@protontech/openpgp
Version:
OpenPGP.js is a Javascript implementation of the OpenPGP protocol. This is defined in RFC 4880.
15 lines (14 loc) • 41.6 kB
JavaScript
/*! OpenPGP.js v6.1.1-patch.4 - 2025-07-14 - this is LGPL licensed code, see LICENSE/our website https://openpgpjs.org/ for more information. */
"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self&&self;import{s as t,a as e,b as n}from"./sha512.min.mjs";import{H as r,a as f,t as i,b as o,c as s,d as a,r as c,w as d,u,s as l}from"./sha3.min.mjs";class h extends r{constructor(t,e){super(),this.finished=!1,this.destroyed=!1,f(t);const n=i(e);if(this.iHash=t.create(),"function"!=typeof this.iHash.update)throw Error("Expected instance of class which extends utils.Hash");this.blockLen=this.iHash.blockLen,this.outputLen=this.iHash.outputLen;const r=this.blockLen,o=new Uint8Array(r);o.set(n.length>r?t.create().update(n).digest():n);for(let t=0;t<o.length;t++)o[t]^=54;this.iHash.update(o),this.oHash=t.create();for(let t=0;t<o.length;t++)o[t]^=106;this.oHash.update(o),o.fill(0)}update(t){return o(this),this.iHash.update(t),this}digestInto(t){o(this),s(t,this.outputLen),this.finished=!0,this.iHash.digestInto(t),this.oHash.update(t),this.oHash.digestInto(t),this.destroy()}digest(){const t=new Uint8Array(this.oHash.outputLen);return this.digestInto(t),t}_cloneInto(t){t||(t=Object.create(Object.getPrototypeOf(this),{}));const{oHash:e,iHash:n,finished:r,destroyed:f,blockLen:i,outputLen:o}=this;return t.finished=r,t.destroyed=f,t.blockLen=i,t.outputLen=o,t.oHash=e._cloneInto(t.oHash),t.iHash=n._cloneInto(t.iHash),t}destroy(){this.destroyed=!0,this.oHash.destroy(),this.iHash.destroy()}}const g=(t,e,n)=>new h(t,e).update(n).digest();g.create=(t,e)=>new h(t,e)
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */;const b=/* @__PURE__ */BigInt(0),y=/* @__PURE__ */BigInt(1),p=/* @__PURE__ */BigInt(2);function m(t){return t instanceof Uint8Array||ArrayBuffer.isView(t)&&"Uint8Array"===t.constructor.name}function w(t){if(!m(t))throw Error("Uint8Array expected")}function B(t,e){if("boolean"!=typeof e)throw Error(t+" boolean expected, got "+e)}const E=/* @__PURE__ */Array.from({length:256},((t,e)=>e.toString(16).padStart(2,"0")));function x(t){w(t);let e="";for(let n=0;n<t.length;n++)e+=E[t[n]];return e}function I(t){const e=t.toString(16);return 1&e.length?"0"+e:e}function v(t){if("string"!=typeof t)throw Error("hex string expected, got "+typeof t);return""===t?b:BigInt("0x"+t)}const S={_0:48,_9:57,A:65,F:70,a:97,f:102};function A(t){return t>=S._0&&t<=S._9?t-S._0:t>=S.A&&t<=S.F?t-(S.A-10):t>=S.a&&t<=S.f?t-(S.a-10):void 0}function O(t){if("string"!=typeof t)throw Error("hex string expected, got "+typeof t);const e=t.length,n=e/2;if(e%2)throw Error("hex string expected, got unpadded hex of length "+e);const r=new Uint8Array(n);for(let e=0,f=0;e<n;e++,f+=2){const n=A(t.charCodeAt(f)),i=A(t.charCodeAt(f+1));if(void 0===n||void 0===i){const e=t[f]+t[f+1];throw Error('hex string expected, got non-hex character "'+e+'" at index '+f)}r[e]=16*n+i}return r}function R(t){return v(x(t))}function z(t){return w(t),v(x(Uint8Array.from(t).reverse()))}function q(t,e){return O(t.toString(16).padStart(2*e,"0"))}function P(t,e){return q(t,e).reverse()}function N(t,e,n){let r;if("string"==typeof e)try{r=O(e)}catch(e){throw Error(t+" must be hex string or Uint8Array, cause: "+e)}else{if(!m(e))throw Error(t+" must be hex string or Uint8Array");r=Uint8Array.from(e)}const f=r.length;if("number"==typeof n&&f!==n)throw Error(t+" of length "+n+" expected, got "+f);return r}function H(...t){let e=0;for(let n=0;n<t.length;n++){const r=t[n];w(r),e+=r.length}const n=new Uint8Array(e);for(let e=0,r=0;e<t.length;e++){const f=t[e];n.set(f,r),r+=f.length}return n}const L=t=>"bigint"==typeof t&&b<=t;function T(t,e,n){return L(t)&&L(e)&&L(n)&&e<=t&&t<n}function F(t,e,n,r){if(!T(e,n,r))throw Error("expected valid "+t+": "+n+" <= n < "+r+", got "+e)}function U(t){let e;for(e=0;t>b;t>>=y,e+=1);return e}const Z=t=>(p<<BigInt(t-1))-y,k=t=>new Uint8Array(t),G=t=>Uint8Array.from(t);function C(t,e,n){if("number"!=typeof t||t<2)throw Error("hashLen must be a number");if("number"!=typeof e||e<2)throw Error("qByteLen must be a number");if("function"!=typeof n)throw Error("hmacFn must be a function");let r=k(t),f=k(t),i=0;const o=()=>{r.fill(1),f.fill(0),i=0},s=(...t)=>n(f,r,...t),a=(t=k())=>{f=s(G([0]),t),r=s(),0!==t.length&&(f=s(G([1]),t),r=s())},c=()=>{if(i++>=1e3)throw Error("drbg: tried 1000 values");let t=0;const n=[];for(;t<e;){r=s();const e=r.slice();n.push(e),t+=r.length}return H(...n)};return(t,e)=>{let n;for(o(),a(t);!(n=e(c()));)a();return o(),n}}const j={bigint:t=>"bigint"==typeof t,function:t=>"function"==typeof t,boolean:t=>"boolean"==typeof t,string:t=>"string"==typeof t,stringOrUint8Array:t=>"string"==typeof t||m(t),isSafeInteger:t=>Number.isSafeInteger(t),array:t=>Array.isArray(t),field:(t,e)=>e.Fp.isValid(t),hash:t=>"function"==typeof t&&Number.isSafeInteger(t.outputLen)};function V(t,e,n={}){const r=(e,n,r)=>{const f=j[n];if("function"!=typeof f)throw Error("invalid validator function");const i=t[e];if(!