UNPKG

openpgp

Version:

OpenPGP.js is a Javascript implementation of the OpenPGP protocol. This is defined in RFC 4880.

5 lines • 234 kB
/*! OpenPGP.js v6.3.2 - 2026-09-24 - this is LGPL licensed code, see LICENSE/our website https://openpgpjs.org/ for more information. */
const e="undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{},t=Symbol("doneWritingPromise"),r=Symbol("doneWritingResolve"),i=Symbol("doneWritingReject"),n=Symbol("readingIndex");class s extends Array{constructor(){super(),Object.setPrototypeOf(this,s.prototype),this[t]=new Promise(((e,t)=>{this[r]=e,this[i]=t})),this[t].catch((()=>{}))}}function a(e){return e&&e.getReader&&Array.isArray(e)}function o(e){if(!a(e)){const t=e.getWriter(),r=t.releaseLock;return t.releaseLock=()=>{t.closed.catch((function(){})),r.call(t)},t}this.stream=e}function c(t){if(a(t))return"array";if(e.ReadableStream&&e.ReadableStream.prototype.isPrototypeOf(t))return"web";if(t&&!(e.ReadableStream&&t instanceof e.ReadableStream)&&"function"==typeof t._read&&"object"==typeof t._readableState)throw Error("Native Node streams are no longer supported: please manually convert the stream to a WebStream, using e.g. `stream.Readable.toWeb`");return!(!t||!t.getReader)&&"web-like"}function u(e){return Uint8Array.prototype.isPrototypeOf(e)}function h(e){if(1===e.length)return e[0];let t=0;for(let r=0;r<e.length;r++){if(!u(e[r]))throw Error("concatUint8Array: Data must be in the form of a Uint8Array");t+=e[r].length}const r=new Uint8Array(t);let i=0;return e.forEach((function(e){r.set(e,i),i+=e.length})),r}s.prototype.getReader=function(){return void 0===this[n]&&(this[n]=0),{read:async()=>(await this[t],this[n]===this.length?{value:void 0,done:!0}:{value:this[this[n]++],done:!1})}},s.prototype.readToEnd=async function(e){await this[t];const r=e(this.slice(this[n]));return this.length=0,r},s.prototype.clone=function(){const e=new s;return e[t]=this[t].then((()=>{e.push(...this)})),e},o.prototype.write=async function(e){this.stream.push(e)},o.prototype.close=async function(){this.stream[r]()},o.prototype.abort=async function(e){return this.stream[i](e),e},o.prototype.releaseLock=function(){},"object"==typeof e.process&&e.process.versions;const y=new WeakSet,l=Symbol("externalBuffer");function p(e){if(this.stream=e,e[l]&&(this[l]=e[l].slice()),a(e)){const t=e.getReader();return this._read=t.read.bind(t),this._releaseLock=()=>{},void(this._cancel=()=>{})}if(c(e)){const t=e.getReader();return this._read=t.read.bind(t),this._releaseLock=()=>{t.closed.catch((function(){})),t.releaseLock()},void(this._cancel=t.cancel.bind(t))}let t=!1;this._read=async()=>t||y.has(e)?{value:void 0,done:!0}:(t=!0,{value:e,done:!1}),this._releaseLock=()=>{if(t)try{y.add(e)}catch{}}}function g(e){return c(e)?e:new ReadableStream({start(t){t.enqueue(e),t.close()}})}function d(e){const t=c(e);if(t){if("array"!==t)throw Error("Can't convert Stream to ArrayStream here, call `readToEnd` first");return e}const r=new s;return(async()=>{const t=B(r);await t.write(e),await t.close()})(),r}function f(e){return e.some((e=>c(e)&&!a(e)))?function(e){const t=e.map(g),r=w((async function(e){await Promise.all(n.map((t=>x(t,e))))}));let i=Promise.resolve();const n=t.map(((e,n)=>A(e,((e,s)=>(i=i.then((()=>m(e,r.writable,{preventClose:n!==t.length-1}))),i)))));return r.readable}(e):e.some((e=>a(e)))?function(e){const t=new s;let r=Promise.resolve();return e.forEach(((i,n)=>(r=r.then((()=>m(i,t,{preventClose:n!==e.length-1}))),r))),t}(e):"string"==typeof e[0]?e.join(""):h(e)}async function m(e,t,{preventClose:r=!1,preventAbort:i=!1,preventCancel:n=!1}={}){if(c(e)&&!a(e)&&!a(t)){e=g(e);try{if(e[l]){const r=B(t);for(let t=0;t<e[l].length;t++)await r.ready,await r.write(e[l][t]);r.releaseLock()}await e.pipeTo(t,{preventClose:r,preventAbort:i,preventCancel:n})}catch{}return}c(e)||(e=d(e));const s=C(e),o=B(t);try{for(;;){await o.ready;const{done:e,value:t}=await s.read();if(e){r||await o.close();break}await o.write(t)}}catch(e){i||await o.abort(e)}finally{s.releaseLock(),o.releaseLock()}}function w(e){let t,r,i,n=!1,s=!1;return{readable:new ReadableStream({start(e){i=e},pull(){t?t():n=!0},async cancel(t){s=!0,e&&await e(t),r&&r(t)}},{highWaterMark:0}),writable:new WritableStream({write:async function(e){if(s)throw Error("Stream is cancelled");i.enqueue(e),n?n=!1:(await new Promise(((e,i)=>{t=e,r=i})),t=null,r=null)},close:i.close.bind(i),abort:i.error.bind(i)})}}function b(e,t=()=>{},r=()=>{},i={highWaterMark:0}){if(c(e))return v(e,t,r,i);const n=t(e),s=r();return void 0!==n&&void 0!==s?f([n,s]):void 0!==n?n:s}async function k(e,t=async()=>{},r=async()=>{},i={highWaterMark:1}){if(c(e))return v(e,t,r,i);const n=await t(e),s=await r();return void 0!==n&&void 0!==s?f([n,s]):void 0!==n?n:s}function v(e,t,r,i){if(a(e)){const i=new s;return(async()=>{const n=B(i);try{const i=await D(e),s=await t(i),a=await r();let o;o=void 0!==s&&void 0!==a?f([s,a]):void 0!==s?s:a,await n.write(o),await n.close()}catch(e){await n.abort(e)}})(),i}if(c(e)){let n,s=!1;return new ReadableStream({start(){n=e.getReader()},async pull(i){if(s)return i.close(),void e.releaseLock();try{for(;;){const{value:a,done:o}=await n.read();s=o;const c=await(o?r:t)(a);if(void 0!==c)return void i.enqueue(c);if(o)return i.close(),void e.releaseLock()}}catch(e){i.error(e)}},async cancel(e){await n.cancel(e)}},i)}throw Error("Unreachable")}function A(e,t){if(c(e)&&!a(e)){let r;const i=new TransformStream({start(e){r=e}}),n=m(e,i.writable),s=w((async function(e){r.error(e),await n,await new Promise((e=>setTimeout(e)))}));return t(i.readable,s.writable),s.readable}e=d(e);const r=new s;return t(e,r),r}function K(e,t){let r;const i=A(e,((e,n)=>{const s=C(e);s.remainder=()=>(s.releaseLock(),m(e,n),i),r=t(s)}));return r}function E(e){if(a(e))return e.clone();if(c(e)){const t=function(e){if(a(e))throw Error("ArrayStream cannot be tee()d, use clone() instead");if(c(e)){const t=g(e).tee();return t[0][l]=t[1][l]=e[l],t}return[U(e),U(e)]}(e);return P(e,t[0]),t[1]}return U(e)}function S(e){return a(e)?E(e):c(e)?new ReadableStream({start(t){const r=A(e,(async(e,r)=>{const i=C(e),n=B(r);try{for(;;){await n.ready;const{done:e,value:r}=await i.read();if(e){try{t.close()}catch{}return void await n.close()}try{t.enqueue(r)}catch{}await n.write(r)}}catch(e){t.error(e),await n.abort(e)}}));P(e,r)}}):U(e)}function P(e,t){Object.entries(Object.getOwnPropertyDescriptors(e.constructor.prototype)).forEach((([r,i])=>{"constructor"!==r&&(i.value?i.value=i.value.bind(t):i.get=i.get.bind(t),Object.defineProperty(e,r,i))}))}function U(e,t=0,r=1/0){if(a(e))throw Error("Not implemented");if(c(e)){if(t>=0&&r>=0){let i,n=0;return new ReadableStream({start(){i=e.getReader()},async pull(s){try{for(;;){if(!(n<r))return s.close(),void e.releaseLock();{const{value:a,done:o}=await i.read();if(o)return s.close(),void e.releaseLock();let c;if(n+a.length>=t&&(c=U(a,Math.max(t-n,0),r-n)),n+=a.length,c)return void s.enqueue(c)}}}catch(e){s.error(e)}},async cancel(e){await i.cancel(e)}},{highWaterMark:0})}if(t<0&&(r<0||r===1/0)){let i=[];return b(e,(e=>{e.length>=-t?i=[e]:i.push(e)}),(()=>U(f(i),t,r)))}if(0===t&&r<0){let i;return b(e,(e=>{const n=i?f([i,e]):e;if(n.length>=-r)return i=U(n,r),U(n,t,r);i=n}))}return console.warn(`stream.slice(input, ${t}, ${r}) not implemented efficiently.`),I((async()=>U(await D(e),t,r)))}return e[l]&&(e=f(e[l].concat([e]))),u(e)?e.subarray(t,r===1/0?e.length:r):e.slice(t,r)}async function D(e,t=f){return a(e)?e.readToEnd(t):c(e)?C(e).readToEnd(t):e}async function x(e,t){if(c(e)){if(e.cancel){const r=await e.cancel(t);return await new Promise((e=>setTimeout(e))),r}if(e.destroy)return e.destroy(t),await new Promise((e=>setTimeout(e))),t}}function I(e){const t=new s;return(async()=>{const r=B(t);try{await r.write(await e()),await r.close()}catch(e){await r.abort(e)}})(),t}function C(e){return new p(e)}function B(e){return new o(e)}p.prototype.read=async function(){if(this[l]&&this[l].length){return{done:!1,value:this[l].shift()}}return this._read()},p.prototype.releaseLock=function(){this[l]&&(this.stream[l]=this[l]),this._releaseLock()},p.prototype.cancel=function(e){return this._cancel(e)},p.prototype.readLine=async function(){let e,t=[];for(;!e;){let{done:r,value:i}=await this.read();if(i+="",r)return t.length?f(t):void 0;const n=i.indexOf("\n")+1;n&&(e=f(t.concat(i.substr(0,n))),t=[]),n!==i.length&&t.push(i.substr(n))}return this.unshift(...t),e},p.prototype.readByte=async function(){const{done:e,value:t}=await this.read();if(e)return;const r=t[0];return this.unshift(U(t,1)),r},p.prototype.readBytes=async function(e){const t=[];let r=0;for(;;){const{done:i,value:n}=await this.read();if(i)return t.length?f(t):void 0;if(t.push(n),r+=n.length,r>=e){const r=f(t);return this.unshift(U(r,e)),U(r,0,e)}}},p.prototype.peekBytes=async function(e){const t=await this.readBytes(e);return this.unshift(t),t},p.prototype.unshift=function(...e){this[l]||(this[l]=[]),1===e.length&&u(e[0])&&this[l].length&&e[0].length&&this[l][0].byteOffset>=e[0].length?this[l][0]=new Uint8Array(this[l][0].buffer,this[l][0].byteOffset-e[0].length,this[l][0].byteLength+e[0].length):this[l].unshift(...e.filter((e=>e&&e.length)))},p.prototype.readToEnd=async function(e=f){const t=[];for(;;){const{done:e,value:r}=await this.read();if(e)break;t.push(r)}return e(t)};const T=Symbol("byValue");var M={curve:{nistP256:"nistP256",p256:"nistP256",nistP384:"nistP384",p384:"nistP384",nistP521:"nistP521",p521:"nistP521",secp256k1:"secp256k1",ed25519Legacy:"ed25519Legacy",ed25519:"ed25519Legacy",curve25519Legacy:"curve25519Legacy",curve25519:"curve25519Legacy",brainpoolP256r1:"brainpoolP256r1",brainpoolP384r1:"brainpoolP384r1",brainpoolP512r1:"brainpoolP512r1"},s2k:{simple:0,salted:1,iterated:3,argon2:4,gnu:101},publicKey:{rsaEncryptSign:1,rsaEncrypt:2,rsaSign:3,elgamal:16,dsa:17,ecdh:18,ecdsa:19,eddsaLegacy:22,aedh:23,aedsa:24,x25519:25,x448:26,ed25519:27,ed448:28},symmetric:{idea:1,tripledes:2,cast5:3,blowfish:4,aes128:7,aes192:8,aes256:9,twofish:10},compression:{uncompressed:0,zip:1,zlib:2,bzip2:3},hash:{md5:1,sha1:2,ripemd:3,sha256:8,sha384:9,sha512:10,sha224:11,sha3_256:12,sha3_512:14},webHash:{"SHA-1":2,"SHA-256":8,"SHA-384":9,"SHA-512":10},aead:{eax:1,ocb:2,gcm:3,experimentalGCM:100},packet:{publicKeyEncryptedSessionKey:1,signature:2,symEncryptedSessionKey:3,onePassSignature:4,secretKey:5,publicKey:6,secretSubkey:7,compressedData:8,symmetricallyEncryptedData:9,marker:10,literalData:11,trust:12,userID:13,publicSubkey:14,userAttribute:17,symEncryptedIntegrityProtectedData:18,modificationDetectionCode:19,aeadEncryptedData:20,padding:21},literal:{binary:98,text:116,utf8:117,mime:109},signature:{binary:0,text:1,standalone:2,certGeneric:16,certPersona:17,certCasual:18,certPositive:19,certRevocation:48,subkeyBinding:24,keyBinding:25,key:31,keyRevocation:32,subkeyRevocation:40,timestamp:64,thirdParty:80},signatureSubpacket:{signatureCreationTime:2,signatureExpirationTime:3,exportableCertification:4,trustSignature:5,regularExpression:6,revocable:7,keyExpirationTime:9,placeholderBackwardsCompatibility:10,preferredSymmetricAlgorithms:11,revocationKey:12,issuerKeyID:16,notationData:20,preferredHashAlgorithms:21,preferredCompressionAlgorithms:22,keyServerPreferences:23,preferredKeyServer:24,primaryUserID:25,policyURI:26,keyFlags:27,signersUserID:28,reasonForRevocation:29,features:30,signatureTarget:31,embeddedSignature:32,issuerFingerprint:33,preferredAEADAlgorithms:34,preferredCipherSuites:39},keyFlags:{certifyKeys:1,signData:2,encryptCommunication:4,encryptStorage:8,splitPrivateKey:16,authentication:32,sharedPrivateKey:128},armor:{multipartSection:0,multipartLast:1,signed:2,message:3,publicKey:4,privateKey:5,signature:6},reasonForRevocation:{noReason:0,keySuperseded:1,keyCompromised:2,keyRetired:3,userIDInvalid:32},features:{modificationDetection:1,aead:2,v5Keys:4,seipdv2:8},write:function(e,t){if("number"==typeof t&&(t=this.read(e,t)),void 0!==e[t])return e[t];throw Error("Invalid enum value.")},read:function(e,t){if(e[T]||(e[T]=[],Object.entries(e).forEach((([t,r])=>{e[T][r]=t}))),void 0!==e[T][t])return e[T][t];throw Error("Invalid enum value.")}};const L={preferredHashAlgorithm:M.hash.sha512,preferredSymmetricAlgorithm:M.symmetric.aes256,preferredCompressionAlgorithm:M.compression.uncompressed,aeadProtect:!1,parseAEADEncryptedV4KeysAsLegacy:!1,preferredAEADAlgorithm:M.aead.gcm,aeadChunkSizeByte:12,v6Keys:!1,enableParsingV5Entities:!1,s2kType:M.s2k.iterated,s2kIterationCountByte:224,s2kArgon2Params:{passes:3,parallelism:4,memoryExponent:16},maxArgon2MemoryExponent:30,allowUnauthenticatedMessages:!1,allowUnauthenticatedStream:!1,minRSABits:2047,passwordCollisionCheck:!1,allowInsecureDecryptionWithSigningKeys:!1,allowInsecureVerificationWithReformattedKeys:!1,allowMissingKeyFlags:!1,constantTimePKCS1Decryption:!1,constantTimePKCS1DecryptionSupportedSymmetricAlgorithms:new Set([M.symmetric.aes128,M.symmetric.aes192,M.symmetric.aes256]),ignoreUnsupportedPackets:!0,ignoreMalformedPackets:!1,enforceGrammar:!0,additionalAllowedPackets:[],showVersion:!1,showComment:!1,versionString:"OpenPGP.js 6.3.2",commentString:"https://openpgpjs.org",maxUserIDLength:5120,maxDecompressedMessageSize:1/0,knownNotations:[],nonDeterministicSignaturesViaNotation:!0,useEllipticFallback:!0,rejectHashAlgorithms:new Set([M.hash.md5,M.hash.ripemd]),rejectMessageHashAlgorithms:new Set([M.hash.md5,M.hash.ripemd,M.hash.sha1]),rejectPublicKeyAlgorithms:new Set([M.publicKey.elgamal,M.publicKey.dsa]),rejectCurves:new Set([M.curve.secp256k1])},F=(()=>{try{return"development"===process.env.NODE_ENV}catch{}return!1})(),N={isString:function(e){return"string"==typeof e||e instanceof String},nodeRequire:()=>{},isArray:function(e){return e instanceof Array},isUint8Array:u,isStream:c,getNobleCurve:async(e,t)=>{if(!L.useEllipticFallback)throw Error("This curve is only supported in the full build of OpenPGP.js");const{nobleCurves:r}=await import("./noble_curves.min.mjs");switch(e){case M.publicKey.ecdh:case M.publicKey.ecdsa:{const e=r.get(t);if(!e)throw Error("Unsupported curve");return e}case M.publicKey.x448:return r.get("x448");case M.publicKey.ed448:return r.get("ed448");default:throw Error("Unsupported curve")}},readNumber:function(e){let t=0;for(let r=0;r<e.length;r++)t+=256**r*e[e.length-1-r];return t},writeNumber:function(e,t){const r=new Uint8Array(t);for(let i=0;i<t;i++)r[i]=e>>8*(t-i-1)&255;return r},readDate:function(e){const t=N.readNumber(e);return new Date(1e3*t)},writeDate:function(e){const t=Math.floor(e.getTime()/1e3);return N.writeNumber(t,4)},normalizeDate:function(e=Date.now()){return null===e||e===1/0?e:new Date(1e3*Math.floor(+e/1e3))},readMPI:function(e){const t=(e[0]<<8|e[1])+7>>>3;return N.readExactSubarray(e,2,2+t)},readExactSubarray:function(e,t,r){if(e.length<r)throw Error("Input array too short");return e.subarray(t,r)},leftPad(e,t){if(e.length>t)throw Error("Input array too long");const r=new Uint8Array(t),i=t-e.length;return r.set(e,i),r},uint8ArrayToMPI:function(e){const t=N.uint8ArrayBitLength(e);if(0===t)throw Error("Zero MPI");const r=e.subarray(e.length-Math.ceil(t/8)),i=new Uint8Array([(65280&t)>>8,255&t]);return N.concatUint8Array([i,r])},uint8ArrayBitLength:function(e){let t;for(t=0;t<e.length&&0===e[t];t++);if(t===e.length)return 0;const r=e.subarray(t);return 8*(r.length-1)+N.nbits(r[0])},hexToUint8Array:function(e){const t=new Uint8Array(e.length>>1);for(let r=0;r<e.length>>1;r++)t[r]=parseInt(e.substr(r<<1,2),16);return t},uint8ArrayToHex:function(e){const t="0123456789abcdef";let r="";return e.forEach((e=>{r+=t[e>>4]+t[15&e]})),r},stringToUint8Array:function(e){return b(e,(e=>{if(!N.isString(e))throw Error("stringToUint8Array: Data must be in the form of a string");const t=new Uint8Array(e.length);for(let r=0;r<e.length;r++)t[r]=e.charCodeAt(r);return t}))},uint8ArrayToString:function(e){const t=[],r=16384,i=(e=new Uint8Array(e)).length;for(let n=0;n<i;n+=r)t.push(String.fromCharCode.apply(String,e.subarray(n,n+r<i?n+r:i)));return t.join("")},encodeUTF8:function(e){const t=new TextEncoder("utf-8");function r(e,r=!1){return t.encode(e,{stream:!r})}return b(e,r,(()=>r("",!0)))},decodeUTF8:function(e){const t=new TextDecoder("utf-8");function r(e,r=!1){return t.decode(e,{stream:!r})}return b(e,r,(()=>r(new Uint8Array,!0)))},concat:f,concatUint8Array:h,equalsUint8Array:function(e,t){if(!N.isUint8Array(e)||!N.isUint8Array(t))throw Error("Data must be in the form of a Uint8Array");if(e.length!==t.length)return!1;for(let r=0;r<e.length;r++)if(e[r]!==t[r])return!1;return!0},findLastIndex:function(e,t){for(let r=e.length;r>=0;r--)if(t(e[r],r,e))return r;return-1},timingSafeEqualsUint8Array:function(e,t){if(e.length!==t.length)throw Error("Equal input arrays expected");let r=1;for(let i=0;i<e.length;i++)r&=e[i]===t[i];return!!r},writeChecksum:function(e){let t=0;for(let r=0;r<e.length;r++)t=t+e[r]&65535;return N.writeNumber(t,2)},printDebug:function(e){F&&console.log("[OpenPGP.js debug]",e)},printDebugError:function(e){F&&console.error("[OpenPGP.js debug]",e)},nbits:function(e){let t=1,r=e>>>16;return 0!==r&&(e=r,t+=16),r=e>>8,0!==r&&(e=r,t+=8),r=e>>4,0!==r&&(e=r,t+=4),r=e>>2,0!==r&&(e=r,t+=2),r=e>>1,0!==r&&(e=r,t+=1),t},double:function(e){const t=new Uint8Array(e.length),r=e.length-1;for(let i=0;i<r;i++)t[i]=e[i]<<1^e[i+1]>>7;return t[r]=e[r]<<1^135*(e[0]>>7),t},shiftRight:function(e,t){if(t)for(let r=e.length-1;r>=0;r--)e[r]>>=t,r>0&&(e[r]|=e[r-1]<<8-t);return e},getWebCrypto:function(){const t=void 0!==e&&e.crypto&&e.crypto.subtle||this.getNodeCrypto()?.webcrypto.subtle;if(!t)throw Error("The WebCrypto API is not available");return t},getNodeCrypto:function(){return this.nodeRequire("crypto")},getNodeZlib:function(){return this.nodeRequire("zlib")},getNodeBuffer:function(){return(this.nodeRequire("buffer")||{}).Buffer},getHardwareConcurrency:function(){if("undefined"!=typeof navigator)return navigator.hardwareConcurrency||1;return this.nodeRequire("os").cpus().length},isEmailAddress:function(e){if(!N.isString(e))return!1;return/^[^\p{C}\p{Z}@<>\\]+@[^\p{C}\p{Z}@<>\\]+[^\p{C}\p{Z}\p{P}]$/u.test(e)},canonicalizeEOL:function(e){let t=!1;return b(e,(e=>{let r;t&&(e=N.concatUint8Array([new Uint8Array([13]),e])),13===e[e.length-1]?(t=!0,e=e.subarray(0,-1)):t=!1;const i=[];for(let t=0;r=e.indexOf(10,t)+1,r;t=r)13!==e[r-2]&&i.push(r);if(!i.length)return e;const n=new Uint8Array(e.length+i.length);let s=0;for(let t=0;t<i.length;t++){const r=e.subarray(i[t-1]||0,i[t]);n.set(r,s),s+=r.length,n[s-1]=13,n[s]=10,s++}return n.set(e.subarray(i[i.length-1]||0),s),n}),(()=>t?new Uint8Array([13]):void 0))},nativeEOL:function(e){let t=!1;return b(e,(e=>{let r;13===(e=t&&10!==e[0]?N.concatUint8Array([new Uint8Array([13]),e]):new Uint8Array(e))[e.length-1]?(t=!0,e=e.subarray(0,-1)):t=!1;let i=0;for(let t=0;t!==e.length;t=r){r=e.indexOf(13,t)+1,r||(r=e.length);const n=r-(10===e[r]?1:0);t&&e.copyWithin(i,t,n),i+=n-t}return e.subarray(0,i)}),(()=>t?new Uint8Array([13]):void 0))},removeTrailingSpaces:function(e){return e.split("\n").map((e=>{let t=e.length-1;for(;t>=0&&(" "===e[t]||"\t"===e[t]||"\r"===e[t]);t--);return e.substr(0,t+1)})).join("\n")},wrapError:function(e,t){if(!t)return e instanceof Error?e:Error(e);if(e instanceof Error){try{e.message+=": "+t.message,e.cause=t}catch{}return e}return Error(e+": "+t.message,{cause:t})},constructAllowedPackets:function(e){const t={};return e.forEach((e=>{if(!e.tag)throw Error("Invalid input: expected a packet class");t[e.tag]=e})),t},anyPromise:function(e){return new Promise(((t,r)=>{let i;Promise.all(e.map((async e=>{try{t(await e)}catch(e){i=e}}))).then((()=>{r(i)}))}))},selectUint8Array:function(e,t,r){const i=Math.max(t.length,r.length),n=new Uint8Array(i);let s=0;for(let i=0;i<n.length;i++)n[i]=t[i]&256-e|r[i]&255+e,s+=e&i<t.length|1-e&i<r.length;return n.subarray(0,s)},selectUint8:function(e,t,r){return t&256-e|r&255+e},isAES:function(e){return e===M.symmetric.aes128||e===M.symmetric.aes192||e===M.symmetric.aes256}},z=N.getNodeBuffer();let R,O;function j(e){let t=new Uint8Array;return b(e,(e=>{t=N.concatUint8Array([t,e]);const r=[],i=Math.floor(t.length/45),n=45*i,s=R(t.subarray(0,n));for(let e=0;e<i;e++)r.push(s.substr(60*e,60)),r.push("\n");return t=t.subarray(n),r.join("")}),(()=>t.length?R(t)+"\n":""))}function H(e){let t="";return b(e,(e=>{t+=e;let r=0;const i=[" ","\t","\r","\n"];for(let e=0;e<i.length;e++){const n=i[e];for(let e=t.indexOf(n);-1!==e;e=t.indexOf(n,e+1))r++}let n=t.length;for(;n>0&&(n-r)%4!=0;n--)i.includes(t[n])&&r--;const s=O(t.substr(0,n));return t=t.substr(n),s}),(()=>O(t)))}function G(e){return H(e.replace(/-/g,"+").replace(/_/g,"/"))}function q(e,t){let r=j(e).replace(/[\r\n]/g,"");return r=r.replace(/[+]/g,"-").replace(/[/]/g,"_").replace(/[=]/g,""),r}function _(e){const t=e.match(/^-----BEGIN PGP (MESSAGE, PART \d+\/\d+|MESSAGE, PART \d+|SIGNED MESSAGE|MESSAGE|PUBLIC KEY BLOCK|PRIVATE KEY BLOCK|SIGNATURE)-----$/m);if(!t)throw Error("Unknown ASCII armor type");return/MESSAGE, PART \d+\/\d+/.test(t[1])?M.armor.multipartSection:/MESSAGE, PART \d+/.test(t[1])?M.armor.multipartLast:/SIGNED MESSAGE/.test(t[1])?M.armor.signed:/MESSAGE/.test(t[1])?M.armor.message:/PUBLIC KEY BLOCK/.test(t[1])?M.armor.publicKey:/PRIVATE KEY BLOCK/.test(t[1])?M.armor.privateKey:/SIGNATURE/.test(t[1])?M.armor.signature:void 0}function W(e,t){let r="";return t.showVersion&&(r+="Version: "+t.versionString+"\n"),t.showComment&&(r+="Comment: "+t.commentString+"\n"),e&&(r+="Comment: "+e+"\n"),r+="\n",r}function V(e){const t=function(e){let t=13501623;return b(e,(e=>{const r=X?Math.floor(e.length/4):0,i=new Uint32Array(e.buffer,e.byteOffset,r);for(let e=0;e<r;e++)t^=i[e],t=$[0][t>>24&255]^$[1][t>>16&255]^$[2][t>>8&255]^$[3][255&t];for(let i=4*r;i<e.length;i++)t=t>>8^$[0][255&t^e[i]]}),(()=>new Uint8Array([t,t>>8,t>>16])))}(e);return j(t)}z?(R=e=>z.from(e).toString("base64"),O=e=>{const t=z.from(e,"base64");return new Uint8Array(t.buffer,t.byteOffset,t.byteLength)}):(R=e=>btoa(N.uint8ArrayToString(e)),O=e=>N.stringToUint8Array(atob(e)));const $=[Array(255),Array(255),Array(255),Array(255)];for(let e=0;e<=255;e++){let t=e<<16;for(let e=0;e<8;e++)t=t<<1^(8388608&t?8801531:0);$[0][e]=(16711680&t)>>16|65280&t|(255&t)<<16}for(let e=0;e<=255;e++)$[1][e]=$[0][e]>>8^$[0][255&$[0][e]];for(let e=0;e<=255;e++)$[2][e]=$[1][e]>>8^$[0][255&$[1][e]];for(let e=0;e<=255;e++)$[3][e]=$[2][e]>>8^$[0][255&$[2][e]];const X=function(){const e=new ArrayBuffer(2);return new DataView(e).setInt16(0,255,!0),255===new Int16Array(e)[0]}();function Q(e){for(let t=0;t<e.length;t++)/^([^\s:]|[^\s:][^:]*[^\s:]): .+$/.test(e[t])||N.printDebugError(Error("Improperly formatted armor header: "+e[t])),/^(Version|Comment|MessageID|Hash|Charset): .+$/.test(e[t])||N.printDebugError(Error("Unknown header: "+e[t]))}function Y(e){let t=e;const r=e.lastIndexOf("=");return r>=0&&r!==e.length-1&&(t=e.slice(0,r)),t}function Z(e){return new Promise(((t,r)=>{try{const i=/^-----[^-]+-----$/m,n=/^[ \f\r\t\u00a0\u2000-\u200a\u202f\u205f\u3000]*$/;let s;const a=[];let o,c,u=a,h=[];const y=H(A(e,(async(e,l)=>{const p=C(e);try{for(;;){let e=await p.readLine();if(void 0===e)throw Error("Misformed armored text");if(e=N.removeTrailingSpaces(e.replace(/[\r\n]/g,"")),s)if(o)c||s!==M.armor.signed||(i.test(e)?(h=h.join("\r\n"),c=!0,Q(u),u=[],o=!1):h.push(e.replace(/^- /,"")));else if(i.test(e)&&r(Error("Mandatory blank line missing between armor headers and armor data")),n.test(e)){if(Q(u),o=!0,c||s!==M.armor.signed){t({text:h,data:y,headers:a,type:s});break}}else u.push(e);else i.test(e)&&(s=_(e))}}catch(e){return void r(e)}const g=B(l);try{for(;;){await g.ready;const{done:e,value:t}=await p.read();if(e)throw Error("Misformed armored text");const r=t+"";if(-1!==r.indexOf("=")||-1!==r.indexOf("-")){let e=await p.readToEnd();e.length||(e=""),e=r+e,e=N.removeTrailingSpaces(e.replace(/\r/g,""));const t=e.split(i);if(1===t.length)throw Error("Misformed armored text");const n=Y(t[0].slice(0,-1));await g.write(n);break}await g.write(r)}await g.ready,await g.close()}catch(e){await g.abort(e)}})))}catch(e){r(e)}})).then((async e=>(a(e.data)&&(e.data=await D(e.data)),e)))}function J(e,t,r,i,n,s=!1,a=L){let o,c;e===M.armor.signed&&(o=t.text,c=t.hash,t=t.data);const u=s&&S(t),h=[];switch(e){case M.armor.multipartSection:h.push("-----BEGIN PGP MESSAGE, PART "+r+"/"+i+"-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP MESSAGE, PART "+r+"/"+i+"-----\n");break;case M.armor.multipartLast:h.push("-----BEGIN PGP MESSAGE, PART "+r+"-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP MESSAGE, PART "+r+"-----\n");break;case M.armor.signed:h.push("-----BEGIN PGP SIGNED MESSAGE-----\n"),h.push(c?`Hash: ${c}\n\n`:"\n"),h.push(o.replace(/^-/gm,"- -")),h.push("\n-----BEGIN PGP SIGNATURE-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP SIGNATURE-----\n");break;case M.armor.message:h.push("-----BEGIN PGP MESSAGE-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP MESSAGE-----\n");break;case M.armor.publicKey:h.push("-----BEGIN PGP PUBLIC KEY BLOCK-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP PUBLIC KEY BLOCK-----\n");break;case M.armor.privateKey:h.push("-----BEGIN PGP PRIVATE KEY BLOCK-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP PRIVATE KEY BLOCK-----\n");break;case M.armor.signature:h.push("-----BEGIN PGP SIGNATURE-----\n"),h.push(W(n,a)),h.push(j(t)),u&&h.push("=",V(u)),h.push("-----END PGP SIGNATURE-----\n")}return N.concat(h)}const ee=BigInt(0),te=BigInt(1);function re(e){const t="0123456789ABCDEF";let r="";return e.forEach((e=>{r+=t[e>>4]+t[15&e]})),BigInt("0x0"+r)}function ie(e,t){const r=e%t;return r<ee?r+t:r}function ne(e,t,r){const i=-e;return t&i|r&~i}function se(e,t,r){if(r===ee)throw Error("Modulo cannot be zero");if(r===te)return BigInt(0);if(t<ee)throw Error("Unsopported negative exponent");let i=t,n=e;n%=r;let s=BigInt(1);for(;i>ee;){const e=i&te;i>>=te;s=ne(e,s*n%r,s),n=n*n%r}return s}function ae(e){return e>=ee?e:-e}function oe(e,t){const{gcd:r,x:i}=function(e,t){let r=BigInt(0),i=BigInt(1),n=BigInt(1),s=BigInt(0),a=ae(e),o=ae(t);const c=e<ee,u=t<ee;for(;o!==ee;){const e=a/o;let t=r;r=n-e*r,n=t,t=i,i=s-e*i,s=t,t=o,o=a%o,a=t}return{x:c?-n:n,y:u?-s:s,gcd:a}}(e,t);if(r!==te)throw Error("Inverse does not exist");return ie(i+t,t)}function ce(e){const t=Number(e);if(t>Number.MAX_SAFE_INTEGER)throw Error("Number can only safely store up to 53 bits");return t}function ue(e,t){return(e>>BigInt(t)&te)===ee?0:1}function he(e){const t=e<ee?BigInt(-1):ee;let r=1,i=e;for(;(i>>=te)!==t;)r++;return r}function ye(e){const t=e<ee?BigInt(-1):ee,r=BigInt(8);let i=1,n=e;for(;(n>>=r)!==t;)i++;return i}function le(e,t="be",r){let i=e.toString(16);i.length%2==1&&(i="0"+i);const n=i.length/2,s=new Uint8Array(r||n),a=r?r-n:0;let o=0;for(;o<n;)s[o+a]=parseInt(i.slice(2*o,2*o+2),16),o++;return"be"!==t&&s.reverse(),s}const pe=N.getNodeCrypto();function ge(e){const t="undefined"!=typeof crypto?crypto:pe?.webcrypto;if(t?.getRandomValues){const r=new Uint8Array(e);return t.getRandomValues(r)}throw Error("No secure random number generator available.")}function de(e,t){if(t<e)throw Error("Illegal parameter value: max <= min");const r=t-e;return ie(re(ge(ye(r)+8)),r)+e}const fe=BigInt(1);function me(e,t,r){const i=BigInt(30),n=fe<<BigInt(e-1),s=[1,6,5,4,3,2,1,4,3,2,1,2,1,4,3,2,1,2,1,4,3,2,1,6,5,4,3,2,1,2];let a=de(n,n<<fe),o=ce(ie(a,i));do{a+=BigInt(s[o]),o=(o+s[o])%s.length,he(a)>e&&(a=ie(a,n<<fe),a+=n,o=ce(ie(a,i)))}while(!we(a,t,r));return a}function we(e,t,r){return(!t||function(e,t){let r=e,i=t;for(;i!==ee;){const e=i;i=r%i,r=e}return r}(e-fe,t)===fe)&&(!!function(e){const t=BigInt(0);return be.every((r=>ie(e,r)!==t))}(e)&&(!!function(e,t=BigInt(2)){return se(t,e-fe,e)===fe}(e)&&!!function(e,t){const r=he(e);t||(t=Math.max(1,r/48|0));const i=e-fe;let n=0;for(;!ue(i,n);)n++;const s=e>>BigInt(n);for(;t>0;t--){let t,r=se(de(BigInt(2),i),s,e);if(r!==fe&&r!