerHeight-600)/2;return window.open(e,"auth0:authorize:popup","left=".concat(t,",top=").concat(n,",width=").concat(400,",height=").concat(600,",resizable,scrollbars=yes,status=1"))})(""),!t.popup))throw new M;const o=this._applySessionTransferToken(e.authorizationParams||{}),i=await this._prepareAuthorizeUrl(o,{response_mode:"web_message"},window.location.origin);t.popup.location.href=i.url;const r=await((e,t)=>new Promise((n,o)=>{let i;const r=setInterval(()=>{e.popup&&e.popup.closed&&(clearInterval(r),clearTimeout(s),window.removeEventListener("message",i,!1),o(new W(e.popup)))},1e3),s=setTimeout(()=>{clearInterval(r),o(new j(e.popup)),window.removeEventListener("message",i,!1)},1e3*(e.timeoutInSeconds||60));i=function(a){if(a.origin===t&&a.data&&"authorization_response"===a.data.type){if(clearTimeout(s),clearInterval(r),window.removeEventListener("message",i,!1),!1!==e.closePopup&&e.popup.close(),a.data.response.error)return o(A.fromPayload(a.data.response));n(a.data.response)}},window.addEventListener("message",i)}))(Object.assign(Object.assign({},t),{timeoutInSeconds:t.timeoutInSeconds||this.options.authorizeTimeoutInSeconds||60}),new URL(i.url).origin);if(i.state!==r.state)throw new A("state_mismatch","Invalid state");const s=(null===(n=e.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization;await this._requestToken({audience:i.audience,scope:i.scope,code_verifier:i.code_verifier,grant_type:"authorization_code",code:r.code,redirect_uri:i.redirect_uri},{nonceIn:i.nonce,organization:s})}async getUser(){var e;if(await this._isSessionCeilingReached())return;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.user}async getIdTokenClaims(){var e;if(await this._isSessionCeilingReached())return;const t=await this._getIdTokenFromCache();return null===(e=null==t?void 0:t.decodedToken)||void 0===e?void 0:e.claims}async loginWithRedirect(){var n;const o=bt(arguments.length>0&&void 0!==arguments[0]?arguments[0]:{}),i=o.openUrl,r=o.fragment,s=o.appState,a=t(o,["openUrl","fragment","appState"]),c=(null===(n=a.authorizationParams)||void 0===n?void 0:n.organization)||this.options.authorizationParams.organization,u=this._applySessionTransferToken(a.authorizationParams||{}),l=await this._prepareAuthorizeUrl(u),d=l.url,h=t(l,["url"]);this.transactionManager.create(Object.assign(Object.assign(Object.assign({},h),{appState:s,response_type:e.ResponseType.Code}),c&&{organization:c}));const p=r?"".concat(d,"#").concat(r):d;i?await i(p):window.location.assign(p)}async handleRedirectCallback(){const t=(arguments.length>0&&void 0!==arguments[0]?arguments[0]:window.location.href).split("?").slice(1);if(0===t.length)throw new Error("There are no query params available for parsing.");const n=this.transactionManager.get();if(!n)throw new A("missing_transaction","Invalid state");this.transactionManager.remove();const o=(e=>{e.indexOf("#")>-1&&(e=e.substring(0,e.indexOf("#")));const t=new URLSearchParams(e);return{state:t.get("state"),code:t.get("code")||void 0,connect_code:t.get("connect_code")||void 0,error:t.get("error")||void 0,error_description:t.get("error_description")||void 0}})(t.join(""));return n.response_type===e.ResponseType.ConnectCode?this._handleConnectAccountRedirectCallback(o,n):this._handleLoginRedirectCallback(o,n)}async _handleLoginRedirectCallback(t,n){const o=t.code,i=t.state,r=t.error,s=t.error_description;if(r)throw new x(r,s||r,i,n.appState);if(!n.code_verifier||n.state&&n.state!