(r&&void 0===i||f(i,t)))throw Error("param "+e+" is invalid. Expected "+n+", got "+i)};for(const[t,n]of Object.entries(e))r(t,n,!1);for(const[t,e]of Object.entries(n))r(t,e,!0);return t}function _(t){const e=new WeakMap;return(n,...r)=>{const f=e.get(n);if(void 0!==f)return f;const i=t(n,...r);return e.set(n,i),i}}var K=/*#__PURE__*/Object.freeze({__proto__:null,aInRange:F,abool:B,abytes:w,bitGet:function(t,e){return t>>BigInt(e)&y},bitLen:U,bitMask:Z,bitSet:function(t,e,n){return t|(n?y:b)<<BigInt(e)},bytesToHex:x,bytesToNumberBE:R,bytesToNumberLE:z,concatBytes:H,createHmacDrbg:C,ensureBytes:N,equalBytes:function(t,e){if(t.length!==e.length)return!1;let n=0;for(let r=0;r<t.length;r++)n|=t[r]^e[r];return 0===n},hexToBytes:O,hexToNumber:v,inRange:T,isBytes:m,memoized:_,notImplemented:()=>{throw Error("not implemented")},numberToBytesBE:q,numberToBytesLE:P,numberToHexUnpadded:I,numberToVarBytesBE:function(t){return O(I(t))},utf8ToBytes:function(t){if("string"!=typeof t)throw Error("string expected");return new Uint8Array((new TextEncoder).encode(t))},validateObject:V});
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */const Y=BigInt(0),M=BigInt(1),D=/* @__PURE__ */BigInt(2),W=/* @__PURE__ */BigInt(3),J=/* @__PURE__ */BigInt(4),Q=/* @__PURE__ */BigInt(5),X=/* @__PURE__ */BigInt(8);function $(t,e){const n=t%e;return n>=Y?n:e+n}function tt(t,e,n){if(e<Y)throw Error("invalid exponent, negatives unsupported");if(n<=Y)throw Error("invalid modulus");if(n===M)return Y;let r=M;for(;e>Y;)e&M&&(r=r*t%n),t=t*t%n,e>>=M;return r}function et(t,e,n){let r=t;for(;e-- >Y;)r*=r,r%=n;return r}function nt(t,e){if(t===Y)throw Error("invert: expected non-zero number");if(e<=Y)throw Error("invert: expected positive modulus, got "+e);let n=$(t,e),r=e,f=Y,i=M;for(;n!==Y;){const t=r%n,e=f-i*(r/n);r=n,n=t,f=i,i=e}if(r!==M)throw Error("invert: does not exist");return $(f,e)}function rt(t){if(t%J===W){const e=(t+M)/J;return function(t,n){const r=t.pow(n,e);if(!t.eql(t.sqr(r),n))throw Error("Cannot find square root");return r}}if(t%X===Q){const e=(t-Q)/X;return function(t,n){const r=t.mul(n,D),f=t.pow(r,e),i=t.mul(n,f),o=t.mul(t.mul(i,D),f),s=t.mul(i,t.sub(o,t.ONE));if(!t.eql(t.sqr(s),n))throw Error("Cannot find square root");return s}}return function(t){const e=(t-M)/D;let n,r,f;for(n=t-M,r=0;n%D===Y;n/=D,r++);for(f=D;f<t&&tt(f,e,t)!==t-M;f++)if(f>1e3)throw Error("Cannot find square root: likely non-prime P");if(1===r){const e=(t+M)/J;return function(t,n){const r=t.pow(n,e);if(!t.eql(t.sqr(r),n))throw Error("Cannot find square root");return r}}const i=(n+M)/D;return function(t,o){if(t.pow(o,e)===t.neg(t.ONE))throw Error("Cannot find square root");let s=r,a=t.pow(t.mul(t.ONE,f),n),c=t.pow(o,i),d=t.pow(o,n);for(;!t.eql(d,t.ONE);){if(t.eql(d,t.ZERO))return t.ZERO;let e=1;for(let n=t.sqr(d);e<s&&!t.eql(n,t.ONE);e++)n=t.sqr(n);const n=t.pow(a,M<<BigInt(s-e-1));a=t.sqr(n),c=t.mul(c,n),d=t.mul(d,a),s=e}return c}}(t)}const ft=["create","isValid","is0","neg","inv","sqrt","sqr","eql","add","sub","mul","pow","div","addN","subN","mulN","sqrN"];function it(t,e){const n=void 0!==e?e:t.toString(2).length;return{nBitLength:n,nByteLength:Math.ceil(n/8)}}function ot(t,e,n=!1,r={}){if(t<=Y)throw Error("invalid field: expected ORDER > 0, got "+t);const{nBitLength:f,nByteLength:i}=it(t,e);if(i>2048)throw Error("invalid field: expected ORDER of <= 2048 bytes");let o;const s=Object.freeze({ORDER:t,BITS:f,BYTES:i,MASK:Z(f),ZERO:Y,ONE:M,create:e=>$(e,t),isValid:e=>{if("bigint"!=typeof e)throw Error("invalid field element: expected bigint, got "+typeof e);return Y<=e&&e<t},is0:t=>t===Y,isOdd:t=>(t&M)===M,neg:e=>$(-e,t),eql:(t,e)=>t===e,sqr:e=>$(e*e,t),add:(e,n)=>$(e+n,t),sub:(e,n)=>$(e-n,t),mul:(e,n)=>$(e*n,t),pow:(t,e)=>function(t,e,n){if(n<Y)throw Error("invalid exponent, negatives unsupported");if(n===Y)return t.ONE;if(n===M)return e;let r=t.ONE,f=e;for(;n>Y;)n&M&&(r=t.mul(r,f)),f=t.sqr(f),n>>=M;return r}(s,t,e),div:(e,n)=>$(e*nt(n,t),t),sqrN:t=>t*t,addN:(t,e)=>t+e,subN:(t,e)=>t-e,mulN:(t,e)=>t*e,inv:e=>nt(e,t),sqrt:r.sqrt||(e=>(o||(o=rt(t)),o(s,e))),invertBatch:t=>function(t,e){const n=Array(e.length),r=e.reduce(((e,r,f)=>t.is0(r)?e:(n[f]=e,t.mul(e,r))),t.ONE),f=t.inv(r);return e.reduceRight(((e,r,f)=>t.is0(r)?e:(n[f]=t.mul(e,n[f]),t.mul(e,r))),f),n}(s,t),cmov:(t,e,n)=>n?e:t,toBytes:t=>n?P(t,i):q(t,i),fromBytes:t=>{if(t.length!==i)throw Error("Field.fromBytes: expected "+i+" bytes, got "+t.length);return n?z(t):R(t)}});return Object.freeze(s)}function st(t){if("bigint"!=typeof t)throw Error("field order must be bigint");const e=t.toString(2).length;return Math.ceil(e/8)}function at(t){const e=st(t);return e+Math.ceil(e/2)}
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