==i){for(t=1;t<n;t++){if(r=ie(r*r,e),r===fe)return!1;if(r===i)break}if(t===n)return!1}}return!0}(e,r)))}const be=[7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727,733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997,1009,1013,1019,1021,1031,1033,1039,1049,1051,1061,1063,1069,1087,1091,1093,1097,1103,1109,1117,1123,1129,1151,1153,1163,1171,1181,1187,1193,1201,1213,1217,1223,1229,1231,1237,1249,1259,1277,1279,1283,1289,1291,1297,1301,1303,1307,1319,1321,1327,1361,1367,1373,1381,1399,1409,1423,1427,1429,1433,1439,1447,1451,1453,1459,1471,1481,1483,1487,1489,1493,1499,1511,1523,1531,1543,1549,1553,1559,1567,1571,1579,1583,1597,1601,1607,1609,1613,1619,1621,1627,1637,1657,1663,1667,1669,1693,1697,1699,1709,1721,1723,1733,1741,1747,1753,1759,1777,1783,1787,1789,1801,1811,1823,1831,1847,1861,1867,1871,1873,1877,1879,1889,1901,1907,1913,1931,1933,1949,1951,1973,1979,1987,1993,1997,1999,2003,2011,2017,2027,2029,2039,2053,2063,2069,2081,2083,2087,2089,2099,2111,2113,2129,2131,2137,2141,2143,2153,2161,2179,2203,2207,2213,2221,2237,2239,2243,2251,2267,2269,2273,2281,2287,2293,2297,2309,2311,2333,2339,2341,2347,2351,2357,2371,2377,2381,2383,2389,2393,2399,2411,2417,2423,2437,2441,2447,2459,2467,2473,2477,2503,2521,2531,2539,2543,2549,2551,2557,2579,2591,2593,2609,2617,2621,2633,2647,2657,2659,2663,2671,2677,2683,2687,2689,2693,2699,2707,2711,2713,2719,2729,2731,2741,2749,2753,2767,2777,2789,2791,2797,2801,2803,2819,2833,2837,2843,2851,2857,2861,2879,2887,2897,2903,2909,2917,2927,2939,2953,2957,2963,2969,2971,2999,3001,3011,3019,3023,3037,3041,3049,3061,3067,3079,3083,3089,3109,3119,3121,3137,3163,3167,3169,3181,3187,3191,3203,3209,3217,3221,3229,3251,3253,3257,3259,3271,3299,3301,3307,3313,3319,3323,3329,3331,3343,3347,3359,3361,3371,3373,3389,3391,3407,3413,3433,3449,3457,3461,3463,3467,3469,3491,3499,3511,3517,3527,3529,3533,3539,3541,3547,3557,3559,3571,3581,3583,3593,3607,3613,3617,3623,3631,3637,3643,3659,3671,3673,3677,3691,3697,3701,3709,3719,3727,3733,3739,3761,3767,3769,3779,3793,3797,3803,3821,3823,3833,3847,3851,3853,3863,3877,3881,3889,3907,3911,3917,3919,3923,3929,3931,3943,3947,3967,3989,4001,4003,4007,4013,4019,4021,4027,4049,4051,4057,4073,4079,4091,4093,4099,4111,4127,4129,4133,4139,4153,4157,4159,4177,4201,4211,4217,4219,4229,4231,4241,4243,4253,4259,4261,4271,4273,4283,4289,4297,4327,4337,4339,4349,4357,4363,4373,4391,4397,4409,4421,4423,4441,4447,4451,4457,4463,4481,4483,4493,4507,4513,4517,4519,4523,4547,4549,4561,4567,4583,4591,4597,4603,4621,4637,4639,4643,4649,4651,4657,4663,4673,4679,4691,4703,4721,4723,4729,4733,4751,4759,4783,4787,4789,4793,4799,4801,4813,4817,4831,4861,4871,4877,4889,4903,4909,4919,4931,4933,4937,4943,4951,4957,4967,4969,4973,4987,4993,4999].map((e=>BigInt(e)));const ke=N.getWebCrypto(),ve=N.getNodeCrypto(),Ae=ve&&ve.getHashes();function Ke(e){if(ve&&Ae.includes(e))return async function(t){const r=ve.createHash(e);return b(t,(e=>{r.update(e)}),(()=>new Uint8Array(r.digest())))}}function Ee(e,t){const r=async()=>{const{nobleHashes:t}=await import("./noble_hashes.min.mjs"),r=t.get(e);if(!r)throw Error("Unsupported hash");return r};return async function(e){if(a(e)&&(e=await D(e)),N.isStream(e)){const t=(await r()).create();return b(e,(e=>{t.update(e)}),(()=>t.digest()))}if(ke&&t)return new Uint8Array(await ke.digest(t,e));return(await r())(e)}}const Se=Ke("md5")||Ee("md5"),Pe=Ke("sha1")||Ee("sha1","SHA-1"),Ue=Ke("sha224")||Ee("sha224"),De=Ke("sha256")||Ee("sha256","SHA-256"),xe=Ke("sha384")||Ee("sha384","SHA-384"),Ie=Ke("sha512")||Ee("sha512","SHA-512"),Ce=Ke("ripemd160")||Ee("ripemd160"),Be=Ke("sha3-256")||Ee("sha3_256"),Te=Ke("sha3-512")||Ee("sha3_512");function Me(e,t){switch(e){case M.hash.md5:return Se(t);case M.hash.sha1:return Pe(t);case M.hash.ripemd:return Ce(t);case M.hash.sha256:return De(t);case M.hash.sha384:return xe(t);case M.hash.sha512:return Ie(t);case M.hash.sha224:return Ue(t);case M.hash.sha3_256:return Be(t);case M.hash.sha3_512:return Te(t);default:throw Error("Unsupported hash function")}}function Le(e){switch(e){case M.hash.md5:return 16;case M.hash.sha1:case M.hash.ripemd:return 20;case M.hash.sha256:return 32;case M.hash.sha384:return 48;case M.hash.sha512:return 64;case M.hash.sha224:return 28;case M.hash.sha3_256:return 32;case M.hash.sha3_512:return 64;default:throw Error("Invalid hash algorithm.")}}const Fe=[];function Ne(e,t){const r=e.length;if(r>t-11)throw Error("Message too long");const i=function(e){const t=new Uint8Array(e);let r=0;for(;r<e;){const i=ge(e-r);for(let e=0;e<i.length;e++)0!==i[e]&&(t[r++]=i[e])}return t}(t-r-3),n=new Uint8Array(t);return n[1]=2,n.set(i,2),n.set(e,t-r),n}function ze(e,t){let r=2,i=1;for(let t=r;t<e.length;t++)i&=0!==e[t],r+=i;const n=r-2,s=e.subarray(r+1),a=0===e[0]&2===e[1]&n>=8&!i;if(t)return N.selectUint8Array(a,s,t);if(a)return s;throw Error("Decryption error")}function Re(e,t,r){let i;if(t.length!==Le(e))throw Error("Invalid hash length");const n=new Uint8Array(Fe[e].length);for(i=0;i<Fe[e].length;i++)n[i]=Fe[e][i];const s=n.length+t.length;if(r<s+11)throw Error("Intended encoded message length too short");const a=new Uint8Array(r-s-3).fill(255),o=new Uint8Array(r);return o[1]=1,o.set(a,2),o.set(n,r-s),o.set(t,r-t.length),o}Fe[1]=[48,32,48,12,6,8,42,134,72,134,247,13,2,5,5,0,4,16],Fe[2]=[48,33,48,9,6,5,43,14,3,2,26,5,0,4,20],Fe[3]=[48,33,48,9,6,5,43,36,3,2,1,5,0,4,20],Fe[8]=[48,49,48,13,6,9,96,134,72,1,101,3,4,2,1,5,0,4,32],Fe[9]=[48,65,48,13,6,9,96,134,72,1,101,3,4,2,2,5,0,4,48],Fe[10]=[48,81,48,13,6,9,96,134,72,1,101,3,4,2,3,5,0,4,64],Fe[11]=[48,45,48,13,6,9,96,134,72,1,101,3,4,2,4,5,0,4,28],Fe[12]=[48,49,48,13,6,9,96,134,72,1,101,3,4,2,8,5,0,4,32],Fe[14]=[48,81,48,13,6,9,96,134,72,1,101,3,4,2,10,5,0,4,64];const Oe=N.getWebCrypto(),je=N.getNodeCrypto(),He=BigInt(1);async function Ge(e,t,r,i,n,s,a,o,c){if(Le(e)>=r.length)throw Error("Digest size cannot exceed key modulus size");if(t&&!N.isStream(t))if(N.getWebCrypto())try{return await async function(e,t,r,i,n,s,a,o){const c=Ve(r,i,n,s,a,o),u={name:"RSASSA-PKCS1-v1_5",hash:{name:e}},h=await Oe.importKey("jwk",c,u,!1,["sign"]);return new Uint8Array(await Oe.sign("RSASSA-PKCS1-v1_5",h,t))}(M.read(M.webHash,e),t,r,i,n,s,a,o)}catch(e){N.printDebugError(e)}else if(N.getNodeCrypto())return function(e,t,r,i,n,s,a,o){const c=je.createSign(M.read(M.hash,e));c.write(t),c.end();const u=Ve(r,i,n,s,a,o);return new Uint8Array(c.sign({key:u,format:"jwk",type:"pkcs1"}))}(e,t,r,i,n,s,a,o);return function(e,t,r,i){t=re(t);const n=re(Re(e,i,ye(t)));return r=re(r),le(se(n,r,t),"be",ye(t))}(e,r,n,c)}async function qe(e,t,r,i,n,s){if(t&&!N.isStream(t))if(N.getWebCrypto())try{return await async function(e,t,r,i,n){const s=$e(i,n),a=await Oe.importKey("jwk",s,{name:"RSASSA-PKCS1-v1_5",hash:{name:e}},!1,["verify"]);return Oe.verify("RSASSA-PKCS1-v1_5",a,r,t)}(M.read(M.webHash,e),t,r,i,n)}catch(e){N.printDebugError(e)}else if(N.getNodeCrypto())return function(e,t,r,i,n){const s=$e(i,n),a={key:s,format:"jwk",type:"pkcs1"},o=je.createVerify(M.read(M.hash,e));o.write(t),o.end();try{return o.verify(a,r)}catch{return!1}}(e,t,r,i,n);return function(e,t,r,i,n){if(r=re(r),t=re(t),i=re(i),t>=r)throw Error("Signature size cannot exceed modulus size");const s=le(se(t,i,r),"be",ye(r)),a=Re(e,n,ye(r));return N.equalsUint8Array(s,a)}(e,r,i,n,s)}async function _e(e,t,r){return N.getNodeCrypto()?function(e,t,r){const i=$e(t,r),n={key:i,format:"jwk",type:"pkcs1",padding:je.constants.RSA_PKCS1_PADDING};return new Uint8Array(je.publicEncrypt(n,e))}(e,t,r):function(e,t,r){if(t=re(t),e=re(Ne(e,ye(t))),r=re(r),e>=t)throw Error("Message size cannot exceed modulus size");return le(se(e,r,t),"be",ye(t))}(e,t,r)}async function We(e,t,r,i,n,s,a,o){if(N.getNodeCrypto()&&!o)try{return function(e,t,r,i,n,s,a){const o=Ve(t,r,i,n,s,a),c={key:o,format:"jwk",type:"pkcs1",padding:je.constants.RSA_PKCS1_PADDING};try{return new Uint8Array(je.privateDecrypt(c,e))}catch{throw Error("Decryption error")}}(e,t,r,i,n,s,a)}catch(e){N.printDebugError(e)}return function(e,t,r,i,n,s,a,o){if(e=re(e),t=re(t),r=re(r),i=re(i),n=re(n),s=re(s),a=re(a),e>=t)throw Error("Data too large.");const c=ie(i,s-He),u=ie(i,n-He),h=de(BigInt(2),t),y=se(oe(h,t),r,t);e=ie(e*y,t);const l=se(e,u,n),p=se(e,c,s),g=ie(a*(p-l),s);let d=g*n+l;return d=ie(d*h,t),ze(le(d,"be",ye(t)),o)}(e,t,r,i,n,s,a,o)}function Ve(e,t,r,i,n,s){const a=re(i),o=re(n),c=re(r);let u=ie(c,o-He),h=ie(c,a-He);return h=le(h),u=le(u),{kty:"RSA",n:q(e),e:q(t),d:q(r),p:q(n),q:q(i),dp:q(u),dq:q(h),qi:q(s),ext:!0}}function $e(e,t){return{kty:"RSA",n:q(e),e:q(t),ext:!0}}function Xe(e,t){return{n:G(e.n),e:le(t),d:G(e.d),p:G(e.q),q:G(e.p),u:G(e.qi)}}const Qe=BigInt(1);const Ye={"2a8648ce3d030107":M.curve.nistP256,"2b81040022":M.curve.nistP384,"2b81040023":M.curve.nistP521,"2b8104000a":M.curve.secp256k1,"2b06010401da470f01":M.curve.ed25519Legacy,"2b060104019755010501":M.curve.curve25519Legacy,"2b2403030208010107":M.curve.brainpoolP256r1,"2b240303020801010b":M.curve.brainpoolP384r1,"2b240303020801010d":M.curve.brainpoolP512r1};class Ze{constructor(e){if(e instanceof Ze)this.oid=e.oid;else if(N.isArray(e)||N.isUint8Array(e)){if(6===(e=new Uint8Array(e))[0]){if(e[1]!==e.length-2)throw Error("Length mismatch in DER encoded oid");e=e.subarray(2)}this.oid=e}else this.oid=""}read(e){if(e.length>=1){const t=e[0];if(e.length>=1+t)return this.oid=e.subarray(1,1+t),1+this.oid.length}throw Error("Invalid oid")}write(){return N.concatUint8Array([new Uint8Array([this.oid.length]),this.oid])}toHex(){return N.uint8ArrayToHex(this.oid)}getName(){const e=Ye[this.toHex()];if(!e)throw Error("Unknown curve object identifier.");return e}}function Je(e){let t,r=0;const i=e[0];return i<192?([r]=e,t=1):i<255?(r=(e[0]-192<<8)+e[1]+192,t=2):255===i&&(r=N.readNumber(e.subarray(1,5)),t=5),{len:r,offset:t}}function et(e){return e<192?new Uint8Array([e]):e>191&&e<8384?new Uint8Array([192+(e-192>>8),e-192&255]):N.concatUint8Array([new Uint8Array([255]),N.writeNumber(e,4)])}function tt(e){if(e<0||e>30)throw Error("Partial Length power must be between 1 and 30");return new Uint8Array([224+e])}function rt(e){return new Uint8Array([192|e])}function it(e,t){return N.concatUint8Array([rt(e),et(t)])}function nt(e){return[M.packet.literalData,M.packet.compressedData,M.packet.symmetricallyEncryptedData,M.packet.symEncryptedIntegrityProtectedData,M.packet.aeadEncryptedData].includes(e)}async function st(e,t,r){let i,n;try{const a=await e.peekBytes(2);if(!a||a.length<2||!(128&a[0]))throw Error("Error during parsing. This message / key probably does not conform to a valid OpenPGP format.");const o=await e.readByte();let c,u,h=-1,y=-1;y=0,64&o&&(y=1),y?h=63&o:(h=(63&o)>>2,u=3&o);const l=nt(h);let p,g=null;if(t&&l){if("array"===t){const e=new s;i=B(e),g=e}else{const e=new TransformStream;i=B(e.writable),g=e.readable}n=r({tag:h,packet:g})}else g=[];do{if(y){const t=await e.readByte();if(p=!1,t<192)c=t;else if(t>=192&&t<224)c=(t-192<<8)+await e.readByte()+192;else if(t>223&&t<255){if(c=1<<(31&t),p=!0,!l)throw new TypeError("This packet type does not support partial lengths.")}else c=(await e.readByte()<<24|await e.readByte()<<16|await e.readByte()<<8|await e.readByte())>>>0}else switch(u){case 0:c=await e.readByte();break;case 1:c=await e.readByte()<<8|await e.readByte();break;case 2:c=(await e.readByte()<<24|await e.readByte()<<16|await e.readByte()<<8|await e.readByte())>>>0;break;default:c=1/0}if(c>0){let t=0;for(;;){i&&await i.ready;const{done:r,value:n}=await e.read();if(r){if(c===1/0)break;throw Error("Unexpected end of packet")}const s=c===1/0?n:n.subarray(0,c-t);if(i?await i.write(s):g.push(s),t+=n.length,t>=c){e.unshift(n.subarray(c-t+n.length));break}}}}while(p);i?(await i.ready,await i.close()):(g=N.concatUint8Array(g),await r({tag:h,packet:g}))}catch(e){if(i)return await i.abort(e),!0;throw e}finally{i&&await n}}class at extends Error{constructor(...e){super(...e),Error.captureStackTrace&&Error.captureStackTrace(this,at),this.name="UnsupportedError"}}class ot extends at{constructor(...e){super(...e),Error.captureStackTrace&&Error.captureStackTrace(this,at),this.name="UnknownPacketError"}}class ct extends at{constructor(...e){super(...e),Error.captureStackTrace&&Error.captureStackTrace(this,at),this.name="MalformedPacketError"}}class ut{constructor(e,t){this.tag=e,this.rawContent=t}write(){return this.rawContent}}async function ht(e){switch(e){case M.publicKey.ed25519:try{const e=N.getWebCrypto(),t=await e.generateKey("Ed25519",!0,["sign","verify"]).catch((e=>{if("OperationError"===e.name){const e=Error("Unexpected key generation issue");throw e.name="NotSupportedError",e}throw e})),r=await e.exportKey("jwk",t.privateKey),i=await e.exportKey("jwk",t.publicKey);return{A:new Uint8Array(G(i.x)),seed:G(r.d)}}catch(t){if("NotSupportedError"!==t.name)throw t;const{default:r}=await import("./nacl-fast.min.mjs"),i=ge(gt(e)),{publicKey:n}=r.sign.keyPair.fromSeed(i);return{A:n,seed:i}}case M.publicKey.ed448:{const e=await N.getNobleCurve(M.publicKey.ed448),{secretKey:t,publicKey:r}=e.keygen();return{A:r,seed:t}}default:throw Error("Unsupported EdDSA algorithm")}}async function yt(e,t,r,i,n,s){if(Le(t)<Le(dt(e)))throw Error("Hash algorithm too weak for EdDSA.");switch(e){case M.publicKey.ed25519:try{const t=N.getWebCrypto(),r=mt(e,i,n),a=await t.importKey("jwk",r,"Ed25519",!1,["sign"]);return{RS:new Uint8Array(await t.sign("Ed25519",a,s))}}catch(e){if("NotSupportedError"!==e.name)throw e;const{default:t}=await import("./nacl-fast.min.mjs"),r=N.concatUint8Array([n,i]);return{RS:t.sign.detached(s,r)}}case M.publicKey.ed448:return{RS:(await N.getNobleCurve(M.publicKey.ed448)).sign(s,n)};default:throw Error("Unsupported EdDSA algorithm")}}async function lt(e,t,{RS:r},i,n,s){if(Le(t)<Le(dt(e)))throw Error("Hash algorithm too weak for EdDSA.");switch(e){case M.publicKey.ed25519:try{const t=N.getWebCrypto(),i=ft(e,n),a=await t.importKey("jwk",i,"Ed25519",!1,["verify"]);return await t.verify("Ed25519",a,r,s)}catch(e){if("NotSupportedError"!==e.name)throw e;const{default:t}=await import("./nacl-fast.min.mjs");return t.sign.detached.verify(s,r,n)}case M.publicKey.ed448:return(await N.getNobleCurve(M.publicKey.ed448)).verify(r,s,n);default:throw Error("Unsupported EdDSA algorithm")}}async function pt(e,t,r){switch(e){case M.publicKey.ed25519:try{const i=N.getWebCrypto(),n=mt(e,t,r),s=ft(e,t),a=await i.importKey("jwk",n,"Ed25519",!1,["sign"]),o=await i.importKey("jwk",s,"Ed25519",!1,["verify"]),c=ge(8),u=new Uint8Array(await i.sign("Ed25519",a,c));return await i.verify("Ed25519",o,u,c)}catch(e){if("NotSupportedError"!==e.name)return!1;const{default:i}=await import("./nacl-fast.min.mjs"),{publicKey:n}=i.sign.keyPair.fromSeed(r);return N.equalsUint8Array(t,n)}case M.publicKey.ed448:{const e=(await N.getNobleCurve(M.publicKey.ed448)).getPublicKey(r);return N.equalsUint8Array(t,e)}default:return!1}}function gt(e){switch(e){case M.publicKey.ed25519:return 32;case M.publicKey.ed448:return 57;default:throw Error("Unsupported EdDSA algorithm")}}function dt(e){switch(e){case M.publicKey.ed25519:return M.hash.sha256;case M.publicKey.ed448:return M.hash.sha512;default:throw Error("Unknown EdDSA algo")}}const ft=(e,t)=>{if(e===M.publicKey.ed25519){return{kty:"OKP",crv:"Ed25519",x:q(t),ext:!0}}throw Error("Unsupported EdDSA algorithm")},mt=(e,t,r)=>{if(e===M.publicKey.ed25519){const i=ft(e,t);return i.d=q(r),i}throw Error("Unsupported EdDSA algorithm")};var wt=/*#__PURE__*/Object.freeze({__proto__:null,generate:ht,getPayloadSize:gt,getPreferredHashAlgo:dt,sign:yt,validateParams:pt,verify:lt});
/*! noble-ciphers - MIT License (c) 2023 Paul Miller (paulmillr.com) */function bt(e){return e instanceof Uint8Array||ArrayBuffer.isView(e)&&"Uint8Array"===e.constructor.name}function kt(e,...t){if(!bt(e))throw Error("Uint8Array expected");if(t.length>0&&!t.includes(e.length))throw Error("Uint8Array expected of length "+t+", got length="+e.length)}function vt(e,t=!0){if(e.destroyed)throw Error("Hash instance has been destroyed");if(t&&e.finished)throw Error("Hash#digest() has already been called")}function At(e,t){kt(e);const r=t.outputLen;if(e.length<r)throw Error("digestInto() expects output buffer of length at least "+r)}function Kt(e){return new Uint8Array(e.buffer,e.byteOffset,e.byteLength)}function Et(e){return new Uint32Array(e.buffer,e.byteOffset,Math.floor(e.byteLength/4))}function St(...e){for(let t=0;t<e.length;t++)e[t].fill(0)}function Pt(e){return new DataView(e.buffer,e.byteOffset,e.byteLength)}const Ut=/* @__PURE__ */(()=>68===new Uint8Array(new Uint32Array([287454020]).buffer)[0])();function Dt(e){if("string"==typeof e)e=function(e){if("string"!=typeof e)throw Error("string expected");return new Uint8Array((new TextEncoder).encode(e))}(e);else{if(!bt(e))throw Error("Uint8Array expected, got "+typeof e);e=Ft(e)}return e}function xt(e,t){return e.buffer===t.buffer&&e.byteOffset<t.byteOffset+t.byteLength&&t.byteOffset<e.byteOffset+e.byteLength}function It(e,t){if(xt(e,t)&&e.byteOffset<t.byteOffset)throw Error("complex overlap of input and output is not supported")}function Ct(e,t){if(e.length!==t.length)return!1;let r=0;for(let i=0;i<e.length;i++)r|=e[i]^t[i];return 0===r}const Bt=(e,t)=>{function r(r,...i){if(kt(r),!Ut)throw Error("Non little-endian hardware is not yet supported");if(void 0!==e.nonceLength){const t=i[0];if(!t)throw Error("nonce / iv required");e.varSizeNonce?kt(t):kt(t,e.nonceLength)}const n=e.tagLength;n&&void 0!==i[1]&&kt(i[1]);const s=t(r,...i),a=(e,t)=>{if(void 0!==t){if(2!==e)throw Error("cipher output not supported");kt(t)}};let o=!1;return{encrypt(e,t){if(o)throw Error("cannot encrypt() twice with same key + nonce");return o=!0,kt(e),a(s.encrypt.length,t),s.encrypt(e,t)},decrypt(e,t){if(kt(e),n&&e.length<n)throw Error("invalid ciphertext length: smaller than tagLength="+n);return a(s.decrypt.length,t),s.decrypt(e,t)}}}return Object.assign(r,e),r};function Tt(e,t,r=!0){if(void 0===t)return new Uint8Array(e);if(t.length!==e)throw Error("invalid output length, expected "+e+", got: "+t.length);if(r&&!Lt(t))throw Error("invalid output, must be aligned");return t}function Mt(e,t,r,i){if("function"==typeof e.setBigUint64)return e.setBigUint64(t,r,i);const n=BigInt(32),s=BigInt(4294967295),a=Number(r>>n&s),o=Number(r&s);e.setUint32(t+0,a,i),e.setUint32(t+4,o,i)}function Lt(e){return e.byteOffset%4==0}function Ft(e){return Uint8Array.from(e)}const Nt=16,zt=/* @__PURE__ */new Uint8Array(16),Rt=Et(zt),Ot=e=>(e>>>0&255)<<24|(e>>>8&255)<<16|(e>>>16&255)<<8|e>>>24&255;class jt{constructor(e,t){this.blockLen=Nt,this.outputLen=Nt,this.s0=0,this.s1=0,this.s2=0,this.s3=0,this.finished=!1,kt(e=Dt(e),16);const r=Pt(e);let i=r.getUint32(0,!1),n=r.getUint32(4,!1),s=r.getUint32(8,!1),a=r.getUint32(12,!1);const o=[];for(let e=0;e<128;e++)o.push({s0:Ot(i),s1:Ot(n),s2:Ot(s),s3:Ot(a)}),({s0:i,s1:n,s2:s,s3:a}={s3:(h=s)<<31|(y=a)>>>1,s2:(u=n)<<31|h>>>1,s1:(c=i)<<31|u>>>1,s0:c>>>1^225<<24&-(1&y)});var c,u,h,y;const l=(p=t||1024)>65536?8:p>1024?4:2;var p;if(![1,2,4,8].includes(l))throw Error("ghash: invalid window size, expected 2, 4 or 8");this.W=l;const g=128/l,d=this.windowSize=2**l,f=[];for(let e=0;e<g;e++)for(let t=0;t<d;t++){let r=0,i=0,n=0,s=0;for(let a=0;a<l;a++){if(!(t>>>l-a-1&1))continue;const{s0:c,s1:u,s2:h,s3:y}=o[l*e+a];r^=c,i^=u,n^=h,s^=y}f.push({s0:r,s1:i,s2:n,s3:s})}this.t=f}_updateBlock(e,t,r,i){e^=this.s0,t^=this.s1,r^=this.s2,i^=this.s3;const{W:n,t:s,windowSize:a}=this;let o=0,c=0,u=0,h=0;const y=(1<<n)-1;let l=0;for(const p of[e,t,r,i])for(let e=0;e<4;e++){const t=p>>>8*e&255;for(let e=8/n-1;e>=0;e--){const r=t>>>n*e&y,{s0:i,s1:p,s2:g,s3:d}=s[l*a+r];o^=i,c^=p,u^=g,h^=d,l+=1}}this.s0=o,this.s1=c,this.s2=u,this.s3=h}update(e){vt(this),kt(e=Dt(e));const t=Et(e),r=Math.floor(e.length/Nt),i=e.length%Nt;for(let e=0;e<r;e++)this._updateBlock(t[4*e+0],t[4*e+1],t[4*e+2],t[4*e+3]);return i&&(zt.set(e.subarray(r*Nt)),this._updateBlock(Rt[0],Rt[1],Rt[2],Rt[3]),St(Rt)),this}destroy(){const{t:e}=this;for(const t of e)t.s0=0,t.s1=0,t.s2=0,t.s3=0}digestInto(e){vt(this),At(e,this),this.finished=!0;const{s0:t,s1:r,s2:i,s3:n}=this,s=Et(e);return s[0]=t,s[1]=r,s[2]=i,s[3]=n,e}digest(){const e=new Uint8Array(Nt);return this.digestInto(e),this.destroy(),e}}class Ht extends jt{constructor(e,t){kt(e=Dt(e));const r=function(e){e.reverse();const t=1&e[15];let r=0;for(let t=0;t<e.length;t++){const i=e[t];e[t]=i>>>1|r,r=(1&i)<<7}return e[0]^=225&-t,e}(Ft(e));super(r,t),St(r)}update(e){e=Dt(e),vt(this);const t=Et(e),r=e.length%Nt,i=Math.floor(e.length/Nt);for(let e=0;e<i;e++)this._updateBlock(Ot(t[4*e+3]),Ot(t[4*e+2]),Ot(t[4*e+1]),Ot(t[4*e+0]));return r&&(zt.set(e.subarray(i*Nt)),this._updateBlock(Ot(Rt[3]),Ot(Rt[2]),Ot(Rt[1]),Ot(Rt[0])),St(Rt)),this}digestInto(e){vt(this),At(e,this),this.finished=!0;const{s0:t,s1:r,s2:i,s3:n}=this,s=Et(e);return s[0]=t,s[1]=r,s[2]=i,s[3]=n,e.reverse()}}function Gt(e){const t=(t,r)=>e(r,t.length).update(Dt(t)).digest(),r=e(new Uint8Array(16),0);return t.outputLen=r.outputLen,t.blockLen=r.blockLen,t.create=(t,r)=>e(t,r),t}const qt=Gt(((e,t)=>new jt(e,t)));Gt(((e,t)=>new Ht(e,t)));const _t=16,Wt=/* @__PURE__ */new Uint8Array(_t);function Vt(e){return e<<1^283&-(e>>7)}function $t(e,t){let r=0;for(;t>0;t>>=1)r^=e&-(1&t),e=Vt(e);return r}const Xt=/* @__PURE__ */(()=>{const e=new Uint8Array(256);for(let t=0,r=1;t<256;t++,r^=Vt(r))e[t]=r;const t=new Uint8Array(256);t[0]=99;for(let r=0;r<255;r++){let i=e[255-r];i|=i<<8,t[e[r]]=255&(i^i>>4^i>>5^i>>6^i>>7^99)}return St(e),t})(),Qt=/* @__PURE__ */Xt.map(((e,t)=>Xt.indexOf(t))),Yt=e=>e<<8|e>>>24,Zt=e=>e<<24&4278190080|e<<8&16711680|e>>>8&65280|e>>>24&255;function Jt(e,t){if(256!==e.length)throw Error("Wrong sbox length");const r=new Uint32Array(256).map(((r,i)=>t(e[i]))),i=r.map(Yt),n=i.map(Yt),s=n.map(Yt),a=new Uint32Array(65536),o=new Uint32Array(65536),c=new Uint16Array(65536);for(let t=0;t<256;t++)for(let u=0;u<256;u++){const h=256*t+u;a[h]=r[t]^i[u],o[h]=n[t]^s[u],c[h]=e[t]<<8|e[u]}return{sbox:e,sbox2:c,T0:r,T1:i,T2:n,T3:s,T01:a,T23:o}}const er=/* @__PURE__ */Jt(Xt,(e=>$t(e,3)<<24|e<<16|e<<8|$t(e,2))),tr=/* @__PURE__ */Jt(Qt,(e=>$t(e,11)<<24|$t(e,13)<<16|$t(e,9)<<8|$t(e,14))),rr=/* @__PURE__ */(()=>{const e=new Uint8Array(16);for(let t=0,r=1;t<16;t++,r=Vt(r))e[t]=r;return e})();function ir(e){kt(e);const t=e.length;if(![16,24,32].includes(t))throw Error("aes: invalid key size, should be 16, 24 or 32, got "+t);const{sbox2:r}=er,i=[];Lt(e)||i.push(e=Ft(e));const n=Et(e),s=n.length,a=e=>ar(r,e,e,e,e),o=new Uint32Array(t+28);o.set(n);for(let e=s;e<o.length;e++){let t=o[e-1];e%s==0?t=a((c=t)<<24|c>>>8)^rr[e/s-1]:s>6&&e%s==4&&(t=a(t)),o[e]=o[e-s]^t}var c;return St(...i),o}function nr(e){const t=ir(e),r=t.slice(),i=t.length,{sbox2:n}=er,{T0:s,T1:a,T2:o,T3:c}=tr;for(let e=0;e<i;e+=4)for(let n=0;n<4;n++)r[e+n]=t[i-e-4+n];St(t);for(let e=4;e<i-4;e++){const t=r[e],i=ar(n,t,t,t,t);r[e]=s[255&i]^a[i>>>8&255]^o[i>>>16&255]^c[i>>>24]}return r}function sr(e,t,r,i,n,s){return e[r<<8&65280|i>>>8&255]^t[n>>>8&65280|s>>>24&255]}function ar(e,t,r,i,n){return e[255&t|65280&r]|e[i>>>16&255|n>>>16&65280]<<16}function or(e,t,r,i,n){const{sbox2:s,T01:a,T23:o}=er;let c=0;t^=e[c++],r^=e[c++],i^=e[c++],n^=e[c++];const u=e.length/4-2;for(let s=0;s<u;s++){const s=e[c++]^sr(a,o,t,r,i,n),u=e[c++]^sr(a,o,r,i,n,t),h=e[c++]^sr(a,o,i,n,t,r),y=e[c++]^sr(a,o,n,t,r,i);t=s,r=u,i=h,n=y}return{s0:e[c++]^ar(s,t,r,i,n),s1:e[c++]^ar(s,r,i,n,t),s2:e[c++]^ar(s,i,n,t,r),s3:e[c++]^ar(s,n,t,r,i)}}function cr(e,t,r,i,n){const{sbox2:s,T01:a,T23:o}=tr;let c=0;t^=e[c++],r^=e[c++],i^=e[c++],n^=e[c++];const u=e.length/4-2;for(let s=0;s<u;s++){const s=e[c++]^sr(a,o,t,n,i,r),u=e[c++]^sr(a,o,r,t,n,i),h=e[c++]^sr(a,o,i,r,t,n),y=e[c++]^sr(a,o,n,i,r,t);t=s,r=u,i=h,n=y}return{s0:e[c++]^ar(s,t,n,i,r),s1:e[c++]^ar(s,r,t,n,i),s2:e[c++]^ar(s,i,r,t,n),s3:e[c++]^ar(s,n,i,r,t)}}function ur(e,t,r,i){kt(t,_t),kt(r);const n=r.length;It(r,i=Tt(n,i));const s=t,a=Et(s);let{s0:o,s1:c,s2:u,s3:h}=or(e,a[0],a[1],a[2],a[3]);const y=Et(r),l=Et(i);for(let t=0;t+4<=y.length;t+=4){l[t+0]=y[t+0]^o,l[t+1]=y[t+1]^c,l[t+2]=y[t+2]^u,l[t+3]=y[t+3]^h;let r=1;for(let e=s.length-1;e>=0;e--)r=r+(255&s[e])|0,s[e]=255&r,r>>>=8;({s0:o,s1:c,s2:u,s3:h}=or(e,a[0],a[1],a[2],a[3]))}const p=_t*Math.floor(y.length/4);if(p<n){const e=new Uint32Array([o,c,u,h]),t=Kt(e);for(let e=p,s=0;e<n;e++,s++)i[e]=r[e]^t[s];St(e)}return i}function hr(e,t,r,i,n){kt(r,_t),kt(i),n=Tt(i.length,n);const s=r,a=Et(s),o=Pt(s),c=Et(i),u=Et(n),h=t?0:12,y=i.length;let l=o.getUint32(h,t),{s0:p,s1:g,s2:d,s3:f}=or(e,a[0],a[1],a[2],a[3]);for(let r=0;r+4<=c.length;r+=4)u[r+0]=c[r+0]^p,u[r+1]=c[r+1]^g,u[r+2]=c[r+2]^d,u[r+3]=c[r+3]^f,l=l+1>>>0,o.setUint32(h,l,t),({s0:p,s1:g,s2:d,s3:f}=or(e,a[0],a[1],a[2],a[3]));const m=_t*Math.floor(c.length/4);if(m<y){const e=new Uint32Array([p,g,d,f]),t=Kt(e);for(let e=m,r=0;e<y;e++,r++)n[e]=i[e]^t[r];St(e)}return n}const yr=/* @__PURE__ */Bt({blockSize:16,nonceLength:16},(function(e,t){function r(r,i){if(kt(r),void 0!==i&&(kt(i),!Lt(i)))throw Error("unaligned destination");const n=ir(e),s=Ft(t),a=[n,s];Lt(r)||a.push(r=Ft(r));const o=ur(n,s,r,i);return St(...a),o}return{encrypt:(e,t)=>r(e,t),decrypt:(e,t)=>r(e,t)}}));const lr=/* @__PURE__ */Bt({blockSize:16,nonceLength:16},(function(e,t,r={}){const i=!r.disablePadding;return{encrypt(r,n){const s=ir(e),{b:a,o,out:c}=function(e,t,r){kt(e);let i=e.length;const n=i%_t;if(!t&&0!==n)throw Error("aec/(cbc-ecb): unpadded plaintext with disabled padding");Lt(e)||(e=Ft(e));const s=Et(e);if(t){let e=_t-n;e||(e=_t),i+=e}return It(e,r=Tt(i,r)),{b:s,o:Et(r),out:r}}(r,i,n);let u=t;const h=[s];Lt(u)||h.push(u=Ft(u));const y=Et(u);let l=y[0],p=y[1],g=y[2],d=y[3],f=0;for(;f+4<=a.length;)l^=a[f+0],p^=a[f+1],g^=a[f+2],d^=a[f+3],({s0:l,s1:p,s2:g,s3:d}=or(s,l,p,g,d)),o[f++]=l,o[f++]=p,o[f++]=g,o[f++]=d;if(i){const e=function(e){const t=new Uint8Array(16),r=Et(t);t.set(e);const i=_t-e.length;for(let e=_t-i;e<_t;e++)t[e]=i;return r}(r.subarray(4*f));l^=e[0],p^=e[1],g^=e[2],d^=e[3],({s0:l,s1:p,s2:g,s3:d}=or(s,l,p,g,d)),o[f++]=l,o[f++]=p,o[f++]=g,o[f++]=d}return St(...h),c},decrypt(r,n){!function(e){if(kt(e),e.length%_t!=0)throw Error("aes-(cbc/ecb).decrypt ciphertext should consist of blocks with size 16")}(r);const s=nr(e);let a=t;const o=[s];Lt(a)||o.push(a=Ft(a));const c=Et(a);n=Tt(r.length,n),Lt(r)||o.push(r=Ft(r)),It(r,n);const u=Et(r),h=Et(n);let y=c[0],l=c[1],p=c[2],g=c[3];for(let e=0;e+4<=u.length;){const t=y,r=l,i=p,n=g;y=u[e+0],l=u[e+1],p=u[e+2],g=u[e+3];const{s0:a,s1:o,s2:c,s3:d}=cr(s,y,l,p,g);h[e++]=a^t,h[e++]=o^r,h[e++]=c^i,h[e++]=d^n}return St(...o),function(e,t){if(!t)return e;const r=e.length;if(!r)throw Error("aes/pcks5: empty ciphertext not allowed");const i=e[r-1];if(i<=0||i>16)throw Error("aes/pcks5: wrong padding");const n=e.subarray(0,-i);for(let t=0;t<i;t++)if(e[r-t-1]!==i)throw Error("aes/pcks5: wrong padding");return n}(n,i)}}})),pr=/* @__PURE__ */Bt({blockSize:16,nonceLength:16},(function(e,t){function r(r,i,n){kt(r);const s=r.length;if(xt(r,n=Tt(s,n)))throw Error("overlapping src and dst not supported.");const a=ir(e);let o=t;const c=[a];Lt(o)||c.push(o=Ft(o)),Lt(r)||c.push(r=Ft(r));const u=Et(r),h=Et(n),y=i?h:u,l=Et(o);let p=l[0],g=l[1],d=l[2],f=l[3];for(let e=0;e+4<=u.length;){const{s0:t,s1:r,s2:i,s3:n}=or(a,p,g,d,f);h[e+0]=u[e+0]^t,h[e+1]=u[e+1]^r,h[e+2]=u[e+2]^i,h[e+3]=u[e+3]^n,p=y[e++],g=y[e++],d=y[e++],f=y[e++]}const m=_t*Math.floor(u.length/4);if(m<s){({s0:p,s1:g,s2:d,s3:f}=or(a,p,g,d,f));const e=Kt(new Uint32Array([p,g,d,f]));for(let t=m,i=0;t<s;t++,i++)n[t]=r[t]^e[i];St(e)}return St(...c),n}return{encrypt:(e,t)=>r(e,!0,t),decrypt:(e,t)=>r(e,!1,t)}}));function gr(e,t,r,i,n){const s=n?n.length:0,a=e.create(r,i.length+s);n&&a.update(n);const o=function(e,t,r){const i=new Uint8Array(16),n=Pt(i);return Mt(n,0,BigInt(t),r),Mt(n,8,BigInt(e),r),i}(8*i.length,8*s,t);a.update(i),a.update(o);const c=a.digest();return St(o),c}const dr=/* @__PURE__ */Bt({blockSize:16,nonceLength:12,tagLength:16,varSizeNonce:!0},(function(e,t,r){if(t.length<8)throw Error("aes/gcm: invalid nonce length");function i(e,t,i){const n=gr(qt,!1,e,i,r);for(let e=0;e<t.length;e++)n[e]^=t[e];return n}function n(){const r=ir(e),i=Wt.slice(),n=Wt.slice();if(hr(r,!1,n,n,i),12===t.length)n.set(t);else{const e=Wt.slice();Mt(Pt(e),8,BigInt(8*t.length),!1);const r=qt.create(i).update(t).update(e);r.digestInto(n),r.destroy()}return{xk:r,authKey:i,counter:n,tagMask:hr(r,!1,n,Wt)}}return{encrypt(e){const{xk:t,authKey:r,counter:s,tagMask:a}=n(),o=new Uint8Array(e.length+16),c=[t,r,s,a];Lt(e)||c.push(e=Ft(e)),hr(t,!1,s,e,o.subarray(0,e.length));const u=i(r,a,o.subarray(0,o.length-16));return c.push(u),o.set(u,e.length),St(...c),o},decrypt(e){const{xk:t,authKey:r,counter:s,tagMask:a}=n(),o=[t,r,a,s];Lt(e)||o.push(e=Ft(e));const c=e.subarray(0,-16),u=e.subarray(-16),h=i(r,a,c);if(o.push(h),!Ct(h,u))throw Error("aes/gcm: invalid ghash tag");const y=hr(t,!1,s,c);return St(...o),y}}}));function fr(e){return e instanceof Uint32Array||ArrayBuffer.isView(e)&&"Uint32Array"===e.constructor.name}function mr(e,t){if(kt(t,16),!fr(e))throw Error("_encryptBlock accepts result of expandKeyLE");const r=Et(t);let{s0:i,s1:n,s2:s,s3:a}=or(e,r[0],r[1],r[2],r[3]);return r[0]=i,r[1]=n,r[2]=s,r[3]=a,t}function wr(e,t){if(kt(t,16),!fr(e))throw Error("_decryptBlock accepts result of expandKeyLE");const r=Et(t);let{s0:i,s1:n,s2:s,s3:a}=cr(e,r[0],r[1],r[2],r[3]);return r[0]=i,r[1]=n,r[2]=s,r[3]=a,t}const br={encrypt(e,t){if(t.length>=2**32)throw Error("plaintext should be less than 4gb");const r=ir(e);if(16===t.length)mr(r,t);else{const e=Et(t);let i=e[0],n=e[1];for(let t=0,s=1;t<6;t++)for(let t=2;t<e.length;t+=2,s++){const{s0:a,s1:o,s2:c,s3:u}=or(r,i,n,e[t],e[t+1]);i=a,n=o^Zt(s),e[t]=c,e[t+1]=u}e[0]=i,e[1]=n}r.fill(0)},decrypt(e,t){if(t.length-8>=2**32)throw Error("ciphertext should be less than 4gb");const r=nr(e),i=t.length/8-1;if(1===i)wr(r,t);else{const e=Et(t);let n=e[0],s=e[1];for(let t=0,a=6*i;t<6;t++)for(let t=2*i;t>=1;t-=2,a--){s^=Zt(a);const{s0:i,s1:o,s2:c,s3:u}=cr(r,n,s,e[t],e[t+1]);n=i,s=o,e[t]=c,e[t+1]=u}e[0]=n,e[1]=s}r.fill(0)}},kr=/* @__PURE__ */new Uint8Array(8).fill(166),vr=/* @__PURE__ */Bt({blockSize:8},(e=>({encrypt(t){if(!t.length||t.length%8!