==i)throw new A("state_mismatch","Invalid state");const a=n.organization,c=n.nonce,u=n.redirect_uri;return await this._requestToken(Object.assign({audience:n.audience,scope:n.scope,code_verifier:n.code_verifier,grant_type:"authorization_code",code:o},u?{redirect_uri:u}:{}),{nonceIn:c,organization:a}),{appState:n.appState,response_type:e.ResponseType.Code}}async _handleConnectAccountRedirectCallback(t,n){const o=t.connect_code,i=t.state,r=t.error,s=t.error_description;if(r)throw new I(r,s||r,n.connection,i,n.appState);if(!o)throw new A("missing_connect_code","Missing connect code");if(!(n.code_verifier&&n.state&&n.auth_session&&n.redirect_uri&&n.state===i))throw new A("state_mismatch","Invalid state");const a=await this.myAccount.completeAccount({auth_session:n.auth_session,connect_code:o,redirect_uri:n.redirect_uri,code_verifier:n.code_verifier});return Object.assign(Object.assign({},a),{appState:n.appState,response_type:e.ResponseType.ConnectCode})}async _maybeCreateAnonymousSession(){if(this.options.createAnonymousSessionOnFailedSilentAuth){if(this.anonymous.hasSession())return;try{await this.anonymous.getTokenSilently()}catch(e){console.debug("[auth0-spa-js] Anonymous session creation failed",e)}}}async checkSession(e){if(!this.cookieStorage.get(this.isAuthenticatedCookieName)){if(!this.cookieStorage.get(wt))return void await this._maybeCreateAnonymousSession();this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(wt)}try{await this.getTokenSilently(e)}catch(e){e instanceof A&&"login_required"===e.error&&e.error_description!==S&&await this._maybeCreateAnonymousSession()}}async getTokenSilently(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var t,n;const o=Object.assign(Object.assign({cacheMode:"on"},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:ze(this.scope,null===(t=e.authorizationParams)||void 0===t?void 0:t.scope,(null===(n=e.authorizationParams)||void 0===n?void 0:n.audience)||this.options.authorizationParams.audience)})}),i=await this._getTokenSilently(o);return e.detailedResponse?i:null==i?void 0:i.access_token}async _getTokenSilently(e){const n=e.cacheMode,o=t(e,["cacheMode"]);if(await this._isSessionCeilingReached())return;if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||C,clientId:this.options.clientId,cacheMode:n});if(e)return e}if("cache-only"===n)return;const i=(r=this.options.clientId,s=o.authorizationParams.audience||"default","".concat("auth0.lock.getTokenSilently",".").concat(r,".").concat(s));var r,s;try{return await this.lockManager.runWithLock(i,5e3,async()=>{if("off"!==n){const e=await this._getEntryFromCache({scope:o.authorizationParams.scope,audience:o.authorizationParams.audience||C,clientId:this.options.clientId});if(e)return e}const e=this.options.useRefreshTokens?await this._getTokenUsingRefreshToken(o):await this._getTokenFromIFrame(o),t=e.id_token,i=e.token_type,r=e.access_token,s=e.oauthTokenScope,a=e.expires_in;return Object.assign(Object.assign({id_token:t,token_type:i,access_token:r},s?{scope:s}:null),{expires_in:a})})}catch(e){if(this._isInteractiveError(e)&&"popup"===this.options.interactiveErrorHandler)return await this._handleInteractiveErrorWithPopup(o);throw e}}_isInteractiveError(e){return e instanceof N||e instanceof A&&this._isIframeMfaError(e)}_isIframeMfaError(e){return"login_required"===e.error&&e.error_description===S}async _handleInteractiveErrorWithPopup(e){try{await this.loginWithPopup({authorizationParams:e.authorizationParams});const t=await this._getEntryFromCache({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||C,clientId:this.options.clientId});if(!t)throw new