const ct=BigInt(0),dt=BigInt(1);function ut(t,e){const n=e.negate();return t?n:e}function lt(t,e){if(!Number.isSafeInteger(t)||t<=0||t>e)throw Error("invalid window size, expected [1.."+e+"], got W="+t)}function ht(t,e){lt(t,e);return{windows:Math.ceil(e/t)+1,windowSize:2**(t-1)}}const gt=new WeakMap,bt=new WeakMap;function yt(t){return bt.get(t)||1}function pt(t,e){return{constTimeNegate:ut,hasPrecomputes:t=>1!==yt(t),unsafeLadder(e,n,r=t.ZERO){let f=e;for(;n>ct;)n&dt&&(r=r.add(f)),f=f.double(),n>>=dt;return r},precomputeWindow(t,n){const{windows:r,windowSize:f}=ht(n,e),i=[];let o=t,s=o;for(let t=0;t<r;t++){s=o,i.push(s);for(let t=1;t<f;t++)s=s.add(o),i.push(s);o=s.double()}return i},wNAF(n,r,f){const{windows:i,windowSize:o}=ht(n,e);let s=t.ZERO,a=t.BASE;const c=BigInt(2**n-1),d=2**n,u=BigInt(n);for(let t=0;t<i;t++){const e=t*o;let n=Number(f&c);f>>=u,n>o&&(n-=d,f+=dt);const i=e,l=e+Math.abs(n)-1,h=t%2!=0,g=n<0;0===n?a=a.add(ut(h,r[i])):s=s.add(ut(g,r[l]))}return{p:s,f:a}},wNAFUnsafe(n,r,f,i=t.ZERO){const{windows:o,windowSize:s}=ht(n,e),a=BigInt(2**n-1),c=2**n,d=BigInt(n);for(let t=0;t<o;t++){const e=t*s;if(f===ct)break;let n=Number(f&a);if(f>>=d,n>s&&(n-=c,f+=dt),0===n)continue;let o=r[e+Math.abs(n)-1];n<0&&(o=o.negate()),i=i.add(o)}return i},getPrecomputes(t,e,n){let r=gt.get(e);return r||(r=this.precomputeWindow(e,t),1!==t&>.set(e,n(r))),r},wNAFCached(t,e,n){const r=yt(t);return this.wNAF(r,this.getPrecomputes(r,t,n),e)},wNAFCachedUnsafe(t,e,n,r){const f=yt(t);return 1===f?this.unsafeLadder(t,e,r):this.wNAFUnsafe(f,this.getPrecomputes(f,t,n),e,r)},setWindowSize(t,n){lt(n,e),bt.set(t,n),gt.delete(t)}}}function mt(t,e,n,r){if(function(t,e){if(!Array.isArray(t))throw Error("array expected");t.forEach(((t,n)=>{if(!(t instanceof e))throw Error("invalid point at index "+n)}))}(n,t),function(t,e){if(!Array.isArray(t))throw Error("array of scalars expected");t.forEach(((t,n)=>{if(!e.isValid(t))throw Error("invalid scalar at index "+n)}))}(r,e),n.length!==r.length)throw Error("arrays of points and scalars must have equal length");const f=t.ZERO,i=U(BigInt(n.length)),o=i>12?i-3:i>4?i-2:i?2:1,s=(1<<o)-1,a=Array(s+1).fill(f);let c=f;for(let t=Math.floor((e.BITS-1)/o)*o;t>=0;t-=o){a.fill(f);for(let e=0;e<r.length;e++){const f=r[e],i=Number(f>>BigInt(t)&BigInt(s));a[i]=a[i].add(n[e])}let e=f;for(let t=a.length-1,n=f;t>0;t--)n=n.add(a[t]),e=e.add(n);if(c=c.add(e),0!==t)for(let t=0;t<o;t++)c=c.double()}return c}function wt(t){return V(t.Fp,ft.reduce(((t,e)=>(t[e]="function",t)),{ORDER:"bigint",MASK:"bigint",BYTES:"isSafeInteger",BITS:"isSafeInteger"})),V(t,{n:"bigint",h:"bigint",Gx:"field",Gy:"field"},{nBitLength:"isSafeInteger",nByteLength:"isSafeInteger"}),Object.freeze({...it(t.n,t.nBitLength),...t,p:t.Fp.ORDER})}
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */function Bt(t){void 0!==t.lowS&&B("lowS",t.lowS),void 0!==t.prehash&&B("prehash",t.prehash)}const{bytesToNumberBE:Et,hexToBytes:xt}=K,It={Err:class extends Error{constructor(t=""){super(t)}},_tlv:{encode:(t,e)=>{const{Err:n}=It;if(t<0||t>256)throw new n("tlv.encode: wrong tag");if(1&e.length)throw new n("tlv.encode: unpadded data");const r=e.length/2,f=I(r);if(f.length/2&128)throw new n("tlv.encode: long form length too big");const i=r>127?I(f.length/2|128):"";return I(t)+i+f+e},decode(t,e){const{Err:n}=It;let r=0;if(t<0||t>256)throw new n("tlv.encode: wrong tag");if(e.length<2||e[r++]!==t)throw new n("tlv.decode: wrong tlv");const f=e[r++];let i=0;if(!!(128&f)){const t=127&f;if(!t)throw new n("tlv.decode(long): indefinite length not supported");if(t>4)throw new n("tlv.decode(long): byte length is too big");const o=e.subarray(r,r+t);if(o.length!==t)throw new n("tlv.decode: length bytes not complete");if(0===o[0])throw new n("tlv.decode(long): zero leftmost byte");for(const t of o)i=i<<8|t;if(r+=t,i<128)throw new n("tlv.decode(long): not minimal encoding")}else i=f;const o=e.subarray(r,r+i);if(o.length!==i)throw new n("tlv.decode: wrong value length");return{v:o,l:e.subarray(r+i)}}},_int:{encode(t){const{Err:e}=It;if(t<vt)throw new e("integer: negative integers are not allowed");let n=I(t);if(8&Number.parseInt(n[0],16)&&(n="00"+n),1&n.length)throw new e("unexpected DER parsing assertion: unpadded hex");return n},decode(t){const{Err:e}=It;if(128&t[0])throw new e("invalid signature integer: negative");if(0===t[0]&&!(128&t[1]))throw new e("invalid signature integer: unnecessary leading zero");return Et(t)}},toSig(t){const{Err:e,_int:n,_tlv:r}=It,f="string"==typeof t?xt(t):t;w(f);const{v:i,l:o}=r.decode(48,f);if(o.length)throw new e("invalid signature: left bytes after parsing");const{v:s,l:a}=r.decode(2,i),{v:c,l:d}=r.decode(2,a);if(d.length)throw new e("invalid signature: left bytes after parsing");return{r:n.decode(s),s:n.decode(c)}},hexFromSig(t){const{_tlv:e,_int:n}=It,r=e.encode(2,n.encode(t.r))+e.encode(2,n.encode(t.s));return e.encode(48,r)}},vt=BigInt(0),St=BigInt(1);BigInt(2);const At=BigInt(3);function Ot(t){const e=function(t){const e=wt(t);V(e,{a:"field",b:"field"},{allowedPrivateKeyLengths:"array",wrapPrivateKey:"boolean",isTorsionFree:"function",clearCofactor:"function",allowInfinityPoint:"boolean",fromBytes:"function",toBytes:"function"});const{endo:n,Fp:r,a:f}=e;if(n){if(!r.eql(f,r.ZERO))throw Error("invalid endomorphism, can only be defined for Koblitz curves that have a=0");if("object"!=typeof n||"bigint"!=typeof n.beta||"function"!