=0)throw Error("invalid plaintext length");if(8===t.length)throw Error("8-byte keys not allowed in AESKW, use AESKWP instead");const r=function(...e){let t=0;for(let r=0;r<e.length;r++){const i=e[r];kt(i),t+=i.length}const r=new Uint8Array(t);for(let t=0,i=0;t<e.length;t++){const n=e[t];r.set(n,i),i+=n.length}return r}(kr,t);return br.encrypt(e,r),r},decrypt(t){if(t.length%8!=0||t.length<24)throw Error("invalid ciphertext length");const r=Ft(t);if(br.decrypt(e,r),!Ct(r.subarray(0,8),kr))throw Error("integrity check failed");return r.subarray(0,8).fill(0),r.subarray(8)}}))),Ar={expandKeyLE:ir,expandKeyDecLE:nr,encrypt:or,decrypt:cr,encryptBlock:mr,decryptBlock:wr,ctrCounter:ur,ctr32:hr};async function Kr(e){switch(e){case M.symmetric.aes128:case M.symmetric.aes192:case M.symmetric.aes256:throw Error("Not a legacy cipher");case M.symmetric.cast5:case M.symmetric.blowfish:case M.symmetric.twofish:case M.symmetric.tripledes:{const{legacyCiphers:t}=await import("./legacy_ciphers.min.mjs"),r=M.read(M.symmetric,e),i=t.get(r);if(!i)throw Error("Unsupported cipher algorithm");return i}default:throw Error("Unsupported cipher algorithm")}}function Er(e){switch(e){case M.symmetric.aes128:case M.symmetric.aes192:case M.symmetric.aes256:case M.symmetric.twofish:return 16;case M.symmetric.blowfish:case M.symmetric.cast5:case M.symmetric.tripledes:return 8;default:throw Error("Unsupported cipher")}}function Sr(e){switch(e){case M.symmetric.aes128:case M.symmetric.blowfish:case M.symmetric.cast5:return 16;case M.symmetric.aes192:case M.symmetric.tripledes:return 24;case M.symmetric.aes256:case M.symmetric.twofish:return 32;default:throw Error("Unsupported cipher")}}function Pr(e){return{keySize:Sr(e),blockSize:Er(e)}}const Ur=N.getWebCrypto();async function Dr(e,t,r){const{keySize:i}=Pr(e);if(!N.isAES(e)||t.length!==i)throw Error("Unexpected algorithm or key size");try{const e=await Ur.importKey("raw",t,{name:"AES-KW"},!1,["wrapKey"]),i=await Ur.importKey("raw",r,{name:"HMAC",hash:"SHA-256"},!0,["sign"]),n=await Ur.wrapKey("raw",i,e,{name:"AES-KW"});return new Uint8Array(n)}catch(e){if("NotSupportedError"!==e.name&&(24!==t.length||"OperationError"!==e.name))throw e;N.printDebugError("Browser did not support operation: "+e.message)}return vr(t).encrypt(r)}async function xr(e,t,r){const{keySize:i}=Pr(e);if(!N.isAES(e)||t.length!==i)throw Error("Unexpected algorithm or key size");let n;try{n=await Ur.importKey("raw",t,{name:"AES-KW"},!1,["unwrapKey"])}catch(e){if("NotSupportedError"!==e.name&&(24!==t.length||"OperationError"!==e.name))throw e;return N.printDebugError("Browser did not support operation: "+e.message),vr(t).decrypt(r)}try{const e=await Ur.unwrapKey("raw",r,n,{name:"AES-KW"},{name:"HMAC",hash:"SHA-256"},!0,["sign"]);return new Uint8Array(await Ur.exportKey("raw",e))}catch(e){if("OperationError"===e.name)throw Error("Key Data Integrity failed");throw e}}async function Ir(e,t,r,i,n){const s=N.getWebCrypto(),a=M.read(M.webHash,e);if(!a)throw Error("Hash algo not supported with HKDF");const o=await s.importKey("raw",t,"HKDF",!1,["deriveBits"]),c=await s.deriveBits({name:"HKDF",hash:a,salt:r,info:i},o,8*n);return new Uint8Array(c)}const Cr={x25519:N.encodeUTF8("OpenPGP X25519"),x448:N.encodeUTF8("OpenPGP X448")};async function Br(e){switch(e){case M.publicKey.x25519:try{const e=N.getWebCrypto(),t=await e.generateKey("X25519",!0,["deriveKey","deriveBits"]).catch((e=>{if("OperationError"===e.name){const e=Error("Unexpected key generation issue");throw e.name="NotSupportedError",e}throw e})),r=await e.exportKey("jwk",t.privateKey),i=await e.exportKey("jwk",t.publicKey);if(r.x!==i.x){const e=Error("Unexpected mismatching public point");throw e.name="NotSupportedError",e}return{A:new Uint8Array(G(i.x)),k:G(r.d)}}catch(e){if("NotSupportedError"!==e.name)throw e;const{default:t}=await import("./nacl-fast.min.mjs"),{secretKey:r,publicKey:i}=t.box.keyPair();return{A:i,k:r}}case M.publicKey.x448:{const e=await N.getNobleCurve(M.publicKey.x448),{secretKey:t,publicKey:r}=e.keygen();return{A:r,k:t}}default:throw Error("Unsupported ECDH algorithm")}}async function Tr(e,t,r){switch(e){case M.publicKey.x25519:try{const{ephemeralPublicKey:i,sharedSecret:n}=await Nr(e,t),s=await zr(e,i,t,r);return N.equalsUint8Array(n,s)}catch{return!1}case M.publicKey.x448:{const e=(await N.getNobleCurve(M.publicKey.x448)).getPublicKey(r);return N.equalsUint8Array(t,e)}default:return!1}}async function Mr(e,t,r){const{ephemeralPublicKey:i,sharedSecret:n}=await Nr(e,r),s=N.concatUint8Array([i,r,n]);switch(e){case M.publicKey.x25519:{const e=M.symmetric.aes128,{keySize:r}=Pr(e),n=await Ir(M.hash.sha256,s,new Uint8Array,Cr.x25519,r);return{ephemeralPublicKey:i,wrappedKey:await Dr(e,n,t)}}case M.publicKey.x448:{const e=M.symmetric.aes256,{keySize:r}=Pr(M.symmetric.aes256),n=await Ir(M.hash.sha512,s,new Uint8Array,Cr.x448,r);return{ephemeralPublicKey:i,wrappedKey:await Dr(e,n,t)}}default:throw Error("Unsupported ECDH algorithm")}}async function Lr(e,t,r,i,n){const s=await zr(e,t,i,n),a=N.concatUint8Array([t,i,s]);switch(e){case M.publicKey.x25519:{const e=M.symmetric.aes128,{keySize:t}=Pr(e);return xr(e,await Ir(M.hash.sha256,a,new Uint8Array,Cr.x25519,t),r)}case M.publicKey.x448:{const e=M.symmetric.aes256,{keySize:t}=Pr(M.symmetric.aes256);return xr(e,await Ir(M.hash.sha512,a,new Uint8Array,Cr.x448,t),r)}default:throw Error("Unsupported ECDH algorithm")}}function Fr(e){switch(e){case M.publicKey.x25519:return 32;case M.publicKey.x448:return 56;default:throw Error("Unsupported ECDH algorithm")}}async function Nr(e,t){switch(e){case M.publicKey.x25519:try{const r=N.getWebCrypto(),i=await r.generateKey("X25519",!0,["deriveKey","deriveBits"]).catch((e=>{if("OperationError"===e.name){const e=Error("Unexpected key generation issue");throw e.name="NotSupportedError",e}throw e})),n=await r.exportKey("jwk",i.publicKey);if((await r.exportKey("jwk",i.privateKey)).x!==n.x){const e=Error("Unexpected mismatching public point");throw e.name="NotSupportedError",e}const s=Or(e,t),a=await r.importKey("jwk",s,"X25519",!1,[]),o=await r.deriveBits({name:"X25519",public:a},i.privateKey,8*Fr(e));return{sharedSecret:new Uint8Array(o),ephemeralPublicKey:new Uint8Array(G(n.x))}}catch(e){if("NotSupportedError"!==e.name)throw e;const{default:r}=await import("./nacl-fast.min.mjs"),{secretKey:i,publicKey:n}=r.box.keyPair(),s=r.scalarMult(i,t);return Rr(s),{ephemeralPublicKey:n,sharedSecret:s}}case M.publicKey.x448:{const e=await N.getNobleCurve(M.publicKey.x448),{secretKey:r,publicKey:i}=e.keygen(),n=e.getSharedSecret(r,t);return Rr(n),{ephemeralPublicKey:i,sharedSecret:n}}default:throw Error("Unsupported ECDH algorithm")}}async function zr(e,t,r,i){switch(e){case M.publicKey.x25519:try{const n=N.getWebCrypto(),s=function(e,t,r){if(e===M.publicKey.x25519){const i=Or(e,t);return i.d=q(r),i}throw Error("Unsupported ECDH algorithm")}(e,r,i),a=Or(e,t),o=await n.importKey("jwk",s,"X25519",!1,["deriveKey","deriveBits"]),c=await n.importKey("jwk",a,"X25519",!1,[]),u=await n.deriveBits({name:"X25519",public:c},o,8*Fr(e));return new Uint8Array(u)}catch(e){if("NotSupportedError"!==e.name)throw e;const{default:r}=await import("./nacl-fast.min.mjs"),n=r.scalarMult(i,t);return Rr(n),n}case M.publicKey.x448:{const e=(await N.getNobleCurve(M.publicKey.x448)).getSharedSecret(i,t);return Rr(e),e}default:throw Error("Unsupported ECDH algorithm")}}function Rr(e){let t=0;for(let r=0;r<e.length;r++)t|=e[r];if(0===t)throw Error("Unexpected low order point")}function Or(e,t){if(e===M.publicKey.x25519){return{kty:"OKP",crv:"X25519",x:q(t),ext:!0}}throw Error("Unsupported ECDH algorithm")}var jr=/*#__PURE__*/Object.freeze({__proto__:null,decrypt:Lr,encrypt:Mr,generate:Br,generateEphemeralEncryptionMaterial:Nr,getPayloadSize:Fr,recomputeSharedSecret:zr,validateParams:Tr});const Hr=N.getWebCrypto(),Gr=N.getNodeCrypto(),qr={[M.curve.nistP256]:"P-256",[M.curve.nistP384]:"P-384",[M.curve.nistP521]:"P-521"},_r=Gr?Gr.getCurves():[],Wr=Gr?{[M.curve.secp256k1]:_r.includes("secp256k1")?"secp256k1":void 0,[M.curve.nistP256]:_r.includes("prime256v1")?"prime256v1":void 0,[M.curve.nistP384]:_r.includes("secp384r1")?"secp384r1":void 0,[M.curve.nistP521]:_r.includes("secp521r1")?"secp521r1":void 0,[M.curve.ed25519Legacy]:_r.includes("ED25519")?"ED25519":void 0,[M.curve.curve25519Legacy]:_r.includes("X25519")?"X25519":void 0,[M.curve.brainpoolP256r1]:_r.includes("brainpoolP256r1")?"brainpoolP256r1":void 0,[M.curve.brainpoolP384r1]:_r.includes("brainpoolP384r1")?"brainpoolP384r1":void 0,[M.curve.brainpoolP512r1]:_r.includes("brainpoolP512r1")?"brainpoolP512r1":void 0}:{},Vr={[M.curve.nistP256]:{oid:[6,8,42,134,72,206,61,3,1,7],keyType:M.publicKey.ecdsa,hash:M.hash.sha256,cipher:M.symmetric.aes128,node:Wr[M.curve.nistP256],web:qr[M.curve.nistP256],payloadSize:32,sharedSize:256,wireFormatLeadingByte:4},[M.curve.nistP384]:{oid:[6,5,43,129,4,0,34],keyType:M.publicKey.ecdsa,hash:M.hash.sha384,cipher:M.symmetric.aes192,node:Wr[M.curve.nistP384],web:qr[M.curve.nistP384],payloadSize:48,sharedSize:384,wireFormatLeadingByte:4},[M.curve.nistP521]:{oid:[6,5,43,129,4,0,35],keyType:M.publicKey.ecdsa,hash:M.hash.sha512,cipher:M.symmetric.aes256,node:Wr[M.curve.nistP521],web:qr[M.curve.nistP521],payloadSize:66,sharedSize:528,wireFormatLeadingByte:4},[M.curve.secp256k1]:{oid:[6,5,43,129,4,0,10],keyType:M.publicKey.ecdsa,hash:M.hash.sha256,cipher:M.symmetric.aes128,node:Wr[M.curve.secp256k1],payloadSize:32,wireFormatLeadingByte:4},[M.curve.ed25519Legacy]:{oid:[6,9,43,6,1,4,1,218,71,15,1],keyType:M.publicKey.eddsaLegacy,hash:M.hash.sha512,node:!1,payloadSize:32,wireFormatLeadingByte:64},[M.curve.curve25519Legacy]:{oid:[6,10,43,6,1,4,1,151,85,1,5,1],keyType:M.publicKey.ecdh,hash:M.hash.sha256,cipher:M.symmetric.aes128,node:!1,payloadSize:32,wireFormatLeadingByte:64},[M.curve.brainpoolP256r1]:{oid:[6,9,43,36,3,3,2,8,1,1,7],keyType:M.publicKey.ecdsa,hash:M.hash.sha256,cipher:M.symmetric.aes128,node:Wr[M.curve.brainpoolP256r1],payloadSize:32,wireFormatLeadingByte:4},[M.curve.brainpoolP384r1]:{oid:[6,9,43,36,3,3,2,8,1,1,11],keyType:M.publicKey.ecdsa,hash:M.hash.sha384,cipher:M.symmetric.aes192,node:Wr[M.curve.brainpoolP384r1],payloadSize:48,wireFormatLeadingByte:4},[M.curve.brainpoolP512r1]:{oid:[6,9,43,36,3,3,2,8,1,1,13],keyType:M.publicKey.ecdsa,hash:M.hash.sha512,cipher:M.symmetric.aes256,node:Wr[M.curve.brainpoolP512r1],payloadSize:64,wireFormatLeadingByte:4}};class $r{constructor(e){try{this.name=e instanceof Ze?e.getName():M.write(M.curve,e)}catch{throw new at("Unknown curve")}const t=Vr[this.name];this.keyType=t.keyType,this.oid=t.oid,this.hash=t.hash,this.cipher=t.cipher,this.node=t.node,this.web=t.web,this.payloadSize=t.payloadSize,this.sharedSize=t.sharedSize,this.wireFormatLeadingByte=t.wireFormatLeadingByte,this.web&&N.getWebCrypto()?this.type="web":this.node&&N.getNodeCrypto()?this.type="node":this.name===M.curve.curve25519Legacy?this.type="curve25519Legacy":this.name===M.curve.ed25519Legacy&&(this.type="ed25519Legacy")}async genKeyPair(){switch(this.type){case"web":try{return await async function(e,t){const r=await Hr.generateKey({name:"ECDSA",namedCurve:qr[e]},!0,["sign","verify"]),i=await Hr.exportKey("jwk",r.privateKey);return{publicKey:ei(await Hr.exportKey("jwk",r.publicKey),t),privateKey:G(i.d)}}(this.name,this.wireFormatLeadingByte)}catch(e){return N.printDebugError("Browser did not support generating ec key "+e.message),Jr(this.name)}case"node":return function(e){const t=Gr.createECDH(Wr[e]);return t.generateKeys(),{publicKey:new Uint8Array(t.getPublicKey()),privateKey:new Uint8Array(t.getPrivateKey())}}(this.name);case"curve25519Legacy":{const{k:e,A:t}=await Br(M.publicKey.x25519),r=e.slice().reverse();r[0]=127&r[0]|64,r[31]&=248;return{publicKey:N.concatUint8Array([new Uint8Array([this.wireFormatLeadingByte]),t]),privateKey:r}}case"ed25519Legacy":{const{seed:e,A:t}=await ht(M.publicKey.ed25519);return{publicKey:N.concatUint8Array([new Uint8Array([this.wireFormatLeadingByte]),t]),privateKey:e}}default:return Jr(this.name)}}}async function Xr(e){const t=new $r(e),{oid:r,hash:i,cipher:n}=t,s=await t.genKeyPair();return{oid:r,Q:s.publicKey,secret:N.leftPad(s.privateKey,t.payloadSize),hash:i,cipher:n}}function Qr(e){return Vr[e.getName()].hash}async function Yr(e,t,r,i){const n={[M.curve.nistP256]:!0,[M.curve.nistP384]:!0,[M.curve.nistP521]:!0,[M.curve.secp256k1]:!0,[M.curve.curve25519Legacy]:e===M.publicKey.ecdh,[M.curve.brainpoolP256r1]:!0,[M.curve.brainpoolP384r1]:!0,[M.curve.brainpoolP512r1]:!0},s=t.getName();if(!n[s])return!1;if(s===M.curve.curve25519Legacy){const e=i.slice().reverse();return!(r.length<1||64!==r[0])&&Tr(M.publicKey.x25519,r.subarray(1),e)}const a=(await N.getNobleCurve(M.publicKey.ecdsa,s)).getPublicKey(i,!1);return!!N.equalsUint8Array(a,r)}function Zr(e,t){const{payloadSize:r,wireFormatLeadingByte:i,name:n}=e,s=n===M.curve.curve25519Legacy||n===M.curve.ed25519Legacy?r:2*r;if(t[0]!==i||t.length!==s+1)throw Error("Invalid point encoding")}async function Jr(e){const t=await N.getNobleCurve(M.publicKey.ecdsa,e),{secretKey:r}=t.keygen();return{publicKey:t.getPublicKey(r,!1),privateKey:r}}function ei(e,t){const r=G(e.x),i=G(e.y),n=new Uint8Array(r.length+i.length+1);return n[0]=t,n.set(r,1),n.set(i,r.length+1),n}function ti(e,t,r){const i=e,n=r.slice(1,i+1),s=r.slice(i+1,2*i+1);return{kty:"EC",crv:t,x:q(n),y:q(s),ext:!0}}function ri(e,t,r,i){const n=ti(e,t,r);return n.d=q(i),n}const ii=N.getWebCrypto(),ni=N.getNodeCrypto();async function si(e,t,r,i,n,s){const a=new $r(e);if(Zr(a,i),r&&!N.isStream(r)){const e={publicKey:i,privateKey:n};switch(a.type){case"web":try{return await async function(e,t,r,i){const n=e.payloadSize,s=ri(e.payloadSize,qr[e.name],i.publicKey,i.privateKey),a=await ii.importKey("jwk",s,{name:"ECDSA",namedCurve:qr[e.name],hash:{name:M.read(M.webHash,e.hash)}},!1,["sign"]),o=new Uint8Array(await ii.sign({name:"ECDSA",namedCurve:qr[e.name],hash:{name:M.read(M.webHash,t)}},a,r));return{r:o.slice(0,n),s:o.slice(n,n<<1)}}(a,t,r,e)}catch(e){if("nistP521"!==a.name&&("DataError"===e.name||"OperationError"===e.name))throw e;N.printDebugError("Browser did not support signing: "+e.message)}break;case"node":return function(e,t,r,i){const n=N.nodeRequire("eckey-utils"),s=N.getNodeBuffer(),{privateKey:a}=n.generateDer({curveName:Wr[e.name],privateKey:s.from(i)}),o=ni.createSign(M.read(M.hash,t));o.write(r),o.end();const c=new Uint8Array(o.sign({key:a,format:"der",type:"sec1",dsaEncoding:"ieee-p1363"})),u=e.payloadSize;return{r:c.subarray(0,u),s:c.subarray(u,u<<1)}}(a,t,r,n)}}const o=(await N.getNobleCurve(M.publicKey.ecdsa,a.name)).sign(s,n,{lowS:!1});return{r:le(o.r,"be",a.payloadSize),s:le(o.s,"be",a.payloadSize)}}async function ai(e,t,r,i,n,s){const a=new $r(e);Zr(a,n);const o=async()=>0===s[0]&&oi(a,r,s.subarray(1),n);if(i&&!N.isStream(i))switch(a.type){case"web":try{const e=await async function(e,t,{r,s:i},n,s){const a=ti(e.payloadSize,qr[e.name],s),o=await ii.importKey("jwk",a,{name:"ECDSA",namedCurve:qr[e.name],hash:{name:M.read(M.webHash,e.hash)}},!1,["verify"]),c=N.concatUint8Array([r,i]).buffer;return ii.verify({name:"ECDSA",namedCurve:qr[e.name],hash:{name:M.read(M.webHash,t)}},o,c,n)}(a,t,r,i,n);return e||o()}catch(e){if("nistP521"!==a.name&&("DataError"===e.name||"OperationError"===e.name))throw e;N.printDebugError("Browser did not support verifying: "+e.message)}break;case"node":{const e=function(e,t,{r,s:i},n,s){const a=N.nodeRequire("eckey-utils"),o=N.getNodeBuffer(),{publicKey:c}=a.generateDer({curveName:Wr[e.name],publicKey:o.from(s)}),u=ni.createVerify(M.read(M.hash,t));u.write(n),u.end();const h=N.concatUint8Array([r,i]);try{return u.verify({key:c,format:"der",type:"spki",dsaEncoding:"ieee-p1363"},h)}catch{return!1}}(a,t,r,i,n);return e||o()}}return await oi(a,r,s,n)||o()}async function oi(e,t,r,i){return(await N.getNobleCurve(M.publicKey.ecdsa,e.name)).verify(N.concatUint8Array([t.r,t.s]),r,i,{lowS:!1})}var ci=/*#__PURE__*/Object.freeze({__proto__:null,sign:si,validateParams:async function(e,t,r){const i=new $r(e);if(i.keyType!==M.publicKey.ecdsa)return!1;switch(i.type){case"web":case"node":{const i=ge(8),n=M.hash.sha256,s=await Me(n,i);try{const a=await si(e,n,i,t,r,s);return await ai(e,n,a,i,t,s)}catch{return!1}}default:return Yr(M.publicKey.ecdsa,e,t,r)}},verify:ai});async function ui(e,t,r,i,n,s){if(Zr(new $r(e),i),Le(t)<Le(M.hash.sha256))throw Error("Hash algorithm too weak for EdDSA.");const{RS:a}=await yt(M.publicKey.ed25519,t,0,i.subarray(1),n,s);return{r:a.subarray(0,32),s:a.subarray(32)}}async function hi(e,t,{r,s:i},n,s,a){if(Zr(new $r(e),s),Le(t)<Le(M.hash.sha256))throw Error("Hash algorithm too weak for EdDSA.");const o=N.concatUint8Array([r,i]);return lt(M.publicKey.ed25519,t,{RS:o},0,s.subarray(1),a)}async function yi(e,t,r){return e.getName()===M.curve.ed25519Legacy&&(!(t.length<1||64!==t[0])&&pt(M.publicKey.ed25519,t.subarray(1),r))}var li=/*#__PURE__*/Object.freeze({__proto__:null,sign:ui,validateParams:yi,verify:hi});function pi(e){const t=e.length;if(t>0){const r=e[t-1];if(r>=1){const i=e.subarray(t-r),n=new Uint8Array(r).fill(r);if(N.equalsUint8Array(i,n))return e.subarray(0,t-r)}}throw Error("Invalid padding")}function gi(e,t,r,i){return N.concatUint8Array([t.write(),new Uint8Array([e]),r.write(),N.stringToUint8Array("Anonymous Sender    "),i])}async function di(e,t,r,i,n=!1,s=!1){let a;if(n){for(a=0;a<t.length&&0===t[a];a++);t=t.subarray(a)}if(s){for(a=t.length-1;a>=0&&0===t[a];a--);t=t.subarray(0,a+1)}return(await Me(e,N.concatUint8Array([new Uint8Array([0,0,0,1]),t,i]))).subarray(0,r)}async function fi(e,t){switch(e.type){case"curve25519Legacy":{const{sharedSecret:r,ephemeralPublicKey:i}=await Nr(M.publicKey.x25519,t.subarray(1));return{publicKey:N.concatUint8Array([new Uint8Array([e.wireFormatLeadingByte]),i]),sharedKey:r}}case"web":if(e.web&&N.getWebCrypto())try{return await async function(e,t){const r=N.getWebCrypto(),i=ti(e.payloadSize,e.web,t);let n=r.generateKey({name:"ECDH",namedCurve:e.web},!0,["deriveKey","deriveBits"]),s=r.importKey("jwk",i,{name:"ECDH",namedCurve:e.web},!1,[]);[n,s]=await Promise.all([n,s]);let a=r.deriveBits({name:"ECDH",namedCurve:e.web,public:s},n.privateKey,e.sharedSize),o=r.exportKey("jwk",n.publicKey);[a,o]=await Promise.all([a,o]);const c=new Uint8Array(a),u=new Uint8Array(ei(o,e.wireFormatLeadingByte));return{publicKey:u,sharedKey:c}}(e,t)}catch(r){return N.printDebugError(r),vi(e,t)}break;case"node":return function(e,t){const r=N.getNodeCrypto(),i=r.createECDH(e.node);i.generateKeys();const n=new Uint8Array(i.computeSecret(t));return{publicKey:new Uint8Array(i.getPublicKey()),sharedKey:n}}(e,t);default:return vi(e,t)}}async function mi(e,t,r,i,n){const s=function(e){const t=8-e.length%8,r=new Uint8Array(e.length+t).fill(t);return r.set(e),r}(r),a=new $r(e);Zr(a,i);const{publicKey:o,sharedKey:c}=await fi(a,i),u=gi(M.publicKey.ecdh,e,t,n),{keySize:h}=Pr(t.cipher),y=await di(t.hash,c,h,u);return{publicKey:o,wrappedKey:await Dr(t.cipher,y,s)}}async function wi(e,t,r,i){if(i.length!==e.payloadSize){const t=new Uint8Array(e.payloadSize);t.set(i,e.payloadSize-i.length),i=t}switch(e.type){case"curve25519Legacy":{const e=i.slice().reverse();return{secretKey:e,sharedKey:await zr(M.publicKey.x25519,t.subarray(1),r.subarray(1),e)}}case"web":if(e.web&&N.getWebCrypto())try{return await async function(e,t,r,i){const n=N.getWebCrypto(),s=ri(e.payloadSize,e.web,r,i);let a=n.importKey("jwk",s,{name:"ECDH",namedCurve:e.web},!0,["deriveKey","deriveBits"]);const o=ti(e.payloadSize,e.web,t);let c=n.importKey("jwk",o,{name:"ECDH",namedCurve:e.web},!0,[]);[a,c]=await Promise.all([a,c]);let u=n.deriveBits({name:"ECDH",namedCurve:e.web,public:c},a,e.sharedSize),h=n.exportKey("jwk",a);[u,h]=await Promise.all([u,h]);const y=new Uint8Array(u);return{secretKey:G(h.d),sharedKey:y}}(e,t,r,i)}catch(r){return N.printDebugError(r),ki(e,t,i)}break;case"node":return function(e,t,r){const i=N.getNodeCrypto(),n=i.createECDH(e.node);n.setPrivateKey(r);const s=new Uint8Array(n.computeSecret(t));return{secretKey:new Uint8Array(n.getPrivateKey()),sharedKey:s}}(e,t,i);default:return ki(e,t,i)}}async function bi(e,t,r,i,n,s,a){const o=new $r(e);Zr(o,n),Zr(o,r);const{sharedKey:c}=await wi(o,r,n,s),u=gi(M.publicKey.ecdh,e,t,a),{keySize:h}=Pr(t.cipher);let y;for(let e=0;e<3;e++)try{const r=await di(t.hash,c,h,u,1===e,2===e);return pi(await xr(t.cipher,r,i))}catch(e){y=e}throw y}async function ki(e,t,r){return{secretKey:r,sharedKey:(await N.getNobleCurve(M.publicKey.ecdh,e.name)).getSharedSecret(r,t).subarray(1)}}async function vi(e,t){const r=await N.getNobleCurve(M.publicKey.ecdh,e.name),{publicKey:i,privateKey:n}=await e.genKeyPair();return{publicKey:i,sharedKey:r.getSharedSecret(n,t).subarray(1)}}var Ai=/*#__PURE__*/Object.freeze({__proto__:null,CurveWithOID:$r,ecdh:/*#__PURE__*/Object.freeze({__proto__:null,decrypt:bi,encrypt:mi,validateParams:async function(e,t,r){return Yr(M.publicKey.ecdh,e,t,r)}}),ecdhX:jr,ecdsa:ci,eddsa:wt,eddsaLegacy:li,generate:Xr,getPreferredHashAlgo:Qr});const Ki=BigInt(0),Ei=BigInt(1);class Si{constructor(e){e&&(this.data=e)}read(e){if(e.length>=1){const t=e[0];if(e.length>=1+t)return this.data=e.subarray(1,1+t),1+this.data.length}throw Error("Invalid symmetric key")}write(){return N.concatUint8Array([new Uint8Array([this.data.length]),this.data])}}class Pi{constructor(e){if(e){const{hash:t,cipher:r}=e;this.hash=t,this.cipher=r}else this.hash=null,this.cipher=null}read(e){if(e.length<4||3!==e[0]||1!==e[1])throw new at("Cannot read KDFParams");return this.hash=e[2],this.cipher=e[3],4}write(){return new Uint8Array([3,1,this.hash,this.cipher])}}class Ui{static fromObject({wrappedKey:e,algorithm:t}){const r=new Ui;return r.wrappedKey=e,r.algorithm=t,r}read(e){let t=0,r=e[t++];this.algorithm=r%2?e[t++]:null,r-=r%2,this.wrappedKey=N.readExactSubarray(e,t,t+r),t+=r}write(){return N.concatUint8Array([this.algorithm?new Uint8Array([this.wrappedKey.length+1,this.algorithm]):new Uint8Array([this.wrappedKey.length]),this.wrappedKey])}}async function Di(e,t,r,i,n){switch(e){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:{const{n:e,e:t}=r;return{c:await _e(i,e,t)}}case M.publicKey.elgamal:{const{p:e,g:t,y:n}=r;return async function(e,t,r,i){t=re(t),r=re(r),i=re(i);const n=re(Ne(e,ye(t))),s=de(Qe,t-Qe);return{c1:le(se(r,s,t)),c2:le(ie(se(i,s,t)*n,t))}}(i,e,t,n)}case M.publicKey.ecdh:{const{oid:e,Q:t,kdfParams:s}=r,{publicKey:a,wrappedKey:o}=await mi(e,s,i,t,n);return{V:a,C:new Si(o)}}case M.publicKey.x25519:case M.publicKey.x448:{if(t&&!N.isAES(t))throw Error("X25519 and X448 keys can only encrypt AES session keys");const{A:n}=r,{ephemeralPublicKey:s,wrappedKey:a}=await Mr(e,i,n);return{ephemeralPublicKey:s,C:Ui.fromObject({algorithm:t,wrappedKey:a})}}default:return[]}}async function xi(e,t,r,i,n,s){switch(e){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaEncrypt:{const{c:e}=i,{n,e:a}=t,{d:o,p:c,q:u,u:h}=r;return We(e,n,a,o,c,u,h,s)}case M.publicKey.elgamal:{const{c1:e,c2:n}=i;return async function(e,t,r,i,n){return e=re(e),t=re(t),r=re(r),ze(le(ie(oe(se(e,i=re(i),r),r)*t,r),"be",ye(r)),n)}(e,n,t.p,r.x,s)}case M.publicKey.ecdh:{const{oid:e,Q:s,kdfParams:a}=t,{d:o}=r,{V:c,C:u}=i;return bi(e,a,c,u.data,s,o,n)}case M.publicKey.x25519:case M.publicKey.x448:{const{A:n}=t,{k:s}=r,{ephemeralPublicKey:a,C:o}=i;if(null!==o.algorithm&&!N.isAES(o.algorithm))throw Error("AES session key expected");return Lr(e,a,o.wrappedKey,n,s)}default:throw Error("Unknown public key encryption algorithm.")}}function Ii(e,t,r){let i=0;switch(e){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:{const e=N.readMPI(t.subarray(i));i+=e.length+2;const r=N.readMPI(t.subarray(i));i+=r.length+2;const n=N.readMPI(t.subarray(i));i+=n.length+2;const s=N.readMPI(t.subarray(i));return i+=s.length+2,{read:i,privateParams:{d:e,p:r,q:n,u:s}}}case M.publicKey.dsa:case M.publicKey.elgamal:{const e=N.readMPI(t.subarray(i));return i+=e.length+2,{read:i,privateParams:{x:e}}}case M.publicKey.ecdsa:case M.publicKey.ecdh:{const n=Fi(e,r.oid);let s=N.readMPI(t.subarray(i));return i+=s.length+2,s=N.leftPad(s,n),{read:i,privateParams:{d:s}}}case M.publicKey.eddsaLegacy:{const n=Fi(e,r.oid);if(r.oid.getName()!==M.curve.ed25519Legacy)throw Error("Unexpected OID for eddsaLegacy");let s=N.readMPI(t.subarray(i));return i+=s.length+2,s=N.leftPad(s,n),{read:i,privateParams:{seed:s}}}case M.publicKey.ed25519:case M.publicKey.ed448:{const r=Fi(e),n=N.readExactSubarray(t,i,i+r);return i+=n.length,{read:i,privateParams:{seed:n}}}case M.publicKey.x25519:case M.publicKey.x448:{const r=Fi(e),n=N.readExactSubarray(t,i,i+r);return i+=n.length,{read:i,privateParams:{k:n}}}default:throw new at("Unknown public key encryption algorithm.")}}function Ci(e,t){const r=new Set([M.publicKey.ed25519,M.publicKey.x25519,M.publicKey.ed448,M.publicKey.x448]),i=Object.keys(t).map((i=>{const n=t[i];return N.isUint8Array(n)?r.has(e)?n:N.uint8ArrayToMPI(n):n.write()}));return N.concatUint8Array(i)}function Bi(e,t,r){switch(e){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:return async function(e,t){if(t=BigInt(t),N.getWebCrypto()){const r={name:"RSASSA-PKCS1-v1_5",modulusLength:e,publicExponent:le(t),hash:{name:"SHA-1"}},i=await Oe.generateKey(r,!0,["sign","verify"]);return Xe(await Oe.exportKey("jwk",i.privateKey),t)}if(N.getNodeCrypto()){const r={modulusLength:e,publicExponent:ce(t),publicKeyEncoding:{type:"pkcs1",format:"jwk"},privateKeyEncoding:{type:"pkcs1",format:"jwk"}},i=await new Promise(((e,t)=>{je.generateKeyPair("rsa",r,((r,i,n)=>{r?t(r):e(n)}))}));return Xe(i,t)}let r,i,n;do{i=me(e-(e>>1),t,40),r=me(e>>1,t,40),n=r*i}while(he(n)!==e);const s=(r-He)*(i-He);return i<r&&([r,i]=[i,r]),{n:le(n),e:le(t),d:le(oe(t,s)),p:le(r),q:le(i),u:le(oe(r,i))}}(t,65537).then((({n:e,e:t,d:r,p:i,q:n,u:s})=>({privateParams:{d:r,p:i,q:n,u:s},publicParams:{n:e,e:t}})));case M.publicKey.ecdsa:return Xr(r).then((({oid:e,Q:t,secret:r})=>({privateParams:{d:r},publicParams:{oid:new Ze(e),Q:t}})));case M.publicKey.eddsaLegacy:return Xr(r).then((({oid:e,Q:t,secret:r})=>({privateParams:{seed:r},publicParams:{oid:new Ze(e),Q:t}})));case M.publicKey.ecdh:return Xr(r).then((({oid:e,Q:t,secret:r,hash:i,cipher:n})=>({privateParams:{d:r},publicParams:{oid:new Ze(e),Q:t,kdfParams:new Pi({hash:i,cipher:n})}})));case M.publicKey.ed25519:case M.publicKey.ed448:return ht(e).then((({A:e,seed:t})=>({privateParams:{seed:t},publicParams:{A:e}})));case M.publicKey.x25519:case M.publicKey.x448:return Br(e).then((({A:e,k:t})=>({privateParams:{k:t},publicParams:{A:e}})));case M.publicKey.dsa:case M.publicKey.elgamal:throw Error("Unsupported algorithm for key generation.");default:throw Error("Unknown public key algorithm.")}}async function Ti(e,t,r){if(!t||!r)throw Error("Missing key parameters");switch(e){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:{const{n:e,e:i}=t,{d:n,p:s,q:a,u:o}=r;return async function(e,t,r,i,n,s){if(e=re(e),(i=re(i))*(n=re(n))!==e)return!1;const a=BigInt(2);if(ie(i*(s=re(s)),n)!==BigInt(1))return!1;t=re(t),r=re(r);const o=de(a,a<<BigInt(Math.floor(he(e)/3))),c=o*r*t;return!(ie(c,i-He)!==o||ie(c,n-He)!==o)}(e,i,n,s,a,o)}case M.publicKey.dsa:{const{p:e,q:i,g:n,y:s}=t,{x:a}=r;return async function(e,t,r,i,n){const s=re(e),a=re(t),o=re(r),c=re(i);if(o<=Ei||o>=s)return!1;if(ie(s-Ei,a)!==Ki)return!1;if(se(o,a,s)!==Ei)return!1;const u=BigInt(he(a));if(u<BigInt(150)||!we(a,null,32))return!1;const h=re(n),y=BigInt(2);return c===se(o,a*de(y<<u-Ei,y<<u)+h,s)}(e,i,n,s,a)}case M.publicKey.elgamal:{const{p:e,g:i,y:n}=t,{x:s}=r;return async function(e,t,r,i){const n=re(e),s=re(t),a=re(r);if(s<=Qe||s>=n)return!1;const o=BigInt(he(n));if(o<BigInt(1023))return!1;if(se(s,n-Qe,n)!==Qe)return!1;let c=s,u=BigInt(1);const h=BigInt(2),y=h<<BigInt(17);for(;u<y;){if(c=ie(c*s,n),c===Qe)return!1;u++}const l=re(i),p=de(h<<o-Qe,h<<o);return a===se(s,(n-Qe)*p+l,n)}(e,i,n,s)}case M.publicKey.ecdsa:case M.publicKey.ecdh:{const i=Ai[M.read(M.publicKey,e)],{oid:n,Q:s}=t,{d:a}=r;return i.validateParams(n,s,a)}case M.publicKey.eddsaLegacy:{const{Q:e,oid:i}=t,{seed:n}=r;return yi(i,e,n)}case M.publicKey.ed25519:case M.publicKey.ed448:{const{A:i}=t,{seed:n}=r;return pt(e,i,n)}case M.publicKey.x25519:case M.publicKey.x448:{const{A:i}=t,{k:n}=r;return Tr(e,i,n)}default:throw Error("Unknown public key algorithm.")