A("interactive_handler_cache_miss","Token not found in cache after interactive authentication");return t}catch(e){throw e}}async getTokenWithPopup(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{},t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{};var n,o;const i=Object.assign(Object.assign({},e),{authorizationParams:Object.assign(Object.assign(Object.assign({},this.options.authorizationParams),e.authorizationParams),{scope:ze(this.scope,null===(n=e.authorizationParams)||void 0===n?void 0:n.scope,(null===(o=e.authorizationParams)||void 0===o?void 0:o.audience)||this.options.authorizationParams.audience)})});t=Object.assign(Object.assign({},b),t),await this.loginWithPopup(i,t);return(await this.cacheManager.get(new Ze({scope:i.authorizationParams.scope,audience:i.authorizationParams.audience||C,clientId:this.options.clientId}),void 0,this.options.useMrrt)).access_token}async isAuthenticated(){return!!await this.getUser()}_buildLogoutUrl(e){null!==e.clientId?e.clientId=e.clientId||this.options.clientId:delete e.clientId;const n=e.logoutParams||{},o=n.federated,i=t(n,["federated"]),r=o?"&federated":"";return this._url("/v2/logout?".concat(V(Object.assign({clientId:e.clientId},i))))+r}async revokeRefreshToken(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(!this.options.useRefreshTokens)return;const t=e.audience||this.options.authorizationParams.audience||C,n=await this.cacheManager.getRefreshTokensByAudience(t,this.options.clientId);await async function(e,t){let n=e.baseUrl,o=e.timeout,i=e.auth0Client,r=e.useFormData,s=e.refreshTokens,a=e.audience,c=e.client_id,u=e.onRefreshTokenRevoked;const l=o||_,d="refresh_token",h="".concat(n,"/oauth/revoke"),p={"Content-Type":r?"application/x-www-form-urlencoded":"application/json","Auth0-Client":btoa(JSON.stringify(F(i||E)))};if(t){const e={client_id:c,token_type_hint:d},n=r?V(e):JSON.stringify(e);try{return await We({type:"revoke",timeout:l,fetchUrl:h,fetchOptions:{method:"POST",body:n,headers:p},useFormData:r,auth:{audience:null!=a?a:C}},t)}catch(e){throw new A("revoke_error",e.message)}}for(const e of s){const t={client_id:c,token_type_hint:d,token:e},n=r?V(t):JSON.stringify(t),o=await Me(h,{method:"POST",body:n,headers:p},l);if(!o.ok){let e,t;try{var f=JSON.parse(await o.text());e=f.error,t=f.error_description}catch(e){}throw new A(e||"revoke_error",t||"HTTP error ".concat(o.status))}await(null==u?void 0:u(e))}}({baseUrl:this.domainUrl,timeout:this.httpTimeoutMs,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,client_id:this.options.clientId,refreshTokens:n,audience:t,onRefreshTokenRevoked:e=>this.cacheManager.stripRefreshToken(e)},this.worker),this.onlineAccess&&await this._clearLocalSession()}async logout(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};var n;this.options.enterpriseConnect&&!0!==(null===(n=e.logoutParams)||void 0===n?void 0:n.federated)&&console.warn("Enterprise Connect logout without `federated: true` leaves the enterprise IdP session alive; the next login may silently reuse the previous user.");const o=bt(e),i=o.openUrl,r=t(o,["openUrl"]);await this._clearLocalSession(e.clientId);const s=this._buildLogoutUrl(r);i?await i(s):!1!