=typeof n.splitScalar)throw Error("invalid endomorphism, expected beta: bigint and splitScalar: function")}return Object.freeze({...e})}(t),{Fp:n}=e,r=ot(e.n,e.nBitLength),f=e.toBytes||((t,e,r)=>{const f=e.toAffine();return H(Uint8Array.from([4]),n.toBytes(f.x),n.toBytes(f.y))}),i=e.fromBytes||(t=>{const e=t.subarray(1);return{x:n.fromBytes(e.subarray(0,n.BYTES)),y:n.fromBytes(e.subarray(n.BYTES,2*n.BYTES))}});function o(t){const{a:r,b:f}=e,i=n.sqr(t),o=n.mul(i,t);return n.add(n.add(o,n.mul(t,r)),f)}if(!n.eql(n.sqr(e.Gy),o(e.Gx)))throw Error("bad generator point: equation left != right");function s(t){const{allowedPrivateKeyLengths:n,nByteLength:r,wrapPrivateKey:f,n:i}=e;if(n&&"bigint"!=typeof t){if(m(t)&&(t=x(t)),"string"!=typeof t||!n.includes(t.length))throw Error("invalid private key");t=t.padStart(2*r,"0")}let o;try{o="bigint"==typeof t?t:R(N("private key",t,r))}catch(e){throw Error("invalid private key, expected hex or "+r+" bytes, got "+typeof t)}return f&&(o=$(o,i)),F("private key",o,St,i),o}function a(t){if(!(t instanceof u))throw Error("ProjectivePoint expected")}const c=_(((t,e)=>{const{px:r,py:f,pz:i}=t;if(n.eql(i,n.ONE))return{x:r,y:f};const o=t.is0();null==e&&(e=o?n.ONE:n.inv(i));const s=n.mul(r,e),a=n.mul(f,e),c=n.mul(i,e);if(o)return{x:n.ZERO,y:n.ZERO};if(!n.eql(c,n.ONE))throw Error("invZ was invalid");return{x:s,y:a}})),d=_((t=>{if(t.is0()){if(e.allowInfinityPoint&&!n.is0(t.py))return;throw Error("bad point: ZERO")}const{x:r,y:f}=t.toAffine();if(!n.isValid(r)||!n.isValid(f))throw Error("bad point: x or y not FE");const i=n.sqr(f),s=o(r);if(!n.eql(i,s))throw Error("bad point: equation left != right");if(!t.isTorsionFree())throw Error("bad point: not in prime-order subgroup");return!0}));class u{constructor(t,e,r){if(this.px=t,this.py=e,this.pz=r,null==t||!n.isValid(t))throw Error("x required");if(null==e||!n.isValid(e))throw Error("y required");if(null==r||!n.isValid(r))throw Error("z required");Object.freeze(this)}static fromAffine(t){const{x:e,y:r}=t||{};if(!t||!n.isValid(e)||!n.isValid(r))throw Error("invalid affine point");if(t instanceof u)throw Error("projective point not allowed");const f=t=>n.eql(t,n.ZERO);return f(e)&&f(r)?u.ZERO:new u(e,r,n.ONE)}get x(){return this.toAffine().x}get y(){return this.toAffine().y}static normalizeZ(t){const e=n.invertBatch(t.map((t=>t.pz)));return t.map(((t,n)=>t.toAffine(e[n]))).map(u.fromAffine)}static fromHex(t){const e=u.fromAffine(i(N("pointHex",t)));return e.assertValidity(),e}static fromPrivateKey(t){return u.BASE.multiply(s(t))}static msm(t,e){return mt(u,r,t,e)}_setWindowSize(t){h.setWindowSize(this,t)}assertValidity(){d(this)}hasEvenY(){const{y:t}=this.toAffine();if(n.isOdd)return!n.isOdd(t);throw Error("Field doesn't support isOdd")}equals(t){a(t);const{px:e,py:r,pz:f}=this,{px:i,py:o,pz:s}=t,c=n.eql(n.mul(e,s),n.mul(i,f)),d=n.eql(n.mul(r,s),n.mul(o,f));return c&&d}negate(){return new u(this.px,n.neg(this.py),this.pz)}double(){const{a:t,b:r}=e,f=n.mul(r,At),{px:i,py:o,pz:s}=this;let a=n.ZERO,c=n.ZERO,d=n.ZERO,l=n.mul(i,i),h=n.mul(o,o),g=n.mul(s,s),b=n.mul(i,o);return b=n.add(b,b),d=n.mul(i,s),d=n.add(d,d),a=n.mul(t,d),c=n.mul(f,g),c=n.add(a,c),a=n.sub(h,c),c=n.add(h,c),c=n.mul(a,c),a=n.mul(b,a),d=n.mul(f,d),g=n.mul(t,g),b=n.sub(l,g),b=n.mul(t,b),b=n.add(b,d),d=n.add(l,l),l=n.add(d,l),l=n.add(l,g),l=n.mul(l,b),c=n.add(c,l),g=n.mul(o,s),g=n.add(g,g),l=n.mul(g,b),a=n.sub(a,l),d=n.mul(g,h),d=n.add(d,d),d=n.add(d,d),new u(a,c,d)}add(t){a(t);const{px:r,py:f,pz:i}=this,{px:o,py:s,pz:c}=t;let d=n.ZERO,l=n.ZERO,h=n.ZERO;const g=e.a,b=n.mul(e.b,At);let y=n.mul(r,o),p=n.mul(f,s),m=n.mul(i,c),w=n.add(r,f),B=n.add(o,s);w=n.mul(w,B),B=n.add(y,p),w=n.sub(w,B),B=n.add(r,i);let E=n.add(o,c);return B=n.mul(B,E),E=n.add(y,m),B=n.sub(B,E),E=n.add(f,i),d=n.add(s,c),E=n.mul(E,d),d=n.add(p,m),E=n.sub(E,d),h=n.mul(g,B),d=n.mul(b,m),h=n.add(d,h),d=n.sub(p,h),h=n.add(p,h),l=n.mul(d,h),p=n.add(y,y),p=n.add(p,y),m=n.mul(g,m),B=n.mul(b,B),p=n.add(p,m),m=n.sub(y,m),m=n.mul(g,m),B=n.add(B,m),y=n.mul(p,B),l=n.add(l,y),y=n.mul(E,B),d=n.mul(w,d),d=n.sub(d,y),y=n.mul(w,p),h=n.mul(E,h),h=n.add(h,y),new u(d,l,h)}subtract(t){return this.add(t.negate())}is0(){return this.equals(u.ZERO)}wNAF(t){return h.wNAFCached(this,t,u.normalizeZ)}multiplyUnsafe(t){const{endo:r,n:f}=e;F("scalar",t,vt,f);const i=u.ZERO;if(t===vt)return i;if(this.is0()||t===St)return this;if(!r||h.hasPrecomputes(this))return h.wNAFCachedUnsafe(this,t,u.normalizeZ);let{k1neg:o,k1:s,k2neg:a,k2:c}=r.splitScalar(t),d=i,l=i,g=this;for(;s>vt||c>vt;)s&St&&(d=d.add(g)),c&St&&(l=l.add(g)),g=g.double(),s>>=St,c>>=St;return o&&(d=d.negate()),a&&(l=l.negate()),l=new u(n.mul(l.px,r.beta),l.py,l.pz),d.add(l)}multiply(t){const{endo:r,n:f}=e;let i,o;if(F("scalar",t,St,f),r){const{k1neg:e,k1:f,k2neg:s,k2:a}=r.splitScalar(t);let{p:c,f:d}=this.wNAF(f),{p:l,f:g}=this.wNAF(a);c=h.constTimeNegate(e,c),l=h.constTimeNegate(s,l),l=new u(n.mul(l.px,r.beta),l.py,l.pz),i=c.add(l),o=d.add(g)}else{const{p:e,f:n}=this.wNAF(t);i=e,o=n}return u.normalizeZ([i,o])[0]}multiplyAndAddUnsafe(t,e,n){const r=u.BASE,f=(t,e)=>e!==vt&&e!