}}function Mi(e){const{keySize:t}=Pr(e);return ge(t)}function Li(e){try{e.getName()}catch{throw new at("Unknown curve OID")}}function Fi(e,t){switch(e){case M.publicKey.ecdsa:case M.publicKey.ecdh:case M.publicKey.eddsaLegacy:return new $r(t).payloadSize;case M.publicKey.ed25519:case M.publicKey.ed448:return gt(e);case M.publicKey.x25519:case M.publicKey.x448:return Fr(e);default:throw Error("Unknown elliptic algo")}}const Ni=N.getWebCrypto(),zi=N.getNodeCrypto(),Ri=zi?zi.getCiphers():[],Oi={idea:Ri.includes("idea-cfb")?"idea-cfb":void 0,tripledes:Ri.includes("des-ede3-cfb")?"des-ede3-cfb":void 0,cast5:Ri.includes("cast5-cfb")?"cast5-cfb":void 0,blowfish:Ri.includes("bf-cfb")?"bf-cfb":void 0,aes128:Ri.includes("aes-128-cfb")?"aes-128-cfb":void 0,aes192:Ri.includes("aes-192-cfb")?"aes-192-cfb":void 0,aes256:Ri.includes("aes-256-cfb")?"aes-256-cfb":void 0};function ji(e){const{blockSize:t}=Pr(e),r=ge(t),i=new Uint8Array([r[r.length-2],r[r.length-1]]);return N.concat([r,i])}async function Hi(e,t,r,i,n){const s=M.read(M.symmetric,e);if(N.getNodeCrypto()&&Oi[s])return function(e,t,r,i){const n=M.read(M.symmetric,e),s=new zi.createCipheriv(Oi[n],t,i);return b(r,(e=>new Uint8Array(s.update(e))))}(e,t,r,i);if(N.isAES(e))return async function(e,t,r,i){if(Ni&&await qi.isSupported(e)){const n=new qi(e,t,i);return N.isStream(r)?k(r,(e=>n.encryptChunk(e)),(()=>n.finish())):n.encrypt(r)}if(N.isStream(r)){const n=new _i(!0,e,t,i);return k(r,(e=>n.processChunk(e)),(()=>n.finish()))}return pr(t,i).encrypt(r)}(e,t,r,i);const a=new(await Kr(e))(t),o=a.blockSize,c=i.slice();let u=new Uint8Array;const h=e=>{e&&(u=N.concatUint8Array([u,e]));const t=new Uint8Array(u.length);let r,i=0;for(;e?u.length>=o:u.length;){const e=a.encrypt(c);for(r=0;r<o;r++)c[r]=u[r]^e[r],t[i++]=c[r];u=u.subarray(o)}return t.subarray(0,i)};return b(r,h,h)}async function Gi(e,t,r,i){const n=M.read(M.symmetric,e);if(zi&&Oi[n])return function(e,t,r,i){const n=M.read(M.symmetric,e),s=new zi.createDecipheriv(Oi[n],t,i);return b(r,(e=>new Uint8Array(s.update(e))))}(e,t,r,i);if(N.isAES(e))return function(e,t,r,i){if(N.isStream(r)){const n=new _i(!1,e,t,i);return k(r,(e=>n.processChunk(e)),(()=>n.finish()))}return pr(t,i).decrypt(r)}(e,t,r,i);const s=new(await Kr(e))(t),a=s.blockSize;let o=i,c=new Uint8Array;const u=e=>{e&&(c=N.concatUint8Array([c,e]));const t=new Uint8Array(c.length);let r,i=0;for(;e?c.length>=a:c.length;){const e=s.encrypt(o);for(o=c.subarray(0,a),r=0;r<a;r++)t[i++]=o[r]^e[r];c=c.subarray(a)}return t.subarray(0,i)};return b(r,u,u)}class qi{constructor(e,t,r){const{blockSize:i}=Pr(e);this.key=t,this.iv=r,this.prevBlock=r.slice(),this.nextBlock=new Uint8Array(i),this.i=0,this.blockSize=i,this.zeroBlock=new Uint8Array(this.blockSize)}static isSupported(e){const{keySize:t}=Pr(e);return Ni.importKey("raw",new Uint8Array(t),"aes-cbc",!1,["encrypt"]).then((()=>!0),(()=>!1))}async _runCBC(e,t){const r="AES-CBC";this.keyRef=this.keyRef||await Ni.importKey("raw",this.key,r,!1,["encrypt"]);const i=await Ni.encrypt({name:r,iv:t||this.zeroBlock},this.keyRef,e);return new Uint8Array(i).subarray(0,e.length)}async encryptChunk(e){const t=this.nextBlock.length-this.i,r=e.subarray(0,t);if(this.nextBlock.set(r,this.i),this.i+e.length>=2*this.blockSize){const r=(e.length-t)%this.blockSize,i=N.concatUint8Array([this.nextBlock,e.subarray(t,e.length-r)]),n=N.concatUint8Array([this.prevBlock,i.subarray(0,i.length-this.blockSize)]),s=await this._runCBC(n);return Wi(s,i),this.prevBlock=s.slice(-this.blockSize),r>0&&this.nextBlock.set(e.subarray(-r)),this.i=r,s}let i;if(this.i+=r.length,this.i===this.nextBlock.length){const t=this.nextBlock;i=await this._runCBC(this.prevBlock),Wi(i,t),this.prevBlock=i.slice(),this.i=0;const n=e.subarray(r.length);this.nextBlock.set(n,this.i),this.i+=n.length}else i=new Uint8Array;return i}async finish(){let e;if(0===this.i)e=new Uint8Array;else{this.nextBlock=this.nextBlock.subarray(0,this.i);const t=this.nextBlock,r=await this._runCBC(this.prevBlock);Wi(r,t),e=r.subarray(0,t.length)}return this.clearSensitiveData(),e}clearSensitiveData(){this.nextBlock.fill(0),this.prevBlock.fill(0),this.keyRef=null,this.key=null}async encrypt(e){const t=(await this._runCBC(N.concatUint8Array([new Uint8Array(this.blockSize),e]),this.iv)).subarray(0,e.length);return Wi(t,e),this.clearSensitiveData(),t}}class _i{constructor(e,t,r,i){this.forEncryption=e;const{blockSize:n}=Pr(t);this.key=Ar.expandKeyLE(r),i.byteOffset%4!=0&&(i=i.slice()),this.prevBlock=Vi(i),this.nextBlock=new Uint8Array(n),this.i=0,this.blockSize=n}_runCFB(e){const t=Vi(e),r=new Uint8Array(e.length),i=Vi(r);for(let e=0;e+4<=i.length;e+=4){const{s0:r,s1:n,s2:s,s3:a}=Ar.encrypt(this.key,this.prevBlock[0],this.prevBlock[1],this.prevBlock[2],this.prevBlock[3]);i[e+0]=t[e+0]^r,i[e+1]=t[e+1]^n,i[e+2]=t[e+2]^s,i[e+3]=t[e+3]^a,this.prevBlock=(this.forEncryption?i:t).slice(e,e+4)}return r}async processChunk(e){const t=this.nextBlock.length-this.i,r=e.subarray(0,t);if(this.nextBlock.set(r,this.i),this.i+e.length>=2*this.blockSize){const r=(e.length-t)%this.blockSize,i=N.concatUint8Array([this.nextBlock,e.subarray(t,e.length-r)]),n=this._runCFB(i);return r>0&&this.nextBlock.set(e.subarray(-r)),this.i=r,n}let i;if(this.i+=r.length,this.i===this.nextBlock.length){i=this._runCFB(this.nextBlock),this.i=0;const t=e.subarray(r.length);this.nextBlock.set(t,this.i),this.i+=t.length}else i=new Uint8Array;return i}async finish(){let e;if(0===this.i)e=new Uint8Array;else{e=this._runCFB(this.nextBlock).subarray(0,this.i)}return this.clearSensitiveData(),e}clearSensitiveData(){this.nextBlock.fill(0),this.prevBlock.fill(0),this.key.fill(0)}}function Wi(e,t){const r=Math.min(e.length,t.length);for(let i=0;i<r;i++)e[i]=e[i]^t[i]}const Vi=e=>new Uint32Array(e.buffer,e.byteOffset,Math.floor(e.byteLength/4));const $i=N.getWebCrypto(),Xi=N.getNodeCrypto(),Qi=16;function Yi(e,t){const r=e.length-Qi;for(let i=0;i<Qi;i++)e[i+r]^=t[i];return e}const Zi=new Uint8Array(Qi);async function Ji(e){const t=await en(e),r=N.double(await t(Zi)),i=N.double(r);return async function(e){return(await t(function(e,t,r){if(e.length&&e.length%Qi==0)return Yi(e,t);const i=new Uint8Array(e.length+(Qi-e.length%Qi));return i.set(e),i[e.length]=128,Yi(i,r)}(e,r,i))).subarray(-16)}}async function en(e){if(N.getNodeCrypto())return async function(t){const r=new Xi.createCipheriv("aes-"+8*e.length+"-cbc",e,Zi).update(t);return new Uint8Array(r)};if(N.getWebCrypto())try{return e=await $i.importKey("raw",e,{name:"AES-CBC",length:8*e.length},!1,["encrypt"]),async function(t){const r=await $i.encrypt({name:"AES-CBC",iv:Zi,length:128},e,t);return new Uint8Array(r).subarray(0,r.byteLength-Qi)}}catch(t){if("NotSupportedError"!==t.name&&(24!==e.length||"OperationError"!==t.name))throw t;N.printDebugError("Browser did not support operation: "+t.message)}return async function(t){return lr(e,Zi,{disablePadding:!0}).encrypt(t)}}const tn=N.getWebCrypto(),rn=N.getNodeCrypto(),nn=N.getNodeBuffer(),sn=16,an=sn,on=new Uint8Array(sn),cn=new Uint8Array(sn);cn[15]=1;const un=new Uint8Array(sn);async function hn(e){const t=await Ji(e);return function(e,r){return t(N.concatUint8Array([e,r]))}}async function yn(e){if(N.getNodeCrypto())return async function(t,r){const i=new rn.createCipheriv("aes-"+8*e.length+"-ctr",e,r),n=nn.concat([i.update(t),i.final()]);return new Uint8Array(n)};if(N.getWebCrypto())try{const t=await tn.importKey("raw",e,{name:"AES-CTR",length:8*e.length},!1,["encrypt"]);return async function(e,r){const i=await tn.encrypt({name:"AES-CTR",counter:r,length:128},t,e);return new Uint8Array(i)}}catch(t){if("NotSupportedError"!==t.name&&(24!==e.length||"OperationError"!==t.name))throw t;N.printDebugError("Browser did not support operation: "+t.message)}return async function(t,r){return yr(e,r).encrypt(t)}}async function ln(e,t){if(e!==M.symmetric.aes128&&e!==M.symmetric.aes192&&e!==M.symmetric.aes256)throw Error("EAX mode supports only AES cipher");const[r,i]=await Promise.all([hn(t),yn(t)]);return{encrypt:async function(e,t,n){const[s,a]=await Promise.all([r(on,t),r(cn,n)]),o=await i(e,s),c=await r(un,o);for(let e=0;e<an;e++)c[e]^=a[e]^s[e];return N.concatUint8Array([o,c])},decrypt:async function(e,t,n){if(e.length<an)throw Error("Invalid EAX ciphertext");const s=e.subarray(0,-16),a=e.subarray(-16),[o,c,u]=await Promise.all([r(on,t),r(cn,n),r(un,s)]),h=u;for(let e=0;e<an;e++)h[e]^=c[e]^o[e];if(!N.timingSafeEqualsUint8Array(a,h))throw Error("Authentication tag mismatch");return await i(s,o)}}}un[15]=2,ln.getNonce=function(e,t){const r=e.slice();for(let e=0;e<t.length;e++)r[8+e]^=t[e];return r},ln.blockLength=sn,ln.ivLength=16,ln.tagLength=an;const pn=16,gn=16;function dn(e){let t=0;for(let r=1;!(e&r);r<<=1)t++;return t}function fn(e,t){for(let r=0;r<e.length;r++)e[r]^=t[r];return e}function mn(e,t){return fn(e.slice(),t)}const wn=new Uint8Array(pn),bn=new Uint8Array([1]);async function kn(e,t){const{keySize:r}=Pr(e);if(!N.isAES(e)||t.length!==r)throw Error("Unexpected algorithm or key size");let i=0;const n=e=>lr(t,wn,{disablePadding:!0}).encrypt(e),s=e=>lr(t,wn,{disablePadding:!0}).decrypt(e);let a;function o(e,t,r,s){const o=t.length/pn|0;!function(e,t){const r=N.nbits(Math.max(e.length,t.length)/pn|0)-1;for(let e=i+1;e<=r;e++)a[e]=N.double(a[e-1]);i=r}(t,s);const c=N.concatUint8Array([wn.subarray(0,15-r.length),bn,r]),u=63&c[15];c[15]&=192;const h=n(c),y=N.concatUint8Array([h,mn(h.subarray(0,8),h.subarray(1,9))]),l=N.shiftRight(y.subarray(0+(u>>3),17+(u>>3)),8-(7&u)).subarray(1),p=new Uint8Array(pn),g=new Uint8Array(t.length+gn);let d,f=0;for(d=0;d<o;d++)fn(l,a[dn(d+1)]),g.set(fn(e(mn(l,t)),l),f),fn(p,e===n?t:g.subarray(f)),t=t.subarray(pn),f+=pn;if(t.length){fn(l,a.x);const r=n(l);g.set(mn(t,r),f);const i=new Uint8Array(pn);i.set(e===n?t:g.subarray(f,-16),0),i[t.length]=128,fn(p,i),f+=t.length}const m=fn(n(fn(fn(p,l),a.$)),function(e){if(!e.length)return wn;const t=e.length/pn|0,r=new Uint8Array(pn),i=new Uint8Array(pn);for(let s=0;s<t;s++)fn(r,a[dn(s+1)]),fn(i,n(mn(r,e))),e=e.subarray(pn);if(e.length){fn(r,a.x);const t=new Uint8Array(pn);t.set(e,0),t[e.length]=128,fn(t,r),fn(i,n(t))}return i}(s));return g.set(m,f),g}return function(){const e=n(wn),t=N.double(e);a=[],a[0]=N.double(t),a.x=e,a.$=t}(),{encrypt:async function(e,t,r){return o(n,e,t,r)},decrypt:async function(e,t,r){if(e.length<gn)throw Error("Invalid OCB ciphertext");const i=e.subarray(-16);e=e.subarray(0,-16);const n=o(s,e,t,r);if(N.timingSafeEqualsUint8Array(i,n.subarray(-16)))return n.subarray(0,-16);throw Error("Authentication tag mismatch")}}}kn.getNonce=function(e,t){const r=e.slice();for(let e=0;e<t.length;e++)r[7+e]^=t[e];return r},kn.blockLength=pn,kn.ivLength=15,kn.tagLength=gn;const vn=N.getWebCrypto(),An=N.getNodeCrypto(),Kn=N.getNodeBuffer(),En=16,Sn="AES-GCM";async function Pn(e,t){if(e!==M.symmetric.aes128&&e!==M.symmetric.aes192&&e!==M.symmetric.aes256)throw Error("GCM mode supports only AES cipher");if(N.getNodeCrypto())return{encrypt:async function(e,r,i=new Uint8Array){const n=new An.createCipheriv("aes-"+8*t.length+"-gcm",t,r);n.setAAD(i);const s=Kn.concat([n.update(e),n.final(),n.getAuthTag()]);return new Uint8Array(s)},decrypt:async function(e,r,i=new Uint8Array){const n=new An.createDecipheriv("aes-"+8*t.length+"-gcm",t,r);n.setAAD(i),n.setAuthTag(e.slice(e.length-En,e.length));const s=Kn.concat([n.update(e.slice(0,e.length-En)),n.final()]);return new Uint8Array(s)}};if(N.getWebCrypto())try{const e=await vn.importKey("raw",t,{name:Sn},!1,["encrypt","decrypt"]),r=navigator.userAgent.match(/Version\/13\.\d(\.\d)* Safari/)||navigator.userAgent.match(/Version\/(13|14)\.\d(\.\d)* Mobile\/\S* Safari/);return{encrypt:async function(i,n,s=new Uint8Array){if(r&&!i.length)return dr(t,n,s).encrypt(i);const a=await vn.encrypt({name:Sn,iv:n,additionalData:s,tagLength:128},e,i);return new Uint8Array(a)},decrypt:async function(i,n,s=new Uint8Array){if(r&&i.length===En)return dr(t,n,s).decrypt(i);try{const t=await vn.decrypt({name:Sn,iv:n,additionalData:s,tagLength:128},e,i);return new Uint8Array(t)}catch(e){if("OperationError"===e.name)throw Error("Authentication tag mismatch")}}}}catch(e){if("NotSupportedError"!==e.name&&(24!==t.length||"OperationError"!==e.name))throw e;N.printDebugError("Browser did not support operation: "+e.message)}return{encrypt:async function(e,r,i){return dr(t,r,i).encrypt(e)},decrypt:async function(e,r,i){return dr(t,r,i).decrypt(e)}}}function Un(e,t=!1){switch(e){case M.aead.eax:return ln;case M.aead.ocb:return kn;case M.aead.gcm:return Pn;case M.aead.experimentalGCM:if(!t)throw Error("Unexpected non-standard `experimentalGCM` AEAD algorithm provided in `config.preferredAEADAlgorithm`: use `gcm` instead");return Pn;default:throw Error("Unsupported AEAD mode")}}async function Dn(e,t,r,i,n,s){switch(e){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaEncrypt:case M.publicKey.rsaSign:{const{n:e,e:a}=i;return qe(t,n,N.leftPad(r.s,e.length),e,a,s)}case M.publicKey.dsa:{const{g:e,p:t,q:n,y:a}=i,{r:o,s:c}=r;return async function(e,t,r,i,n,s,a,o){if(t=re(t),r=re(r),s=re(s),a=re(a),n=re(n),o=re(o),t<=Ki||t>=a||r<=Ki||r>=a)return N.printDebug("invalid DSA Signature"),!1;const c=ie(re(i.subarray(0,ye(a))),a),u=oe(r,a);if(u===Ki)return N.printDebug("invalid DSA Signature"),!1;n=ie(n,s),o=ie(o,s);const h=ie(c*u,a),y=ie(t*u,a);return ie(ie(se(n,h,s)*se(o,y,s),s),a)===t}(0,o,c,s,e,t,n,a)}case M.publicKey.ecdsa:{const{oid:e,Q:a}=i,o=new $r(e).payloadSize;return ai(e,t,{r:N.leftPad(r.r,o),s:N.leftPad(r.s,o)},n,a,s)}case M.publicKey.eddsaLegacy:{const{oid:e,Q:n}=i,a=new $r(e).payloadSize;return hi(e,t,{r:N.leftPad(r.r,a),s:N.leftPad(r.s,a)},0,n,s)}case M.publicKey.ed25519:case M.publicKey.ed448:{const{A:n}=i;return lt(e,t,r,0,n,s)}default:throw Error("Unknown signature algorithm.")}}async function xn(e,t,r,i,n,s){if(!r||!i)throw Error("Missing key parameters");switch(e){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaEncrypt:case M.publicKey.rsaSign:{const{n:e,e:a}=r,{d:o,p:c,q:u,u:h}=i;return{s:await Ge(t,n,e,a,o,c,u,h,s)}}case M.publicKey.dsa:{const{g:e,p:t,q:n}=r,{x:a}=i;return async function(e,t,r,i,n,s){const a=BigInt(0);let o,c,u,h;i=re(i),n=re(n),r=re(r),s=re(s),r=ie(r,i),s=ie(s,n);const y=ie(re(t.subarray(0,ye(n))),n);for(;;){if(o=de(Ei,n),c=ie(se(r,o,i),n),c===a)continue;const e=ie(s*c,n);if(h=ie(y+e,n),u=ie(oe(o,n)*h,n),u!==a)break}return{r:le(c,"be",ye(i)),s:le(u,"be",ye(i))}}(0,s,e,t,n,a)}case M.publicKey.elgamal:throw Error("Signing with Elgamal is not defined in the OpenPGP standard.");case M.publicKey.ecdsa:{const{oid:e,Q:a}=r,{d:o}=i;return si(e,t,n,a,o,s)}case M.publicKey.eddsaLegacy:{const{oid:e,Q:n}=r,{seed:a}=i;return ui(e,t,0,n,a,s)}case M.publicKey.ed25519:case M.publicKey.ed448:{const{A:n}=r,{seed:a}=i;return yt(e,t,0,n,a,s)}default:throw Error("Unknown signature algorithm.")}}Pn.getNonce=function(e,t){const r=e.slice();for(let e=0;e<t.length;e++)r[4+e]^=t[e];return r},Pn.blockLength=16,Pn.ivLength=12,Pn.tagLength=En;class In extends Error{constructor(...e){super(...e),Error.captureStackTrace&&Error.captureStackTrace(this,In),this.name="Argon2OutOfMemoryError"}}let Cn,Bn;class Tn{constructor(e=L){const{passes:t,parallelism:r,memoryExponent:i}=e.s2kArgon2Params;this.type="argon2",this.salt=null,this.t=t,this.p=r,this.encodedM=i}generateSalt(){this.salt=ge(16)}read(e){let t=0;return this.salt=e.subarray(t,t+16),t+=16,this.t=e[t++],this.p=e[t++],this.encodedM=e[t++],t}write(){const e=[new Uint8Array([M.write(M.s2k,this.type)]),this.salt,new Uint8Array([this.t,this.p,this.encodedM])];return N.concatUint8Array(e)}async produceKey(e,t,r){if(r.maxArgon2MemoryExponent>30)throw new In("'config.maxArgon2MemoryExponent' exceeds the max allowed value of 30");if(this.encodedM>r.maxArgon2MemoryExponent)throw new In("Argon2 required memory exceeds `config.maxArgon2MemoryExponent`");const i=1<<this.encodedM;try{Cn=Cn||(await import("./argon2id.min.mjs")).default,Bn=Bn||Cn();const r=await Bn,n=r({version:19,type:2,password:N.encodeUTF8(e),salt:this.salt,tagLength:t,memorySize:i,parallelism:this.p,passes:this.t});return i>1048576&&(Bn=Cn(),Bn.catch((()=>{}))),n}catch(e){throw e.message&&(e.message.includes("Unable to grow instance memory")||e.message.includes("failed to grow memory")||e.message.includes("WebAssembly.Memory.grow")||e.message.includes("Out of memory"))?new In("Could not allocate required memory for Argon2"):e}}}class Mn{constructor(e,t=L){this.algorithm=M.hash.sha256,this.type=M.read(M.s2k,e),this.c=t.s2kIterationCountByte,this.salt=null}generateSalt(){switch(this.type){case"salted":case"iterated":this.salt=ge(8)}}getCount(){return 16+(15&this.c)<<6+(this.c>>4)}read(e){let t=0;switch(this.algorithm=e[t++],this.type){case"simple":break;case"salted":this.salt=e.subarray(t,t+8),t+=8;break;case"iterated":this.salt=e.subarray(t,t+8),t+=8,this.c=e[t++];break;case"gnu":if("GNU"!==N.uint8ArrayToString(e.subarray(t,t+3)))throw new at("Unknown s2k type.");t+=3;if(1001!==1e3+e[t++])throw new at("Unknown s2k gnu protection mode.");this.type="gnu-dummy";break;default:throw new at("Unknown s2k type.")}return t}write(){if("gnu-dummy"===this.type)return new Uint8Array([101,0,...N.stringToUint8Array("GNU"),1]);const e=[new Uint8Array([M.write(M.s2k,this.type),this.algorithm])];switch(this.type){case"simple":break;case"salted":e.push(this.salt);break;case"iterated":e.push(this.salt),e.push(new Uint8Array([this.c]));break;case"gnu":throw Error("GNU s2k type not supported.");default:throw Error("Unknown s2k type.")}return N.concatUint8Array(e)}async produceKey(e,t,r){e=N.encodeUTF8(e);const i=[];let n=0,s=0;for(;n<t;){let t;switch(this.type){case"simple":t=N.concatUint8Array([new Uint8Array(s),e]);break;case"salted":t=N.concatUint8Array([new Uint8Array(s),this.salt,e]);break;case"iterated":{const r=N.concatUint8Array([this.salt,e]);let i=r.length;const n=Math.max(this.getCount(),i);t=new Uint8Array(s+n),t.set(r,s);for(let e=s+i;e<n;e+=i,i*=2)t.copyWithin(e,s,e);break}case"gnu":throw Error("GNU s2k type not supported.");default:throw Error("Unknown s2k type.")}const r=await Me(this.algorithm,t);i.push(r),n+=r.length,s++}return N.concatUint8Array(i).subarray(0,t)}}const Ln=new Set([M.s2k.argon2,M.s2k.iterated]);function Fn(e,t=L){switch(e){case M.s2k.argon2:return new Tn(t);case M.s2k.iterated:case M.s2k.gnu:case M.s2k.salted:case M.s2k.simple:return new Mn(e,t);default:throw new at("Unsupported S2K type")}}function Nn(e){const{s2kType:t}=e;if(!Ln.has(t))throw Error("The provided `config.s2kType` value is not allowed");return Fn(t,e)}var zn=Uint8Array,Rn=Uint16Array,On=Int32Array,jn=new zn([0,0,0,0,0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3,4,4,4,4,5,5,5,5,0,0,0,0]),Hn=new zn([0,0,0,0,1,1,2,2,3,3,4,4,5,5,6,6,7,7,8,8,9,9,10,10,11,11,12,12,13,13,0,0]),Gn=new zn([16,17,18,0,8,7,9,6,10,5,11,4,12,3,13,2,14,1,15]),qn=function(e,t){for(var r=new Rn(31),i=0;i<31;++i)r[i]=t+=1<<e[i-1];var n=new On(r[30]);for(i=1;i<30;++i)for(var s=r[i];s<r[i+1];++s)n[s]=s-r[i]<<5|i;return{b:r,r:n}},_n=qn(jn,2),Wn=_n.b,Vn=_n.r;Wn[28]=258,Vn[258]=28;for(var $n=qn(Hn,0),Xn=$n.b,Qn=$n.r,Yn=new Rn(32768),Zn=0;Zn<32768;++Zn){var Jn=(43690&Zn)>>1|(21845&Zn)<<1;Jn=(61680&(Jn=(52428&Jn)>>2|(13107&Jn)<<2))>>4|(3855&Jn)<<4,Yn[Zn]=((65280&Jn)>>8|(255&Jn)<<8)>>1}var es=function(e,t,r){for(var i=e.length,n=0,s=new Rn(t);n<i;++n)e[n]&&++s[e[n]-1];var a,o=new Rn(t);for(n=1;n<t;++n)o[n]=o[n-1]+s[n-1]<<1;if(r){a=new Rn(1<<t);var c=15-t;for(n=0;n<i;++n)if(e[n])for(var u=n<<4|e[n],h=t-e[n],y=o[e[n]-1]++<<h,l=y|(1<<h)-1;y<=l;++y)a[Yn[y]>>c]=u}else for(a=new Rn(i),n=0;n<i;++n)e[n]&&(a[n]=Yn[o[e[n]-1]++]>>15-e[n]);return a},ts=new zn(288);for(Zn=0;Zn<144;++Zn)ts[Zn]=8;for(Zn=144;Zn<256;++Zn)ts[Zn]=9;for(Zn=256;Zn<280;++Zn)ts[Zn]=7;for(Zn=280;Zn<288;++Zn)ts[Zn]=8;var rs=new zn(32);for(Zn=0;Zn<32;++Zn)rs[Zn]=5;var is=/*#__PURE__*/es(ts,9,0),ns=/*#__PURE__*/es(ts,9,1),ss=/*#__PURE__*/es(rs,5,0),as=/*#__PURE__*/es(rs,5,1),os=function(e){for(var t=e[0],r=1;r<e.length;++r)e[r]>t&&(t=e[r]);return t},cs=function(e,t,r){var i=t/8|0;return(e[i]|e[i+1]<<8)>>(7&t)&r},us=function(e,t){var r=t/8|0;return(e[r]|e[r+1]<<8|e[r+2]<<16)>>(7&t)},hs=function(e){return(e+7)/8|0},ys=function(e,t,r){return(null==t||t<0)&&(t=0),(null==r||r>e.length)&&(r=e.length),new zn(e.subarray(t,r))},ls=["unexpected EOF","invalid block type","invalid length/literal","invalid distance","stream finished","no stream handler",,"no callback","invalid UTF-8 data","extra field too long","date not in range 1980-2099","filename too long","stream finishing","invalid zip data"],ps=function(e,t,r){var i=Error(t||ls[e]);if(i.code=e,Error.captureStackTrace&&Error.captureStackTrace(i,ps),!r)throw i;return i},gs=function(e,t,r){r<<=7&t;var i=t/8|0;e[i]|=r,e[i+1]|=r>>8},ds=function(e,t,r){r<<=7&t;var i=t/8|0;e[i]|=r,e[i+1]|=r>>8,e[i+2]|=r>>16},fs=function(e,t){for(var r=[],i=0;i<e.length;++i)e[i]&&r.push({s:i,f:e[i]});var n=r.length,s=r.slice();if(!n)return{t:Ks,l:0};if(1==n){var a=new zn(r[0].s+1);return a[r[0].s]=1,{t:a,l:1}}r.sort((function(e,t){return e.f-t.f})),r.push({s:-1,f:25001});var o=r[0],c=r[1],u=0,h=1,y=2;for(r[0]={s:-1,f:o.f+c.f,l:o,r:c};h!=n-1;)o=r[r[u].f<r[y].f?u++:y++],c=r[u!=h&&r[u].f<r[y].f?u++:y++],r[h++]={s:-1,f:o.f+c.f,l:o,r:c};var l=s[0].s;for(i=1;i<n;++i)s[i].s>l&&(l=s[i].s);var p=new Rn(l+1),g=ms(r[h-1],p,0);if(g>t){i=0;var d=0,f=g-t,m=1<<f;for(s.sort((function(e,t){return p[t.s]-p[e.s]||e.f-t.f}));i<n;++i){var w=s[i].s;if(!(p[w]>t))break;d+=m-(1<<g-p[w]),p[w]=t}for(d>>=f;d>0;){var b=s[i].s;p[b]<t?d-=1<<t-p[b]++-1:++i}for(;i>=0&&d;--i){var k=s[i].s;p[k]==t&&(--p[k],++d)}g=t}return{t:new zn(p),l:g}},ms=function(e,t,r){return-1==e.s?Math.max(ms(e.l,t,r+1),ms(e.r,t,r+1)):t[e.s]=r},ws=function(e){for(var t=e.length;t&&!e[--t];);for(var r=new Rn(++t),i=0,n=e[0],s=1,a=function(e){r[i++]=e},o=1;o<=t;++o)if(e[o]==n&&o!=t)++s;else{if(!n&&s>2){for(;s>138;s-=138)a(32754);s>2&&(a(s>10?s-11<<5|28690:s-3<<5|12305),s=0)}else if(s>3){for(a(n),--s;s>6;s-=6)a(8304);s>2&&(a(s-3<<5|8208),s=0)}for(;s--;)a(n);s=1,n=e[o]}return{c:r.subarray(0,i),n:t}},bs=function(e,t){for(var r=0,i=0;i<t.length;++i)r+=e[i]*t[i];return r},ks=function(e,t,r){var i=r.length,n=hs(t+2);e[n]=255&i,e[n+1]=i>>8,e[n+2]=255^e[n],e[n+3]=255^e[n+1];for(var s=0;s<i;++s)e[n+s+4]=r[s];return 8*(n+4+i)},vs=function(e,t,r,i,n,s,a,o,c,u,h){gs(t,h++,r),++n[256];for(var y=fs(n,15),l=y.t,p=y.l,g=fs(s,15),d=g.t,f=g.l,m=ws(l),w=m.c,b=m.n,k=ws(d),v=k.c,A=k.n,K=new Rn(19),E=0;E<w.length;++E)++K[31&w[E]];for(E=0;E<v.length;++E)++K[31&v[E]];for(var S=fs(K,7),P=S.t,U=S.l,D=19;D>4&&!P[Gn[D-1]];--D);var x,I,C,B,T=u+5<<3,M=bs(n,ts)+bs(s,rs)+a,L=bs(n,l)+bs(s,d)+a+14+3*D+bs(K,P)+2*K[16]+3*K[17]+7*K[18];if(c>=0&&T<=M&&T<=L)return ks(t,h,e.subarray(c,c+u));if(gs(t,h,1+(L<M)),h+=2,L<M){x=es(l,p,0),I=l,C=es(d,f,0),B=d;var F=es(P,U,0);gs(t,h,b-257),gs(t,h+5,A-1),gs(t,h+10,D-4),h+=14;for(E=0;E<D;++E)gs(t,h+3*E,P[Gn[E]]);h+=3*D;for(var N=[w,v],z=0;z<2;++z){var R=N[z];for(E=0;E<R.length;++E){var O=31&R[E];gs(t,h,F[O]),h+=P[O],O>15&&(gs(t,h,R[E]>>5&127),h+=R[E]>>12)}}}else x=is,I=ts,C=ss,B=rs;for(E=0;E<o;++E){var j=i[E];if(j>255){ds(t,h,x[(O=j>>18&31)+257]),h+=I[O+257],O>7&&(gs(t,h,j>>23&31),h+=jn[O]);var H=31&j;ds(t,h,C[H]),h+=B[H],H>3&&(ds(t,h,j>>5&8191),h+=Hn[H])}else ds(t,h,x[j]),h+=I[j]}return ds(t,h,x[256]),h+I[256]},As=/*#__PURE__*/new On([65540,131080,131088,131104,262176,1048704,1048832,2114560,2117632]),Ks=/*#__PURE__*/new zn(0),Es=function(){var e=1,t=0;return{p:function(r){for(var i=e,n=t,s=0|r.length,a=0;a!=s;){for(var o=Math.min(a+2655,s);a<o;++a)n+=i+=r[a];i=(65535&i)+15*(i>>16),n=(65535&n)+15*(n>>16)}e=i,t=n},d:function(){return(255&(e%=65521))<<24|(65280&e)<<8|(255&(t%=65521))<<8|t>>8}}},Ss=function(e,t,r,i,n){if(!n&&(n={l:1},t.dictionary)){var s=t.dictionary.subarray(-32768),a=new zn(s.length+e.length);a.set(s),a.set(e,s.length),e=a,n.w=s.length}return function(e,t,r,i,n,s){var a=s.z||e.length,o=new zn(i+a+5*(1+Math.ceil(a/7e3))+n),c=o.subarray(i,o.length-n),u=s.l,h=7&(s.r||0);if(t){h&&(c[0]=s.r>>3);for(var y=As[t-1],l=y>>13,p=8191&y,g=(1<<r)-1,d=s.p||new Rn(32768),f=s.h||new Rn(g+1),m=Math.ceil(r/3),w=2*m,b=function(t){return(e[t]^e[t+1]<<m^e[t+2]<<w)&g},k=new On(25e3),v=new Rn(288),A=new Rn(32),K=0,E=0,S=s.i||0,P=0,U=s.w||0,D=0;S+2<a;++S){var x=b(S),I=32767&S,C=f[x];if(d[I]=C,f[x]=I,U<=S){var B=a-S;if((K>7e3||P>24576)&&(B>423||!u)){h=vs(e,c,0,k,v,A,E,P,D,S-D,h),P=K=E=0,D=S;for(var T=0;T<286;++T)v[T]=0;for(T=0;T<30;++T)A[T]=0}var M=2,L=0,F=p,N=I-C&32767;if(B>2&&x==b(S-N))for(var z=Math.min(l,B)-1,R=Math.min(32767,S),O=Math.min(258,B);N<=R&&--F&&I!=C;){if(e[S+M]==e[S+M-N]){for(var j=0;j<O&&e[S+j]==e[S+j-N];++j);if(j>M){if(M=j,L=N,j>z)break;var H=Math.min(N,j-2),G=0;for(T=0;T<H;++T){var q=S-N+T&32767,_=q-d[q]&32767;_>G&&(G=_,C=q)}}}N+=(I=C)-(C=d[I])&32767}if(L){k[P++]=268435456|Vn[M]<<18|Qn[L];var W=31&Vn[M],V=31&Qn[L];E+=jn[W]+Hn[V],++v[257+W],++A[V],U=S+M,++K}else k[P++]=e[S],++v[e[S]]}}for(S=Math.max(S,U);S<a;++S)k[P++]=e[S],++v[e[S]];h=vs(e,c,u,k,v,A,E,P,D,S-D,h),u||(s.r=7&h|c[h/8|0]<<3,h-=7,s.h=f,s.p=d,s.i=S,s.w=U)}else{for(S=s.w||0;S<a+u;S+=65535){var $=S+65535;$>=a&&(c[h/8|0]=u,$=a),h=ks(c,h+1,e.subarray(S,$))}s.i=a}return ys(o,0,i+hs(h)+n)}(e,null==t.level?6:t.level,null==t.mem?n.l?Math.ceil(1.5*Math.max(8,Math.min(13,Math.log(e.length)))):20:12+t.mem,r,i,n)},Ps=function(e,t,r){for(;r;++t)e[t]=r,r>>>=8},Us=/*#__PURE__*/function(){function e(e,t){if("function"==typeof e&&(t=e,e={}),this.ondata=t,this.o=e||{},this.s={l:0,i:32768,w:32768,z:32768},this.b=new zn(98304),this.o.dictionary){var r=this.o.dictionary.subarray(-32768);this.b.set(r,32768-r.length),this.s.i=32768-r.length}}return e.prototype.p=function(e,t){this.ondata(Ss(e,this.o,0,0,this.s),t)},e.prototype.push=function(e,t){this.ondata||ps(5),this.s.l&&ps(4);var r=e.length+this.s.z;if(r>this.b.length){if(r>2*this.b.length-32768){var i=new zn(-32768&r);i.set(this.b.subarray(0,this.s.z)),this.b=i}var n=this.b.length-this.s.z;this.b.set(e.subarray(0,n),this.s.z),this.s.z=this.b.length,this.p(this.b,!1),this.b.set(this.b.subarray(-32768)),this.b.set(e.subarray(n),32768),this.s.z=e.length-n+32768,this.s.i=32766,this.s.w=32768}else this.b.set(e,this.s.z),this.s.z+=e.length;this.s.l=1&t,(this.s.z>this.s.w+8191||t)&&(this.p(this.b,t||!1),this.s.w=this.s.i,this.s.i-=2),t&&(this.s=this.o={},this.b=Ks)},e.prototype.flush=function(e){if(this.ondata||ps(5),this.s.l&&ps(4),this.p(this.b,!1),this.s.w=this.s.i,this.s.i-=2,e){var t=new zn(6);t[0]=this.s.r>>3;var r=ks(t,this.s.r,Ks);this.s.r=0,this.ondata(t.subarray(0,r>>3),!1)}},e}(),Ds=/*#__PURE__*/function(){function e(e,t){"function"==typeof e&&(t=e,e={}),this.ondata=t;var r=e&&e.dictionary&&e.dictionary.subarray(-32768);this.s={i:0,b:r?r.length:0},this.o=new zn(32768),this.p=new zn(0),r&&this.o.set(r)}return e.prototype.e=function(e){if(this.ondata||ps(5),this.d&&ps(4),this.p.length){if(e.length){var t=new zn(this.p.length+e.length);t.set(this.p),t.set(e,this.p.length),this.p=t}}else this.p=e},e.prototype.c=function(e){this.s.i=+(this.d=e||!1);var t=this.s.b,r=function(e,t,r,i){var n=e.length;if(!n||t.f&&!t.l)return r||new zn(0);var s=!r,a=s||2!=t.i,o=t.i;s&&(r=new zn(3*n));var c=function(e){var t=r.length;if(e>t){var i=new zn(Math.max(2*t,e));i.set(r),r=i}},u=t.f||0,h=t.p||0,y=t.b||0,l=t.l,p=t.d,g=t.m,d=t.n,f=8*n;do{if(!l){u=cs(e,h,1);var m=cs(e,h+1,3);if(h+=3,!m){var w=e[(x=hs(h)+4)-4]|e[x-3]<<8,b=x+w;if(b>n){o&&ps(0);break}a&&c(y+w),r.set(e.subarray(x,b),y),t.b=y+=w,t.p=h=8*b,t.f=u;continue}if(1==m)l=ns,p=as,g=9,d=5;else if(2==m){var k=cs(e,h,31)+257,v=cs(e,h+10,15)+4,A=k+cs(e,h+5,31)+1;h+=14;for(var K=new zn(A),E=new zn(19),S=0;S<v;++S)E[Gn[S]]=cs(e,h+3*S,7);h+=3*v;var P=os(E),U=(1<<P)-1,D=es(E,P,1);for(S=0;S<A;){var x,I=D[cs(e,h,U)];if(h+=15&I,(x=I>>4)<16)K[S++]=x;else{var C=0,B=0;for(16==x?(B=3+cs(e,h,3),h+=2,C=K[S-1]):17==x?(B=3+cs(e,h,7),h+=3):18==x&&(B=11+cs(e,h,127),h+=7);B--;)K[S++]=C}}var T=K.subarray(0,k),M=K.subarray(k);g=os(T),d=os(M),l=es(T,g,1),p=es(M,d,1)}else ps(1);if(h>f){o&&ps(0);break}}a&&c(y+131072);for(var L=(1<<g)-1,F=(1<<d)-1,N=h;;N=h){var z=(C=l[us(e,h)&L])>>4;if((h+=15&C)>f){o&&ps(0);break}if(C||ps(2),z<256)r[y++]=z;else{if(256==z){N=h,l=null;break}var R=z-254;if(z>264){var O=jn[S=z-257];R=cs(e,h,(1<<O)-1)+Wn[S],h+=O}var j=p[us(e,h)&F],H=j>>4;if(j||ps(3),h+=15&j,M=Xn[H],H>3&&(O=Hn[H],M+=us(e,h)&(1<<O)-1,h+=O),h>f){o&&ps(0);break}a&&c(y+131072);var G=y+R;if(y<M){var q=0-M,_=Math.min(M,G);for(q+y<0&&ps(3);y<_;++y)r[y]=i[q+y]}for(;y<G;++y)r[y]=r[y-M]}}t.l=l,t.p=N,t.b=y,t.f=u,l&&(u=1,t.m=g,t.d=p,t.n=d)}while(!u);return y!=r.length&&s?ys(r,0,y):r.subarray(0,y)}(this.p,this.s,this.o);this.ondata(ys(r,t,this.s.b),this.d),this.o=ys(r,this.s.b-32768),this.s.b=this.o.length,this.p=ys(this.p,this.s.p/8|0),this.s.p&=7},e.prototype.push=function(e,t){this.e(e),this.c(t)},e}(),xs=/*#__PURE__*/function(){function e(e,t){this.c=Es(),this.v=1,Us.call(this,e,t)}return e.prototype.push=function(e,t){this.c.p(e),Us.prototype.push.call(this,e,t)},e.prototype.p=function(e,t){var r=Ss(e,this.o,this.v&&(this.o.dictionary?6:2),t&&4,this.s);this.v&&(function(e,t){var r=t.level,i=0==r?0:r<6?1:9==r?3:2;if(e[0]=120,e[1]=i<<6|(t.dictionary&&32),e[1]|=31-(e[0]<<8|e[1])%31,t.dictionary){var n=Es();n.p(t.dictionary),Ps(e,2,n.d())}}(r,this.o),this.v=0),t&&Ps(r,r.length-4,this.c.d()),this.ondata(r,t)},e.prototype.flush=function(e){Us.prototype.flush.call(this,e)},e}(),Is=/*#__PURE__*/function(){function e(e,t){Ds.call(this,e,t),this.v=e&&e.dictionary?2:1}return e.prototype.push=function(e,t){if(Ds.prototype.e.call(this,e),this.v){if(this.p.length<6&&!t)return;this.p=this.p.subarray((r=this.p,i=this.v-1,(8!=(15&r[0])||r[0]>>4>7||(r[0]<<8|r[1])%31)&&ps(6,"invalid zlib data"),(r[1]>>5&1)==+!i&&ps(6,"invalid zlib data: "+(32&r[1]?"need":"unexpected")+" dictionary"),2+(r[1]>>3&4))),this.v=0}var r,i;t&&(this.p.length<4&&ps(6,"invalid zlib data"),this.p=this.p.subarray(0,-4)),Ds.prototype.c.call(this,t)},e}(),Cs="undefined"!