==i&&window.location.assign(s)}async _getTokenFromIFrame(e){const t=(n=this.options.clientId,"".concat("auth0.lock.getTokenFromIFrame",".").concat(n));var n;try{return await this.lockManager.runWithLock(t,5e3,async()=>{const t=Object.assign(Object.assign({},e.authorizationParams),{prompt:"none"}),n=this.cookieStorage.get(this.orgHintCookieName);n&&!t.organization&&(t.organization=n);const o=await this._prepareAuthorizeUrl(t,{response_mode:"web_message"},window.location.origin),i=o.url,r=o.state,s=o.nonce,a=o.code_verifier,c=o.redirect_uri,u=o.scope,l=o.audience;if(window.crossOriginIsolated)throw new A("login_required","The application is running in a Cross-Origin Isolated context, silently retrieving a token without refresh token is not possible.");const d=e.timeoutInSeconds||this.options.authorizeTimeoutInSeconds;let h;try{h=new URL(this.domainUrl).origin}catch(e){h=this.domainUrl}const p=await function(e,t){let n=arguments.length>2&&void 0!==arguments[2]?arguments[2]:60;return new Promise((o,i)=>{const r=window.document.createElement("iframe");r.setAttribute("width","0"),r.setAttribute("height","0"),r.style.display="none";const s=()=>{window.document.body.contains(r)&&(window.document.body.removeChild(r),window.removeEventListener("message",a,!1))};let a;const c=setTimeout(()=>{i(new O),s()},1e3*n);a=function(e){if(e.origin!=t)return;if(!e.data||"authorization_response"!==e.data.type)return;const n=e.source;n&&n.close(),e.data.response.error?i(A.fromPayload(e.data.response)):o(e.data.response),clearTimeout(c),window.removeEventListener("message",a,!1),setTimeout(s,2e3)},window.addEventListener("message",a,!1),window.document.body.appendChild(r),r.setAttribute("src",e)})}(i,h,d);if(r!==p.state)throw new A("state_mismatch","Invalid state");const f=await this._requestToken(Object.assign(Object.assign({},e.authorizationParams),{code_verifier:a,code:p.code,grant_type:"authorization_code",redirect_uri:c,timeout:e.authorizationParams.timeout||this.httpTimeoutMs}),{nonceIn:s,organization:t.organization});return Object.assign(Object.assign({},f),{scope:u,oauthTokenScope:f.scope,audience:l})})}catch(e){if("login_required"===e.error){e instanceof A&&this._isIframeMfaError(e)&&"popup"===this.options.interactiveErrorHandler||this.logout({openUrl:!1})}throw e}}async _getTokenUsingRefreshToken(e){const t=await this.cacheManager.get(new Ze({scope:e.authorizationParams.scope,audience:e.authorizationParams.audience||C,clientId:this.options.clientId}),void 0,this.options.useMrrt);if(!(t&&t.refresh_token||this.worker)){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw new K(e.authorizationParams.audience||C,e.authorizationParams.scope)}const n=e.authorizationParams.redirect_uri||this.options.authorizationParams.redirect_uri||window.location.origin,o="number"==typeof e.timeoutInSeconds?1e3*e.timeoutInSeconds:null,i=((e,t,n,o)=>{var i;if(e&&n&&o){if(t.audience!==n)return t.scope;const e=o.split(" "),r=(null===(i=t.scope)||void 0===i?void 0:i.split(" "))||[],s=r.every(t=>e.includes(t));return e.length>=r.length&&s?o:t.scope}return t.scope})(this.options.useMrrt,e.authorizationParams,null==t?void 0:t.audience,null==t?void 0:t.scope);try{const u=await this._requestToken(Object.assign(Object.assign(Object.assign({},e.authorizationParams),{grant_type:"refresh_token",refresh_token:t&&t.refresh_token,redirect_uri:n}),o&&{timeout:o}),{scopesToRequest:i});if(await this._propagateRotatedRefreshToken(null==t?void 0:t.refresh_token,u.refresh_token),this.options.useMrrt){if(r=null==t?void 0:t.audience,s=null==t?void 0:t.scope,a=e.authorizationParams.audience,c=e.authorizationParams.scope,r!==a||!