==St&&t.equals(r)?t.multiply(e):t.multiplyUnsafe(e),i=f(this,e).add(f(t,n));return i.is0()?void 0:i}toAffine(t){return c(this,t)}isTorsionFree(){const{h:t,isTorsionFree:n}=e;if(t===St)return!0;if(n)return n(u,this);throw Error("isTorsionFree() has not been declared for the elliptic curve")}clearCofactor(){const{h:t,clearCofactor:n}=e;return t===St?this:n?n(u,this):this.multiplyUnsafe(e.h)}toRawBytes(t=!0){return B("isCompressed",t),this.assertValidity(),f(u,this,t)}toHex(t=!0){return B("isCompressed",t),x(this.toRawBytes(t))}}u.BASE=new u(e.Gx,e.Gy,n.ONE),u.ZERO=new u(n.ZERO,n.ONE,n.ZERO);const l=e.nBitLength,h=pt(u,e.endo?Math.ceil(l/2):l);return{CURVE:e,ProjectivePoint:u,normPrivateKeyToScalar:s,weierstrassEquation:o,isWithinCurveOrder:function(t){return T(t,St,e.n)}}}function Rt(t){const e=function(t){const e=wt(t);return V(e,{hash:"hash",hmac:"function",randomBytes:"function"},{bits2int:"function",bits2int_modN:"function",lowS:"boolean"}),Object.freeze({lowS:!0,...e})}(t),{Fp:n,n:r}=e,f=n.BYTES+1,i=2*n.BYTES+1;function o(t){return $(t,r)}function s(t){return nt(t,r)}const{ProjectivePoint:a,normPrivateKeyToScalar:c,weierstrassEquation:d,isWithinCurveOrder:u}=Ot({...e,toBytes(t,e,r){const f=e.toAffine(),i=n.toBytes(f.x),o=H;return B("isCompressed",r),r?o(Uint8Array.from([e.hasEvenY()?2:3]),i):o(Uint8Array.from([4]),i,n.toBytes(f.y))},fromBytes(t){const e=t.length,r=t[0],o=t.subarray(1);if(e!==f||2!==r&&3!==r){if(e===i&&4===r){return{x:n.fromBytes(o.subarray(0,n.BYTES)),y:n.fromBytes(o.subarray(n.BYTES,2*n.BYTES))}}throw Error("invalid Point, expected length of "+f+", or uncompressed "+i+", got "+e)}{const t=R(o);if(!T(t,St,n.ORDER))throw Error("Point is not on curve");const e=d(t);let f;try{f=n.sqrt(e)}catch(t){const e=t instanceof Error?": "+t.message:"";throw Error("Point is not on curve"+e)}return!(1&~r)!==((f&St)===St)&&(f=n.neg(f)),{x:t,y:f}}}}),l=t=>x(q(t,e.nByteLength));function h(t){return t>r>>St}const g=(t,e,n)=>R(t.slice(e,n));class b{constructor(t,e,n){this.r=t,this.s=e,this.recovery=n,this.assertValidity()}static fromCompact(t){const n=e.nByteLength;return t=N("compactSignature",t,2*n),new b(g(t,0,n),g(t,n,2*n))}static fromDER(t){const{r:e,s:n}=It.toSig(N("DER",t));return new b(e,n)}assertValidity(){F("r",this.r,St,r),F("s",this.s,St,r)}addRecoveryBit(t){return new b(this.r,this.s,t)}recoverPublicKey(t){const{r,s:f,recovery:i}=this,c=E(N("msgHash",t));if(null==i||![0,1,2,3].includes(i))throw Error("recovery id invalid");const d=2===i||3===i?r+e.n:r;if(d>=n.ORDER)throw Error("recovery id 2 or 3 invalid");const u=1&i?"03":"02",h=a.fromHex(u+l(d)),g=s(d),b=o(-c*g),y=o(f*g),p=a.BASE.multiplyAndAddUnsafe(h,b,y);if(!p)throw Error("point at infinify");return p.assertValidity(),p}hasHighS(){return h(this.s)}normalizeS(){return this.hasHighS()?new b(this.r,o(-this.s),this.recovery):this}toDERRawBytes(){return O(this.toDERHex())}toDERHex(){return It.hexFromSig({r:this.r,s:this.s})}toCompactRawBytes(){return O(this.toCompactHex())}toCompactHex(){return l(this.r)+l(this.s)}}const y={isValidPrivateKey(t){try{return c(t),!0}catch(t){return!1}},normPrivateKeyToScalar:c,randomPrivateKey:()=>{const t=at(e.n);return function(t,e,n=!1){const r=t.length,f=st(e),i=at(e);if(r<16||r<i||r>1024)throw Error("expected "+i+"-1024 bytes of input, got "+r);const o=$(n?R(t):z(t),e-M)+M;return n?P(o,f):q(o,f)}(e.randomBytes(t),e.n)},precompute:(t=8,e=a.BASE)=>(e._setWindowSize(t),e.multiply(BigInt(3)),e)};function p(t){const e=m(t),n="string"==typeof t,r=(e||n)&&t.length;return e?r===f||r===i:n?r===2*f||r===2*i:t instanceof a}const w=e.bits2int||function(t){if(t.length>8192)throw Error("input is too large");const n=R(t),r=8*t.length-e.nBitLength;return r>0?n>>BigInt(r):n},E=e.bits2int_modN||function(t){return o(w(t))},I=Z(e.nBitLength);function v(t){return F("num < 2^"+e.nBitLength,t,vt,I),q(t,e.nByteLength)}function S(t,r,f=A){if(["recovered","canonical"].some((t=>t in f)))throw Error("sign() legacy options not supported");const{hash:i,randomBytes:d}=e;let{lowS:l,prehash:g,extraEntropy:y}=f;null==l&&(l=!0),t=N("msgHash",t),Bt(f),g&&(t=N("prehashed msgHash",i(t)));const p=E(t),m=c(r),B=[v(m),v(p)];if(null!=y&&!1!==y){const t=!0===y?d(n.BYTES):y;B.push(N("extraEntropy",t))}const x=H(...B),I=p;return{seed:x,k2sig:function(t){const e=w(t);if(!u(e))return;const n=s(e),r=a.BASE.multiply(e).toAffine(),f=o(r.x);if(f===vt)return;const i=o(n*o(I+f*m));if(i===vt)return;let c=(r.x===f?0:2)|Number(r.y&St),d=i;return l&&h(i)&&(d=function(t){return h(t)?o(-t):t}(i),c^=1),new b(f,d,c)}}}const A={lowS:e.lowS,prehash:!1},L={lowS:e.lowS,prehash:!1};return a.BASE._setWindowSize(8),{CURVE:e,getPublicKey:function(t,e=!0){return a.fromPrivateKey(t).toRawBytes(e)},getSharedSecret:function(t,e,n=!0){if(p(t))throw Error("first arg must be private key");if(!p(e))throw Error("second arg must be public key");return a.fromHex(e).multiply(c(t)).toRawBytes(n)},sign:function(t,n,r=A){const{seed:f,k2sig:i}=S(t,n,r),o=e;return C(o.hash.outputLen,o.nByteLength,o.hmac)(f,i)},verify:function(t,n,r,f=L){const i=t;n=N("msgHash",n),r=N("publicKey",r);const{lowS:c,prehash:d,format:u}=f;if(Bt(f),"strict"in f)throw Error("options.strict was renamed to lowS");if(void 0!==u&&"compact"!==u&&"der"!==u)throw Error("format must be compact or der");const l="string"==typeof i||m(i),h=!l&&!u&&"object"==typeof i&&null!==i&&"bigint"==typeof i.r&&"bigint"==typeof i.s;if(!l&&!h)throw Error("invalid signature, expected Uint8Array, hex string or Signature instance");let g,y;try{if(h&&(g=new b(i.r,i.s)),l){try{"compact"!==u&&(g=b.fromDER(i))}catch(t){if(!(t instanceof It.Err))throw t}g||"der"===u||(g=b.fromCompact(i))}y=a.fromHex(r)}catch(t){return!1}if(!g)return!1;if(c&&g.hasHighS())return!1;d&&(n=e.hash(n));const{r:p,s:w}=g,B=E(n),x=s(w),I=o(B*x),v=o(p*x),S=a.BASE.multiplyAndAddUnsafe(y,I,v)?.toAffine();return!!S&&o(S.x)===p},ProjectivePoint:a,Signature:b,utils:y}}