=typeof TextDecoder&&/*#__PURE__*/new TextDecoder;try{Cs.decode(Ks,{stream:!0})}catch(e){}class Bs{static get tag(){return M.packet.literalData}constructor(e=new Date){this.format=M.literal.utf8,this.date=N.normalizeDate(e),this.text=null,this.data=null,this.filename=""}setText(e,t=M.literal.utf8){this.format=t,this.text=e,this.data=null}getText(e=!1){return(null===this.text||N.isStream(this.text))&&(this.text=N.decodeUTF8(N.nativeEOL(this.getBytes(e)))),this.text}setBytes(e,t){this.format=t,this.data=e,this.text=null}getBytes(e=!1){return null===this.data&&(this.data=N.canonicalizeEOL(N.encodeUTF8(this.text))),e?S(this.data):this.data}setFilename(e){this.filename=e}getFilename(){return this.filename}async read(e){await K(e,(async e=>{const t=await e.readByte(),r=await e.readByte();this.filename=N.decodeUTF8(await e.readBytes(r)),this.date=N.readDate(await e.readBytes(4));let i=e.remainder();a(i)&&(i=await D(i)),this.setBytes(i,t)}))}writeHeader(){const e=N.encodeUTF8(this.filename),t=new Uint8Array([e.length]),r=new Uint8Array([this.format]),i=N.writeDate(this.date);return N.concatUint8Array([r,t,e,i])}write(){const e=this.writeHeader(),t=this.getBytes();return N.concat([e,t])}}class Ts{constructor(){this.bytes=""}read(e){return this.bytes=N.uint8ArrayToString(e.subarray(0,8)),this.bytes.length}write(){return N.stringToUint8Array(this.bytes)}toHex(){return N.uint8ArrayToHex(N.stringToUint8Array(this.bytes))}equals(e,t=!1){return t&&(e.isWildcard()||this.isWildcard())||this.bytes===e.bytes}isNull(){return""===this.bytes}isWildcard(){return/^0+$/.test(this.toHex())}static mapToHex(e){return e.toHex()}static fromID(e){const t=new Ts;return t.read(N.hexToUint8Array(e)),t}static wildcard(){const e=new Ts;return e.read(new Uint8Array(8)),e}}const Ms=Symbol("verified"),Ls="salt@notations.openpgpjs.org",Fs=new Set([M.signatureSubpacket.issuerKeyID,M.signatureSubpacket.issuerFingerprint,M.signatureSubpacket.embeddedSignature]);class Ns{static get tag(){return M.packet.signature}constructor(){this.version=null,this.signatureType=null,this.hashAlgorithm=null,this.publicKeyAlgorithm=null,this.signatureData=null,this.unhashedSubpackets=[],this.unknownSubpackets=[],this.signedHashValue=null,this.salt=null,this.created=null,this.signatureExpirationTime=null,this.signatureNeverExpires=!0,this.exportable=null,this.trustLevel=null,this.trustAmount=null,this.regularExpression=null,this.revocable=null,this.keyExpirationTime=null,this.keyNeverExpires=null,this.preferredSymmetricAlgorithms=null,this.revocationKeyClass=null,this.revocationKeyAlgorithm=null,this.revocationKeyFingerprint=null,this.issuerKeyID=new Ts,this.rawNotations=[],this.notations={},this.preferredHashAlgorithms=null,this.preferredCompressionAlgorithms=null,this.keyServerPreferences=null,this.preferredKeyServer=null,this.isPrimaryUserID=null,this.policyURI=null,this.keyFlags=null,this.signersUserID=null,this.reasonForRevocationFlag=null,this.reasonForRevocationString=null,this.features=null,this.signatureTargetPublicKeyAlgorithm=null,this.signatureTargetHashAlgorithm=null,this.signatureTargetHash=null,this.embeddedSignature=null,this.issuerKeyVersion=null,this.issuerFingerprint=null,this.preferredAEADAlgorithms=null,this.preferredCipherSuites=null,this.revoked=null,this[Ms]=null}read(e,t=L){let r=0;if(this.version=e[r++],5===this.version&&!t.enableParsingV5Entities)throw new at("Support for v5 entities is disabled; turn on `config.enableParsingV5Entities` if needed");if(4!==this.version&&5!==this.version&&6!==this.version)throw new at(`Version ${this.version} of the signature packet is unsupported.`);if(this.signatureType=e[r++],this.publicKeyAlgorithm=e[r++],this.hashAlgorithm=e[r++],r+=this.readSubPackets(e.subarray(r,e.length),!0),!this.created)throw Error("Missing signature creation time subpacket.");if(this.signatureData=e.subarray(0,r),r+=this.readSubPackets(e.subarray(r,e.length),!1),this.signedHashValue=e.subarray(r,r+2),r+=2,6===this.version){const t=e[r++];this.salt=e.subarray(r,r+t),r+=t}const i=e.subarray(r,e.length),{read:n,signatureParams:s}=function(e,t){let r=0;switch(e){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaEncrypt:case M.publicKey.rsaSign:{const e=N.readMPI(t.subarray(r));return r+=e.length+2,{read:r,signatureParams:{s:e}}}case M.publicKey.dsa:case M.publicKey.ecdsa:{const e=N.readMPI(t.subarray(r));r+=e.length+2;const i=N.readMPI(t.subarray(r));return r+=i.length+2,{read:r,signatureParams:{r:e,s:i}}}case M.publicKey.eddsaLegacy:{const e=N.readMPI(t.subarray(r));r+=e.length+2;const i=N.readMPI(t.subarray(r));return r+=i.length+2,{read:r,signatureParams:{r:e,s:i}}}case M.publicKey.ed25519:case M.publicKey.ed448:{const i=2*gt(e),n=N.readExactSubarray(t,r,r+i);return r+=n.length,{read:r,signatureParams:{RS:n}}}default:throw new at("Unknown signature algorithm.")}}(this.publicKeyAlgorithm,i);if(n<i.length)throw Error("Error reading MPIs");this.params=s}writeParams(){return this.params instanceof Promise?I((async()=>Ci(this.publicKeyAlgorithm,await this.params))):Ci(this.publicKeyAlgorithm,this.params)}write(){const e=[];return e.push(this.signatureData),e.push(this.writeUnhashedSubPackets()),e.push(this.signedHashValue),6===this.version&&(e.push(new Uint8Array([this.salt.length])),e.push(this.salt)),e.push(this.writeParams()),N.concat(e)}async sign(e,t,r=new Date,i=!1,n){this.version=e.version,this.created=N.normalizeDate(r),this.issuerKeyVersion=e.version,this.issuerFingerprint=e.getFingerprintBytes(),this.issuerKeyID=e.getKeyID();const s=[new Uint8Array([this.version,this.signatureType,this.publicKeyAlgorithm,this.hashAlgorithm])];if(6===this.version){const e=Rs(this.hashAlgorithm);if(null===this.salt)this.salt=ge(e);else if(e!==this.salt.length)throw Error("Provided salt does not have the required length")}else if(n.nonDeterministicSignaturesViaNotation){if(0!==this.rawNotations.filter((({name:e})=>e===Ls)).length)throw Error("Unexpected existing salt notation");{const e=ge(Rs(this.hashAlgorithm));this.rawNotations.push({name:Ls,value:e,humanReadable:!1,critical:!1})}}s.push(this.writeHashedSubPackets()),this.unhashedSubpackets=[],this.signatureData=N.concat(s);const a=this.toHash(this.signatureType,t,i),o=await this.hash(this.signatureType,t,a,i);this.signedHashValue=U(E(o),0,2);const c=async()=>xn(this.publicKeyAlgorithm,this.hashAlgorithm,e.publicParams,e.privateParams,a,await D(o));N.isStream(o)?this.params=c():(this.params=await c(),this[Ms]=!0)}writeHashedSubPackets(){const e=M.signatureSubpacket,t=[];let r;if(null===this.created)throw Error("Missing signature creation time");t.push(zs(e.signatureCreationTime,!0,N.writeDate(this.created))),null!==this.signatureExpirationTime&&t.push(zs(e.signatureExpirationTime,!0,N.writeNumber(this.signatureExpirationTime,4))),null!==this.exportable&&t.push(zs(e.exportableCertification,!0,new Uint8Array([this.exportable?1:0]))),null!==this.trustLevel&&(r=new Uint8Array([this.trustLevel,this.trustAmount]),t.push(zs(e.trustSignature,!0,r))),null!==this.regularExpression&&t.push(zs(e.regularExpression,!0,this.regularExpression)),null!==this.revocable&&t.push(zs(e.revocable,!0,new Uint8Array([this.revocable?1:0]))),null!==this.keyExpirationTime&&t.push(zs(e.keyExpirationTime,!0,N.writeNumber(this.keyExpirationTime,4))),null!==this.preferredSymmetricAlgorithms&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.preferredSymmetricAlgorithms)),t.push(zs(e.preferredSymmetricAlgorithms,!1,r))),null!==this.revocationKeyClass&&(r=new Uint8Array([this.revocationKeyClass,this.revocationKeyAlgorithm]),r=N.concat([r,this.revocationKeyFingerprint]),t.push(zs(e.revocationKey,!1,r))),!this.issuerKeyID.isNull()&&this.issuerKeyVersion<5&&t.push(zs(e.issuerKeyID,!1,this.issuerKeyID.write())),this.rawNotations.forEach((({name:i,value:n,humanReadable:s,critical:a})=>{r=[new Uint8Array([s?128:0,0,0,0])];const o=N.encodeUTF8(i);r.push(N.writeNumber(o.length,2)),r.push(N.writeNumber(n.length,2)),r.push(o),r.push(n),r=N.concat(r),t.push(zs(e.notationData,a,r))})),null!==this.preferredHashAlgorithms&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.preferredHashAlgorithms)),t.push(zs(e.preferredHashAlgorithms,!1,r))),null!==this.preferredCompressionAlgorithms&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.preferredCompressionAlgorithms)),t.push(zs(e.preferredCompressionAlgorithms,!1,r))),null!==this.keyServerPreferences&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.keyServerPreferences)),t.push(zs(e.keyServerPreferences,!1,r))),null!==this.preferredKeyServer&&t.push(zs(e.preferredKeyServer,!1,N.encodeUTF8(this.preferredKeyServer))),null!==this.isPrimaryUserID&&t.push(zs(e.primaryUserID,!1,new Uint8Array([this.isPrimaryUserID?1:0]))),null!==this.policyURI&&t.push(zs(e.policyURI,!1,N.encodeUTF8(this.policyURI))),null!==this.keyFlags&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.keyFlags)),t.push(zs(e.keyFlags,!0,r))),null!==this.signersUserID&&t.push(zs(e.signersUserID,!1,N.encodeUTF8(this.signersUserID))),null!==this.reasonForRevocationFlag&&(r=N.stringToUint8Array(String.fromCharCode(this.reasonForRevocationFlag)+this.reasonForRevocationString),t.push(zs(e.reasonForRevocation,!0,r))),null!==this.features&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.features)),t.push(zs(e.features,!1,r))),null!==this.signatureTargetPublicKeyAlgorithm&&(r=[new Uint8Array([this.signatureTargetPublicKeyAlgorithm,this.signatureTargetHashAlgorithm])],r.push(N.stringToUint8Array(this.signatureTargetHash)),r=N.concat(r),t.push(zs(e.signatureTarget,!0,r))),null!==this.embeddedSignature&&t.push(zs(e.embeddedSignature,!0,this.embeddedSignature.write())),null!==this.issuerFingerprint&&(r=[new Uint8Array([this.issuerKeyVersion]),this.issuerFingerprint],r=N.concat(r),t.push(zs(e.issuerFingerprint,this.version>=5,r))),null!==this.preferredAEADAlgorithms&&(r=N.stringToUint8Array(N.uint8ArrayToString(this.preferredAEADAlgorithms)),t.push(zs(e.preferredAEADAlgorithms,!1,r))),null!==this.preferredCipherSuites&&(r=new Uint8Array([].concat(...this.preferredCipherSuites)),t.push(zs(e.preferredCipherSuites,!1,r)));const i=N.concat(t),n=N.writeNumber(i.length,6===this.version?4:2);return N.concat([n,i])}writeUnhashedSubPackets(){const e=this.unhashedSubpackets.map((({type:e,critical:t,body:r})=>zs(e,t,r))),t=N.concat(e),r=N.writeNumber(t.length,6===this.version?4:2);return N.concat([r,t])}readSubPacket(e,t=!0){let r=0;const i=!!(128&e[r]),n=127&e[r];if(r++,t||(this.unhashedSubpackets.push({type:n,critical:i,body:e.subarray(r,e.length)}),Fs.has(n)))switch(n){case M.signatureSubpacket.signatureCreationTime:this.created=N.readDate(e.subarray(r,e.length));break;case M.signatureSubpacket.signatureExpirationTime:{const t=N.readNumber(e.subarray(r,e.length));this.signatureNeverExpires=0===t,this.signatureExpirationTime=t;break}case M.signatureSubpacket.exportableCertification:this.exportable=1===e[r++];break;case M.signatureSubpacket.trustSignature:this.trustLevel=e[r++],this.trustAmount=e[r++];break;case M.signatureSubpacket.regularExpression:this.regularExpression=e[r];break;case M.signatureSubpacket.revocable:this.revocable=1===e[r++];break;case M.signatureSubpacket.keyExpirationTime:{const t=N.readNumber(e.subarray(r,e.length));this.keyExpirationTime=t,this.keyNeverExpires=0===t;break}case M.signatureSubpacket.preferredSymmetricAlgorithms:this.preferredSymmetricAlgorithms=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.revocationKey:this.revocationKeyClass=e[r++],this.revocationKeyAlgorithm=e[r++],this.revocationKeyFingerprint=e.subarray(r,r+20);break;case M.signatureSubpacket.issuerKeyID:if(4===this.version)this.issuerKeyID.read(e.subarray(r,e.length));else if(t)throw Error("Unexpected Issuer Key ID subpacket");break;case M.signatureSubpacket.notationData:{const t=!!(128&e[r]);r+=4;const n=N.readNumber(e.subarray(r,r+2));r+=2;const s=N.readNumber(e.subarray(r,r+2));r+=2;const a=N.decodeUTF8(e.subarray(r,r+n)),o=e.subarray(r+n,r+n+s);this.rawNotations.push({name:a,humanReadable:t,value:o,critical:i}),t&&(this.notations[a]=N.decodeUTF8(o));break}case M.signatureSubpacket.preferredHashAlgorithms:this.preferredHashAlgorithms=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.preferredCompressionAlgorithms:this.preferredCompressionAlgorithms=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.keyServerPreferences:this.keyServerPreferences=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.preferredKeyServer:this.preferredKeyServer=N.decodeUTF8(e.subarray(r,e.length));break;case M.signatureSubpacket.primaryUserID:this.isPrimaryUserID=0!==e[r++];break;case M.signatureSubpacket.policyURI:this.policyURI=N.decodeUTF8(e.subarray(r,e.length));break;case M.signatureSubpacket.keyFlags:this.keyFlags=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.signersUserID:this.signersUserID=N.decodeUTF8(e.subarray(r,e.length));break;case M.signatureSubpacket.reasonForRevocation:this.reasonForRevocationFlag=e[r++],this.reasonForRevocationString=N.decodeUTF8(e.subarray(r,e.length));break;case M.signatureSubpacket.features:this.features=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.signatureTarget:{this.signatureTargetPublicKeyAlgorithm=e[r++],this.signatureTargetHashAlgorithm=e[r++];const t=Le(this.signatureTargetHashAlgorithm);this.signatureTargetHash=N.uint8ArrayToString(e.subarray(r,r+t));break}case M.signatureSubpacket.embeddedSignature:this.embeddedSignature=new Ns,this.embeddedSignature.read(e.subarray(r,e.length));break;case M.signatureSubpacket.issuerFingerprint:this.issuerKeyVersion=e[r++],this.issuerFingerprint=e.subarray(r,e.length),this.issuerKeyVersion>=5?this.issuerKeyID.read(this.issuerFingerprint):this.issuerKeyID.read(this.issuerFingerprint.subarray(-8));break;case M.signatureSubpacket.preferredAEADAlgorithms:this.preferredAEADAlgorithms=[...e.subarray(r,e.length)];break;case M.signatureSubpacket.preferredCipherSuites:this.preferredCipherSuites=[];for(let t=r;t<e.length;t+=2)this.preferredCipherSuites.push([e[t],e[t+1]]);break;default:this.unknownSubpackets.push({type:n,critical:i,body:e.subarray(r,e.length)})}}readSubPackets(e,t=!0,r){const i=6===this.version?4:2,n=N.readNumber(e.subarray(0,i));let s=i;for(;s<i+n;){const i=Je(e.subarray(s,e.length));s+=i.offset,this.readSubPacket(e.subarray(s,s+i.len),t,r),s+=i.len}return s}toSign(e,t){const r=M.signature;switch(e){case r.binary:return null!==t.text?N.encodeUTF8(t.getText(!0)):t.getBytes(!0);case r.text:{const e=t.getBytes(!0);return N.canonicalizeEOL(e)}case r.standalone:return new Uint8Array(0);case r.certGeneric:case r.certPersona:case r.certCasual:case r.certPositive:case r.certRevocation:{let e,i;if(t.userID)i=180,e=t.userID;else{if(!t.userAttribute)throw Error("Either a userID or userAttribute packet needs to be supplied for certification.");i=209,e=t.userAttribute}const n=e.write();return N.concat([this.toSign(r.key,t),new Uint8Array([i]),N.writeNumber(n.length,4),n])}case r.subkeyBinding:case r.subkeyRevocation:case r.keyBinding:return N.concat([this.toSign(r.key,t),this.toSign(r.key,{key:t.bind})]);case r.key:if(void 0===t.key)throw Error("Key packet is required for this signature.");return t.key.writeForHash(this.version);case r.keyRevocation:return this.toSign(r.key,t);case r.timestamp:return new Uint8Array(0);case r.thirdParty:throw Error("Not implemented");default:throw Error("Unknown signature type.")}}calculateTrailer(e,t){let r=0;return b(E(this.signatureData),(e=>{r+=e.length}),(()=>{const i=[];return 5!==this.version||this.signatureType!==M.signature.binary&&this.signatureType!==M.signature.text||(t?i.push(new Uint8Array(6)):i.push(e.writeHeader())),i.push(new Uint8Array([this.version,255])),5===this.version&&i.push(new Uint8Array(4)),i.push(N.writeNumber(r,4)),N.concat(i)}))}toHash(e,t,r=!1){const i=this.toSign(e,t);return N.concat([this.salt||new Uint8Array,i,this.signatureData,this.calculateTrailer(t,r)])}async hash(e,t,r,i=!1){if(6===this.version&&this.salt.length!==Rs(this.hashAlgorithm))throw Error("Signature salt does not have the expected length");return r||(r=this.toHash(e,t,i)),Me(this.hashAlgorithm,r)}async verify(e,t,r,i=new Date,n=!1,s=L){if(!this.issuerKeyID.equals(e.getKeyID()))throw Error("Signature was not issued by the given public key");if(this.publicKeyAlgorithm!==e.algorithm)throw Error("Public key algorithm used to sign signature does not match issuer key algorithm.");const a=t===M.signature.binary||t===M.signature.text;if(!(this[Ms]&&!a)){let i,s;if(this.hashed?s=await this.hashed:(i=this.toHash(t,r,n),s=await this.hash(t,r,i)),s=await D(s),this.signedHashValue[0]!==s[0]||this.signedHashValue[1]!==s[1])throw Error("Signed digest did not match");if(this.params=await this.params,this[Ms]=await Dn(this.publicKeyAlgorithm,this.hashAlgorithm,this.params,e.publicParams,i,s),!this[Ms])throw Error("Signature verification failed")}const o=N.normalizeDate(i);if(o&&this.created>o)throw Error("Signature creation time is in the future");if(o&&o>=this.getExpirationTime())throw Error("Signature is expired");if(s.rejectHashAlgorithms.has(this.hashAlgorithm))throw Error("Insecure hash algorithm: "+M.read(M.hash,this.hashAlgorithm).toUpperCase());if(s.rejectMessageHashAlgorithms.has(this.hashAlgorithm)&&[M.signature.binary,M.signature.text].includes(this.signatureType))throw Error("Insecure message hash algorithm: "+M.read(M.hash,this.hashAlgorithm).toUpperCase());if(this.unknownSubpackets.forEach((({type:e,critical:t})=>{if(t)throw Error("Unknown critical signature subpacket type "+e)})),this.rawNotations.forEach((({name:e,critical:t})=>{if(t&&s.knownNotations.indexOf(e)<0)throw Error("Unknown critical notation: "+e)})),null!==this.revocationKeyClass)throw Error("This key is intended to be revoked with an authorized key, which OpenPGP.js does not support.")}isExpired(e=new Date){const t=N.normalizeDate(e);return null!==t&&!(this.created<=t&&t<this.getExpirationTime())}getExpirationTime(){return this.signatureNeverExpires?1/0:new Date(this.created.getTime()+1e3*this.signatureExpirationTime)}}function zs(e,t,r){const i=[];return i.push(et(r.length+1)),i.push(new Uint8Array([(t?128:0)|e])),i.push(r),N.concat(i)}function Rs(e){switch(e){case M.hash.sha256:return 16;case M.hash.sha384:return 24;case M.hash.sha512:return 32;case M.hash.sha224:case M.hash.sha3_256:return 16;case M.hash.sha3_512:return 32;default:throw Error("Unsupported hash function")}}class Os{static get tag(){return M.packet.onePassSignature}static fromSignaturePacket(e,t){const r=new Os;return r.version=6===e.version?6:3,r.signatureType=e.signatureType,r.hashAlgorithm=e.hashAlgorithm,r.publicKeyAlgorithm=e.publicKeyAlgorithm,r.issuerKeyID=e.issuerKeyID,r.salt=e.salt,r.issuerFingerprint=e.issuerFingerprint,r.flags=t?1:0,r}constructor(){this.version=null,this.signatureType=null,this.hashAlgorithm=null,this.publicKeyAlgorithm=null,this.salt=null,this.issuerKeyID=null,this.issuerFingerprint=null,this.flags=null}read(e){let t=0;if(this.version=e[t++],3!==this.version&&6!==this.version)throw new at(`Version ${this.version} of the one-pass signature packet is unsupported.`);if(this.signatureType=e[t++],this.hashAlgorithm=e[t++],this.publicKeyAlgorithm=e[t++],6===this.version){const r=e[t++];this.salt=e.subarray(t,t+r),t+=r,this.issuerFingerprint=e.subarray(t,t+32),t+=32,this.issuerKeyID=new Ts,this.issuerKeyID.read(this.issuerFingerprint)}else this.issuerKeyID=new Ts,this.issuerKeyID.read(e.subarray(t,t+8)),t+=8;return this.flags=e[t++],this}write(){const e=[new Uint8Array([this.version,this.signatureType,this.hashAlgorithm,this.publicKeyAlgorithm])];return 6===this.version?e.push(new Uint8Array([this.salt.length]),this.salt,this.issuerFingerprint):e.push(this.issuerKeyID.write()),e.push(new Uint8Array([this.flags])),N.concatUint8Array(e)}calculateTrailer(...e){return I((async()=>Ns.prototype.calculateTrailer.apply(await this.correspondingSig,e)))}async verify(){const e=await this.correspondingSig;if(!e||e.constructor.tag!==M.packet.signature)throw Error("Corresponding signature packet missing");if(e.signatureType!==this.signatureType||e.hashAlgorithm!==this.hashAlgorithm||e.publicKeyAlgorithm!==this.publicKeyAlgorithm||!e.issuerKeyID.equals(this.issuerKeyID)||3===this.version&&6===e.version||6===this.version&&6!==e.version||6===this.version&&!N.equalsUint8Array(e.issuerFingerprint,this.issuerFingerprint)||6===this.version&&!N.equalsUint8Array(e.salt,this.salt))throw Error("Corresponding signature packet does not match one-pass signature packet");return e.hashed=this.hashed,e.verify.apply(e,arguments)}}function js(e,t){if(!t[e]){let t;try{t=M.read(M.packet,e)}catch{throw new ot("Unknown packet type with tag: "+e)}throw Error("Packet not allowed in this context: "+t)}return new t[e]}Os.prototype.hash=Ns.prototype.hash,Os.prototype.toHash=Ns.prototype.toHash,Os.prototype.toSign=Ns.prototype.toSign;class Hs extends Array{static async fromBinary(e,t,r=L,i=null,n=!1){const s=new Hs;return await s.read(e,t,r,i,n),s}async read(e,t,r=L,i=null,n=!1){let s;r.additionalAllowedPackets.length&&(s=N.constructAllowedPackets(r.additionalAllowedPackets),t={...t,...s}),this.stream=A(e,(async(e,a)=>{const o=C(e),c=B(a);try{let a=N.isStream(e);for(;;){let e,u;if(await c.ready,await st(o,a,(async a=>{try{if(a.tag===M.packet.marker||a.tag===M.packet.trust||a.tag===M.packet.padding)return;const e=js(a.tag,t);try{i?.recordPacket(a.tag,s)}catch(e){if(r.enforceGrammar)throw e;N.printDebugError(e)}e.packets=new Hs,e.fromStream=N.isStream(a.packet),u=e.fromStream;try{await e.read(a.packet,r)}catch(t){if(!(t instanceof at))throw N.wrapError(new ct(`Parsing ${e.constructor.name} failed`),t);throw t}await c.write(e)}catch(t){const i=t instanceof ot&&a.tag<=39,s=t instanceof at&&!(t instanceof ot)&&!r.ignoreUnsupportedPackets,o=t instanceof ct&&!r.ignoreMalformedPackets,u=nt(a.tag);if(i||s||o||u||!(t instanceof ot||t instanceof at||t instanceof ct))n?e=t:await c.abort(t);else{const e=new ut(a.tag,a.packet);await c.write(e)}N.printDebugError(t)}})),u&&(a=null),e)throw await o.readToEnd(),e;const h=await o.peekBytes(2);if(!h||!h.length){try{i?.recordEnd()}catch(e){if(r.enforceGrammar)throw e;N.printDebugError(e)}return await c.ready,void await c.close()}}}catch(e){await c.abort(e)}}));const a=C(this.stream);for(;;){const{done:e,value:t}=await a.read();if(e?this.stream=null:this.push(t),e||nt(t.constructor.tag))break}a.releaseLock()}write(){const e=[];for(let t=0;t<this.length;t++){const r=this[t]instanceof ut?this[t].tag:this[t].constructor.tag,i=this[t].write();if(N.isStream(i)&&nt(this[t].constructor.tag)){let t=[],n=0;const s=512;e.push(rt(r)),e.push(b(i,(e=>{if(t.push(e),n+=e.length,n>=s){const e=Math.min(Math.log(n)/Math.LN2|0,30),r=2**e,i=N.concat([tt(e)].concat(t));return t=[i.subarray(1+r)],n=t[0].length,i.subarray(0,1+r)}}),(()=>N.concat([et(n)].concat(t)))))}else{if(N.isStream(i)){let t=0;e.push(b(E(i),(e=>{t+=e.length}),(()=>it(r,t))))}else e.push(it(r,i.length));e.push(i)}}return N.concat(e)}filterByTag(...e){const t=new Hs,r=e=>t=>e===t;for(let i=0;i<this.length;i++)e.some(r(this[i].constructor.tag))&&t.push(this[i]);return t}findPacket(e){return this.find((t=>t.constructor.tag===e))}indexOfTag(...e){const t=[],r=this,i=e=>t=>e===t;for(let n=0;n<this.length;n++)e.some(i(r[n].constructor.tag))&&t.push(n);return t}}class Gs extends Error{constructor(...e){super(...e),Error.captureStackTrace&&Error.captureStackTrace(this,Gs),this.name="GrammarError"}}var qs;!function(e){e[e.EmptyMessage=0]="EmptyMessage",e[e.PlaintextOrEncryptedData=1]="PlaintextOrEncryptedData",e[e.EncryptedSessionKeys=2]="EncryptedSessionKeys",e[e.StandaloneAdditionalAllowedData=3]="StandaloneAdditionalAllowedData"}(qs||(qs={}));class _s{constructor(){this.state=qs.EmptyMessage,this.leadingOnePassSignatureCounter=0}recordPacket(e,t){switch(this.state){case qs.EmptyMessage:case qs.StandaloneAdditionalAllowedData:switch(e){case M.packet.literalData:case M.packet.compressedData:case M.packet.aeadEncryptedData:case M.packet.symEncryptedIntegrityProtectedData:case M.packet.symmetricallyEncryptedData:return void(this.state=qs.PlaintextOrEncryptedData);case M.packet.signature:if(this.state===qs.StandaloneAdditionalAllowedData&&--this.leadingOnePassSignatureCounter<0)throw new Gs("Trailing signature packet without OPS");return;case M.packet.onePassSignature:if(this.state===qs.StandaloneAdditionalAllowedData)throw new Gs("OPS following StandaloneAdditionalAllowedData");return void this.leadingOnePassSignatureCounter++;case M.packet.publicKeyEncryptedSessionKey:case M.packet.symEncryptedSessionKey:return void(this.state=qs.EncryptedSessionKeys);default:if(!t?.[e])throw new Gs(`Unexpected packet ${e} in state ${this.state}`);return void(this.state=qs.StandaloneAdditionalAllowedData)}case qs.PlaintextOrEncryptedData:if(e===M.packet.signature){if(--this.leadingOnePassSignatureCounter<0)throw new Gs("Trailing signature packet without OPS");return void(this.state=qs.PlaintextOrEncryptedData)}if(!t?.[e])throw new Gs(`Unexpected packet ${e} in state ${this.state}`);return void(this.state=qs.PlaintextOrEncryptedData);case qs.EncryptedSessionKeys:switch(e){case M.packet.publicKeyEncryptedSessionKey:case M.packet.symEncryptedSessionKey:return void(this.state=qs.EncryptedSessionKeys);case M.packet.symEncryptedIntegrityProtectedData:case M.packet.aeadEncryptedData:case M.packet.symmetricallyEncryptedData:return void(this.state=qs.PlaintextOrEncryptedData);case M.packet.signature:if(--this.leadingOnePassSignatureCounter<0)throw new Gs("Trailing signature packet without OPS");return void(this.state=qs.PlaintextOrEncryptedData);default:if(!t?.[e])throw new Gs(`Unexpected packet ${e} in state ${this.state}`);this.state=qs.EncryptedSessionKeys}}}recordEnd(){switch(this.state){case qs.EmptyMessage:case qs.PlaintextOrEncryptedData:case qs.EncryptedSessionKeys:case qs.StandaloneAdditionalAllowedData:if(this.leadingOnePassSignatureCounter>0)throw new Gs("Missing trailing signature packets")}}}const Ws=/*#__PURE__*/N.constructAllowedPackets([Bs,Os,Ns]);class Vs{static get tag(){return M.packet.compressedData}constructor(e=L){this.packets=null,this.algorithm=e.preferredCompressionAlgorithm,this.compressed=null}async read(e,t=L){await K(e,(async e=>{this.algorithm=await e.readByte(),this.compressed=e.remainder(),await this.decompress(t)}))}write(){return null===this.compressed&&this.compress(),N.concat([new Uint8Array([this.algorithm]),this.compressed])}async decompress(e=L){const t=M.read(M.compression,this.algorithm),r=Zs[t];if(!r)throw Error(t+" decompression not supported");let i=await r(this.compressed,e);if(e.maxDecompressedMessageSize!==1/0){let t=0;i=b(i,(r=>{if(t+=r.length,t>e.maxDecompressedMessageSize)throw Error("Maximum decompressed message size exceeded");return r}))}c(this.compressed)&&!a(this.compressed)||(i=await D(i)),this.packets=await Hs.fromBinary(i,Ws,e,new _s)}compress(){const e=M.read(M.compression,this.algorithm),t=Ys[e];if(!t)throw Error(e+" compression not supported");const r=this.packets.write();let i=t(r);c(r)&&!a(r)||(i=I((()=>D(i)))),this.compressed=i}}function $s(e,t){return(r,i)=>{let n;if(n=a(r)?new ReadableStream({async start(e){try{e.enqueue(await D(r)),e.close()}catch(t){e.error(t)}}}):c(r)?r:g(r),n=function(e){const t=C(e);return new ReadableStream({async pull(e){try{const{value:r,done:i}=await t.read();if(i)return void e.close();for(let t=0;t<=r.length;t+=65536)(!t||t<r.length)&&e.enqueue(r.subarray(t,t+65536))}catch(t){e.error(t)}}},{highWaterMark:0})}(n),e)try{const t=e();return n.pipeThrough(t)}catch(e){if("TypeError"!==e.name)throw e}const s=C(n),o=new t;let u=!1,h=!1;return new ReadableStream({start(e){o.ondata=(t,r)=>{e.enqueue(t),u=!0,r&&(e.close(),h=!0)}},async pull(){for(u=!1;!u&&!h;){const{done:e,value:t}=await s.read();if(e)return void o.push(new Uint8Array,!0);t.length&&o.push(t)}}},{highWaterMark:0})}}function Xs(){return async function(e,t){const{default:r}=await import("./unbzip2-stream.min.mjs").then((function(e){return e.i}));return r(g(e),t.maxDecompressedMessageSize)}}const Qs=e=>({compressor:"undefined"!=typeof CompressionStream&&(()=>new CompressionStream(e)),decompressor:"undefined"!=typeof DecompressionStream&&(()=>new DecompressionStream(e))}),Ys={zip:/*#__PURE__*/$s(Qs("deflate-raw").compressor,Us),zlib:/*#__PURE__*/$s(Qs("deflate").compressor,xs)},Zs={uncompressed:(e,t)=>e,zip:/*#__PURE__*/$s(Qs("deflate-raw").decompressor,Ds),zlib:/*#__PURE__*/$s(Qs("deflate").decompressor,Is),bzip2:/*#__PURE__*/Xs()};function Js(e,t,r){if("function"==typeof e.setBigUint64)return e.setBigUint64(t,BigInt(r));if(r<=4294967295)e.setUint32(t,0),e.setUint32(t+4,r);else{const i=BigInt(r);e.setUint32(t,Number(i>>BigInt(32))),e.setUint32(t+4,Number(i&BigInt(4294967295)))}}const ea=/*#__PURE__*/N.constructAllowedPackets([Bs,Vs,Os,Ns]);class ta{static get tag(){return M.packet.symEncryptedIntegrityProtectedData}static fromObject({version:e,aeadAlgorithm:t}){if(1!==e&&2!==e)throw Error("Unsupported SEIPD version");const r=new ta;return r.version=e,2===e&&(r.aeadAlgorithm=t),r}constructor(){this.version=null,this.cipherAlgorithm=null,this.aeadAlgorithm=null,this.chunkSizeByte=null,this.salt=null,this.encrypted=null,this.packets=null}async read(e){await K(e,(async e=>{if(this.version=await e.readByte(),1!==this.version&&2!==this.version)throw new at(`Version ${this.version} of the SEIP packet is unsupported.