((e,t)=>{const n=(null==t?void 0:t.split(" "))||[];return((null==e?void 0:e.split(" "))||[]).every(e=>n.includes(e))})(c,s)){const t=_t(i,u.scope,this.onlineAccess);if(t){if(this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e);throw await this.cacheManager.remove(this.options.clientId,e.authorizationParams.audience,e.authorizationParams.scope),new U(e.authorizationParams.audience||"default",t)}}}return Object.assign(Object.assign({},u),{scope:e.authorizationParams.scope,oauthTokenScope:u.scope,audience:e.authorizationParams.audience||C})}catch(t){if(t.message){if(t.message.includes("user is blocked"))throw await this.logout({openUrl:!1}),t;if((t.message.includes("Missing Refresh Token")||t.message.includes("invalid refresh token"))&&this.options.useRefreshTokensFallback)return await this._getTokenFromIFrame(e)}throw t}var r,s,a,c}async _propagateRotatedRefreshToken(e,t){!this.onlineAccess&&t&&e&&await this.cacheManager.updateEntry(e,t,this.options.clientId,this.options.useMrrt)}async _saveEntryInCache(e){const n=e.decodedToken.claims,o=n.session_expiry,i=n.iat;if(void 0!==o){if("number"!=typeof o)throw new A("invalid_token","Invalid session_expiry: value must be a number.");if(o>=1e10)throw new A("invalid_token","Invalid session_expiry: value appears to be in milliseconds; expected a Unix timestamp in seconds.");if(void 0===i||o<=i)throw new A("invalid_token","Invalid session_expiry: session ceiling is before or at the token issue time.")}const r=e.id_token,s=e.decodedToken,a=t(e,["id_token","decodedToken"]);this.userCache.set(De,{id_token:r,decodedToken:s}),await this.cacheManager.setIdToken(this.options.clientId,e.id_token,e.decodedToken),await this.cacheManager.set(a)}async _clearLocalSession(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:this.options.clientId;var t;null===e?await this.cacheManager.clear():await this.cacheManager.clear(e),this.cookieStorage.remove(this.orgHintCookieName,{cookieDomain:this.options.cookieDomain}),this.cookieStorage.remove(this.isAuthenticatedCookieName,{cookieDomain:this.options.cookieDomain}),this.userCache.remove(De);try{await(null===(t=this.dpop)||void 0===t?void 0:t.clear())}catch(e){}if(this.worker)try{await We({type:"clear"},this.worker)}catch(e){}}async _isSessionCeilingReached(){var e,t;const n=this.userCache.get(De),o=null!=n?n:await this.cacheManager.getIdToken(new Ze({clientId:this.options.clientId})),i=null===(t=null===(e=null==o?void 0:o.decodedToken)||void 0===e?void 0:e.claims)||void 0===t?void 0:t.session_expiry;if(void 0===i)return!1;const r=await this.nowProvider();return Math.floor(r/1e3)>=i-30&&(await this._clearLocalSession(),!0)}async _getIdTokenFromCache(){const e=this.options.authorizationParams.audience||C,t=this.scope[e],n=await this.cacheManager.getIdToken(new Ze({clientId:this.options.clientId,audience:e,scope:t})),o=this.userCache.get(De);return n&&n.id_token===(null==o?void 0:o.id_token)?o:(this.userCache.set(De,n),n)}async _getEntryFromCache(e){let t=e.scope,n=e.audience,o=e.clientId,i=e.cacheMode;const r=await this.cacheManager.get(new Ze({scope:t,audience:n,clientId:o}),60,this.options.useMrrt,i);if(r&&r.access_token){const e=r.token_type,t=r.access_token,n=r.oauthTokenScope,o=r.expires_in,i=await this._getIdTokenFromCache();return i&&Object.assign(Object.assign({id_token:i.id_token,token_type:e||"Bearer",access_token:t},n?{scope:n}:null),{expires_in:o})}}_storeMfaContext(e,t,n){e instanceof N&&this.mfa.setMFAAuthDetails(e.mfa_token,t,n,e.mfa_requirements)}async _requestToken(e,t){var n,o,i,r,s,a;const c=t||{},u=c.nonceIn,l=c.organization,d=c.scopesToRequest;try{const t=await Ue(Object.assign(Object.assign({baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,useMrrt:this.options.useMrrt,dpop:this.dpop,preserveRefreshToken:this.onlineAccess},e),{scope:d||e.scope}),this.worker);let c=await this._verifyIdToken(t.id_token,u,l);if("authorization_code"===e.grant_type){const e=await this._getIdTokenFromCache();(null===(o=null===(n=null==e?void 0:e.decodedToken)||void 0===n?void 0:n.claims)||void 0===o?void 0:o.sub)&&e.decodedToken.claims.sub!