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */function zt(t){return{hash:t,hmac:(e,...n)=>g(t,e,a(...n)),randomBytes:c}}function qt(t,e){const n=e=>Rt({...t,...zt(e)});return Object.freeze({...n(e),create:n})}
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */BigInt(4);const Pt=ot(BigInt("0xffffffff00000001000000000000000000000000ffffffffffffffffffffffff")),Nt=qt({a:Pt.create(BigInt("-3")),b:BigInt("0x5ac635d8aa3a93e7b3ebbd55769886bc651d06b0cc53b0f63bce3c3e27d2604b"),Fp:Pt,n:BigInt("0xffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632551"),Gx:BigInt("0x6b17d1f2e12c4247f8bce6e563a440f277037d812deb33a0f4a13945d898c296"),Gy:BigInt("0x4fe342e2fe1a7f9b8ee7eb4a7c0f9e162bce33576b315ececbb6406837bf51f5"),h:BigInt(1),lowS:!1},t),Ht=ot(BigInt("0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffeffffffff0000000000000000ffffffff")),Lt=qt({a:Ht.create(BigInt("-3")),b:BigInt("0xb3312fa7e23ee7e4988e056be3f82d19181d9c6efe8141120314088f5013875ac656398d8a2ed19d2a85c8edd3ec2aef"),Fp:Ht,n:BigInt("0xffffffffffffffffffffffffffffffffffffffffffffffffc7634d81f4372ddf581a0db248b0a77aecec196accc52973"),Gx:BigInt("0xaa87ca22be8b05378eb1c71ef320ad746e1d3b628ba79b9859f741e082542a385502f25dbf55296c3a545e3872760ab7"),Gy:BigInt("0x3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f"),h:BigInt(1),lowS:!1},e),Tt=ot(BigInt("0x1ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff")),Ft={a:Tt.create(BigInt("-3")),b:BigInt("0x0051953eb9618e1c9a1f929a21a0b68540eea2da725b99b315f3b8b489918ef109e156193951ec7e937b1652c0bd3bb1bf073573df883d2c34f1ef451fd46b503f00"),Fp:Tt,n:BigInt("0x01fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffa51868783bf2f966b7fcc0148f709a5d03bb5c9b8899c47aebb6fb71e91386409"),Gx:BigInt("0x00c6858e06b70404e9cd9e3ecb662395b4429c648139053fb521f828af606b4d3dbaa14b5e77efe75928fe1dc127a2ffa8de3348b3c1856a429bf97e7e31c2e5bd66"),Gy:BigInt("0x011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650"),h:BigInt(1)},Ut=qt({a:Ft.a,b:Ft.b,Fp:Tt,n:Ft.n,Gx:Ft.Gx,Gy:Ft.Gy,h:Ft.h,lowS:!1,allowedPrivateKeyLengths:[130,131,132]},n),Zt=BigInt(0),kt=BigInt(1),Gt=BigInt(2),Ct=BigInt(8),jt={zip215:!0};function Vt(t){const e=function(t){const e=wt(t);return V(t,{hash:"function",a:"bigint",d:"bigint",randomBytes:"function"},{adjustScalarBytes:"function",domain:"function",uvRatio:"function",mapToCurve:"function"}),Object.freeze({...e})}(t),{Fp:n,n:r,prehash:f,hash:i,randomBytes:o,nByteLength:s,h:a}=e,c=Gt<<BigInt(8*s)-kt,d=n.create,u=ot(e.n,e.nBitLength),l=e.uvRatio||((t,e)=>{try{return{isValid:!0,value:n.sqrt(t*n.inv(e))}}catch(t){return{isValid:!1,value:Zt}}}),h=e.adjustScalarBytes||(t=>t),g=e.domain||((t,e,n)=>{if(B("phflag",n),e.length||n)throw Error("Contexts/pre-hash are not supported");return t});function b(t,e){F("coordinate "+t,e,Zt,c)}function y(t){if(!(t instanceof w))throw Error("ExtendedPoint expected")}const p=_(((t,e)=>{const{ex:r,ey:f,ez:i}=t,o=t.is0();null==e&&(e=o?Ct:n.inv(i));const s=d(r*e),a=d(f*e),c=d(i*e);if(o)return{x:Zt,y:kt};if(c!==kt)throw Error("invZ was invalid");return{x:s,y:a}})),m=_((t=>{const{a:n,d:r}=e;if(t.is0())throw Error("bad point: ZERO");const{ex:f,ey:i,ez:o,et:s}=t,a=d(f*f),c=d(i*i),u=d(o*o),l=d(u*u),h=d(a*n);if(d(u*d(h+c))!==d(l+d(r*d(a*c))))throw Error("bad point: equation left != right (1)");if(d(f*i)!==d(o*s))throw Error("bad point: equation left != right (2)");return!0}));class w{constructor(t,e,n,r){this.ex=t,this.ey=e,this.ez=n,this.et=r,b("x",t),b("y",e),b("z",n),b("t",r),Object.freeze(this)}get x(){return this.toAffine().x}get y(){return this.toAffine().y}static fromAffine(t){if(t instanceof w)throw Error("extended point not allowed");const{x:e,y:n}=t||{};return b("x",e),b("y",n),new w(e,n,kt,d(e*n))}static normalizeZ(t){const e=n.invertBatch(t.map((t=>t.ez)));return t.map(((t,n)=>t.toAffine(e[n]))).map(w.fromAffine)}static msm(t,e){return mt(w,u,t,e)}_setWindowSize(t){v.setWindowSize(this,t)}assertValidity(){m(this)}equals(t){y(t);const{ex:e,ey:n,ez:r}=this,{ex:f,ey:i,ez:o}=t,s=d(e*o),a=d(f*r),c=d(n*o),u=d(i*r);return s===a&&c===u}is0(){return this.equals(w.ZERO)}negate(){return new w(d(-this.ex),this.ey,this.ez,d(-this.et))}double(){const{a:t}=e,{ex:n,ey:r,ez:f}=this,i=d(n*n),o=d(r*r),s=d(Gt*d(f*f)),a=d(t*i),c=n+r,u=d(d(c*c)-i-o),l=a+o,h=l-s,g=a-o,b=d(u*h),y=d(l*g),p=d(u*g),m=d(h*l);return new w(b,y,m,p)}add(t){y(t);const{a:n,d:r}=e,{ex:f,ey:i,ez:o,et:s}=this,{ex:a,ey:c,ez:u,et:l}=t;if(n===BigInt(-1)){const t=d((i-f)*(c+a)),e=d((i+f)*(c-a)),n=d(e-t);if(n===Zt)return this.double();const r=d(o*Gt*l),h=d(s*Gt*u),g=h+r,b=e+t,y=h-r,p=d(g*n),m=d(b*y),B=d(g*y),E=d(n*b);return new w(p,m,E,B)}const h=d(f*a),g=d(i*c),b=d(s*r*l),p=d(o*u),m=d((f+i)*(a+c)-h-g),B=p-b,E=p+b,x=d(g-n*h),I=d(m*B),v=d(E*x),S=d(m*x),A=d(B*E);return new