`);2===this.version&&(this.cipherAlgorithm=await e.readByte(),this.aeadAlgorithm=await e.readByte(),this.chunkSizeByte=await e.readByte(),this.salt=await e.readBytes(32)),this.encrypted=e.remainder()}))}write(){return 2===this.version?N.concat([new Uint8Array([this.version,this.cipherAlgorithm,this.aeadAlgorithm,this.chunkSizeByte]),this.salt,this.encrypted]):N.concat([new Uint8Array([this.version]),this.encrypted])}async encrypt(e,t,r=L){const{blockSize:i,keySize:n}=Pr(e);if(t.length!==n)throw Error("Unexpected session key size");let s=this.packets.write();if(a(s)&&(s=await D(s)),2===this.version)this.cipherAlgorithm=e,this.salt=ge(32),this.chunkSizeByte=r.aeadChunkSizeByte,this.encrypted=await ra(this,"encrypt",t,s);else{const r=await ji(e),n=new Uint8Array([211,20]),a=N.concat([r,s,n]),o=await Me(M.hash.sha1,S(a)),c=N.concat([a,o]);this.encrypted=await Hi(e,t,c,new Uint8Array(i))}return!0}async decrypt(e,t,r=L){if(t.length!==Pr(e).keySize)throw Error("Unexpected session key size");let i,n=E(this.encrypted);a(n)&&(n=await D(n));let s=!1;if(2===this.version){if(this.cipherAlgorithm!==e)throw Error("Unexpected session key algorithm");i=await ra(this,"decrypt",t,n)}else{const{blockSize:a}=Pr(e),o=await Gi(e,t,n,new Uint8Array(a)),c=U(S(o),-20),u=U(o,0,-20),h=Promise.all([D(await Me(M.hash.sha1,S(u))),D(c)]).then((([e,t])=>{if(!N.equalsUint8Array(e,t))throw Error("Modification detected.");return new Uint8Array})),y=U(u,a+2);i=U(y,0,-2),i=f([i,I((()=>h))]),N.isStream(n)&&r.allowUnauthenticatedStream?s=!0:i=await D(i)}return this.packets=await Hs.fromBinary(i,ea,r,new _s,s),!0}}async function ra(e,t,r,i){const n=e instanceof ta&&2===e.version,s=!n&&e.constructor.tag===M.packet.aeadEncryptedData;if(!n&&!s)throw Error("Unexpected packet type");const a=Un(e.aeadAlgorithm,s),o="decrypt"===t?a.tagLength:0,c="encrypt"===t?a.tagLength:0,u=2**(e.chunkSizeByte+6)+o,h=s?8:0,y=new ArrayBuffer(13+h),l=new Uint8Array(y,0,5+h),p=new Uint8Array(y),g=new DataView(y),d=new Uint8Array(y,5,8);l.set([192|e.constructor.tag,e.version,e.cipherAlgorithm,e.aeadAlgorithm,e.chunkSizeByte],0);let f,w,b=0,k=Promise.resolve(),v=0,K=0;if(n){const{keySize:t}=Pr(e.cipherAlgorithm),{ivLength:i}=a,n=new Uint8Array(y,0,5),s=await Ir(M.hash.sha256,r,e.salt,n,t+i);r=s.subarray(0,t),f=s.subarray(t),f.fill(0,f.length-8),w=new DataView(f.buffer,f.byteOffset,f.byteLength)}else f=e.iv;const E=await a(e.cipherAlgorithm,r);return A(i,(async(r,i)=>{if("array"!==N.isStream(r)){const t=new TransformStream({},{highWaterMark:N.getHardwareConcurrency()*2**(e.chunkSizeByte+6),size:e=>e.length});m(t.readable,i),i=t.writable}const s=C(r),a=B(i);try{for(;;){let e=await s.readBytes(u+o)||new Uint8Array;const r=e.subarray(e.length-o);let i,y,m;if(e=e.subarray(0,e.length-o),n)m=f;else{m=f.slice();for(let e=0;e<8;e++)m[f.length-8+e]^=d[e]}if(!b||e.length?(s.unshift(r),i=E[t](e,m,l),i.catch((()=>{})),K+=e.length-o+c):(Js(g,5+h,v),i=E[t](r,m,p),i.catch((()=>{})),K+=c,y=!0),v+=e.length-o,k=k.then((()=>i)).then((async e=>{await a.ready,await a.write(e),K-=e.length})).catch((e=>a.abort(e))),(y||K>a.desiredSize)&&await k,y){await a.close();break}n?Js(w,f.length-8,++b):Js(g,5,++b)}}catch(e){await a.ready.catch((()=>{})),await a.abort(e)}}))}const ia=/*#__PURE__*/N.constructAllowedPackets([Bs,Vs,Os,Ns]);class na{static get tag(){return M.packet.aeadEncryptedData}constructor(){this.version=1,this.cipherAlgorithm=null,this.aeadAlgorithm=M.aead.eax,this.chunkSizeByte=null,this.iv=null,this.encrypted=null,this.packets=null}async read(e){await K(e,(async e=>{const t=await e.readByte();if(1!==t)throw new at(`Version ${t} of the AEAD-encrypted data packet is not supported.`);this.cipherAlgorithm=await e.readByte(),this.aeadAlgorithm=await e.readByte(),this.chunkSizeByte=await e.readByte();const r=Un(this.aeadAlgorithm,!0);this.iv=await e.readBytes(r.ivLength),this.encrypted=e.remainder()}))}write(){return N.concat([new Uint8Array([this.version,this.cipherAlgorithm,this.aeadAlgorithm,this.chunkSizeByte]),this.iv,this.encrypted])}async decrypt(e,t,r=L){this.packets=await Hs.fromBinary(await ra(this,"decrypt",t,E(this.encrypted)),ia,r,new _s)}async encrypt(e,t,r=L){this.cipherAlgorithm=e;const{ivLength:i}=Un(this.aeadAlgorithm,!0);this.iv=ge(i),this.chunkSizeByte=r.aeadChunkSizeByte;const n=this.packets.write();this.encrypted=await ra(this,"encrypt",t,n)}}class sa{static get tag(){return M.packet.publicKeyEncryptedSessionKey}constructor(){this.version=null,this.publicKeyID=new Ts,this.publicKeyVersion=null,this.publicKeyFingerprint=null,this.publicKeyAlgorithm=null,this.sessionKey=null,this.sessionKeyAlgorithm=null,this.encrypted={}}static fromObject({version:e,encryptionKeyPacket:t,anonymousRecipient:r,sessionKey:i,sessionKeyAlgorithm:n}){const s=new sa;if(3!==e&&6!==e)throw Error("Unsupported PKESK version");return s.version=e,6===e&&(s.publicKeyVersion=r?null:t.version,s.publicKeyFingerprint=r?null:t.getFingerprintBytes()),s.publicKeyID=r?Ts.wildcard():t.getKeyID(),s.publicKeyAlgorithm=t.algorithm,s.sessionKey=i,s.sessionKeyAlgorithm=n,s}read(e){let t=0;if(this.version=e[t++],3!==this.version&&6!==this.version)throw new at(`Version ${this.version} of the PKESK packet is unsupported.`);if(6===this.version){const r=e[t++];if(r){this.publicKeyVersion=e[t++];const i=r-1;this.publicKeyFingerprint=e.subarray(t,t+i),t+=i,this.publicKeyVersion>=5?this.publicKeyID.read(this.publicKeyFingerprint):this.publicKeyID.read(this.publicKeyFingerprint.subarray(-8))}else this.publicKeyID=Ts.wildcard()}else t+=this.publicKeyID.read(e.subarray(t,t+8));if(this.publicKeyAlgorithm=e[t++],this.encrypted=function(e,t){let r=0;switch(e){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:return{c:N.readMPI(t.subarray(r))};case M.publicKey.elgamal:{const e=N.readMPI(t.subarray(r));return r+=e.length+2,{c1:e,c2:N.readMPI(t.subarray(r))}}case M.publicKey.ecdh:{const e=N.readMPI(t.subarray(r));r+=e.length+2;const i=new Si;return i.read(t.subarray(r)),{V:e,C:i}}case M.publicKey.x25519:case M.publicKey.x448:{const i=Fi(e),n=N.readExactSubarray(t,r,r+i);r+=n.length;const s=new Ui;return s.read(t.subarray(r)),{ephemeralPublicKey:n,C:s}}default:throw new at("Unknown public key encryption algorithm.")}}(this.publicKeyAlgorithm,e.subarray(t)),this.publicKeyAlgorithm===M.publicKey.x25519||this.publicKeyAlgorithm===M.publicKey.x448)if(3===this.version)this.sessionKeyAlgorithm=M.write(M.symmetric,this.encrypted.C.algorithm);else if(null!==this.encrypted.C.algorithm)throw Error("Unexpected cleartext symmetric algorithm")}write(){const e=[new Uint8Array([this.version])];return 6===this.version?null!==this.publicKeyFingerprint?(e.push(new Uint8Array([this.publicKeyFingerprint.length+1,this.publicKeyVersion])),e.push(this.publicKeyFingerprint)):e.push(new Uint8Array([0])):e.push(this.publicKeyID.write()),e.push(new Uint8Array([this.publicKeyAlgorithm]),Ci(this.publicKeyAlgorithm,this.encrypted)),N.concatUint8Array(e)}async encrypt(e){const t=M.write(M.publicKey,this.publicKeyAlgorithm),r=3===this.version?this.sessionKeyAlgorithm:null,i=5===e.version?e.getFingerprintBytes().subarray(0,20):e.getFingerprintBytes(),n=aa(this.version,t,r,this.sessionKey);this.encrypted=await Di(t,r,e.publicParams,n,i)}async decrypt(e,t){if(this.publicKeyAlgorithm!==e.algorithm)throw Error("Decryption error");const r=t?aa(this.version,this.publicKeyAlgorithm,t.sessionKeyAlgorithm,t.sessionKey):null,i=5===e.version?e.getFingerprintBytes().subarray(0,20):e.getFingerprintBytes(),n=await xi(this.publicKeyAlgorithm,e.publicParams,e.privateParams,this.encrypted,i,r),{sessionKey:s,sessionKeyAlgorithm:a}=function(e,t,r,i){switch(t){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.elgamal:case M.publicKey.ecdh:{const t=r.subarray(0,r.length-2),n=r.subarray(r.length-2),s=N.writeChecksum(t.subarray(t.length%8)),a=s[0]===n[0]&s[1]===n[1],o=6===e?{sessionKeyAlgorithm:null,sessionKey:t}:{sessionKeyAlgorithm:t[0],sessionKey:t.subarray(1)};if(i){const t=a&o.sessionKeyAlgorithm===i.sessionKeyAlgorithm&o.sessionKey.length===i.sessionKey.length;return{sessionKey:N.selectUint8Array(t,o.sessionKey,i.sessionKey),sessionKeyAlgorithm:6===e?null:N.selectUint8(t,o.sessionKeyAlgorithm,i.sessionKeyAlgorithm)}}if(a&&(6===e||M.read(M.symmetric,o.sessionKeyAlgorithm)))return o;throw Error("Decryption error")}case M.publicKey.x25519:case M.publicKey.x448:return{sessionKeyAlgorithm:null,sessionKey:r};default:throw Error("Unsupported public key algorithm")}}(this.version,this.publicKeyAlgorithm,n,t);if(3===this.version){const e=this.publicKeyAlgorithm!==M.publicKey.x25519&&this.publicKeyAlgorithm!==M.publicKey.x448;if(this.sessionKeyAlgorithm=e?a:this.sessionKeyAlgorithm,s.length!==Pr(this.sessionKeyAlgorithm).keySize)throw Error("Unexpected session key size")}this.sessionKey=s}}function aa(e,t,r,i){switch(t){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.elgamal:case M.publicKey.ecdh:return N.concatUint8Array([new Uint8Array(6===e?[]:[r]),i,N.writeChecksum(i.subarray(i.length%8))]);case M.publicKey.x25519:case M.publicKey.x448:return i;default:throw Error("Unsupported public key algorithm")}}class oa{static get tag(){return M.packet.symEncryptedSessionKey}constructor(e=L){this.version=e.aeadProtect?6:4,this.sessionKey=null,this.sessionKeyEncryptionAlgorithm=null,this.sessionKeyAlgorithm=null,this.aeadAlgorithm=M.write(M.aead,e.preferredAEADAlgorithm),this.encrypted=null,this.s2k=null,this.iv=null}read(e){let t=0;if(this.version=e[t++],4!==this.version&&5!==this.version&&6!==this.version)throw new at(`Version ${this.version} of the SKESK packet is unsupported.`);6===this.version&&t++;const r=e[t++];this.version>=5&&(this.aeadAlgorithm=e[t++],6===this.version&&t++);const i=e[t++];if(this.s2k=Fn(i),t+=this.s2k.read(e.subarray(t,e.length)),this.version>=5){const r=Un(this.aeadAlgorithm,!0);this.iv=e.subarray(t,t+=r.ivLength)}this.version>=5||t<e.length?(this.encrypted=e.subarray(t,e.length),this.sessionKeyEncryptionAlgorithm=r):this.sessionKeyAlgorithm=r}write(){const e=null===this.encrypted?this.sessionKeyAlgorithm:this.sessionKeyEncryptionAlgorithm;let t;const r=this.s2k.write();if(6===this.version){const i=r.length,n=3+i+this.iv.length;t=N.concatUint8Array([new Uint8Array([this.version,n,e,this.aeadAlgorithm,i]),r,this.iv,this.encrypted])}else 5===this.version?t=N.concatUint8Array([new Uint8Array([this.version,e,this.aeadAlgorithm]),r,this.iv,this.encrypted]):(t=N.concatUint8Array([new Uint8Array([this.version,e]),r]),null!==this.encrypted&&(t=N.concatUint8Array([t,this.encrypted])));return t}async decrypt(e,t=L){const r=null!==this.sessionKeyEncryptionAlgorithm?this.sessionKeyEncryptionAlgorithm:this.sessionKeyAlgorithm,{blockSize:i,keySize:n}=Pr(r),s=await this.s2k.produceKey(e,n,t);if(this.version>=5){const e=Un(this.aeadAlgorithm,!0),t=new Uint8Array([192|oa.tag,this.version,this.sessionKeyEncryptionAlgorithm,this.aeadAlgorithm]),i=6===this.version?await Ir(M.hash.sha256,s,new Uint8Array,t,n):s,a=await e(r,i);this.sessionKey=await a.decrypt(this.encrypted,this.iv,t)}else if(null!==this.encrypted){const e=await Gi(r,s,this.encrypted,new Uint8Array(i));if(this.sessionKeyAlgorithm=M.write(M.symmetric,e[0]),this.sessionKey=e.subarray(1,e.length),this.sessionKey.length!==Pr(this.sessionKeyAlgorithm).keySize)throw Error("Unexpected session key size")}else this.sessionKey=s}async encrypt(e,t=L){const r=null!==this.sessionKeyEncryptionAlgorithm?this.sessionKeyEncryptionAlgorithm:this.sessionKeyAlgorithm;this.sessionKeyEncryptionAlgorithm=r,this.s2k=Nn(t),this.s2k.generateSalt();const{blockSize:i,keySize:n}=Pr(r),s=await this.s2k.produceKey(e,n,t);if(null===this.sessionKey&&(this.sessionKey=Mi(this.sessionKeyAlgorithm)),this.version>=5){const e=Un(this.aeadAlgorithm);this.iv=ge(e.ivLength);const t=new Uint8Array([192|oa.tag,this.version,this.sessionKeyEncryptionAlgorithm,this.aeadAlgorithm]),i=6===this.version?await Ir(M.hash.sha256,s,new Uint8Array,t,n):s,a=await e(r,i);this.encrypted=await a.encrypt(this.sessionKey,this.iv,t)}else{const e=N.concatUint8Array([new Uint8Array([this.sessionKeyAlgorithm]),this.sessionKey]);this.encrypted=await Hi(r,s,e,new Uint8Array(i))}}}class ca{static get tag(){return M.packet.publicKey}constructor(e=new Date,t=L){this.version=t.v6Keys?6:4,this.created=N.normalizeDate(e),this.algorithm=null,this.publicParams=null,this.expirationTimeV3=0,this.fingerprint=null,this.keyID=null}static fromSecretKeyPacket(e){const t=new ca,{version:r,created:i,algorithm:n,publicParams:s,keyID:a,fingerprint:o}=e;return t.version=r,t.created=i,t.algorithm=n,t.publicParams=s,t.keyID=a,t.fingerprint=o,t}async read(e,t=L){let r=0;if(this.version=e[r++],5===this.version&&!t.enableParsingV5Entities)throw new at("Support for parsing v5 entities is disabled; turn on `config.enableParsingV5Entities` if needed");if(4===this.version||5===this.version||6===this.version){this.created=N.readDate(e.subarray(r,r+4)),r+=4,this.algorithm=e[r++],this.version>=5&&(r+=4);const{read:t,publicParams:i}=function(e,t){let r=0;switch(e){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:{const e=N.readMPI(t.subarray(r));r+=e.length+2;const i=N.readMPI(t.subarray(r));return r+=i.length+2,{read:r,publicParams:{n:e,e:i}}}case M.publicKey.dsa:{const e=N.readMPI(t.subarray(r));r+=e.length+2;const i=N.readMPI(t.subarray(r));r+=i.length+2;const n=N.readMPI(t.subarray(r));r+=n.length+2;const s=N.readMPI(t.subarray(r));return r+=s.length+2,{read:r,publicParams:{p:e,q:i,g:n,y:s}}}case M.publicKey.elgamal:{const e=N.readMPI(t.subarray(r));r+=e.length+2;const i=N.readMPI(t.subarray(r));r+=i.length+2;const n=N.readMPI(t.subarray(r));return r+=n.length+2,{read:r,publicParams:{p:e,g:i,y:n}}}case M.publicKey.ecdsa:{const e=new Ze;r+=e.read(t),Li(e);const i=N.readMPI(t.subarray(r));return r+=i.length+2,{read:r,publicParams:{oid:e,Q:i}}}case M.publicKey.eddsaLegacy:{const e=new Ze;if(r+=e.read(t),Li(e),e.getName()!==M.curve.ed25519Legacy)throw Error("Unexpected OID for eddsaLegacy");let i=N.readMPI(t.subarray(r));return r+=i.length+2,i=N.leftPad(i,33),{read:r,publicParams:{oid:e,Q:i}}}case M.publicKey.ecdh:{const e=new Ze;r+=e.read(t),Li(e);const i=N.readMPI(t.subarray(r));r+=i.length+2;const n=new Pi;return r+=n.read(t.subarray(r)),{read:r,publicParams:{oid:e,Q:i,kdfParams:n}}}case M.publicKey.ed25519:case M.publicKey.ed448:case M.publicKey.x25519:case M.publicKey.x448:{const i=N.readExactSubarray(t,r,r+Fi(e));return r+=i.length,{read:r,publicParams:{A:i}}}default:throw new at("Unknown public key encryption algorithm.")}}(this.algorithm,e.subarray(r));if(6===this.version&&i.oid&&(i.oid.getName()===M.curve.curve25519Legacy||i.oid.getName()===M.curve.ed25519Legacy))throw Error("Legacy curve25519 cannot be used with v6 keys");return this.publicParams=i,r+=t,await this.computeFingerprintAndKeyID(),r}throw new at(`Version ${this.version} of the key packet is unsupported.`)}write(){const e=[];e.push(new Uint8Array([this.version])),e.push(N.writeDate(this.created)),e.push(new Uint8Array([this.algorithm]));const t=Ci(this.algorithm,this.publicParams);return this.version>=5&&e.push(N.writeNumber(t.length,4)),e.push(t),N.concatUint8Array(e)}writeForHash(e){const t=this.writePublicKey(),r=149+e,i=e>=5?4:2;return N.concatUint8Array([new Uint8Array([r]),N.writeNumber(t.length,i),t])}isDecrypted(){return null}getCreationTime(){return this.created}getKeyID(){return this.keyID}async computeFingerprintAndKeyID(){if(await this.computeFingerprint(),this.keyID=new Ts,this.version>=5)this.keyID.read(this.fingerprint.subarray(0,8));else{if(4!==this.version)throw Error("Unsupported key version");this.keyID.read(this.fingerprint.subarray(12,20))}}async computeFingerprint(){const e=this.writeForHash(this.version);if(this.version>=5)this.fingerprint=await Me(M.hash.sha256,e);else{if(4!==this.version)throw Error("Unsupported key version");this.fingerprint=await Me(M.hash.sha1,e)}}getFingerprintBytes(){return this.fingerprint}getFingerprint(){return N.uint8ArrayToHex(this.getFingerprintBytes())}hasSameFingerprintAs(e){return this.version===e.version&&N.equalsUint8Array(this.writePublicKey(),e.writePublicKey())}getAlgorithmInfo(){const e={};e.algorithm=M.read(M.publicKey,this.algorithm);const t=this.publicParams.n||this.publicParams.p;return t?e.bits=N.uint8ArrayBitLength(t):this.publicParams.oid&&(e.curve=this.publicParams.oid.getName()),e}}ca.prototype.readPublicKey=ca.prototype.read,ca.prototype.writePublicKey=ca.prototype.write;const ua=/*#__PURE__*/N.constructAllowedPackets([Bs,Vs,Os,Ns]);class ha{static get tag(){return M.packet.symmetricallyEncryptedData}constructor(){this.encrypted=null,this.packets=null}read(e){this.encrypted=e}write(){return this.encrypted}async decrypt(e,t,r=L){if(!r.allowUnauthenticatedMessages)throw Error("Message is not authenticated.");const{blockSize:i}=Pr(e),n=await D(E(this.encrypted)),s=await Gi(e,t,n.subarray(i+2),n.subarray(2,i+2));this.packets=await Hs.fromBinary(s,ua,r)}async encrypt(e,t,r=L){const i=this.packets.write(),{blockSize:n}=Pr(e),s=await ji(e),a=await Hi(e,t,s,new Uint8Array(n)),o=await Hi(e,t,i,a.subarray(2));this.encrypted=N.concat([a,o])}}class ya{static get tag(){return M.packet.marker}read(e){return 80===e[0]&&71===e[1]&&80===e[2]}write(){return new Uint8Array([80,71,80])}}class la extends ca{static get tag(){return M.packet.publicSubkey}constructor(e,t){super(e,t)}static fromSecretSubkeyPacket(e){const t=new la,{version:r,created:i,algorithm:n,publicParams:s,keyID:a,fingerprint:o}=e;return t.version=r,t.created=i,t.algorithm=n,t.publicParams=s,t.keyID=a,t.fingerprint=o,t}}class pa{static get tag(){return M.packet.userAttribute}constructor(){this.attributes=[]}read(e){let t=0;for(;t<e.length;){const r=Je(e.subarray(t,e.length));t+=r.offset,this.attributes.push(N.uint8ArrayToString(e.subarray(t,t+r.len))),t+=r.len}}write(){const e=[];for(let t=0;t<this.attributes.length;t++)e.push(et(this.attributes[t].length)),e.push(N.stringToUint8Array(this.attributes[t]));return N.concatUint8Array(e)}equals(e){return!!(e&&e instanceof pa)&&this.attributes.every((function(t,r){return t===e.attributes[r]}))}}class ga extends ca{static get tag(){return M.packet.secretKey}constructor(e=new Date,t=L){super(e,t),this.keyMaterial=null,this.isEncrypted=null,this.s2kUsage=0,this.s2k=null,this.symmetric=null,this.aead=null,this.isLegacyAEAD=null,this.privateParams=null,this.usedModernAEAD=null}async read(e,t=L){let r=await this.readPublicKey(e,t);const i=r;this.s2kUsage=e[r++],5===this.version&&r++,6===this.version&&this.s2kUsage&&r++;try{if(255===this.s2kUsage||254===this.s2kUsage||253===this.s2kUsage){this.symmetric=e[r++],253===this.s2kUsage&&(this.aead=e[r++]),6===this.version&&r++;const t=e[r++];if(this.s2k=Fn(t),r+=this.s2k.read(e.subarray(r,e.length)),"gnu-dummy"===this.s2k.type)return}else this.s2kUsage&&(this.symmetric=this.s2kUsage);this.s2kUsage&&(this.isLegacyAEAD=253===this.s2kUsage&&(5===this.version||4===this.version&&t.parseAEADEncryptedV4KeysAsLegacy),253!==this.s2kUsage||this.isLegacyAEAD?(this.iv=e.subarray(r,r+Pr(this.symmetric).blockSize),this.usedModernAEAD=!1):(this.iv=e.subarray(r,r+Un(this.aead).ivLength),this.usedModernAEAD=!0),r+=this.iv.length)}catch(t){if(!this.s2kUsage)throw t;this.unparseableKeyMaterial=e.subarray(i),this.isEncrypted=!0}if(5===this.version&&(r+=4),this.keyMaterial=e.subarray(r),this.isEncrypted=!!this.s2kUsage,!this.isEncrypted){let e;if(6===this.version)e=this.keyMaterial;else if(e=this.keyMaterial.subarray(0,-2),!N.equalsUint8Array(N.writeChecksum(e),this.keyMaterial.subarray(-2)))throw Error("Key checksum mismatch");try{const{read:t,privateParams:r}=Ii(this.algorithm,e,this.publicParams);if(t<e.length)throw Error("Error reading MPIs");this.privateParams=r}catch(e){if(e instanceof at)throw e;throw Error("Error reading MPIs")}}}write(){const e=this.writePublicKey();if(this.unparseableKeyMaterial)return N.concatUint8Array([e,this.unparseableKeyMaterial]);const t=[e];t.push(new Uint8Array([this.s2kUsage]));const r=[];if(255===this.s2kUsage||254===this.s2kUsage||253===this.s2kUsage){r.push(this.symmetric),253===this.s2kUsage&&r.push(this.aead);const e=this.s2k.write();6===this.version&&r.push(e.length),r.push(...e)}return this.s2kUsage&&"gnu-dummy"!==this.s2k.type&&r.push(...this.iv),(5===this.version||6===this.version&&this.s2kUsage)&&t.push(new Uint8Array([r.length])),t.push(new Uint8Array(r)),this.isDummy()||(this.s2kUsage||(this.keyMaterial=Ci(this.algorithm,this.privateParams)),5===this.version&&t.push(N.writeNumber(this.keyMaterial.length,4)),t.push(this.keyMaterial),this.s2kUsage||6===this.version||t.push(N.writeChecksum(this.keyMaterial))),N.concatUint8Array(t)}isDecrypted(){return!1===this.isEncrypted}isMissingSecretKeyMaterial(){return void 0!==this.unparseableKeyMaterial||this.isDummy()}isDummy(){return!(!this.s2k||"gnu-dummy"!==this.s2k.type)}makeDummy(e=L){this.isDummy()||(this.isDecrypted()&&this.clearPrivateParams(),delete this.unparseableKeyMaterial,this.isEncrypted=null,this.keyMaterial=null,this.s2k=Fn(M.s2k.gnu,e),this.s2k.algorithm=0,this.s2k.c=0,this.s2k.type="gnu-dummy",this.s2kUsage=254,this.symmetric=M.symmetric.aes256,this.isLegacyAEAD=null,this.usedModernAEAD=null)}async encrypt(e,t=L){if(this.isDummy())return;if(!this.isDecrypted())throw Error("Key packet is already encrypted");if(!e)throw Error("A non-empty passphrase is required for key encryption.");this.s2k=Nn(t),this.s2k.generateSalt();const r=Ci(this.algorithm,this.privateParams);this.symmetric=M.symmetric.aes256;const{blockSize:i}=Pr(this.symmetric);if(t.aeadProtect){this.s2kUsage=253,this.aead=t.preferredAEADAlgorithm;const n=Un(this.aead);this.isLegacyAEAD=5===this.version,this.usedModernAEAD=!this.isLegacyAEAD;const s=rt(this.constructor.tag),a=await da(this.version,this.s2k,e,this.symmetric,this.aead,s,this.isLegacyAEAD,t),o=await n(this.symmetric,a);this.iv=this.isLegacyAEAD?ge(i):ge(n.ivLength);const c=this.isLegacyAEAD?new Uint8Array:N.concatUint8Array([s,this.writePublicKey()]);this.keyMaterial=await o.encrypt(r,this.iv.subarray(0,n.ivLength),c)}else{this.s2kUsage=254,this.usedModernAEAD=!1;const n=await da(this.version,this.s2k,e,this.symmetric,void 0,void 0,void 0,t);this.iv=ge(i),this.keyMaterial=await Hi(this.symmetric,n,N.concatUint8Array([r,await Me(M.hash.sha1,r)]),this.iv)}}async decrypt(e,t=L){if(this.isDummy())return!1;if(this.unparseableKeyMaterial)throw Error("Key packet cannot be decrypted: unsupported S2K or cipher algo");if(this.isDecrypted())throw Error("Key packet is already decrypted.");let r;const i=rt(this.constructor.tag);if(254!==this.s2kUsage&&253!==this.s2kUsage)throw 255===this.s2kUsage?Error("Encrypted private key is authenticated using an insecure two-byte hash"):Error("Private key is encrypted using an insecure S2K function: unsalted MD5");let n;if(r=await da(this.version,this.s2k,e,this.symmetric,this.aead,i,this.isLegacyAEAD,t),253===this.s2kUsage){const e=Un(this.aead,!0),t=await e(this.symmetric,r);try{const r=this.isLegacyAEAD?new Uint8Array:N.concatUint8Array([i,this.writePublicKey()]);n=await t.decrypt(this.keyMaterial,this.iv.subarray(0,e.ivLength),r)}catch(e){if("Authentication tag mismatch"===e.message)throw Error("Incorrect key passphrase: "+e.message);throw e}}else{const e=await Gi(this.symmetric,r,this.keyMaterial,this.iv);n=e.subarray(0,-20);const t=await Me(M.hash.sha1,n);if(!N.equalsUint8Array(t,e.subarray(-20)))throw Error("Incorrect key passphrase")}try{const{privateParams:e}=Ii(this.algorithm,n,this.publicParams);this.privateParams=e}catch{throw Error("Error reading MPIs")}this.isEncrypted=!1,this.keyMaterial=null,this.s2kUsage=0,this.aead=null,this.symmetric=null,this.isLegacyAEAD=null}async validate(){if(this.isDummy())return;if(!this.isDecrypted())throw Error("Key is not decrypted");if(this.usedModernAEAD)return;let e;try{e=await Ti(this.algorithm,this.publicParams,this.privateParams)}catch{e=!1}if(!e)throw Error("Key is invalid")}async generate(e,t){if(6===this.version&&(this.algorithm===M.publicKey.ecdh&&t===M.curve.curve25519Legacy||this.algorithm===M.publicKey.eddsaLegacy))throw Error(`Cannot generate v6 keys of type 'ecc' with curve ${t}. Generate a key of type 'curve25519' instead`);const{privateParams:r,publicParams:i}=await Bi(this.algorithm,e,t);this.privateParams=r,this.publicParams=i,this.isEncrypted=!1}clearPrivateParams(){this.isMissingSecretKeyMaterial()||(Object.keys(this.privateParams).forEach((e=>{this.privateParams[e].fill(0),delete this.privateParams[e]})),this.privateParams=null,this.isEncrypted=!0)}}async function da(e,t,r,i,n,s,a,o){if("argon2"===t.type&&!n)throw Error("Using Argon2 S2K without AEAD is not allowed");if("simple"===t.type&&6===e)throw Error("Using Simple S2K with version 6 keys is not allowed");const{keySize:c}=Pr(i),u=await t.produceKey(r,c,o);if(!n||5===e||a)return u;const h=N.concatUint8Array([s,new Uint8Array([e,i,n])]);return Ir(M.hash.sha256,u,new Uint8Array,h,c)}class fa{static get tag(){return M.packet.userID}constructor(){this.userID="",this.name="",this.email="",this.comment=""}static fromObject(e){if(N.isString(e)||e.name&&!N.isString(e.name)||e.email&&!N.isEmailAddress(e.email)||e.comment&&!N.isString(e.comment))throw Error("Invalid user ID format");const t=new fa;Object.assign(t,e);const r=[];return t.name&&r.push(t.name),t.comment&&r.push(`(${t.comment})`),t.email&&r.push(`<${t.email}>`),t.userID=r.join(" "),t}read(e,t=L){const r=N.decodeUTF8(e);if(r.length>t.maxUserIDLength)throw Error("User ID string is too long");const i=e=>/^[^\s@]+@[^\s@]+$/.test(e),n=r.indexOf("<"),s=r.lastIndexOf(">");if(-1!==n&&-1!==s&&s>n){const e=r.substring(n+1,s);if(i(e)){this.email=e;const t=r.substring(0,n).trim(),i=t.indexOf("("),s=t.lastIndexOf(")");-1!==i&&-1!==s&&s>i?(this.comment=t.substring(i+1,s).trim(),this.name=t.substring(0,i).trim()):(this.name=t,this.comment="")}}else i(r.trim())&&(this.email=r.trim(),this.name="",this.comment="");this.userID=r}write(){return N.encodeUTF8(this.userID)}equals(e){return e&&e.userID===this.userID}}class ma extends ga{static get tag(){return M.packet.secretSubkey}constructor(e=new Date,t=L){super(e,t)}}class wa{static get tag(){return M.packet.trust}read(){throw new at("Trust packets are not supported")}write(){throw new at("Trust packets are not supported")}}class ba{static get tag(){return M.packet.padding}constructor(){this.padding=null}read(e){}write(){return this.padding}async createPadding(e){this.padding=ge(e)}}const ka=/*#__PURE__*/N.constructAllowedPackets([Ns]);class va{constructor(e){this.packets=e||new Hs}write(){return this.packets.write()}armor(e=L){const t=this.packets.some((e=>e.constructor.tag===Ns.tag&&6!==e.version));return J(M.armor.signature,this.write(),void 0,void 0,void 0,t,e)}getSigningKeyIDs(){return this.packets.map((e=>e.issuerKeyID))}}async function Aa({armoredSignature:e,binarySignature:t,config:r,...i}){r={...L,...r};let n=e||t;if(!n)throw Error("readSignature: must pass options object containing `armoredSignature` or `binarySignature`");if(e&&!N.isString(e))throw Error("readSignature: options.armoredSignature must be a string");if(t&&!N.isUint8Array(t))throw Error("readSignature: options.binarySignature must be a Uint8Array");const s=Object.keys(i);if(s.length>0)throw Error("Unknown option: "+s.join(", "));if(e){const{type:e,data:t}=await Z(n);if(e!==M.armor.signature)throw Error("Armored text not of type signature");n=t}const a=await Hs.fromBinary(n,ka,r);return new va(a)}async function Ka(e,t){const r=new ma(e.date,t);return r.packets=null,r.algorithm=M.write(M.publicKey,e.algorithm),await r.generate(e.rsaBits,e.curve),await r.computeFingerprintAndKeyID(),r}async function Ea(e,t){const r=new ga(e.date,t);return r.packets=null,r.algorithm=M.write(M.publicKey,e.algorithm),await r.generate(e.rsaBits,e.curve,e.config),await r.computeFingerprintAndKeyID(),r}async function Sa(e,t,r,i,n=new Date,s){let a,o;for(let c=e.length-1;c>=0;c--)try{(!a||e[c].created>=a.created)&&(await e[c].verify(t,r,i,n,void 0,s),a=e[c])}catch(e){o=e}if(!a)throw N.wrapError(`Could not find valid ${M.read(M.signature,r)} signature in key ${t.getKeyID().toHex()}`.replace("certGeneric ","self-").replace(/([a-z])([A-Z])/g,((e,t,r)=>t+" "+r.toLowerCase())),o);return a}function Pa(e,t,r=new Date){const i=N.normalizeDate(r);if(null!==i){const r=Ba(e,t);return!(e.created<=i&&i<r)}return!1}async function Ua(e,t,r,i){const n={};n.key=t,n.bind=e;const s={signatureType:M.signature.subkeyBinding};r.sign?