==c.claims.sub&&(await this.cacheManager.clear(this.options.clientId),this.userCache.remove(De))}if("authorization_code"!==e.grant_type){const e=await this._getIdTokenFromCache(),t=null===(r=null===(i=null==e?void 0:e.decodedToken)||void 0===i?void 0:i.claims)||void 0===r?void 0:r.session_expiry;void 0!==t&&(c=Object.assign(Object.assign({},c),{claims:Object.assign(Object.assign({},c.claims),{session_expiry:t})}))}return!t.refresh_token&&this.onlineAccess&&(t.refresh_token=null!==(s=e.refresh_token)&&void 0!==s?s:null===(a=await this.cacheManager.get(new Ze({scope:d||e.scope,audience:e.audience||C,clientId:this.options.clientId}),void 0,this.options.useMrrt))||void 0===a?void 0:a.refresh_token),await this._saveEntryInCache(Object.assign(Object.assign(Object.assign(Object.assign({},t),{decodedToken:c,scope:e.scope,audience:e.audience||C}),t.scope?{oauthTokenScope:t.scope}:null),{client_id:this.options.clientId})),this.cookieStorage.save(this.isAuthenticatedCookieName,!0,{daysUntilExpire:this.sessionCheckExpiryDays,cookieDomain:this.options.cookieDomain}),this._processOrgHint(l||c.claims.org_id),Object.assign(Object.assign({},t),{decodedToken:c})}catch(t){throw"authorization_code"!==e.grant_type&&this._storeMfaContext(t,d||e.scope,e.audience),t}}_buildTokenExchangeParams(e){return Object.assign(Object.assign(Object.assign(Object.assign(Object.assign({},e),{grant_type:"urn:ietf:params:oauth:grant-type:token-exchange",subject_token:e.subject_token,subject_token_type:e.subject_token_type}),e.actor_token&&{actor_token:e.actor_token}),e.actor_token_type&&{actor_token_type:e.actor_token_type}),{scope:ze(this.scope,e.scope,e.audience||this.options.authorizationParams.audience),audience:e.audience||this.options.authorizationParams.audience,organization:e.organization||this.options.authorizationParams.organization})}async loginWithCustomTokenExchange(e){return this._requestToken(this._buildTokenExchangeParams(e))}async customTokenExchange(e){const t=this._buildTokenExchangeParams(e);try{const n=await Ue(Object.assign(Object.assign({},t),{baseUrl:this.domainUrl,client_id:this.options.clientId,auth0Client:this.options.auth0Client,useFormData:this.options.useFormData,timeout:this.httpTimeoutMs,dpop:this.dpop}),this.worker,!0);return n.id_token&&await this._verifyIdToken(n.id_token,void 0,e.organization),n}catch(e){throw this._storeMfaContext(e,t.scope,t.audience),e}}async exchangeToken(e){return this.loginWithCustomTokenExchange(e)}_assertDpop(e){if(!e)throw new Error("`useDpop` option must be enabled before using DPoP.")}getDpopNonce(e){return this._assertDpop(this.dpop),this.dpop.getNonce(e)}setDpopNonce(e,t){return this._assertDpop(this.dpop),this.dpop.setNonce(e,t)}generateDpopProof(e){return this._assertDpop(this.dpop),this.dpop.generateProof(e)}createFetcher(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};return new Pt(e,{isDpopEnabled:()=>!!this.options.useDpop,getAccessToken:e=>{var t;return this.getTokenSilently({authorizationParams:{scope:null===(t=null==e?void 0:e.scope)||void 0===t?void 0:t.join(" "),audience:null==e?void 0:e.audience},detailedResponse:!0})},getDpopNonce:()=>this.getDpopNonce(e.dpopNonceId),setDpopNonce:t=>this.setDpopNonce(t,e.dpopNonceId),generateDpopProof:e=>this.generateDpopProof(e)})}async