w(I,v,A,S)}subtract(t){return this.add(t.negate())}wNAF(t){return v.wNAFCached(this,t,w.normalizeZ)}multiply(t){const e=t;F("scalar",e,kt,r);const{p:n,f}=this.wNAF(e);return w.normalizeZ([n,f])[0]}multiplyUnsafe(t,e=w.ZERO){const n=t;return F("scalar",n,Zt,r),n===Zt?I:this.is0()||n===kt?this:v.wNAFCachedUnsafe(this,n,w.normalizeZ,e)}isSmallOrder(){return this.multiplyUnsafe(a).is0()}isTorsionFree(){return v.unsafeLadder(this,r).is0()}toAffine(t){return p(this,t)}clearCofactor(){const{h:t}=e;return t===kt?this:this.multiplyUnsafe(t)}static fromHex(t,r=!1){const{d:f,a:i}=e,o=n.BYTES;t=N("pointHex",t,o),B("zip215",r);const s=t.slice(),a=t[o-1];s[o-1]=-129&a;const u=z(s),h=r?c:n.ORDER;F("pointHex.y",u,Zt,h);const g=d(u*u),b=d(g-kt),y=d(f*g-i);let{isValid:p,value:m}=l(b,y);if(!p)throw Error("Point.fromHex: invalid y coordinate");const E=(m&kt)===kt,x=!!(128&a);if(!r&&m===Zt&&x)throw Error("Point.fromHex: x=0 and x_0=1");return x!==E&&(m=d(-m)),w.fromAffine({x:m,y:u})}static fromPrivateKey(t){return O(t).point}toRawBytes(){const{x:t,y:e}=this.toAffine(),r=P(e,n.BYTES);return r[r.length-1]|=t&kt?128:0,r}toHex(){return x(this.toRawBytes())}}w.BASE=new w(e.Gx,e.Gy,kt,d(e.Gx*e.Gy)),w.ZERO=new w(Zt,kt,kt,Zt);const{BASE:E,ZERO:I}=w,v=pt(w,8*s);function S(t){return $(t,r)}function A(t){return S(z(t))}function O(t){const e=n.BYTES;t=N("private key",t,e);const r=N("hashed private key",i(t),2*e),f=h(r.slice(0,e)),o=r.slice(e,2*e),s=A(f),a=E.multiply(s),c=a.toRawBytes();return{head:f,prefix:o,scalar:s,point:a,pointBytes:c}}function R(t=new Uint8Array,...e){const n=H(...e);return A(i(g(n,N("context",t),!!f)))}const q=jt;E._setWindowSize(8);return{CURVE:e,getPublicKey:function(t){return O(t).pointBytes},sign:function(t,e,i={}){t=N("message",t),f&&(t=f(t));const{prefix:o,scalar:s,pointBytes:a}=O(e),c=R(i.context,o,t),d=E.multiply(c).toRawBytes(),u=S(c+R(i.context,d,a,t)*s);return F("signature.s",u,Zt,r),N("result",H(d,P(u,n.BYTES)),2*n.BYTES)},verify:function(t,e,r,i=q){const{context:o,zip215:s}=i,a=n.BYTES;t=N("signature",t,2*a),e=N("message",e),r=N("publicKey",r,a),void 0!==s&&B("zip215",s),f&&(e=f(e));const c=z(t.slice(a,2*a));let d,u,l;try{d=w.fromHex(r,s),u=w.fromHex(t.slice(0,a),s),l=E.multiplyUnsafe(c)}catch(t){return!1}if(!s&&d.isSmallOrder())return!1;const h=R(o,u.toRawBytes(),d.toRawBytes(),e);return u.add(d.multiplyUnsafe(h)).subtract(l).clearCofactor().equals(w.ZERO)},ExtendedPoint:w,utils:{getExtendedPublicKey:O,randomPrivateKey:()=>o(n.BYTES),precompute:(t=8,e=w.BASE)=>(e._setWindowSize(t),e.multiply(BigInt(3)),e)}}}
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */const _t=BigInt(0),Kt=BigInt(1);function Yt(t){const e=(V(n=t,{a:"bigint"},{montgomeryBits:"isSafeInteger",nByteLength:"isSafeInteger",adjustScalarBytes:"function",domain:"function",powPminus2:"function",Gu:"bigint"}),Object.freeze({...n}));var n;const{P:r}=e,f=t=>$(t,r),i=e.montgomeryBits,o=Math.ceil(i/8),s=e.nByteLength,a=e.adjustScalarBytes||(t=>t),c=e.powPminus2||(t=>tt(t,r-BigInt(2),r));function d(t,e,n){const r=f(t*(e-n));return[e=f(e-r),n=f(n+r)]}const u=(e.a-BigInt(2))/BigInt(4);function l(t){return P(f(t),o)}function h(t,e){const n=function(t){const e=N("u coordinate",t,o);return 32===s&&(e[31]&=127),z(e)}(e),h=function(t,e){F("u",t,_t,r),F("scalar",e,_t,r);const n=e,o=t;let s,a=Kt,l=_t,h=t,g=Kt,b=_t;for(let t=BigInt(i-1);t>=_t;t--){const e=n>>t&Kt;b^=e,s=d(b,a,h),a=s[0],h=s[1],s=d(b,l,g),l=s[0],g=s[1],b=e;const r=a+l,i=f(r*r),c=a-l,y=f(c*c),p=i-y,m=h+g,w=f((h-g)*r),B=f(m*c),E=w+B,x=w-B;h=f(E*E),g=f(o*f(x*x)),a=f(i*y),l=f(p*(i+f(u*p)))}s=d(b,a,h),a=s[0],h=s[1],s=d(b,l,g),l=s[0],g=s[1];const y=c(l);return f(a*y)}(n,function(t){const e=N("scalar",t),n=e.length;if(n!==o&&n!==s)throw Error("invalid scalar, expected "+o+" or "+s+" bytes, got "+n);return z(a(e))}(t));if(h===_t)throw Error("invalid private or public key received");return l(h)}const g=l(e.Gu);function b(t){return h(t,g)}return{scalarMult:h,scalarMultBase:b,getSharedSecret:(t,e)=>h(t,e),getPublicKey:t=>b(t),utils:{randomPrivateKey:()=>e.randomBytes(e.nByteLength)},GuBytes:g}}
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */const Mt=d((()=>l.create({dkLen:114}))),Dt=(d((()=>l.create({dkLen:64}))),BigInt("726838724295606890549323807888004534353641360687318060281490199180612328166730772686396383698676545930088884461843637361053498018365439")),Wt=BigInt(1),Jt=BigInt(2),Qt=BigInt(3);BigInt(4);const Xt=BigInt(11),$t=BigInt(22),te=BigInt(44),ee=BigInt(88),ne=BigInt(223);function re(t){const e=Dt,n=t*t*t%e,r=n*n*t%e,f=et(r,Qt,e)*r%e,i=et(f,Qt,e)*r%e,o=et(i,Jt,e)*n%e,s=et(o,Xt,e)*o%e,a=et(s,$t,e)*s%e,c=et(a,te,e)*a%e,d=et(c,ee,e)*c%e,u=et(d,te,e)*a%e,l=et(u,Jt,e)*n%e,h=et(l,Wt,e)*t%e;return et(h,ne,e)*l%e}function fe(t){return t[0]&=252,t[55]|=128,t[56]=0,t}const ie=ot(Dt,456,!0),oe={a:BigInt(1),d:BigInt("726838724295606890549323807888004534353641360687318060281490199180612328166730772686396383698676545930088884461843637361053498018326358"),Fp:ie,n:BigInt("181709681073901722637330951972001133588410340171829515070372549795146003961539585716195755291692375963310293709091662304773755859649779"),nBitLength:456,h:BigInt(4),Gx:BigInt("224580040295924300187604334099896036246789641632564134246125461686950415467406032909029192869357953282578032075146446173674602635247710"),Gy:BigInt("298819210078481492676017930443930673437544040154080242095928241372331506189835876003536878655418784733982303233503462500531545062832660"),hash:Mt,randomBytes:c,adjustScalarBytes:fe,domain:(t,e,n)=>{if(e.length>255)throw