(s.keyFlags=[M.keyFlags.signData],s.embeddedSignature=await xa(n,[],e,{signatureType:M.signature.keyBinding},r.date,void 0,void 0,void 0,i)):s.keyFlags=[M.keyFlags.encryptCommunication|M.keyFlags.encryptStorage],r.keyExpirationTime>0&&(s.keyExpirationTime=r.keyExpirationTime,s.keyNeverExpires=!1);return await xa(n,[],t,s,r.date,void 0,void 0,void 0,i)}async function Da(e,t,r=new Date,i=[],n){const s=M.hash.sha256,a=n.preferredHashAlgorithm,o=await Promise.all(e.map((async(e,t)=>(await e.getPrimarySelfSignature(r,i[t],n)).preferredHashAlgorithms||[]))),c=new Map;for(const e of o)for(const t of e)try{const e=M.write(M.hash,t);c.set(e,c.has(e)?c.get(e)+1:1)}catch{}const u=t=>0===e.length||c.get(t)===e.length||t===s,h=()=>{if(0===c.size)return s;const e=Array.from(c.keys()).filter((e=>u(e))).sort(((e,t)=>Le(e)-Le(t)))[0];return Le(e)>=Le(s)?e:s};if(new Set([M.publicKey.ecdsa,M.publicKey.eddsaLegacy,M.publicKey.ed25519,M.publicKey.ed448]).has(t.algorithm)){const e=function(e,t){switch(e){case M.publicKey.ecdsa:case M.publicKey.eddsaLegacy:return Qr(t);case M.publicKey.ed25519:case M.publicKey.ed448:return dt(e);default:throw Error("Unknown elliptic signing algo")}}(t.algorithm,t.publicParams.oid),r=u(a),i=Le(a)>=Le(e);if(r&&i)return a;{const t=h();return Le(t)>=Le(e)?t:e}}return u(a)?a:h()}async function xa(e,t,r,i,n,s,a=[],o=!1,c){if(r.isDummy())throw Error("Cannot sign with a gnu-dummy key.");if(!r.isDecrypted())throw Error("Signing key is not decrypted.");const u=new Ns;return Object.assign(u,i),u.publicKeyAlgorithm=r.algorithm,u.hashAlgorithm=await Da(t,r,n,s,c),u.rawNotations=[...a],await u.sign(r,e,n,o,c),u}async function Ia(e,t,r,i=new Date,n){(e=e[r])&&(t[r].length?await Promise.all(e.map((async function(e){e.isExpired(i)||n&&!await n(e)||t[r].some((function(t){return N.equalsUint8Array(t.writeParams(),e.writeParams())}))||t[r].push(e)}))):t[r]=e)}async function Ca(e,t,r,i,n,s,a=new Date,o){s=s||e;const c=[];return await Promise.all(i.map((async function(e){try{if(!n||e.issuerKeyID.equals(n.issuerKeyID)){const i=![M.reasonForRevocation.keyRetired,M.reasonForRevocation.keySuperseded,M.reasonForRevocation.userIDInvalid].includes(e.reasonForRevocationFlag);await e.verify(s,t,r,i?null:a,!1,o),c.push(e.issuerKeyID)}}catch{}}))),n?(n.revoked=!!c.some((e=>e.equals(n.issuerKeyID)))||(n.revoked||!1),n.revoked):c.length>0}function Ba(e,t){let r;return!1===t.keyNeverExpires&&(r=e.created.getTime()+1e3*t.keyExpirationTime),r?new Date(r):1/0}function Ta(e,t={}){switch(e.type=e.type||t.type,e.curve=e.curve||t.curve,e.rsaBits=e.rsaBits||t.rsaBits,e.keyExpirationTime=void 0!==e.keyExpirationTime?e.keyExpirationTime:t.keyExpirationTime,e.passphrase=N.isString(e.passphrase)?e.passphrase:t.passphrase,e.date=e.date||t.date,e.sign=e.sign||!1,e.type){case"ecc":try{e.curve=M.write(M.curve,e.curve)}catch{throw Error("Unknown curve")}e.curve!==M.curve.ed25519Legacy&&e.curve!==M.curve.curve25519Legacy&&"ed25519"!==e.curve&&"curve25519"!==e.curve||(e.curve=e.sign?M.curve.ed25519Legacy:M.curve.curve25519Legacy),e.sign?e.algorithm=e.curve===M.curve.ed25519Legacy?M.publicKey.eddsaLegacy:M.publicKey.ecdsa:e.algorithm=M.publicKey.ecdh;break;case"curve25519":e.algorithm=e.sign?M.publicKey.ed25519:M.publicKey.x25519;break;case"curve448":e.algorithm=e.sign?M.publicKey.ed448:M.publicKey.x448;break;case"rsa":e.algorithm=M.publicKey.rsaEncryptSign;break;default:throw Error("Unsupported key type "+e.type)}return e}function Ma(e,t,r){switch(e.algorithm){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:case M.publicKey.dsa:case M.publicKey.ecdsa:case M.publicKey.eddsaLegacy:case M.publicKey.ed25519:case M.publicKey.ed448:if(!t.keyFlags&&!r.allowMissingKeyFlags)throw Error("None of the key flags is set: consider passing `config.allowMissingKeyFlags`");return!t.keyFlags||!!(t.keyFlags[0]&M.keyFlags.signData);default:return!1}}function La(e,t,r){switch(e.algorithm){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaEncrypt:case M.publicKey.elgamal:case M.publicKey.ecdh:case M.publicKey.x25519:case M.publicKey.x448:if(!t.keyFlags&&!r.allowMissingKeyFlags)throw Error("None of the key flags is set: consider passing `config.allowMissingKeyFlags`");return!t.keyFlags||!!(t.keyFlags[0]&M.keyFlags.encryptCommunication)||!!(t.keyFlags[0]&M.keyFlags.encryptStorage);default:return!1}}function Fa(e,t,r){if(!t.keyFlags&&!r.allowMissingKeyFlags)throw Error("None of the key flags is set: consider passing `config.allowMissingKeyFlags`");switch(e.algorithm){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaEncrypt:case M.publicKey.elgamal:case M.publicKey.ecdh:case M.publicKey.x25519:case M.publicKey.x448:return!(!(!t.keyFlags||!!(t.keyFlags[0]&M.keyFlags.signData))||!r.allowInsecureDecryptionWithSigningKeys)||(!t.keyFlags||!!(t.keyFlags[0]&M.keyFlags.encryptCommunication)||!!(t.keyFlags[0]&M.keyFlags.encryptStorage));default:return!1}}function Na(e,t){const r=M.write(M.publicKey,e.algorithm),i=e.getAlgorithmInfo();if(t.rejectPublicKeyAlgorithms.has(r))throw Error(i.algorithm+" keys are considered too weak.");switch(r){case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:case M.publicKey.rsaEncrypt:if(i.bits<t.minRSABits)throw Error(`RSA keys shorter than ${t.minRSABits} bits are considered too weak.`);break;case M.publicKey.ecdsa:case M.publicKey.eddsaLegacy:case M.publicKey.ecdh:if(t.rejectCurves.has(i.curve))throw Error(`Support for ${i.algorithm} keys using curve ${i.curve} is disabled.`)}}class za{constructor(e,t){this.userID=e.constructor.tag===M.packet.userID?e:null,this.userAttribute=e.constructor.tag===M.packet.userAttribute?e:null,this.selfCertifications=[],this.otherCertifications=[],this.revocationSignatures=[],this.mainKey=t}toPacketList(){const e=new Hs;return e.push(this.userID||this.userAttribute),e.push(...this.revocationSignatures),e.push(...this.selfCertifications),e.push(...this.otherCertifications),e}clone(){const e=new za(this.userID||this.userAttribute,this.mainKey);return e.selfCertifications=[...this.selfCertifications],e.otherCertifications=[...this.otherCertifications],e.revocationSignatures=[...this.revocationSignatures],e}async certify(e,t,r){const i=this.mainKey.keyPacket,n={userID:this.userID,userAttribute:this.userAttribute,key:i},s=new za(n.userID||n.userAttribute,this.mainKey);return s.otherCertifications=await Promise.all(e.map((async function(e){if(!e.isPrivate())throw Error("Need private key for signing");if(e.hasSameFingerprintAs(i))throw Error("The user's own key can only be used for self-certifications");const s=await e.getSigningKey(void 0,t,void 0,r);return xa(n,[e],s.keyPacket,{signatureType:M.signature.certGeneric,keyFlags:[M.keyFlags.certifyKeys|M.keyFlags.signData]},t,void 0,void 0,void 0,r)}))),await s.update(this,t,r),s}async isRevoked(e,t,r=new Date,i=L){const n=this.mainKey.keyPacket;return Ca(n,M.signature.certRevocation,{key:n,userID:this.userID,userAttribute:this.userAttribute},this.revocationSignatures,e,t,r,i)}async verifyCertificate(e,t,r=new Date,i){const n=this,s=this.mainKey.keyPacket,a={userID:this.userID,userAttribute:this.userAttribute,key:s},{issuerKeyID:o}=e,c=t.filter((e=>e.getKeys(o).length>0));return 0===c.length?null:(await Promise.all(c.map((async t=>{const s=await t.getSigningKey(o,e.created,void 0,i);if(e.revoked||await n.isRevoked(e,s.keyPacket,r,i))throw Error("User certificate is revoked");try{await e.verify(s.keyPacket,M.signature.certGeneric,a,r,void 0,i)}catch(e){throw N.wrapError("User certificate is invalid",e)}}))),!0)}async verifyAllCertifications(e,t=new Date,r){const i=this,n=this.selfCertifications.concat(this.otherCertifications);return Promise.all(n.map((async n=>({keyID:n.issuerKeyID,valid:await i.verifyCertificate(n,e,t,r).catch((()=>!1))}))))}async verify(e=new Date,t){if(!this.selfCertifications.length)throw Error("No self-certifications found");const r=this,i=this.mainKey.keyPacket,n={userID:this.userID,userAttribute:this.userAttribute,key:i};let s;for(let a=this.selfCertifications.length-1;a>=0;a--)try{const s=this.selfCertifications[a];if(s.revoked||await r.isRevoked(s,void 0,e,t))throw Error("Self-certification is revoked");try{await s.verify(i,M.signature.certGeneric,n,e,void 0,t)}catch(e){throw N.wrapError("Self-certification is invalid",e)}return!0}catch(e){s=e}throw s}async update(e,t,r){const i=this.mainKey.keyPacket,n={userID:this.userID,userAttribute:this.userAttribute,key:i};await Ia(e,this,"selfCertifications",t,(async function(e){try{return await e.verify(i,M.signature.certGeneric,n,t,!1,r),!0}catch{return!1}})),await Ia(e,this,"otherCertifications",t),await Ia(e,this,"revocationSignatures",t,(function(e){return Ca(i,M.signature.certRevocation,n,[e],void 0,void 0,t,r)}))}async revoke(e,{flag:t=M.reasonForRevocation.noReason,string:r=""}={},i=new Date,n=L){const s={userID:this.userID,userAttribute:this.userAttribute,key:e},a=new za(s.userID||s.userAttribute,this.mainKey);return a.revocationSignatures.push(await xa(s,[],e,{signatureType:M.signature.certRevocation,reasonForRevocationFlag:M.write(M.reasonForRevocation,t),reasonForRevocationString:r},i,void 0,void 0,!1,n)),await a.update(this),a}}class Ra{constructor(e,t){this.keyPacket=e,this.bindingSignatures=[],this.revocationSignatures=[],this.mainKey=t}toPacketList(){const e=new Hs;return e.push(this.keyPacket),e.push(...this.revocationSignatures),e.push(...this.bindingSignatures),e}clone(){const e=new Ra(this.keyPacket,this.mainKey);return e.bindingSignatures=[...this.bindingSignatures],e.revocationSignatures=[...this.revocationSignatures],e}async isRevoked(e,t,r=new Date,i=L){const n=this.mainKey.keyPacket;return Ca(n,M.signature.subkeyRevocation,{key:n,bind:this.keyPacket},this.revocationSignatures,e,t,r,i)}async verify(e=new Date,t=L){const r=this.mainKey.keyPacket,i={key:r,bind:this.keyPacket},n=await Sa(this.bindingSignatures,r,M.signature.subkeyBinding,i,e,t);if(n.revoked||await this.isRevoked(n,null,e,t))throw Error("Subkey is revoked");if(Pa(this.keyPacket,n,e))throw Error("Subkey is expired");return n}async getExpirationTime(e=new Date,t=L){const r=this.mainKey.keyPacket,i={key:r,bind:this.keyPacket};let n;try{n=await Sa(this.bindingSignatures,r,M.signature.subkeyBinding,i,e,t)}catch{return null}const s=Ba(this.keyPacket,n),a=n.getExpirationTime();return s<a?s:a}async update(e,t=new Date,r=L){const i=this.mainKey.keyPacket;if(!this.hasSameFingerprintAs(e))throw Error("Subkey update method: fingerprints of subkeys not equal");this.keyPacket.constructor.tag===M.packet.publicSubkey&&e.keyPacket.constructor.tag===M.packet.secretSubkey&&(this.keyPacket=e.keyPacket);const n=this,s={key:i,bind:n.keyPacket};await Ia(e,this,"bindingSignatures",t,(async function(e){for(let t=0;t<n.bindingSignatures.length;t++)if(n.bindingSignatures[t].issuerKeyID.equals(e.issuerKeyID))return e.created>n.bindingSignatures[t].created&&(n.bindingSignatures[t]=e),!1;try{return await e.verify(i,M.signature.subkeyBinding,s,t,void 0,r),!0}catch{return!1}})),await Ia(e,this,"revocationSignatures",t,(function(e){return Ca(i,M.signature.subkeyRevocation,s,[e],void 0,void 0,t,r)}))}async revoke(e,{flag:t=M.reasonForRevocation.noReason,string:r=""}={},i=new Date,n=L){const s={key:e,bind:this.keyPacket},a=new Ra(this.keyPacket,this.mainKey);return a.revocationSignatures.push(await xa(s,[],e,{signatureType:M.signature.subkeyRevocation,reasonForRevocationFlag:M.write(M.reasonForRevocation,t),reasonForRevocationString:r},i,void 0,void 0,!1,n)),await a.update(this),a}hasSameFingerprintAs(e){return this.keyPacket.hasSameFingerprintAs(e.keyPacket||e)}}["getKeyID","getFingerprint","getAlgorithmInfo","getCreationTime","isDecrypted"].forEach((e=>{Ra.prototype[e]=function(){return this.keyPacket[e]()}}));const Oa=/*#__PURE__*/N.constructAllowedPackets([Ns]),ja=new Set([M.packet.publicKey,M.packet.secretKey]),Ha=new Set([M.packet.publicKey,M.packet.secretKey,M.packet.publicSubkey,M.packet.secretSubkey]);class Ga{packetListToStructure(e,t=new Set){let r,i,n,s;for(const a of e){if(a instanceof ut){Ha.has(a.tag)&&!s&&(s=ja.has(a.tag)?ja:Ha);continue}const e=a.constructor.tag;if(s){if(!s.has(e))continue;s=null}if(t.has(e))throw Error("Unexpected packet type: "+e);switch(e){case M.packet.publicKey:case M.packet.secretKey:if(this.keyPacket)throw Error("Key block contains multiple keys");if(this.keyPacket=a,i=this.getKeyID(),!i)throw Error("Missing Key ID");break;case M.packet.userID:case M.packet.userAttribute:r=new za(a,this),this.users.push(r);break;case M.packet.publicSubkey:case M.packet.secretSubkey:r=null,n=new Ra(a,this),this.subkeys.push(n);break;case M.packet.signature:switch(a.signatureType){case M.signature.certGeneric:case M.signature.certPersona:case M.signature.certCasual:case M.signature.certPositive:if(!r){N.printDebug("Dropping certification signatures without preceding user packet");continue}a.issuerKeyID.equals(i)?r.selfCertifications.push(a):r.otherCertifications.push(a);break;case M.signature.certRevocation:r?r.revocationSignatures.push(a):this.directSignatures.push(a);break;case M.signature.key:this.directSignatures.push(a);break;case M.signature.subkeyBinding:if(!n){N.printDebug("Dropping subkey binding signature without preceding subkey packet");continue}n.bindingSignatures.push(a);break;case M.signature.keyRevocation:this.revocationSignatures.push(a);break;case M.signature.subkeyRevocation:if(!n){N.printDebug("Dropping subkey revocation signature without preceding subkey packet");continue}n.revocationSignatures.push(a)}}}}toPacketList(){const e=new Hs;return e.push(this.keyPacket),e.push(...this.revocationSignatures),e.push(...this.directSignatures),this.users.map((t=>e.push(...t.toPacketList()))),this.subkeys.map((t=>e.push(...t.toPacketList()))),e}clone(e=!1){const t=new this.constructor(this.toPacketList());return e&&t.getKeys().forEach((e=>{if(e.keyPacket=Object.create(Object.getPrototypeOf(e.keyPacket),Object.getOwnPropertyDescriptors(e.keyPacket)),!e.keyPacket.isDecrypted())return;const t={};Object.keys(e.keyPacket.privateParams).forEach((r=>{t[r]=new Uint8Array(e.keyPacket.privateParams[r])})),e.keyPacket.privateParams=t})),t}getSubkeys(e=null){return this.subkeys.filter((t=>!e||t.getKeyID().equals(e,!0)))}getKeys(e=null){const t=[];return e&&!this.getKeyID().equals(e,!0)||t.push(this),t.concat(this.getSubkeys(e))}getKeyIDs(){return this.getKeys().map((e=>e.getKeyID()))}getUserIDs(){return this.users.map((e=>e.userID?e.userID.userID:null)).filter((e=>null!==e))}write(){return this.toPacketList().write()}async getSigningKey(e=null,t=new Date,r={},i=L){await this.verifyPrimaryKey(t,r,i);const n=this.keyPacket;try{Na(n,i)}catch(e){throw N.wrapError("Could not verify primary key",e)}const s=this.subkeys.slice().sort(((e,t)=>t.keyPacket.created-e.keyPacket.created||t.keyPacket.algorithm-e.keyPacket.algorithm));let a;for(const r of s)if(!e||r.getKeyID().equals(e))try{await r.verify(t,i);const e={key:n,bind:r.keyPacket},s=await Sa(r.bindingSignatures,n,M.signature.subkeyBinding,e,t,i);if(!Ma(r.keyPacket,s,i))continue;if(!s.embeddedSignature)throw Error("Missing embedded signature");return await Sa([s.embeddedSignature],r.keyPacket,M.signature.keyBinding,e,t,i),Na(r.keyPacket,i),r}catch(e){a=e}try{const s=await this.getPrimarySelfSignature(t,r,i);if((!e||n.getKeyID().equals(e))&&Ma(n,s,i))return Na(n,i),this}catch(e){a=e}throw N.wrapError("Could not find valid signing key packet in key "+this.getKeyID().toHex(),a)}async getEncryptionKey(e,t=new Date,r={},i=L){await this.verifyPrimaryKey(t,r,i);const n=this.keyPacket;try{Na(n,i)}catch(e){throw N.wrapError("Could not verify primary key",e)}const s=this.subkeys.slice().sort(((e,t)=>t.keyPacket.created-e.keyPacket.created||t.keyPacket.algorithm-e.keyPacket.algorithm));let a;for(const r of s)if(!e||r.getKeyID().equals(e))try{await r.verify(t,i);const e={key:n,bind:r.keyPacket},s=await Sa(r.bindingSignatures,n,M.signature.subkeyBinding,e,t,i);if(La(r.keyPacket,s,i))return Na(r.keyPacket,i),r}catch(e){a=e}try{const s=await this.getPrimarySelfSignature(t,r,i);if((!e||n.getKeyID().equals(e))&&La(n,s,i))return Na(n,i),this}catch(e){a=e}throw N.wrapError("Could not find valid encryption key packet in key "+this.getKeyID().toHex(),a)}async isRevoked(e,t,r=new Date,i=L){return Ca(this.keyPacket,M.signature.keyRevocation,{key:this.keyPacket},this.revocationSignatures,e,t,r,i)}async verifyPrimaryKey(e=new Date,t={},r=L){const i=this.keyPacket;if(await this.isRevoked(null,null,e,r))throw Error("Primary key is revoked");if(Pa(i,await this.getPrimarySelfSignature(e,t,r),e))throw Error("Primary key is expired");if(6!==i.version){const t=await Sa(this.directSignatures,i,M.signature.key,{key:i},e,r).catch((()=>{}));if(t&&Pa(i,t,e))throw Error("Primary key is expired")}}async getExpirationTime(e,t=L){let r;try{const i=await this.getPrimarySelfSignature(null,e,t),n=Ba(this.keyPacket,i),s=i.getExpirationTime(),a=6!==this.keyPacket.version&&await Sa(this.directSignatures,this.keyPacket,M.signature.key,{key:this.keyPacket},null,t).catch((()=>{}));if(a){const e=Ba(this.keyPacket,a);r=Math.min(n,s,e)}else r=n<s?n:s}catch{r=null}return N.normalizeDate(r)}async getPrimarySelfSignature(e=new Date,t={},r=L){const i=this.keyPacket;if(6===i.version)return Sa(this.directSignatures,i,M.signature.key,{key:i},e,r);const{selfCertification:n}=await this.getPrimaryUser(e,t,r);return n}async getPrimaryUser(e=new Date,t={},r=L){const i=this.keyPacket,n=[];let s;for(let a=0;a<this.users.length;a++)try{const s=this.users[a];if(!s.userID)continue;if(void 0!==t.name&&s.userID.name!==t.name||void 0!==t.email&&s.userID.email!==t.email||void 0!==t.comment&&s.userID.comment!==t.comment)throw Error("Could not find user that matches that user ID");const o={userID:s.userID,key:i},c=await Sa(s.selfCertifications,i,M.signature.certGeneric,o,e,r);n.push({index:a,user:s,selfCertification:c})}catch(e){s=e}if(!n.length)throw s||Error("Could not find primary user");await Promise.all(n.map((async t=>{t.selfCertification.revoked||await t.user.isRevoked(t.selfCertification,null,e,r)})));const a=n.sort((function(e,t){const r=e.selfCertification,i=t.selfCertification;return i.revoked-r.revoked||r.isPrimaryUserID-i.isPrimaryUserID||r.created-i.created})).pop(),{user:o,selfCertification:c}=a;if(c.revoked||await o.isRevoked(c,null,e,r))throw Error("Primary user is revoked");return a}async update(e,t=new Date,r=L){if(!this.hasSameFingerprintAs(e))throw Error("Primary key fingerprints must be equal to update the key");if(!this.isPrivate()&&e.isPrivate()){if(!(this.subkeys.length===e.subkeys.length&&this.subkeys.every((t=>e.subkeys.some((e=>t.hasSameFingerprintAs(e)))))))throw Error("Cannot update public key with private key if subkeys mismatch");return e.update(this,r)}const i=this.clone();return await Ia(e,i,"revocationSignatures",t,(n=>Ca(i.keyPacket,M.signature.keyRevocation,i,[n],null,e.keyPacket,t,r))),await Ia(e,i,"directSignatures",t),await Promise.all(e.users.map((async e=>{const n=i.users.filter((t=>e.userID&&e.userID.equals(t.userID)||e.userAttribute&&e.userAttribute.equals(t.userAttribute)));if(n.length>0)await Promise.all(n.map((i=>i.update(e,t,r))));else{const t=e.clone();t.mainKey=i,i.users.push(t)}}))),await Promise.all(e.subkeys.map((async e=>{const n=i.subkeys.filter((t=>t.hasSameFingerprintAs(e)));if(n.length>0)await Promise.all(n.map((i=>i.update(e,t,r))));else{const t=e.clone();t.mainKey=i,i.subkeys.push(t)}}))),i}async getRevocationCertificate(e=new Date,t=L){const r={key:this.keyPacket},i=await Sa(this.revocationSignatures,this.keyPacket,M.signature.keyRevocation,r,e,t),n=new Hs;n.push(i);const s=6!==this.keyPacket.version;return J(M.armor.publicKey,n.write(),null,null,"This is a revocation certificate",s,t)}async applyRevocationCertificate(e,t=new Date,r=L){const i=await Z(e),n=(await Hs.fromBinary(i.data,Oa,r)).findPacket(M.packet.signature);if(!n||n.signatureType!==M.signature.keyRevocation)throw Error("Could not find revocation signature packet");if(!n.issuerKeyID.equals(this.getKeyID()))throw Error("Revocation signature does not match key");try{await n.verify(this.keyPacket,M.signature.keyRevocation,{key:this.keyPacket},t,void 0,r)}catch(e){throw N.wrapError("Could not verify revocation signature",e)}const s=this.clone();return s.revocationSignatures.push(n),s}async signPrimaryUser(e,t,r,i=L){const{index:n,user:s}=await this.getPrimaryUser(t,r,i),a=await s.certify(e,t,i),o=this.clone();return o.users[n]=a,o}async signAllUsers(e,t=new Date,r=L){const i=this.clone();return i.users=await Promise.all(this.users.map((function(i){return i.certify(e,t,r)}))),i}async verifyPrimaryUser(e,t=new Date,r,i=L){const n=this.keyPacket,{user:s}=await this.getPrimaryUser(t,r,i);return e?await s.verifyAllCertifications(e,t,i):[{keyID:n.getKeyID(),valid:await s.verify(t,i).catch((()=>!1))}]}async verifyAllUsers(e,t=new Date,r=L){const i=this.keyPacket,n=[];return await Promise.all(this.users.map((async s=>{const a=e?await s.verifyAllCertifications(e,t,r):[{keyID:i.getKeyID(),valid:await s.verify(t,r).catch((()=>!1))}];n.push(...a.map((e=>({userID:s.userID?s.userID.userID:null,userAttribute:s.userAttribute,keyID:e.keyID,valid:e.valid}))))}))),n}}["getKeyID","getFingerprint","getAlgorithmInfo","getCreationTime","hasSameFingerprintAs"].forEach((e=>{Ga.prototype[e]=Ra.prototype[e]}));class qa extends Ga{constructor(e){if(super(),this.keyPacket=null,this.revocationSignatures=[],this.directSignatures=[],this.users=[],this.subkeys=[],e&&(this.packetListToStructure(e,new Set([M.packet.secretKey,M.packet.secretSubkey])),!this.keyPacket))throw Error("Invalid key: missing public-key packet")}isPrivate(){return!1}toPublic(){return this}armor(e=L){const t=6!==this.keyPacket.version;return J(M.armor.publicKey,this.toPacketList().write(),void 0,void 0,void 0,t,e)}}class _a extends qa{constructor(e){if(super(),this.packetListToStructure(e,new Set([M.packet.publicKey,M.packet.publicSubkey])),!this.keyPacket)throw Error("Invalid key: missing private-key packet")}isPrivate(){return!0}toPublic(){const e=new Hs,t=this.toPacketList();for(const r of t)switch(r.constructor.tag){case M.packet.secretKey:{const t=ca.fromSecretKeyPacket(r);e.push(t);break}case M.packet.secretSubkey:{const t=la.fromSecretSubkeyPacket(r);e.push(t);break}default:e.push(r)}return new qa(e)}armor(e=L){const t=6!==this.keyPacket.version;return J(M.armor.privateKey,this.toPacketList().write(),void 0,void 0,void 0,t,e)}async getDecryptionKeys(e,t=new Date,r={},i=L){const n=this.keyPacket,s=[];let a=null;for(let r=0;r<this.subkeys.length;r++)if(!e||this.subkeys[r].getKeyID().equals(e,!0)){if(this.subkeys[r].keyPacket.isDummy()){a=a||Error("Gnu-dummy key packets cannot be used for decryption");continue}try{const e={key:n,bind:this.subkeys[r].keyPacket},a=await Sa(this.subkeys[r].bindingSignatures,n,M.signature.subkeyBinding,e,t,i);Fa(this.subkeys[r].keyPacket,a,i)&&s.push(this.subkeys[r])}catch(e){a=e}}const o=await this.getPrimarySelfSignature(t,r,i);if(e&&!n.getKeyID().equals(e,!0)||!Fa(n,o,i)||(n.isDummy()?a=a||Error("Gnu-dummy key packets cannot be used for decryption"):s.push(this)),0===s.length)throw a||Error("No decryption key packets found");return s}isDecrypted(){return this.getKeys().some((({keyPacket:e})=>e.isDecrypted()))}async validate(e=L){if(!this.isPrivate())throw Error("Cannot validate a public key");let t;if(this.keyPacket.isDummy()){const r=await this.getSigningKey(null,null,void 0,{...e,rejectPublicKeyAlgorithms:new Set,minRSABits:0});r&&!r.keyPacket.isDummy()&&(t=r.keyPacket)}else t=this.keyPacket;if(t)return t.validate();{const e=this.getKeys();if(e.map((e=>e.keyPacket.isDummy())).every(Boolean))throw Error("Cannot validate an all-gnu-dummy key");return Promise.all(e.map((e=>e.keyPacket.validate())))}}clearPrivateParams(){this.getKeys().forEach((({keyPacket:e})=>{e.isDecrypted()&&e.clearPrivateParams()}))}async revoke({flag:e=M.reasonForRevocation.noReason,string:t=""}={},r=new Date,i=L){if(!this.isPrivate())throw Error("Need private key for revoking");const n={key:this.keyPacket},s=this.clone();return s.revocationSignatures.push(await xa(n,[],this.keyPacket,{signatureType:M.signature.keyRevocation,reasonForRevocationFlag:M.write(M.reasonForRevocation,e),reasonForRevocationString:t},r,void 0,void 0,void 0,i)),s}async addSubkey(e={}){const t={...L,...e.config};if(e.passphrase)throw Error("Subkey could not be encrypted here, please encrypt whole key");if(e.rsaBits<t.minRSABits)throw Error(`rsaBits should be at least ${t.minRSABits}, got: ${e.rsaBits}`);const r=this.keyPacket;if(r.isDummy())throw Error("Cannot add subkey to gnu-dummy primary key");if(!r.isDecrypted())throw Error("Key is not decrypted");const i=r.getAlgorithmInfo();i.type=function(e){switch(M.write(M.publicKey,e)){case M.publicKey.rsaEncrypt:case M.publicKey.rsaEncryptSign:case M.publicKey.rsaSign:case M.publicKey.dsa:return"rsa";case M.publicKey.ecdsa:case M.publicKey.eddsaLegacy:return"ecc";case M.publicKey.ed25519:return"curve25519";case M.publicKey.ed448:return"curve448";default:throw Error("Unsupported algorithm")}}(i.algorithm),i.rsaBits=i.bits||4096,i.curve=i.curve||"curve25519Legacy",e=Ta(e,i);const n=await Ka(e,{...t,v6Keys:6===this.keyPacket.version});Na(n,t);const s=await Ua(n,r,e,t),a=this.toPacketList();return a.push(n,s),new _a(a)}}const Wa=/*#__PURE__*/N.constructAllowedPackets([ca,la,ga,ma,fa,pa,Ns]);function Va(e){for(const t of e)switch(t.constructor.tag){case M.packet.secretKey:return new _a(e);case M.packet.publicKey:return new qa(e)}throw Error("No key packet found")}async function $a(e,t,r,i){r.passphrase&&await e.encrypt(r.passphrase,i),await Promise.all(t.map((async function(e,t){const n=r.subkeys[t].passphrase;n&&await e.encrypt(n,i)})));const n=new Hs;function s(e,t){return[t,...e.filter((e=>e!==t))]}function a(){const e={};e.keyFlags=[M.keyFlags.certifyKeys|M.keyFlags.signData];const t=s([M.symmetric.aes256,M.symmetric.aes128],i.preferredSymmetricAlgorithm);if(e.preferredSymmetricAlgorithms=t,i.aeadProtect){const r=s([M.aead.gcm,M.aead.eax,M.aead.ocb],i.preferredAEADAlgorithm);e.preferredCipherSuites=r.flatMap((e=>t.map((t=>[t,e]))))}return e.preferredHashAlgorithms=s([M.hash.sha512,M.hash.sha256,M.hash.sha3_512,M.hash.sha3_256],i.preferredHashAlgorithm),e.preferredCompressionAlgorithms=s([M.compression.uncompressed,M.compression.zlib,M.compression.zip],i.preferredCompressionAlgorithm),e.features=[0],e.features[0]|=M.features.modificationDetection,i.aeadProtect&&(e.features[0]|=M.features.seipdv2),r.keyExpirationTime>0&&(e.keyExpirationTime=r.keyExpirationTime,e.keyNeverExpires=!1),e}if(n.push(e),6===e.version){const t={key:e},s=a();s.signatureType=M.signature.key;const o=await xa(t,[],e,s,r.date,void 0,r.signatureNotations,void 0,i);n.push(o)}await Promise.all(r.userIDs.map((async function(t,n){const s=fa.fromObject(t),o={userID:s,key:e},c=6!==e.version?a():{};c.signatureType=M.signature.certPositive,0===n&&(c.isPrimaryUserID=!0);return{userIDPacket:s,signaturePacket:await xa(o,[],e,c,r.date,void 0,r.signatureNotations,void 0,i)}}))).then((e=>{e.forEach((({userIDPacket:e,signaturePacket:t})=>{n.push(e),n.push(t)}))})),await Promise.all(t.map((async function(t,n){const s=r.subkeys[n];return{secretSubkeyPacket:t,subkeySignaturePacket:await Ua(t,e,s,i)}}))).then((e=>{e.forEach((({secretSubkeyPacket:e,subkeySignaturePacket:t})=>{n.push(e),n.push(t)}))}));const o={key:e};return n.push(await xa(o,[],e,{signatureType:M.signature.keyRevocation,reasonForRevocationFlag:M.reasonForRevocation.noReason,reasonForRevocationString:""},r.date,void 0,void 0,void 0,i)),r.passphrase&&e.clearPrivateParams(),t.map((function(e,t){r.subkeys[t].passphrase&&e.clearPrivateParams()})),new _a(n)}async function Xa({armoredKey:e,binaryKey:t,config:r,...i}){if(r={...L,...r},!e&&!t)throw Error("readKey: must pass options object containing `armoredKey` or `binaryKey`");if(e&&!N.isString(e))throw Error("readKey: options.armoredKey must be a string");if(t&&!N.isUint8Array(t))throw Error("readKey: options.binaryKey must be a Uint8Array");const n=Object.keys(i);if(n.length>0)throw Error("Unknown option: "+n.join(", "));let s;if(e){const{type:t,data:r}=await Z(e);if(t!==M.armor.publicKey&&t!==M.armor.privateKey)throw Error("Armored text not of type key");s=r}else s=t;const a=await Hs.fromBinary(s,Wa,r),o=a.indexOfTag(M.packet.publicKey,M.packet.secretKey);if(0===o.length)throw Error("No key packet found");return Va(a.slice(o[0],o[1]))}async function Qa({armoredKey:e,binaryKey:t,config:r,...i}){if(r={...L,...r},!e&&!t)throw Error("readPrivateKey: must pass options object containing `armoredKey` or `binaryKey`");if(e&&!N.isString(e))throw Error("readPrivateKey: options.armoredKey must be a string");if(t&&!N.isUint8Array(t))throw Error("readPrivateKey: options.binaryKey must be a Uint8Array");const n=Object.keys(i);if(n.length>0)throw Error("Unknown option: "+n.join(", "));let s;if(e){const{type:t,data:r}=await Z(e);if(t!==M.armor.privateKey)throw Error("Armored text not of type private key");s=r}else s=t;const a=await Hs.fromBinary(s,Wa,r),o=a.indexOfTag(M.packet.publicKey,M.packet.secretKey);for(let e=0;e<o.length;e++){if(a[o[e]].constructor.tag===M.packet.publicKey)continue;const t=a.slice(o[e],o[e+1]);return new _a(t)}throw Error("No secret key packet found")}async function Ya({armoredKeys:e,binaryKeys:t,config:r,...i}){r={...L,...r};let n=e||t;if(!n)throw Error("readKeys: must pass options object containing `armoredKeys` or `binaryKeys`");if(e&&!N.isString(e))throw Error("readKeys: options.armoredKeys must be a string");if(t&&!N.isUint8Array(t))throw Error("readKeys: options.binaryKeys must be a Uint8Array");const s=Object.keys(i);if(s.length>0)throw Error("Unknown option: "+s.join(", "));if(e){const{type:t,data:r}=await Z(e);if(t!==M.armor.publicKey&&t!