connectAccountWithRedirect(t){const n=t.openUrl,o=t.appState,i=t.connection,r=t.scopes,s=t.authorization_params,a=t.redirectUri,c=void 0===a?this.options.authorizationParams.redirect_uri||window.location.origin:a;if(!i)throw new Error("connection is required");const u=Z(D()),l=D(),d=await G(l),h=q(d),p=await this.myAccount.connectAccount({connection:i,scopes:r,redirect_uri:c,state:u,code_challenge:h,code_challenge_method:"S256",authorization_params:s}),f=p.connect_uri,m=p.connect_params,y=p.auth_session;this.transactionManager.create({state:u,code_verifier:l,auth_session:y,redirect_uri:c,appState:o,connection:i,response_type:e.ResponseType.ConnectCode});const w=new URL(f);w.searchParams.set("ticket",m.ticket),n?await n(w.toString()):window.location.assign(w)}async _requestTokenForPasskey(e){const t=e.audience||this.options.authorizationParams.audience,n=e.organization||this.options.authorizationParams.organization;return this._requestToken(Object.assign(Object.assign(Object.assign({grant_type:"urn:okta:params:oauth:grant-type:webauthn",auth_session:e.authSession,authn_response:e.credential},e.realm&&{realm:e.realm}),n&&{organization:n}),{scope:ze(this.scope,e.scope,t),audience:t}))}async _requestTokenForMfa(e,n){const o=e.mfaToken,i=t(e,["mfaToken"]),r=await this.cacheManager.get(new Ze({scope:i.scope,audience:i.audience||C,clientId:this.options.clientId}),void 0,this.options.useMrrt),s=await this._requestToken(Object.assign(Object.assign({},i),{mfa_token:o}),n);return await this._propagateRotatedRefreshToken(null==r?void 0:r.refresh_token,s.refresh_token),s}}e.AnonymousSessionApiClient=Ku,e.AnonymousSessionClient=Jc,e.AnonymousSessionError=Uc,e.Auth0Client=Uu,e.AuthenticationError=x,e.CacheKey=Ze,e.ConnectError=I,e.GenericError=A,e.InMemoryCache=Fe,e.InvalidConfigurationError=R,e.LocalStorageCache=He,e.MfaApiClient=Su,e.MfaChallengeError=vu,e.MfaEnrollmentError=gu,e.MfaEnrollmentFactorsError=_u,e.MfaError=yu,e.MfaListAuthenticatorsError=wu,e.MfaRequiredError=N,e.MfaVerifyError=bu,e.MissingRefreshTokenError=K,e.MissingScopesError=U,e.MyAccountApiClient=Ct,e.MyAccountApiError=At,e.PasskeyApiClient=Cu,e.PasskeyChallengeError=pc,e.PasskeyError=Tu,e.PasskeyGetTokenError=fc,e.PasskeyRegisterError=hc,e.PopupCancelledError=W,e.PopupOpenError=M,e.PopupTimeoutError=j,e.RefreshTokenMode={Offline:"offline",Online:"online"},e.TimeoutError=O,e.UseDpopNonceError=L,e.User=class{},e.createAuth0Client=async function(e){const t=new Uu(e);return await t.checkSession(),t},e.isFederatedDomain=function(e,t,n){var o;return async function(e,t,n){const o=t.toLowerCase(),i=e.replace(/^https?:\/\//,""),r="".concat(i,"|").concat(o),s=mu.get(r);if(void 0!==s)return s;try{var a;const e=new URL("https://".concat(i,"/.well-known/webfinger"));e.searchParams.set("resource","urn:auth0:discovery:domain:".concat(o)),e.searchParams.set("rel","http://openid.net/specs/connect/1.0/issuer");let t=null!==(a=null==n?void 0:n.customFetch)&&void 0!==a?a:globalThis.fetch;null!=n&&n.telemetry&&!1!==n.telemetry.enabled&&(t=ic(t,n.telemetry));const s=await t(e.toString());return s.ok?(mu.set(r,!0),!0):404===s.status?(mu.set(r,!1,15e3),!1):429===s.status&&(console.warn("[Auth0] isFederatedDomain: rate limit hit (429)"),!1)}catch(e){return!1}}(e.replace(/^https?:\/\//i,"").toLowerCase(),t.toLowerCase(),Object.assign(Object.assign({},n),{telemetry:null!==(o=null==n?void 0:n.telemetry)&&void 0!==o?o:E}))},Object.defineProperty(e,"__esModule",{value:!0})});
//# sourceMappingURL=auth0-spa-js.production.js.map