Error("context must be smaller than 255, got: "+e.length);return a(u("SigEd448"),new Uint8Array([n?1:0,e.length]),e,t)},uvRatio:function(t,e){const n=Dt,r=$(t*t*e,n),f=$(r*t,n),i=$(f*r*e,n),o=$(f*re(i),n),s=$(o*o,n);return{isValid:$(s*e,n)===t,value:o}}},se=/* @__PURE__ */Vt(oe),ae=/* @__PURE__ */(()=>Yt({a:BigInt(156326),montgomeryBits:448,nByteLength:56,P:Dt,Gu:BigInt(5),powPminus2:t=>{const e=Dt;return $(et(re(t),BigInt(2),e)*t,e)},adjustScalarBytes:fe,randomBytes:c}))();ie.ORDER,BigInt(3),BigInt(4),BigInt(156326),BigInt("39082"),BigInt("78163"),BigInt("98944233647732219769177004876929019128417576295529901074099889598043702116001257856802131563896515373927712232092845883226922417596214"),BigInt("315019913931389607337177038330951043522456072897266928557328499619017160722351061360252776265186336876723201881398623946864393857820716"),BigInt("0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff");
/*! noble-curves - MIT License (c) 2022 Paul Miller (paulmillr.com) */
const ce=BigInt("0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2f"),de=BigInt("0xfffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141"),ue=BigInt(1),le=BigInt(2),he=(t,e)=>(t+e/le)/e;const ge=ot(ce,void 0,void 0,{sqrt:function(t){const e=ce,n=BigInt(3),r=BigInt(6),f=BigInt(11),i=BigInt(22),o=BigInt(23),s=BigInt(44),a=BigInt(88),c=t*t*t%e,d=c*c*t%e,u=et(d,n,e)*d%e,l=et(u,n,e)*d%e,h=et(l,le,e)*c%e,g=et(h,f,e)*h%e,b=et(g,i,e)*g%e,y=et(b,s,e)*b%e,p=et(y,a,e)*y%e,m=et(p,s,e)*b%e,w=et(m,n,e)*d%e,B=et(w,o,e)*g%e,E=et(B,r,e)*c%e,x=et(E,le,e);if(!ge.eql(ge.sqr(x),t))throw Error("Cannot find square root");return x}}),be=qt({a:BigInt(0),b:BigInt(7),Fp:ge,n:de,Gx:BigInt("55066263022277343669578718895168534326250603453777594175500187360389116729240"),Gy:BigInt("32670510020758816978083085130507043184471273380659243275938904335757337482424"),h:BigInt(1),lowS:!0,endo:{beta:BigInt("0x7ae96a2b657c07106e64479eac3434e99cf0497512f58995c1396c28719501ee"),splitScalar:t=>{const e=de,n=BigInt("0x3086d221a7d46bcde86c90e49284eb15"),r=-ue*BigInt("0xe4437ed6010e88286f547fa90abfe4c3"),f=BigInt("0x114ca50f7a8e2f3f657c1108d9d44cfd8"),i=n,o=BigInt("0x100000000000000000000000000000000"),s=he(i*t,e),a=he(-r*t,e);let c=$(t-s*n-a*f,e),d=$(-s*r-a*i,e);const u=c>o,l=d>o;if(u&&(c=e-c),l&&(d=e-d),c>o||d>o)throw Error("splitScalar: Endomorphism failed, k="+t);return{k1neg:u,k1:c,k2neg:l,k2:d}}}},t);BigInt(0),be.ProjectivePoint;const ye=ot(BigInt("0xa9fb57dba1eea9bc3e660a909d838d726e3bf623d52620282013481d1f6e5377")),pe=qt({a:ye.create(BigInt("0x7d5a0975fc2c3057eef67530417affe7fb8055c126dc5c6ce94a4b44f330b5d9")),b:BigInt("0x26dc5c6ce94a4b44f330b5d9bbd77cbf958416295cf7e1ce6bccdc18ff8c07b6"),Fp:ye,n:BigInt("0xa9fb57dba1eea9bc3e660a909d838d718c397aa3b561a6f7901e0e82974856a7"),Gx:BigInt("0x8bd2aeb9cb7e57cb2c4b482ffc81b7afb9de27e1e3bd23c23a4453bd9ace3262"),Gy:BigInt("0x547ef835c3dac4fd97f8461a14611dc9c27745132ded8e545c1d54c72f046997"),h:BigInt(1),lowS:!1},t),me=ot(BigInt("0x8cb91e82a3386d280f5d6f7e50e641df152f7109ed5456b412b1da197fb71123acd3a729901d1a71874700133107ec53")),we=qt({a:me.create(BigInt("0x7bc382c63d8c150c3c72080ace05afa0c2bea28e4fb22787139165efba91f90f8aa5814a503ad4eb04a8c7dd22ce2826")),b:BigInt("0x04a8c7dd22ce28268b39b55416f0447c2fb77de107dcd2a62e880ea53eeb62d57cb4390295dbc9943ab78696fa504c11"),Fp:me,n:BigInt("0x8cb91e82a3386d280f5d6f7e50e641df152f7109ed5456b31f166e6cac0425a7cf3ab6af6b7fc3103b883202e9046565"),Gx:BigInt("0x1d1c64f068cf45ffa2a63a81b7c13f6b8847a3e77ef14fe3db7fcafe0cbd10e8e826e03436d646aaef87b2e247d4af1e"),Gy:BigInt("0x8abe1d7520f9c2a45cb1eb8e95cfd55262b70b29feec5864e19c054ff99129280e4646217791811142820341263c5315"),h:BigInt(1),lowS:!1},e),Be=ot(BigInt("0xaadd9db8dbe9c48b3fd4e6ae33c9fc07cb308db3b3c9d20ed6639cca703308717d4d9b009bc66842aecda12ae6a380e62881ff2f2d82c68528aa6056583a48f3")),Ee=qt({a:Be.create(BigInt("0x7830a3318b603b89e2327145ac234cc594cbdd8d3df91610a83441caea9863bc2ded5d5aa8253aa10a2ef1c98b9ac8b57f1117a72bf2c7b9e7c1ac4d77fc94ca")),b:BigInt("0x3df91610a83441caea9863bc2ded5d5aa8253aa10a2ef1c98b9ac8b57f1117a72bf2c7b9e7c1ac4d77fc94cadc083e67984050b75ebae5dd2809bd638016f723"),Fp:Be,n:BigInt("0xaadd9db8dbe9c48b3fd4e6ae33c9fc07cb308db3b3c9d20ed6639cca70330870553e5c414ca92619418661197fac10471db1d381085ddaddb58796829ca90069"),Gx:BigInt("0x81aee4bdd82ed9645a21322e9c4c6a9385ed9f70b5d916c1b43b62eef4d0098eff3b1f78e2d0d48d50d1687b93b97d5f7c6d5047406a5e688b352209bcb9f822"),Gy:BigInt("0x7dde385d566332ecc0eabfa9cf7822fdf209f70024a57b1aa000c55b881f8111b2dcde494a5f485e5bca4bd88a2763aed1ca2b2fa8f0540678cd1e0f3ad80892"),h:BigInt(1),lowS:!1},n),xe=new Map(Object.entries({nistP256:Nt,nistP384:Lt,nistP521:Ut,brainpoolP256r1:pe,brainpoolP384r1:we,brainpoolP512r1:Ee,secp256k1:be,x448:ae,ed448:se}));export{xe as nobleCurves};
//# sourceMappingURL=noble_curves.min.mjs.map