==M.armor.privateKey)throw Error("Armored text not of type key");n=r}const a=[],o=await Hs.fromBinary(n,Wa,r),c=o.indexOfTag(M.packet.publicKey,M.packet.secretKey);if(0===c.length)throw Error("No key packet found");for(let e=0;e<c.length;e++){const t=Va(o.slice(c[e],c[e+1]));a.push(t)}return a}async function Za({armoredKeys:e,binaryKeys:t,config:r}){r={...L,...r};let i=e||t;if(!i)throw Error("readPrivateKeys: must pass options object containing `armoredKeys` or `binaryKeys`");if(e&&!N.isString(e))throw Error("readPrivateKeys: options.armoredKeys must be a string");if(t&&!N.isUint8Array(t))throw Error("readPrivateKeys: options.binaryKeys must be a Uint8Array");if(e){const{type:t,data:r}=await Z(e);if(t!==M.armor.privateKey)throw Error("Armored text not of type private key");i=r}const n=[],s=await Hs.fromBinary(i,Wa,r),a=s.indexOfTag(M.packet.publicKey,M.packet.secretKey);for(let e=0;e<a.length;e++){if(s[a[e]].constructor.tag===M.packet.publicKey)continue;const t=s.slice(a[e],a[e+1]),r=new _a(t);n.push(r)}if(0===n.length)throw Error("No secret key packet found");return n}const Ja=/*#__PURE__*/N.constructAllowedPackets([Bs,Vs,na,ta,ha,sa,oa,Os,Ns]),eo=/*#__PURE__*/N.constructAllowedPackets([oa]),to=/*#__PURE__*/N.constructAllowedPackets([Ns]);class ro{constructor(e){this.packets=e||new Hs}getEncryptionKeyIDs(){const e=[];return this.packets.filterByTag(M.packet.publicKeyEncryptedSessionKey).forEach((function(t){e.push(t.publicKeyID)})),e}getSigningKeyIDs(){const e=this.unwrapCompressed(),t=e.packets.filterByTag(M.packet.onePassSignature);if(t.length>0)return t.map((e=>e.issuerKeyID));return e.packets.filterByTag(M.packet.signature).map((e=>e.issuerKeyID))}async decrypt(e,t,r,i=new Date,n=L){const s=this.packets.filterByTag(M.packet.symmetricallyEncryptedData,M.packet.symEncryptedIntegrityProtectedData,M.packet.aeadEncryptedData);if(0===s.length)throw Error("No encrypted data found");const a=s[0],o=a.cipherAlgorithm,c=r||await this.decryptSessionKeys(e,t,o,i,n);let u=null;const h=Promise.all(c.map((async({algorithm:e,data:t})=>{if(!N.isUint8Array(t)||!a.cipherAlgorithm&&!N.isString(e))throw Error("Invalid session key for decryption.");try{const r=a.cipherAlgorithm||M.write(M.symmetric,e);await a.decrypt(r,t,n)}catch(e){N.printDebugError(e),u=e}})));if(x(a.encrypted),a.encrypted=null,await h,!a.packets||!a.packets.length)throw u||Error("Decryption failed.");const y=new ro(a.packets);return a.packets=new Hs,y}async decryptSessionKeys(e,t,r,i=new Date,n=L){let s,a=[];if(t){const e=this.packets.filterByTag(M.packet.symEncryptedSessionKey);if(0===e.length)throw Error("No symmetrically encrypted session key packet found.");await Promise.all(t.map((async function(t,r){let i;i=r?await Hs.fromBinary(e.write(),eo,n):e,await Promise.all(i.map((async function(e){try{await e.decrypt(t,n),a.push(e)}catch(e){N.printDebugError(e),e instanceof In&&(s=e)}})))})))}else{if(!e)throw Error("No key or password specified.");{const t=this.packets.filterByTag(M.packet.publicKeyEncryptedSessionKey);if(0===t.length)throw Error("No public key encrypted session key packet found.");await Promise.all(t.map((async function(t){await Promise.all(e.map((async function(e){let o;try{o=(await e.getDecryptionKeys(t.publicKeyID,null,void 0,n)).map((e=>e.keyPacket))}catch(e){return void(s=e)}let c=[M.symmetric.aes256,M.symmetric.aes128,M.symmetric.tripledes,M.symmetric.cast5];try{const t=await e.getPrimarySelfSignature(i,void 0,n);t.preferredSymmetricAlgorithms&&(c=c.concat(t.preferredSymmetricAlgorithms))}catch{}await Promise.all(o.map((async function(e){if(!e.isDecrypted())throw Error("Decryption key is not decrypted.");if(n.constantTimePKCS1Decryption&&(t.publicKeyAlgorithm===M.publicKey.rsaEncrypt||t.publicKeyAlgorithm===M.publicKey.rsaEncryptSign||t.publicKeyAlgorithm===M.publicKey.rsaSign||t.publicKeyAlgorithm===M.publicKey.elgamal)){const i=t.write();await Promise.all((r?[r]:Array.from(n.constantTimePKCS1DecryptionSupportedSymmetricAlgorithms)).map((async t=>{const r=new sa;r.read(i);const n={sessionKeyAlgorithm:t,sessionKey:Mi(t)};try{await r.decrypt(e,n),a.push(r)}catch(e){N.printDebugError(e),s=e}})))}else try{await t.decrypt(e);const i=r||t.sessionKeyAlgorithm;if(i&&!c.includes(M.write(M.symmetric,i)))throw Error("A non-preferred symmetric algorithm was used.");a.push(t)}catch(e){N.printDebugError(e),s=e}})))}))),x(t.encrypted),t.encrypted=null})))}}if(a.length>0){if(a.length>1){const e=new Set;a=a.filter((t=>{const r=t.sessionKeyAlgorithm+N.uint8ArrayToString(t.sessionKey);return!e.has(r)&&(e.add(r),!0)}))}return a.map((e=>({data:e.sessionKey,algorithm:e.sessionKeyAlgorithm&&M.read(M.symmetric,e.sessionKeyAlgorithm)})))}throw s||Error("Session key decryption failed.")}getLiteralData(){const e=this.unwrapCompressed().packets.findPacket(M.packet.literalData);return e&&e.getBytes()||null}getFilename(){const e=this.unwrapCompressed().packets.findPacket(M.packet.literalData);return e&&e.getFilename()||null}getText(){const e=this.unwrapCompressed().packets.findPacket(M.packet.literalData);return e?e.getText():null}static async generateSessionKey(e=[],t=new Date,r=[],i=L){const{symmetricAlgo:n,aeadAlgo:s}=await async function(e=[],t=new Date,r=[],i=L){const n=await Promise.all(e.map(((e,n)=>e.getPrimarySelfSignature(t,r[n],i))));if(e.length?n.every((e=>e.features&&e.features[0]&M.features.seipdv2)):i.aeadProtect){const e={symmetricAlgo:M.symmetric.aes128,aeadAlgo:M.aead.ocb},t=[{symmetricAlgo:i.preferredSymmetricAlgorithm,aeadAlgo:i.preferredAEADAlgorithm},{symmetricAlgo:i.preferredSymmetricAlgorithm,aeadAlgo:M.aead.ocb},{symmetricAlgo:M.symmetric.aes128,aeadAlgo:i.preferredAEADAlgorithm}];for(const e of t)if(n.every((t=>t.preferredCipherSuites&&t.preferredCipherSuites.some((t=>t[0]===e.symmetricAlgo&&t[1]===e.aeadAlgo)))))return e;return e}const s=M.symmetric.aes128,a=i.preferredSymmetricAlgorithm;return{symmetricAlgo:n.every((e=>e.preferredSymmetricAlgorithms&&e.preferredSymmetricAlgorithms.includes(a)))?a:s,aeadAlgo:void 0}}(e,t,r,i),a=M.read(M.symmetric,n),o=s?M.read(M.aead,s):void 0;await Promise.all(e.map((e=>e.getEncryptionKey().catch((()=>null)).then((e=>{if(e&&(e.keyPacket.algorithm===M.publicKey.x25519||e.keyPacket.algorithm===M.publicKey.x448)&&!o&&!N.isAES(n))throw Error("Could not generate a session key compatible with the given `encryptionKeys`: X22519 and X448 keys can only be used to encrypt AES session keys; change `config.preferredSymmetricAlgorithm` accordingly.")})))));return{data:Mi(n),algorithm:a,aeadAlgorithm:o}}async encrypt(e,t,r,i=!1,n=[],s=new Date,a=[],o=L){if(r){if(!N.isUint8Array(r.data)||!N.isString(r.algorithm))throw Error("Invalid session key for encryption.")}else if(e&&e.length)r=await ro.generateSessionKey(e,s,a,o);else{if(!t||!t.length)throw Error("No keys, passwords, or session key provided.");r=await ro.generateSessionKey(void 0,void 0,void 0,o)}const{data:c,algorithm:u,aeadAlgorithm:h}=r,y=await ro.encryptSessionKey(c,u,h,e,t,i,n,s,a,o),l=ta.fromObject({version:h?2:1,aeadAlgorithm:h?M.write(M.aead,h):null});l.packets=this.packets;const p=M.write(M.symmetric,u);return await l.encrypt(p,c,o),y.packets.push(l),l.packets=new Hs,y}static async encryptSessionKey(e,t,r,i,n,s=!1,a=[],o=new Date,c=[],u=L){const h=new Hs,y=M.write(M.symmetric,t),l=r&&M.write(M.aead,r);if(i){const t=await Promise.all(i.map((async function(t,r){const i=await t.getEncryptionKey(a[r],o,c,u),n=sa.fromObject({version:l?6:3,encryptionKeyPacket:i.keyPacket,anonymousRecipient:s,sessionKey:e,sessionKeyAlgorithm:y});return await n.encrypt(i.keyPacket),delete n.sessionKey,n})));h.push(...t)}if(n){const t=async function(e,t){try{return await e.decrypt(t,u),1}catch{return 0}},r=(e,t)=>e+t,i=async function(e,s,a,o){const c=new oa(u);if(c.sessionKey=e,c.sessionKeyAlgorithm=s,a&&(c.aeadAlgorithm=a),await c.encrypt(o,u),u.passwordCollisionCheck){if(1!==(await Promise.all(n.map((e=>t(c,e))))).reduce(r))return i(e,s,o)}return delete c.sessionKey,c},s=await Promise.all(n.map((t=>i(e,y,l,t))));h.push(...s)}return new ro(h)}async sign(e=[],t=[],r=null,i=[],n=new Date,s=[],a=[],o=[],c=L){const u=new Hs,h=this.packets.findPacket(M.packet.literalData);if(!h)throw Error("No literal data packet to sign.");const y=await io(h,e,t,r,i,n,s,a,o,!1,c),l=y.map(((e,t)=>Os.fromSignaturePacket(e,0===t))).reverse();return u.push(...l),u.push(h),u.push(...y),new ro(u)}compress(e,t=L){if(e===M.compression.uncompressed)return this;const r=new Vs(t);r.algorithm=e,r.packets=this.packets;const i=new Hs;return i.push(r),new ro(i)}async signDetached(e=[],t=[],r=null,i=[],n=new Date,s=[],a=[],o=[],c=L){const u=this.packets.findPacket(M.packet.literalData);if(!u)throw Error("No literal data packet to sign.");return new va(await io(u,e,t,r,i,n,s,a,o,!0,c))}async verify(e,t=new Date,r=L){const i=this.unwrapCompressed(),n=i.packets.filterByTag(M.packet.literalData);if(1!==n.length)throw Error("Can only verify message with one literal data packet.");let s=i.packets;a(s.stream)&&(s=s.concat(await D(s.stream,(e=>e||[]))));const o=s.filterByTag(M.packet.onePassSignature).reverse(),c=s.filterByTag(M.packet.signature);return o.length&&!c.length&&N.isStream(s.stream)&&!a(s.stream)?(await Promise.all(o.map((async e=>{e.correspondingSig=new Promise(((t,r)=>{e.correspondingSigResolve=t,e.correspondingSigReject=r})),e.signatureData=I((async()=>(await e.correspondingSig).signatureData)),e.hashed=D(await e.hash(e.signatureType,n[0],void 0,!1)),e.hashed.catch((()=>{}))}))),s.stream=A(s.stream,(async(e,t)=>{const r=C(e),i=B(t);try{for(let e=0;e<o.length;e++){const{value:t}=await r.read();o[e].correspondingSigResolve(t)}await r.readToEnd(),await i.ready,await i.close()}catch(e){o.forEach((t=>{t.correspondingSigReject(e)})),await i.abort(e)}})),no(o,n,e,t,!1,r)):no(c,n,e,t,!1,r)}async verifyDetached(e,t,r=new Date,i=L){const n=this.unwrapCompressed().packets.filterByTag(M.packet.literalData);if(1!==n.length)throw Error("Can only verify message with one literal data packet.");return no(e.packets.filterByTag(M.packet.signature),n,t,r,!0,i)}unwrapCompressed(){const e=this.packets.filterByTag(M.packet.compressedData);return e.length?new ro(e[0].packets):this}async appendSignature(e,t=L){await this.packets.read(N.isUint8Array(e)?e:(await Z(e)).data,to,t)}write(){return this.packets.write()}armor(e=L){const t=this.packets[this.packets.length-1],r=t.constructor.tag===ta.tag?2!==t.version:this.packets.some((e=>e.constructor.tag===Ns.tag&&6!==e.version));return J(M.armor.message,this.write(),null,null,null,r,e)}}async function io(e,t,r=[],i=null,n=[],s=new Date,a=[],o=[],c=[],u=!1,h=L){const y=new Hs,l=null===e.text?M.signature.binary:M.signature.text;if(await Promise.all(t.map((async(t,i)=>{const y=a[i];if(!t.isPrivate())throw Error("Need private key for signing");const p=await t.getSigningKey(n[i],s,y,h);return xa(e,r.length?r:[t],p.keyPacket,{signatureType:l},s,o,c,u,h)}))).then((e=>{y.push(...e)})),i){const e=i.packets.filterByTag(M.packet.signature);y.push(...e)}return y}function no(e,t,r,i=new Date,n=!1,s=L){return e.filter((e=>["text","binary"].includes(M.read(M.signature,e.signatureType)))).map((e=>function(e,t,r,i=new Date,n=!1,s=L){let a,o;for(const t of r){const r=t.getKeys(e.issuerKeyID);if(r.length>0){a=t,o=r[0];break}}const c=e instanceof Os?e.correspondingSig:e,u={keyID:e.issuerKeyID,verified:(async()=>{if(!o)throw Error("Could not find signing key with key ID "+e.issuerKeyID.toHex());await e.verify(o.keyPacket,e.signatureType,t[0],i,n,s);const r=await c;if(o.getCreationTime()>r.created)throw Error("Key is newer than the signature");try{await a.getSigningKey(o.getKeyID(),r.created,void 0,s)}catch(e){if(!s.allowInsecureVerificationWithReformattedKeys||!e.message.match(/Signature creation time is in the future/))throw e;await a.getSigningKey(o.getKeyID(),i,void 0,s)}return!0})(),signature:(async()=>{const e=await c,t=new Hs;return e&&t.push(e),new va(t)})()};return u.signature.catch((()=>{})),u.verified.catch((()=>{})),u}(e,t,r,i,n,s)))}async function so({armoredMessage:e,binaryMessage:t,config:r,...i}){r={...L,...r};let n=e||t;if(!n)throw Error("readMessage: must pass options object containing `armoredMessage` or `binaryMessage`");if(e&&!N.isString(e)&&!N.isStream(e))throw Error("readMessage: options.armoredMessage must be a string or stream");if(t&&!N.isUint8Array(t)&&!N.isStream(t))throw Error("readMessage: options.binaryMessage must be a Uint8Array or stream");const s=Object.keys(i);if(s.length>0)throw Error("Unknown option: "+s.join(", "));const a=N.isStream(n);if(e){const{type:e,data:t}=await Z(n);if(e!==M.armor.message)throw Error("Armored text not of type message");n=t}const o=await Hs.fromBinary(n,Ja,r,new _s),c=new ro(o);return c.fromStream=a,c}async function ao({text:e,binary:t,filename:r,date:i=new Date,format:n=(void 0!==e?"utf8":"binary"),...s}){const a=void 0!==e?e:t;if(void 0===a)throw Error("createMessage: must pass options object containing `text` or `binary`");if(e&&!N.isString(e)&&!N.isStream(e))throw Error("createMessage: options.text must be a string or stream");if(t&&!N.isUint8Array(t)&&!N.isStream(t))throw Error("createMessage: options.binary must be a Uint8Array or stream");const o=Object.keys(s);if(o.length>0)throw Error("Unknown option: "+o.join(", "));const c=N.isStream(a),u=new Bs(i);void 0!==e?u.setText(a,M.write(M.literal,n)):u.setBytes(a,M.write(M.literal,n)),void 0!==r&&u.setFilename(r);const h=new Hs;h.push(u);const y=new ro(h);return y.fromStream=c,y}const oo=/*#__PURE__*/N.constructAllowedPackets([Ns]);class co{constructor(e,t){if(this.text=N.removeTrailingSpaces(e).replace(/\r?\n/g,"\r\n"),t&&!(t instanceof va))throw Error("Invalid signature input");this.signature=t||new va(new Hs)}getSigningKeyIDs(){const e=[];return this.signature.packets.forEach((function(t){e.push(t.issuerKeyID)})),e}async sign(e,t=[],r=null,i=[],n=new Date,s=[],a=[],o=[],c=L){const u=new Bs;u.setText(this.text);const h=new va(await io(u,e,t,r,i,n,s,a,o,!0,c));return new co(this.text,h)}verify(e,t=new Date,r=L){const i=this.signature.packets.filterByTag(M.packet.signature),n=new Bs;return n.setText(this.text),no(i,[n],e,t,!0,r)}getText(){return this.text.replace(/\r\n/g,"\n")}armor(e=L){const t=this.signature.packets.some((e=>6!==e.version)),r={hash:t?Array.from(new Set(this.signature.packets.map((e=>M.read(M.hash,e.hashAlgorithm).toUpperCase())))).join():null,text:this.text,data:this.signature.packets.write()};return J(M.armor.signed,r,void 0,void 0,void 0,t,e)}}async function uo({cleartextMessage:e,config:t,...r}){if(t={...L,...t},!e)throw Error("readCleartextMessage: must pass options object containing `cleartextMessage`");if(!N.isString(e))throw Error("readCleartextMessage: options.cleartextMessage must be a string");const i=Object.keys(r);if(i.length>0)throw Error("Unknown option: "+i.join(", "));const n=await Z(e);if(n.type!==M.armor.signed)throw Error("No cleartext signed message.");const s=await Hs.fromBinary(n.data,oo,t);!function(e,t){const r=function(e){const r=e=>t=>e.hashAlgorithm===t;for(let i=0;i<t.length;i++)if(t[i].constructor.tag===M.packet.signature&&!e.some(r(t[i])))return!1;return!0},i=[];if(e.forEach((e=>{const t=e.match(/^Hash: (.+)$/);if(!t)throw Error('Only "Hash" header allowed in cleartext signed message');{const e=t[1].replace(/\s/g,"").split(",").map((e=>{try{return M.write(M.hash,e.toLowerCase())}catch{throw Error("Unknown hash algorithm in armor header: "+e.toLowerCase())}}));i.push(...e)}})),i.length&&!r(i))throw Error("Hash algorithm mismatch in armor header and signature")}(n.headers,s);const a=new va(s);return new co(n.text,a)}async function ho({text:e,...t}){if(!e)throw Error("createCleartextMessage: must pass options object containing `text`");if(!N.isString(e))throw Error("createCleartextMessage: options.text must be a string");const r=Object.keys(t);if(r.length>0)throw Error("Unknown option: "+r.join(", "));return new co(e)}async function yo({userIDs:e=[],passphrase:t,type:r,curve:i,rsaBits:n=4096,keyExpirationTime:s=0,date:a=new Date,subkeys:o=[{}],format:c="armored",signatureNotations:u=[],config:h,...y}){Do(h={...L,...h}),r||i?(r=r||"ecc",i=i||"curve25519Legacy"):(r=h.v6Keys?"curve25519":"ecc",i="curve25519Legacy"),e=xo(e),u=xo(u);const l=Object.keys(y);if(l.length>0)throw Error("Unknown option: "+l.join(", "));if(0===e.length&&!h.v6Keys)throw Error("UserIDs are required for V4 keys");if("rsa"===r&&n<h.minRSABits)throw Error(`rsaBits should be at least ${h.minRSABits}, got: ${n}`);const p={userIDs:e,passphrase:t,type:r,rsaBits:n,curve:i,keyExpirationTime:s,date:a,subkeys:o,signatureNotations:u};try{const{key:e,revocationCertificate:t}=await async function(e,t){e.sign=!0,(e=Ta(e)).subkeys=e.subkeys.map(((t,r)=>Ta(e.subkeys[r],e)));let r=[Ea(e,t)];r=r.concat(e.subkeys.map((e=>Ka(e,t))));const i=await Promise.all(r),n=await $a(i[0],i.slice(1),e,t),s=await n.getRevocationCertificate(e.date,t);return n.revocationSignatures=[],{key:n,revocationCertificate:s}}(p,h);return e.getKeys().forEach((({keyPacket:e})=>Na(e,h))),{privateKey:Bo(e,c,h),publicKey:Bo(e.toPublic(),c,h),revocationCertificate:t}}catch(e){throw N.wrapError("Error generating keypair",e)}}async function lo({privateKey:e,userIDs:t=[],passphrase:r,keyExpirationTime:i=0,date:n,format:s="armored",signatureNotations:a=[],config:o,...c}){Do(o={...L,...o}),t=xo(t),a=xo(a);const u=Object.keys(c);if(u.length>0)throw Error("Unknown option: "+u.join(", "));if(0===t.length&&6!==e.keyPacket.version)throw Error("UserIDs are required for V4 keys");const h={privateKey:e,userIDs:t,passphrase:r,keyExpirationTime:i,date:n,signatureNotations:a};try{const{key:e,revocationCertificate:t}=await async function(e,t){e=o(e);const{privateKey:r}=e;if(!r.isPrivate())throw Error("Cannot reformat a public key");if(r.keyPacket.isDummy())throw Error("Cannot reformat a gnu-dummy primary key");if(!r.getKeys().every((({keyPacket:e})=>e.isDecrypted())))throw Error("Key is not decrypted");const i=r.keyPacket;e.subkeys||(e.subkeys=await Promise.all(r.subkeys.map((async e=>{const r=e.keyPacket,n={key:i,bind:r},s=await Sa(e.bindingSignatures,i,M.signature.subkeyBinding,n,null,t).catch((()=>({})));return{sign:s.keyFlags&&s.keyFlags[0]&M.keyFlags.signData}}))));const n=r.subkeys.map((e=>e.keyPacket));if(e.subkeys.length!==n.length)throw Error("Number of subkey options does not match number of subkeys");e.subkeys=e.subkeys.map((t=>o(t,e)));const s=await $a(i,n,e,t),a=await s.getRevocationCertificate(e.date,t);return s.revocationSignatures=[],{key:s,revocationCertificate:a};function o(e,t={}){return e.keyExpirationTime=e.keyExpirationTime||t.keyExpirationTime,e.passphrase=N.isString(e.passphrase)?e.passphrase:t.passphrase,e.date=e.date||t.date,e}}(h,o);return{privateKey:Bo(e,s,o),publicKey:Bo(e.toPublic(),s,o),revocationCertificate:t}}catch(e){throw N.wrapError("Error reformatting keypair",e)}}async function po({key:e,revocationCertificate:t,reasonForRevocation:r,date:i=new Date,format:n="armored",config:s,...a}){Do(s={...L,...s});const o=Object.keys(a);if(o.length>0)throw Error("Unknown option: "+o.join(", "));try{const a=t?await e.applyRevocationCertificate(t,i,s):await e.revoke(r,i,s);return a.isPrivate()?{privateKey:Bo(a,n,s),publicKey:Bo(a.toPublic(),n,s)}:{privateKey:null,publicKey:Bo(a,n,s)}}catch(e){throw N.wrapError("Error revoking key",e)}}async function go({privateKey:e,passphrase:t,config:r,...i}){Do(r={...L,...r});const n=Object.keys(i);if(n.length>0)throw Error("Unknown option: "+n.join(", "));if(!e.isPrivate())throw Error("Cannot decrypt a public key");const s=e.clone(!0),a=N.isArray(t)?t:[t];try{return await Promise.all(s.getKeys().map((e=>N.anyPromise(a.map((t=>e.keyPacket.decrypt(t,r))))))),await s.validate(r),s}catch(e){throw s.clearPrivateParams(),N.wrapError("Error decrypting private key",e)}}async function fo({privateKey:e,passphrase:t,config:r,...i}){Do(r={...L,...r});const n=Object.keys(i);if(n.length>0)throw Error("Unknown option: "+n.join(", "));if(!e.isPrivate())throw Error("Cannot encrypt a public key");const s=e.clone(!0),a=s.getKeys(),o=N.isArray(t)?t:Array(a.length).fill(t);if(o.length!==a.length)throw Error("Invalid number of passphrases given for key encryption");try{return await Promise.all(a.map((async(e,t)=>{const{keyPacket:i}=e;await i.encrypt(o[t],r),i.clearPrivateParams()}))),s}catch(e){throw s.clearPrivateParams(),N.wrapError("Error encrypting private key",e)}}async function mo({message:e,encryptionKeys:t,signingKeys:r,passwords:i,sessionKey:n,format:s="armored",signature:a=null,wildcard:o=!1,signingKeyIDs:c=[],encryptionKeyIDs:u=[],date:h=new Date,signingUserIDs:y=[],encryptionUserIDs:l=[],signatureNotations:p=[],config:g,...d}){if(Do(g={...L,...g}),Eo(e),Po(s),t=xo(t),r=xo(r),i=xo(i),c=xo(c),u=xo(u),y=xo(y),l=xo(l),p=xo(p),d.detached)throw Error("The `detached` option has been removed from openpgp.encrypt, separately call openpgp.sign instead. Don't forget to remove the `privateKeys` option as well.");if(d.publicKeys)throw Error("The `publicKeys` option has been removed from openpgp.encrypt, pass `encryptionKeys` instead");if(d.privateKeys)throw Error("The `privateKeys` option has been removed from openpgp.encrypt, pass `signingKeys` instead");if(void 0!==d.armor)throw Error("The `armor` option has been removed from openpgp.encrypt, pass `format` instead.");const f=Object.keys(d);if(f.length>0)throw Error("Unknown option: "+f.join(", "));r||(r=[]);try{if((r.length||a)&&(e=await e.sign(r,t,a,c,h,y,u,p,g)),e=e.compress(await async function(e=[],t=new Date,r=[],i=L){const n=M.compression.uncompressed,s=i.preferredCompressionAlgorithm,a=await Promise.all(e.map((async function(e,n){const a=(await e.getPrimarySelfSignature(t,r[n],i)).preferredCompressionAlgorithms;return!!a&&a.indexOf(s)>=0})));return a.every(Boolean)?s:n}(t,h,l,g),g),e=await e.encrypt(t,i,n,o,u,h,l,g),"object"===s)return e;const d="armored"===s?e.armor(g):e.write();return await Io(d)}catch(e){throw N.wrapError("Error encrypting message",e)}}async function wo({message:e,decryptionKeys:t,passwords:r,sessionKeys:i,verificationKeys:n,expectSigned:s=!1,format:a="utf8",signature:o=null,date:c=new Date,config:u,...h}){if(Do(u={...L,...u}),Eo(e),n=xo(n),t=xo(t),r=xo(r),i=xo(i),h.privateKeys)throw Error("The `privateKeys` option has been removed from openpgp.decrypt, pass `decryptionKeys` instead");if(h.publicKeys)throw Error("The `publicKeys` option has been removed from openpgp.decrypt, pass `verificationKeys` instead");const y=Object.keys(h);if(y.length>0)throw Error("Unknown option: "+y.join(", "));try{const h=await e.decrypt(t,r,i,c,u);n||(n=[]);const y={};if(y.signatures=o?await h.verifyDetached(o,n,c,u):await h.verify(n,c,u),y.data="binary"===a?h.getLiteralData():h.getText(),y.filename=h.getFilename(),Co(y,e,...new Set([h,h.unwrapCompressed()])),s){if(0===n.length)throw Error("Verification keys are required to verify message signatures");if(0===y.signatures.length)throw Error("Message is not signed");y.data=f([y.data,I((async()=>(await N.anyPromise(y.signatures.map((e=>e.verified))),"binary"===a?new Uint8Array:"")))])}return y.data=await Io(y.data),y}catch(e){throw N.wrapError("Error decrypting message",e)}}async function bo({message:e,signingKeys:t,recipientKeys:r=[],format:i="armored",detached:n=!1,signingKeyIDs:s=[],date:a=new Date,signingUserIDs:o=[],recipientUserIDs:c=[],signatureNotations:u=[],config:h,...y}){if(Do(h={...L,...h}),So(e),Po(i),t=xo(t),s=xo(s),o=xo(o),r=xo(r),c=xo(c),u=xo(u),y.privateKeys)throw Error("The `privateKeys` option has been removed from openpgp.sign, pass `signingKeys` instead");if(void 0!==y.armor)throw Error("The `armor` option has been removed from openpgp.sign, pass `format` instead.");const l=Object.keys(y);if(l.length>0)throw Error("Unknown option: "+l.join(", "));if(e instanceof co&&"binary"===i)throw Error("Cannot return signed cleartext message in binary format");if(e instanceof co&&n)throw Error("Cannot detach-sign a cleartext message");if(!t||0===t.length)throw Error("No signing keys provided");try{let y;if(y=n?await e.signDetached(t,r,void 0,s,a,o,c,u,h):await e.sign(t,r,void 0,s,a,o,c,u,h),"object"===i)return y;return y="armored"===i?y.armor(h):y.write(),n&&(y=A(e.packets.write(),(async(e,t)=>{await Promise.all([m(y,t),D(e).catch((()=>{}))])}))),await Io(y)}catch(e){throw N.wrapError("Error signing message",e)}}async function ko({message:e,verificationKeys:t,expectSigned:r=!1,format:i="utf8",signature:n=null,date:s=new Date,config:a,...o}){if(Do(a={...L,...a}),So(e),t=xo(t),o.publicKeys)throw Error("The `publicKeys` option has been removed from openpgp.verify, pass `verificationKeys` instead");const c=Object.keys(o);if(c.length>0)throw Error("Unknown option: "+c.join(", "));if(e instanceof co&&"binary"===i)throw Error("Can't return cleartext message data as binary");if(e instanceof co&&n)throw Error("Can't verify detached cleartext signature");try{const o={};if(o.signatures=n?await e.verifyDetached(n,t,s,a):await e.verify(t,s,a),o.data="binary"===i?e.getLiteralData():e.getText(),e.fromStream&&!n&&Co(o,...new Set([e,e.unwrapCompressed()])),r){if(0===o.signatures.length)throw Error("Message is not signed");o.data=f([o.data,I((async()=>(await N.anyPromise(o.signatures.map((e=>e.verified))),"binary"===i?new Uint8Array:"")))])}return o.data=await Io(o.data),o}catch(e){throw N.wrapError("Error verifying signed message",e)}}async function vo({encryptionKeys:e,date:t=new Date,encryptionUserIDs:r=[],config:i,...n}){if(Do(i={...L,...i}),e=xo(e),r=xo(r),n.publicKeys)throw Error("The `publicKeys` option has been removed from openpgp.generateSessionKey, pass `encryptionKeys` instead");const s=Object.keys(n);if(s.length>0)throw Error("Unknown option: "+s.join(", "));try{return await ro.generateSessionKey(e,t,r,i)}catch(e){throw N.wrapError("Error generating session key",e)}}async function Ao({data:e,algorithm:t,aeadAlgorithm:r,encryptionKeys:i,passwords:n,format:s="armored",wildcard:a=!1,encryptionKeyIDs:o=[],date:c=new Date,encryptionUserIDs:u=[],config:h,...y}){if(Do(h={...L,...h}),function(e){if(!N.isUint8Array(e))throw Error("Parameter [data] must be of type Uint8Array")}(e),function(e,t){if(!N.isString(e))throw Error("Parameter ["+t+"] must be of type String")}(t,"algorithm"),Po(s),i=xo(i),n=xo(n),o=xo(o),u=xo(u),y.publicKeys)throw Error("The `publicKeys` option has been removed from openpgp.encryptSessionKey, pass `encryptionKeys` instead");const l=Object.keys(y);if(l.length>0)throw Error("Unknown option: "+l.join(", "));if(!(i&&0!==i.length||n&&0!==n.length))throw Error("No encryption keys or passwords provided.");try{return Bo(await ro.encryptSessionKey(e,t,r,i,n,a,o,c,u,h),s,h)}catch(e){throw N.wrapError("Error encrypting session key",e)}}async function Ko({message:e,decryptionKeys:t,passwords:r,date:i=new Date,config:n,...s}){if(Do(n={...L,...n}),Eo(e),t=xo(t),r=xo(r),s.privateKeys)throw Error("The `privateKeys` option has been removed from openpgp.decryptSessionKeys, pass `decryptionKeys` instead");const a=Object.keys(s);if(a.length>0)throw Error("Unknown option: "+a.join(", "));try{return await e.decryptSessionKeys(t,r,void 0,i,n)}catch(e){throw N.wrapError("Error decrypting session keys",e)}}function Eo(e){if(!(e instanceof ro))throw Error("Parameter [message] needs to be of type Message")}function So(e){if(!(e instanceof co||e instanceof ro))throw Error("Parameter [message] needs to be of type Message or CleartextMessage")}function Po(e){if("armored"!==e&&"binary"!==e&&"object"!==e)throw Error("Unsupported format "+e)}const Uo=Object.keys(L).length;function Do(e){const t=Object.keys(e);if(t.length!==Uo)for(const e of t)if(void 0===L[e])throw Error("Unknown config property: "+e)}function xo(e){return e&&!N.isArray(e)&&(e=[e]),e}async function Io(e){return"array"===N.isStream(e)?D(e):e}function Co(e,t,...r){e.data=A(t.packets.stream,(async(t,i)=>{await m(e.data,i,{preventClose:!0});const n=B(i);try{await D(t,(e=>e)),await Promise.all(r.map((e=>D(e.packets.stream,(e=>e))))),await n.close()}catch(e){await n.abort(e)}}))}function Bo(e,t,r){switch(t){case"object":return e;case"armored":return e.armor(r);case"binary":return e.write();default:throw Error("Unsupported format "+t)}}export{na as AEADEncryptedDataPacket,co as CleartextMessage,Vs as CompressedDataPacket,Gs as GrammarError,Bs as LiteralDataPacket,ya as MarkerPacket,ro as Message,Os as OnePassSignaturePacket,Hs as PacketList,ba as PaddingPacket,_a as PrivateKey,qa as PublicKey,sa as PublicKeyEncryptedSessionKeyPacket,ca as PublicKeyPacket,la as PublicSubkeyPacket,ga as SecretKeyPacket,ma as SecretSubkeyPacket,va as Signature,Ns as SignaturePacket,Ra as Subkey,ta as SymEncryptedIntegrityProtectedDataPacket,oa as SymEncryptedSessionKeyPacket,ha as SymmetricallyEncryptedDataPacket,wa as TrustPacket,ut as UnparseablePacket,pa as UserAttributePacket,fa as UserIDPacket,J as armor,L as config,ho as createCleartextMessage,ao as createMessage,wo as decrypt,go as decryptKey,Ko as decryptSessionKeys,mo as encrypt,fo as encryptKey,Ao as encryptSessionKey,M as enums,yo as generateKey,vo as generateSessionKey,uo as readCleartextMessage,Xa as readKey,Ya as readKeys,so as readMessage,Qa as readPrivateKey,Za as readPrivateKeys,Aa as readSignature,lo as reformatKey,po as revokeKey,bo as sign,Z as unarmor,ko as verify};
//# sourceMappingURL=openpgp.min.mjs.map